|
Plagegeister aller Art und deren Bekämpfung: _GETWINDOWINFO-TrojanerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
24.11.2013, 12:49 | #1 |
| _GETWINDOWINFO-Trojaner Hallo Leute, Heute Früh, nachdem ich den PC angeschaltet habe, hat sich interessanterweise der Internet Explorer mit dem Link: hxxp://www_getwindowinfo/ geöffnet, welcher nicht geschlossen werden kann. Interessante Anmerkung: Ich hatte am Vortag keine Downloads durchgeführt und einen Internet Explorer hatte ich auch nie. Mittlerweile hab ich gesehen, dass viele Leute dieses Problem haben, aber bei jedem die Anleitungen von den Admins anders waren. Was aber gleich blieb ist der Scan mit Farbar Recovery Scan Tool. Also hab ich mir erlaubt, das herunterzuladen und zu scanen, damit meine und eure Zeit nicht umsonst verschwendet wird. :-D Wenn wir schon dabei sind: Seit kurzem taucht immer snap.do als Startseite bei meinen Browsern auf. Daraufhin hab ich mir einen Malwarefighter geholt, und der sagt mir jedes mal, wenn ich meinen Browser schließe: Der IOBit HomePage Schutz hat verhindert, dass ihre Startseite verändert wird. Seitdem taucht es nicht mehr auf, aber blockieren ist sicherlich nicht die endgültige Lösung. Betriebssystem ist Win 7. Hier sind die Ergebnisse: FRST.txt: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2013 03 Ran by Admin (administrator) on PC on 24-11-2013 11:57:20 Running from C:\Users\Admin\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (IObit) C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe (IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Tor\tor.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Smartbar) C:\Users\Admin\AppData\Local\Smartbar\Application\SnapDo.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (BitTorrent, Inc.) C:\Program Files (x86)\BitTorrent\BitTorrent.exe (Windows Net) C:\Users\Admin\AppData\Roaming\Windows Net Data\net.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-07-03] (NVIDIA Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-06-13] (Adobe Systems Incorporated) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.) HKCU\...\Run: [Browser Infrastructure Helper] - C:\Users\Admin\AppData\Local\Smartbar\Application\SnapDo.exe [21024 2013-08-04] (Smartbar) HKCU\...\Run: [BitTorrent] - C:\Program Files (x86)\BitTorrent\BitTorrent.exe [1279384 2012-11-24] (BitTorrent, Inc.) HKCU\...\Run: [Win Update] - C:\Users\Admin\AppData\Roaming\Win Update.exe HKCU\...\Run: [DarkComet RAT] - C:\Users\Admin\Documents\DCSCMIN\IMDCSC.exe HKCU\...\Policies\Explorer: [] HKCU\...\Policies\Explorer: [DisallowRun] 1 MountPoints2: {039796ea-03da-11e2-acc2-806e6f6e6963} - D:\start.exe MountPoints2: {853f4d50-4465-11e2-9c82-001bfcfb8327} - H:\Fairlight\Installer.exe HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-09-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime HKLM-x32\...\Run: [IObit Malware Fighter] - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [1549120 2013-08-16] (IObit) Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Admin\AppData\Roaming\Windows Net Data\net.exe (Windows Net) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2B8F4B822CAECD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at HKCU\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q= HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/software/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q= SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013 SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013 SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013 SearchScopes: HKCU - F4FA9A3599F049448F02069E95A87F8C URL = hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=1A054C60DE739903&affID=119357&tsp=4985 SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013 SearchScopes: HKCU - {26681076-2DF8-44B1-900B-06D059B96AA0} URL = hxxp://search.toggle.com/?lang=en&cid=adfaa7a7&q={searchTerms} BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit) BHO: Speed Test Analysis - {310D38FE-EB4C-467C-8781-B7C2AEB7847D} - C:\Program Files (x86)\Speed Test Analysis\ScriptHost64.dll No File BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Speed Test Analysis - {310D38FE-EB4C-467C-8781-B7C2AEB7847D} - C:\Program Files (x86)\Speed Test Analysis\ScriptHost.dll No File BHO-x32: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: AccelerateTab - {48A789BF-F6D6-4930-9C8B-77855A63EDE1} - C:\Program Files (x86)\Secure Speed Dial\IE\SpeedDial.dll (Secure Speed Dial) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Utility Chest - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files (x86)\UtilityChest_49\bar\1.bin\49bar.dll No File Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {CF67755F-9265-449C-87CF-B945519E073B} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default FF DefaultSearchEngine: Web Search FF SelectedSearchEngine: Web Search FF Homepage: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013|hxxp://www.giga.de/software/ FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&installDate=27/10/2013&q= FF NewTab: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=nt&installDate=27/10/2013 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\bingp.xml FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\toggle.xml FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\Web Search.xml FF Extension: Amazon-Icon - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\amazon-icon@giga.de FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\ascsurfingprotection@iobit.com FF Extension: HDvid Codec - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\hdvc@hdvc.com FF Extension: AD Block - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\searchads@instair.net FF Extension: AccelerateTab - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\speeddial@instair.net FF Extension: Speed Test Analysis - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\speedtestanalysis@SpeedAnalysis.com FF Extension: No Name - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\staged FF Extension: WebSite Recommendation - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\WebSiteRecommendation@weliketheweb.com FF Extension: Snap.Do - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\{96e1573f-e7e4-9f36-0509-dd0e99161bc7} FF Extension: No Name - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\WTB_GLOBAL.sqlite Chrome: ======= CHR HomePage: chrome://newtab CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013" CHR DefaultSearchURL: (Web) - hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013 CHR DefaultSuggestURL: (Web) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR Extension: () - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html CHR Extension: (Speed Test Analysis) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb\1.0.0.5_1 CHR Extension: (Amazon-Icon) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg\1.0_0 CHR Extension: ( "name":"Advanced SystemCare Surfing Protection",) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0 CHR Extension: (Google Wallet) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_1 CHR HKLM-x32\...\Chrome\Extension: [kckgnnipheglejoddfhekdjpbdbinhmb] - C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis\SpeedTestAnalysis.crx CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Admin\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx ==================== Services (Whitelisted) ================= R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [878368 2013-10-25] (IObit) R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.) R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [335168 2013-04-25] (IObit) R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-10-25] (IObit) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-01-26] () S2 SecureUpdateSvc; C:\Program Files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [2472272 2013-10-23] () R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-31] () S4 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [x] S2 Update WebConnect; "C:\Program Files (x86)\WebConnect\updateWebConnect.exe" [x] S2 UtilityChest_49Service; C:\PROGRA~2\UTILIT~2\bar\1.bin\49barsvc.exe [x] S2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [x] S2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [x] ==================== Drivers (Whitelisted) ==================== R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-12] (DT Soft Ltd) S4 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] () R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34336 2013-03-26] (IObit.com) S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [67024 2013-03-12] (Fuzhou Rockchip Electronics Co,Ltd.) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] () S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [204568 2013-08-20] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-03-26] (IObit.com) S3 WinRing0_1_2_0; C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [14544 2012-08-01] (OpenLibSys.org) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-24 11:57 - 2013-11-24 11:57 - 00020033 _____ C:\Users\Admin\Downloads\FRST.txt 2013-11-24 11:56 - 2013-11-24 11:56 - 00000000 ____D C:\FRST 2013-11-24 11:14 - 2013-11-24 11:15 - 01958396 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe 2013-11-23 14:50 - 2013-11-23 14:50 - 00006310 _____ C:\Users\Admin\Downloads\Universal Unbanner v1.0_mpgh.net.rar 2013-11-23 14:47 - 2013-11-23 14:47 - 05718872 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_x64.exe 2013-11-23 13:43 - 2013-11-24 10:52 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Windows Net Data 2013-11-23 13:43 - 2013-11-23 13:43 - 00000187 _____ C:\Users\Admin\Desktop\Amazon.de.url 2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\Downloads\Fast-IP-Changer 2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\ChromeExtensions 2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Tempf72101802004da32e7f86b1d7a0eeae3 2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Temp8bed7913ae785723085e8a147597e773 2013-11-23 13:42 - 2013-11-23 13:43 - 00669952 _____ C:\Users\Admin\Downloads\Fast-IP-Changer-Setup.exe 2013-11-22 16:25 - 2013-11-22 16:25 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-11-22 16:25 - 2013-11-22 16:25 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-11-22 16:25 - 2013-11-22 16:25 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-11-22 16:25 - 2013-11-22 16:25 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-11-22 16:25 - 2013-11-22 16:25 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-11-22 16:24 - 2013-11-22 16:24 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 00023287 _____ C:\Windows\system32\nvinfo.pb 2013-11-22 16:20 - 2013-11-22 16:20 - 00002850 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Admin 2013-11-22 16:20 - 2013-11-22 16:20 - 00001141 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2013-11-22 16:19 - 2013-11-24 10:51 - 00000286 _____ C:\Windows\Tasks\Driver Booster Update.job 2013-11-22 16:19 - 2013-11-22 16:20 - 00002133 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk 2013-11-22 16:19 - 2013-11-22 16:19 - 00003220 _____ C:\Windows\System32\Tasks\Driver Booster Scan 2013-11-22 16:19 - 2013-11-22 16:19 - 00002582 _____ C:\Windows\System32\Tasks\Driver Booster Update 2013-11-22 16:19 - 2013-11-22 16:19 - 00001108 _____ C:\Users\Public\Desktop\Driver Booster.lnk 2013-11-21 20:35 - 2013-11-21 20:35 - 00278869 _____ C:\Users\Admin\Documents\Unbenannt.wma 2013-11-20 18:05 - 2013-11-20 18:05 - 00004644 _____ C:\Users\Admin\Downloads\invite.ics 2013-11-19 16:56 - 2013-11-19 16:56 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled 2013-11-17 23:49 - 2013-11-17 23:49 - 00000000 ____D C:\Users\Admin\Documents\FIFA 12 2013-11-17 23:43 - 2013-11-17 23:43 - 01699550 _____ C:\Users\Admin\Downloads\fifapadconfig.exe 2013-11-17 21:57 - 2013-11-19 20:29 - 00000000 ____D C:\Users\Admin\Documents\FIFA 13 2013-11-17 21:53 - 2013-11-17 21:53 - 00002324 _____ C:\Users\Admin\Desktop\Play FIFA 13 nosTEAM.lnk 2013-11-17 15:18 - 2013-11-17 21:53 - 00000000 ____D C:\Users\Admin\Downloads\FIFA 13 =FIFA Soccer 13= PC full game ^^nosTEAM^^ 2013-11-17 01:12 - 2013-11-17 01:12 - 00000132 _____ C:\Users\Admin\AppData\Roaming\Adobe IllExport-Filter CC - Voreinstellungen 2013-11-15 16:41 - 2013-11-15 16:42 - 58575443 _____ C:\Users\Admin\Downloads\TGN Branding Kit 2.4.zip 2013-11-14 18:51 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-14 18:51 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-14 18:51 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-14 18:51 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-14 18:51 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-14 18:51 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-14 18:51 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-14 18:51 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-14 18:51 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-14 18:51 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-14 18:51 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-14 18:51 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-14 18:51 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-14 18:51 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-14 18:51 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-14 18:51 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-14 18:51 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-14 18:51 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-14 18:51 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-14 18:51 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-14 18:51 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-14 18:07 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-14 18:07 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-14 18:07 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-14 18:06 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-14 18:06 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-14 18:06 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-14 18:06 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-14 18:06 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-14 18:06 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-14 18:06 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-14 18:06 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-14 18:06 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-14 18:06 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-14 18:06 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-14 18:06 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-14 18:06 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-14 18:06 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-14 18:06 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-14 18:06 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-14 18:06 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-14 18:06 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-14 18:06 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-14 18:06 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-14 18:06 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-12 18:20 - 2013-11-12 18:20 - 00003166 _____ C:\Windows\System32\Tasks\SmartDefrag_Startup 2013-11-12 18:20 - 2013-11-12 18:20 - 00003164 _____ C:\Windows\System32\Tasks\SmartDefragUpdate 2013-11-12 18:20 - 2013-05-22 18:49 - 00032600 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe 2013-11-12 18:16 - 2013-11-12 18:16 - 00883928 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2013-11-12 18:16 - 2013-11-12 18:16 - 00108760 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2013-11-12 18:16 - 2013-11-12 18:16 - 00074456 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll 2013-11-12 18:11 - 2013-11-12 18:11 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll 2013-11-12 18:11 - 2013-11-12 18:11 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll 2013-11-12 18:07 - 2013-11-12 18:07 - 00001177 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk 2013-11-12 18:07 - 2013-11-12 18:07 - 00001174 _____ C:\Users\Public\Desktop\Smart Defrag 2.lnk 2013-11-12 18:07 - 2013-05-22 18:49 - 00017720 _____ C:\Windows\system32\Drivers\SmartDefragDriver.sys 2013-11-12 18:00 - 2013-11-22 16:20 - 00001165 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2013-11-12 18:00 - 2013-11-22 16:18 - 00000000 ____D C:\Program Files (x86)\IObit 2013-11-12 18:00 - 2013-11-19 16:57 - 00000000 ____D C:\ProgramData\ProductData 2013-11-12 18:00 - 2013-11-19 16:57 - 00000000 ____D C:\ProgramData\IObit 2013-11-12 18:00 - 2013-11-12 18:07 - 00000000 ____D C:\Users\Admin\AppData\Roaming\IObit 2013-11-12 18:00 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} 2013-11-08 22:42 - 2013-11-23 14:43 - 00000000 ____D C:\Users\Admin\Desktop\TGN 2013-11-05 16:37 - 2013-11-05 16:38 - 00000000 ____D C:\Users\Admin\Documents\RZDB 2013-11-05 16:37 - 2013-11-05 16:37 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mursoft 2013-11-04 21:41 - 2013-11-04 21:42 - 00000000 ____D C:\Program Files (x86)\Audio Recorder Pro 2013-11-03 21:52 - 2013-11-03 21:52 - 00000000 ____D C:\Users\Admin\AppData\Local\TeknoGods_TotalKillaz.eu 2013-11-02 12:35 - 2013-11-02 12:47 - 23244493 _____ C:\Users\Admin\Documents\Media_Intro.mp4 2013-11-01 15:46 - 2013-11-01 15:57 - 03249771 _____ C:\Users\Admin\Documents\GAY.mp4 2013-11-01 12:05 - 2013-11-01 12:17 - 23113631 _____ C:\Users\Admin\Documents\Media Sergio Aktuell.mp4 2013-10-28 20:03 - 2013-10-28 20:06 - 00000600 _____ C:\Users\Admin\PUTTY.RND 2013-10-27 21:31 - 2013-10-27 21:31 - 00000000 ____D C:\Program Files (x86)\SimilarSites 2013-10-27 21:30 - 2013-10-27 21:30 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SimilarSites 2013-10-27 16:57 - 2013-11-12 18:00 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Apple Computer 2013-10-27 12:47 - 2013-10-27 12:48 - 00000000 ____D C:\Users\Admin\AppData\Local\Smartbar 2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis 2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\ProgramData\IBUpdaterService 2013-10-27 12:01 - 2013-10-27 12:01 - 00000000 ____D C:\ProgramData\Apple Computer 2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\Users\Admin\AppData\Local\Apple 2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\ProgramData\Apple 2013-10-27 11:43 - 2008-01-30 18:36 - 00090112 _____ (MindVision Software) C:\Windows\unvise32.exe 2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\REVisionEffects 2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Program Files (x86)\REVisionEffects 2013-10-26 13:44 - 2013-10-26 15:03 - 00000000 ____D C:\Users\Admin\AppData\Local\LooksBuilder 2013-10-26 12:28 - 2013-10-26 12:32 - 00000000 ____D C:\ProgramData\RedGiant 2013-10-26 12:28 - 2013-10-26 12:28 - 00003642 _____ C:\Windows\System32\Tasks\Red Giant Link 2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\ProgramData\Red Giant 2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant Link 2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant 2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\LooksBuilder 2013-10-26 12:28 - 2013-10-08 14:33 - 04890624 _____ C:\Windows\system32\LS3Renderer_x64.dll ==================== One Month Modified Files and Folders ======= 2013-11-24 11:57 - 2013-11-24 11:57 - 00020033 _____ C:\Users\Admin\Downloads\FRST.txt 2013-11-24 11:56 - 2013-11-24 11:56 - 00000000 ____D C:\FRST 2013-11-24 11:53 - 2012-11-24 21:59 - 00000000 ____D C:\Users\Admin\AppData\Roaming\BitTorrent 2013-11-24 11:52 - 2013-09-13 23:51 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype 2013-11-24 11:15 - 2013-11-24 11:14 - 01958396 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe 2013-11-24 11:01 - 2012-11-03 18:19 - 00000000 ____D C:\Users\Admin\AppData\Local\Adobe 2013-11-24 10:59 - 2013-07-27 17:49 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-24 10:59 - 2009-07-14 05:45 - 00015168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-24 10:59 - 2009-07-14 05:45 - 00015168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-24 10:56 - 2012-09-21 11:52 - 01049363 _____ C:\Windows\WindowsUpdate.log 2013-11-24 10:52 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Windows Net Data 2013-11-24 10:51 - 2013-11-22 16:19 - 00000286 _____ C:\Windows\Tasks\Driver Booster Update.job 2013-11-24 10:51 - 2013-10-18 14:30 - 00010932 _____ C:\autoupdate.log 2013-11-24 10:51 - 2013-07-27 17:49 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-24 10:51 - 2012-10-19 22:41 - 00096332 _____ C:\Windows\PFRO.log 2013-11-24 10:51 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-24 10:51 - 2009-07-14 05:51 - 00093444 _____ C:\Windows\setupact.log 2013-11-23 14:50 - 2013-11-23 14:50 - 00006310 _____ C:\Users\Admin\Downloads\Universal Unbanner v1.0_mpgh.net.rar 2013-11-23 14:47 - 2013-11-23 14:47 - 05718872 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_x64.exe 2013-11-23 14:43 - 2013-11-08 22:42 - 00000000 ____D C:\Users\Admin\Desktop\TGN 2013-11-23 13:43 - 2013-11-23 13:43 - 00000187 _____ C:\Users\Admin\Desktop\Amazon.de.url 2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\Downloads\Fast-IP-Changer 2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\ChromeExtensions 2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Tempf72101802004da32e7f86b1d7a0eeae3 2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Temp8bed7913ae785723085e8a147597e773 2013-11-23 13:43 - 2013-11-23 13:42 - 00669952 _____ C:\Users\Admin\Downloads\Fast-IP-Changer-Setup.exe 2013-11-23 13:43 - 2012-09-21 11:56 - 00000000 ___RD C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-23 13:43 - 2012-09-21 11:56 - 00000000 ____D C:\Users\Admin 2013-11-22 16:30 - 2013-07-08 10:23 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-22 16:25 - 2013-11-22 16:25 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-11-22 16:25 - 2013-11-22 16:25 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-11-22 16:25 - 2013-11-22 16:25 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-11-22 16:25 - 2013-11-22 16:25 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-11-22 16:25 - 2013-11-22 16:25 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-11-22 16:25 - 2009-07-13 22:59 - 18286416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-11-22 16:24 - 2013-11-22 16:24 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-11-22 16:24 - 2013-11-22 16:24 - 00023287 _____ C:\Windows\system32\nvinfo.pb 2013-11-22 16:24 - 2013-07-08 10:22 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-11-22 16:24 - 2013-07-08 10:22 - 02695200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-11-22 16:24 - 2009-06-10 21:37 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-11-22 16:20 - 2013-11-22 16:20 - 00002850 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Admin 2013-11-22 16:20 - 2013-11-22 16:20 - 00001141 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2013-11-22 16:20 - 2013-11-22 16:19 - 00002133 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk 2013-11-22 16:20 - 2013-11-12 18:00 - 00001165 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2013-11-22 16:19 - 2013-11-22 16:19 - 00003220 _____ C:\Windows\System32\Tasks\Driver Booster Scan 2013-11-22 16:19 - 2013-11-22 16:19 - 00002582 _____ C:\Windows\System32\Tasks\Driver Booster Update 2013-11-22 16:19 - 2013-11-22 16:19 - 00001108 _____ C:\Users\Public\Desktop\Driver Booster.lnk 2013-11-22 16:18 - 2013-11-12 18:00 - 00000000 ____D C:\Program Files (x86)\IObit 2013-11-21 20:35 - 2013-11-21 20:35 - 00278869 _____ C:\Users\Admin\Documents\Unbenannt.wma 2013-11-21 20:34 - 2012-09-21 11:56 - 00000000 ____D C:\Users\Admin\AppData\Local\VirtualStore 2013-11-20 22:08 - 2013-09-15 19:07 - 00000000 ____D C:\Users\Admin\AppData\Local\Windows Live 2013-11-20 18:29 - 2013-09-21 22:27 - 00000000 ____D C:\Users\Admin\AppData\Roaming\TS3Client 2013-11-20 18:05 - 2013-11-20 18:05 - 00004644 _____ C:\Users\Admin\Downloads\invite.ics 2013-11-19 20:52 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-19 20:29 - 2013-11-17 21:57 - 00000000 ____D C:\Users\Admin\Documents\FIFA 13 2013-11-19 16:59 - 2013-10-22 15:26 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-11-19 16:58 - 2012-10-19 20:17 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Adobe 2013-11-19 16:57 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\ProductData 2013-11-19 16:57 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\IObit 2013-11-19 16:56 - 2013-11-19 16:56 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled 2013-11-17 23:49 - 2013-11-17 23:49 - 00000000 ____D C:\Users\Admin\Documents\FIFA 12 2013-11-17 23:43 - 2013-11-17 23:43 - 01699550 _____ C:\Users\Admin\Downloads\fifapadconfig.exe 2013-11-17 21:53 - 2013-11-17 21:53 - 00002324 _____ C:\Users\Admin\Desktop\Play FIFA 13 nosTEAM.lnk 2013-11-17 21:53 - 2013-11-17 15:18 - 00000000 ____D C:\Users\Admin\Downloads\FIFA 13 =FIFA Soccer 13= PC full game ^^nosTEAM^^ 2013-11-17 20:07 - 2013-09-03 22:23 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-17 13:33 - 2009-07-14 18:58 - 00696620 _____ C:\Windows\system32\perfh007.dat 2013-11-17 13:33 - 2009-07-14 18:58 - 00147916 _____ C:\Windows\system32\perfc007.dat 2013-11-17 13:33 - 2009-07-14 06:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-17 02:00 - 2013-10-22 17:40 - 00000132 _____ C:\Users\Admin\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen 2013-11-17 01:12 - 2013-11-17 01:12 - 00000132 _____ C:\Users\Admin\AppData\Roaming\Adobe IllExport-Filter CC - Voreinstellungen 2013-11-15 16:42 - 2013-11-15 16:41 - 58575443 _____ C:\Users\Admin\Downloads\TGN Branding Kit 2.4.zip 2013-11-15 16:40 - 2013-10-21 15:41 - 00000000 ____D C:\Windows\system32\MRT 2013-11-14 18:51 - 2012-12-20 23:52 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-14 18:48 - 2013-10-21 15:41 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-12 18:20 - 2013-11-12 18:20 - 00003166 _____ C:\Windows\System32\Tasks\SmartDefrag_Startup 2013-11-12 18:20 - 2013-11-12 18:20 - 00003164 _____ C:\Windows\System32\Tasks\SmartDefragUpdate 2013-11-12 18:16 - 2013-11-12 18:16 - 00883928 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2013-11-12 18:16 - 2013-11-12 18:16 - 00108760 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2013-11-12 18:16 - 2013-11-12 18:16 - 00074456 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll 2013-11-12 18:13 - 2012-12-06 20:48 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-11-12 18:11 - 2013-11-12 18:11 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll 2013-11-12 18:11 - 2013-11-12 18:11 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll 2013-11-12 18:07 - 2013-11-12 18:07 - 00001177 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk 2013-11-12 18:07 - 2013-11-12 18:07 - 00001174 _____ C:\Users\Public\Desktop\Smart Defrag 2.lnk 2013-11-12 18:07 - 2013-11-12 18:00 - 00000000 ____D C:\Users\Admin\AppData\Roaming\IObit 2013-11-12 18:00 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} 2013-11-12 18:00 - 2013-10-27 16:57 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Apple Computer 2013-11-11 05:50 - 2012-10-19 20:14 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-06 22:11 - 2013-03-10 11:57 - 00000000 ____D C:\Users\Admin\Downloads\cod mw3 2013-11-05 21:00 - 2013-10-06 18:47 - 00000000 ____D C:\Users\Admin\Documents\Bandicam 2013-11-05 16:38 - 2013-11-05 16:37 - 00000000 ____D C:\Users\Admin\Documents\RZDB 2013-11-05 16:37 - 2013-11-05 16:37 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mursoft 2013-11-05 16:07 - 2013-09-13 23:51 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-05 16:07 - 2013-09-13 23:51 - 00000000 ____D C:\ProgramData\Skype 2013-11-04 21:42 - 2013-11-04 21:41 - 00000000 ____D C:\Program Files (x86)\Audio Recorder Pro 2013-11-04 00:33 - 2013-09-27 19:08 - 00000000 ____D C:\Users\Admin\AppData\Local\fabi.me 2013-11-03 21:52 - 2013-11-03 21:52 - 00000000 ____D C:\Users\Admin\AppData\Local\TeknoGods_TotalKillaz.eu 2013-11-02 12:47 - 2013-11-02 12:35 - 23244493 _____ C:\Users\Admin\Documents\Media_Intro.mp4 2013-11-01 15:57 - 2013-11-01 15:46 - 03249771 _____ C:\Users\Admin\Documents\GAY.mp4 2013-11-01 12:17 - 2013-11-01 12:05 - 23113631 _____ C:\Users\Admin\Documents\Media Sergio Aktuell.mp4 2013-10-28 20:06 - 2013-10-28 20:03 - 00000600 _____ C:\Users\Admin\PUTTY.RND 2013-10-28 16:15 - 2013-10-17 19:18 - 00000000 ____D C:\Program Files (x86)\Secure Speed Dial 2013-10-27 21:31 - 2013-10-27 21:31 - 00000000 ____D C:\Program Files (x86)\SimilarSites 2013-10-27 21:30 - 2013-10-27 21:30 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SimilarSites 2013-10-27 12:48 - 2013-10-27 12:47 - 00000000 ____D C:\Users\Admin\AppData\Local\Smartbar 2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis 2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\ProgramData\IBUpdaterService 2013-10-27 12:45 - 2013-10-22 17:20 - 00000000 ____D C:\Users\Admin\AppData\Roaming\OpenCandy 2013-10-27 12:45 - 2013-10-22 17:20 - 00000000 ____D C:\Users\Admin\AppData\Roaming\DVDVideoSoft 2013-10-27 12:01 - 2013-10-27 12:01 - 00000000 ____D C:\ProgramData\Apple Computer 2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\Users\Admin\AppData\Local\Apple 2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\ProgramData\Apple 2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\REVisionEffects 2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Program Files (x86)\REVisionEffects 2013-10-26 15:03 - 2013-10-26 13:44 - 00000000 ____D C:\Users\Admin\AppData\Local\LooksBuilder 2013-10-26 12:32 - 2013-10-26 12:28 - 00000000 ____D C:\ProgramData\RedGiant 2013-10-26 12:32 - 2012-11-17 19:11 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-10-26 12:30 - 2013-02-03 10:27 - 00000000 ____D C:\Users\Admin\AppData\Local\Downloaded Installations 2013-10-26 12:28 - 2013-10-26 12:28 - 00003642 _____ C:\Windows\System32\Tasks\Red Giant Link 2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\ProgramData\Red Giant 2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant Link 2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant 2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\LooksBuilder Files to move or delete: ==================== C:\Users\Admin\jagex_cl_loginapplet_LIVE.dat C:\Users\Admin\jagex_cl_oldschool_LIVE.dat C:\Users\Admin\jagex_cl_runescape_LIVE.dat C:\Users\Admin\jagex_cl_runescape_LIVE1.dat C:\Users\Admin\jagex_cl_runescape_LIVE2.dat C:\Users\Admin\jagex_cl_runescape_LIVE3.dat C:\Users\Admin\random.dat Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\2qywsnv1.dll C:\Users\Admin\AppData\Local\Temp\amazonicon_v3.exe C:\Users\Admin\AppData\Local\Temp\amazoninstallernircmdc.exe C:\Users\Admin\AppData\Local\Temp\bdfilters.dll C:\Users\Admin\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\Admin\AppData\Local\Temp\install_helper.exe C:\Users\Admin\AppData\Local\Temp\jna1421531977279418979.dll C:\Users\Admin\AppData\Local\Temp\jna2667399310951771970.dll C:\Users\Admin\AppData\Local\Temp\jna51258232191993720.dll C:\Users\Admin\AppData\Local\Temp\NGMDll.dll C:\Users\Admin\AppData\Local\Temp\NGMResource.dll C:\Users\Admin\AppData\Local\Temp\NGMSetup.exe C:\Users\Admin\AppData\Local\Temp\ose00000.exe C:\Users\Admin\AppData\Local\Temp\Quarantine.exe C:\Users\Admin\AppData\Local\Temp\S63GJTpcBQ.exe C:\Users\Admin\AppData\Local\Temp\sdanircmdc.exe C:\Users\Admin\AppData\Local\Temp\sdapskill.exe C:\Users\Admin\AppData\Local\Temp\setup_fsu_cid.exe C:\Users\Admin\AppData\Local\Temp\SimilarBundleGenericDl.exe C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe C:\Users\Admin\AppData\Local\Temp\SmartbarExeInstaller.exe C:\Users\Admin\AppData\Local\Temp\SpeedTestSetup.exe C:\Users\Admin\AppData\Local\Temp\unicows.dll C:\Users\Admin\AppData\Local\Temp\uninst1.exe C:\Users\Admin\AppData\Local\Temp\Uninstaller-3788.exe C:\Users\Admin\AppData\Local\Temp\w0chwtqt.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-21 07:19 ==================== End Of Log ============================ Und Addition.txt: Code:
ATTFilter Ran by Admin at 2013-11-24 12:12:12 Running from C:\Users\Admin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D} ==================== Installed Programs ====================== AccelerateTab (x32 Version: 1.4) Adobe Creative Cloud (x32 Version: 2.1.2.232) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Photoshop CC (x32 Version: 14.0) Adobe Premiere Pro CC (x32 Version: 7.0.0) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) Adobe Shockwave Player 12.0 (x32 Version: 12.0.3.133) Advanced SystemCare 7 (x32 Version: 7.0.6) Akamai NetSession Interface (HKCU) Apple Application Support (x32 Version: 2.1.5) Apple Software Update (x32 Version: 2.1.3.127) Audio Recorder Pro 3.70 (x32) AutoCAD 2013 - Deutsch (German) (Version: 19.0.55.0) AutoCAD 2013 Language Pack - Deutsch (German) (Version: 19.0.55.0) Autodesk Content Service (x32 Version: 3.0.84.0) Autodesk Content Service Language Pack (x32 Version: 3.0.84.0) Autodesk Material Library 2013 (x32 Version: 3.0.13) Autodesk Material Library Base Resolution Image Library 2013 (x32 Version: 3.0.13) Autodesk Sync (Version: 3.5.24.0) Bandicam (x32) Bandisoft MPEG-1 Decoder (x32) BitTorrent (x32 Version: 7.7.2.28499) Color Suite v11.0.1 (x32 Version: 11.0.1) D3DX10 (x32 Version: 15.4.2368.0902) DAEMON Tools Lite (x32 Version: 4.46.1.0327) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition Driver Booster (x32 Version: 1.0) Effects Suite 64-bit (Version: 11.1.0) Effects Suite 64-bit (x32 Version: 11.1.0) FARO LS 1.1.406.58 (x32 Version: 4.6.58.2) Fotogalerie (x32 Version: 16.4.3508.0205) Free YouTube Download version 3.2.14.1022 (x32 Version: 3.2.14.1022) Free YouTube to MP3 Converter version 3.12.13.925 (x32 Version: 3.12.13.925) Google Chrome (x32 Version: 31.0.1650.57) Google Earth Plug-in (x32 Version: 7.1.1.1888) Google Update Helper (x32 Version: 1.3.21.165) HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (Version: 25.0.571.0) HP Deskjet 3050A J611 series Hilfe (x32 Version: 140.0.2.2) HP Update (x32 Version: 5.003.000.004) IObit Malware Fighter (x32 Version: 2.1) IObit Uninstaller (x32 Version: 3.0.4.1082) Java 7 Update 9 (x32 Version: 7.0.90) Java Auto Updater (x32 Version: 2.1.9.0) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft .NET Framework 4 Extended (Version: 4.0.30320) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Excel 2010 (Version: 14.0.6029.1000) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Excel 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared 32-bit MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Word 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft PowerPoint 2010 (Version: 14.0.6029.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Word 2010 (Version: 14.0.6029.1000) Movie Maker (x32 Version: 16.4.3508.0205) Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1) Mozilla Maintenance Service (x32 Version: 23.0.1) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT Redists (Version: 1.0) MSVCRT110 (x32 Version: 16.4.1108.0727) MSVCRT110_amd64 (Version: 16.4.1109.0912) MyFreeCodec (HKCU) Nexon Game Manager (x32) NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49) NVIDIA GeForce Experience 1.5.1 (Version: 1.5.1) NVIDIA Install Application (Version: 2.1002.133.889) NVIDIA PhysX (x32 Version: 9.13.0604) NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604) NVIDIA Systemsteuerung 331.65 (Version: 331.65) NVIDIA Update 6.4.23 (Version: 6.4.23) NVIDIA Update Components (Version: 6.4.23) PDF Settings CC (x32 Version: 12.0) Photo Common (x32 Version: 16.4.3508.0205) Photo Gallery (x32 Version: 16.4.3508.0205) PunkBuster Services (x32 Version: 0.993) QuickTime (x32 Version: 7.71.80.42) Razer Game Booster (x32 Version: 3.7) Red Giant Link (x32 Version: 1.7.19.0) ReelSmart Motion Blur 4, After Effects-compatible plugin set (x32) RuckZuck (x32 Version: 6.0.10) Samsung Kies (x32 Version: 2.6.0.13091_9) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0) Skype™ 6.10 (x32 Version: 6.10.104) Smart Defrag 2 (x32 Version: 2.9) Snap.Do (x32 Version: 1.102.1.11691) Speed Test Analysis (x32 Version: 1.0.0.5) Surfing Protection (x32 Version: 1.0) Sweet Home 3D version 3.7 (x32) swMSM (x32 Version: 12.0.0.1) System Requirements Lab CYRI (x32 Version: 5.0.6.0) TeamSpeak 3 Client (Version: 3.0.12) Twixtor 5, After Effects-compatible plugin set (x32) Twixtor 6, After Effects-compatible plugin set (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition Update for Microsoft Word 2010 (KB2827323) 64-Bit Edition Utility Chest Internet Explorer Toolbar (x32) Windows Live Communications Platform (x32 Version: 16.4.3508.0205) Windows Live Essentials (x32 Version: 16.4.3508.0205) Windows Live ID Sign-in Assistant (Version: 7.250.4311.0) Windows Live Installer (x32 Version: 16.4.3508.0205) Windows Live Photo Common (x32 Version: 16.4.3508.0205) Windows Live PIMT Platform (x32 Version: 16.4.3508.0205) Windows Live SOXE (x32 Version: 16.4.3508.0205) Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205) Windows Live UX Platform (x32 Version: 16.4.3508.0205) Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205) Windows Utils (x32) WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0) WinZipper (x32 Version: 1.4.8) ==================== Restore Points ========================= 14-11-2013 17:47:26 Windows Update 19-11-2013 15:52:51 Windows Update 22-11-2013 15:23:43 Driver Booster : NVIDIA GeForce 8800 GTS ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {135AE771-2D3B-462E-8F30-CE5D99E1CCC4} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {1ECDF9E5-1736-47FA-9F68-D17777C66F26} - System32\Tasks\Red Giant Link => C:\Program Files (x86)\Red Giant Link\Red Giant Link.exe [2013-10-10] () Task: {32E25F8E-1749-45A9-9721-9794EB156E14} - System32\Tasks\SmartDefragUpdate => C:\Program Files (x86)\IObit\Smart Defrag 2\AutoUpdate.exe [2013-05-22] (IObit) Task: {4AA883C5-A4D9-4094-937C-E3D07281461C} - System32\Tasks\ASC7_SkipUac_Admin => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe [2013-11-14] (IObit) Task: {5C452C96-E65D-4030-B3C1-A20719FA7A7D} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2013-09-08] (IObit) Task: {6D939925-0559-4FFF-983F-100C4B9510E2} - System32\Tasks\Razer_Game_Booster_AutoUpdate => C:\Program Files (x86)\Razer\Razer Game Booster\AutoUpdate.exe [2013-06-05] () Task: {71D4CCA7-7AE8-4EAB-B078-AC718607E749} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03] (Sun Microsystems, Inc.) Task: {89659F6B-903E-4AE9-8638-3F6299D0CCB4} - \CPU Grid Computing No Task File Task: {8D5768D7-0BF7-4B7E-B4EF-2B533AF729A3} - System32\Tasks\SmartDefrag_Startup => C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe [2013-09-13] (IObit) Task: {8DE526A6-E0DE-4613-B213-435FFB35B8F7} - \The Bluetooth service discovery No Task File Task: {A327627E-50BC-4181-AFB4-661E3EB00912} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [2011-03-24] (Hewlett-Packard) Task: {A72FE025-AA38-40EE-BCF7-ABC9A84C4852} - \AdobeFlashPlayerUpdate 2 No Task File Task: {A7B37A96-087C-4BC9-BCE0-469A9FAABD66} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2013-09-08] (IObit) Task: {AC6C9BFE-6D97-4EC4-8BCA-482E1FF41A1C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-27] (Google Inc.) Task: {AE193498-0C1E-4429-9017-6CC81CA63ACA} - System32\Tasks\AdobeAAMUpdater-1.0-PC-Admin => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2013-06-13] (Adobe Systems Incorporated) Task: {C37565D0-014E-47D4-83EA-4411ED708EF9} - System32\Tasks\hpUrlLauncher.exe_{F897C458-ADC9-403E-BBD9-FF9E01A0A29F} => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\utils\hpUrlLauncher.exe [2011-06-08] (Hewlett-Packard Co.) Task: {DB0FF65C-8F09-4C52-BAEC-0FAD6A5A706C} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe Task: {E35029B4-73DE-4341-8C43-FFAADAF0D4FB} - \AdobeFlashPlayerUpdate No Task File Task: {E389FFAE-9FD5-4610-BB82-17FA20CF858E} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {E4D749A2-89E1-4257-81F6-3F4FBE02D0D5} - System32\Tasks\{901D29C3-49F3-49F5-9378-C1DCB736EDE9} => C:\Users\Admin\Downloads\Xpadder.exe Task: {F1E0DC7B-D17A-4019-B6D8-0AB183F8E8E0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-27] (Google Inc.) Task: C:\Windows\Tasks\Driver Booster Update.job => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-30 09:01 - 2013-08-30 09:01 - 03358064 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll 2013-11-22 16:19 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\sqlite3.dll 2013-11-12 18:07 - 2013-09-11 19:06 - 00048960 _____ () C:\Program Files (x86)\IObit\Smart Defrag 2\NtfsData.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00032800 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00056352 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00150560 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00112672 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 01767456 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00078880 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00013344 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00726048 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00081952 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00014368 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00016928 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll 2013-08-04 19:51 - 2013-08-04 19:51 - 00020512 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll 2013-08-04 19:51 - 2013-08-04 19:51 - 00026144 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00057888 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00014368 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll 2013-07-16 13:20 - 2013-07-16 13:20 - 00911128 _____ () C:\Windows\assembly\GAC_32\System.Data.SQLite\1.0.66.0__db937bc2d44ff139\System.Data.SQLite.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00014880 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00052256 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00048160 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\MACTrackBarLib.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00026144 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll 2013-08-04 19:51 - 2013-08-04 19:51 - 00026144 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll 2013-08-04 19:41 - 2013-08-04 19:41 - 00194080 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.dll 2013-08-04 19:40 - 2013-08-04 19:40 - 00068640 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll 2013-08-04 19:50 - 2013-08-04 19:50 - 00246304 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.NetSeer.dll 2013-09-03 14:25 - 2013-09-03 14:25 - 32726528 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll 2013-03-13 12:42 - 2013-06-05 13:21 - 00071560 _____ () C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\zlib1.dll 2013-08-30 09:00 - 2013-08-30 09:00 - 00381808 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CCInvokeAAM.dll 2013-11-17 20:07 - 2013-11-14 12:28 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libglesv2.dll 2013-11-17 20:07 - 2013-11-14 12:28 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libegl.dll 2013-11-17 20:07 - 2013-11-14 12:29 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll 2013-11-17 20:07 - 2013-11-14 12:29 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll 2013-11-17 20:07 - 2013-11-14 12:28 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll 2013-11-17 20:07 - 2013-11-14 12:29 - 13582800 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:373E1720 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/18/2013 01:10:17 AM) (Source: IMFservice) (User: ) Description: Das Handle ist ungültig Error: (11/18/2013 01:10:17 AM) (Source: IMFservice) (User: ) Description: Das Handle ist ungültig Error: (11/10/2013 11:52:02 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel: 0x4f186c8f Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0xffff3fa4 ID des fehlerhaften Prozesses: 0x330 Startzeit der fehlerhaften Anwendung: 0xiw5mp.exe0 Pfad der fehlerhaften Anwendung: iw5mp.exe1 Pfad des fehlerhaften Moduls: iw5mp.exe2 Berichtskennung: iw5mp.exe3 Error: (11/10/2013 11:47:10 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel: 0x4f186c8f Name des fehlerhaften Moduls: nvd3dum.dll, Version: 9.18.13.2049, Zeitstempel: 0x51c40fa2 Ausnahmecode: 0xc0000005 Fehleroffset: 0x004af57a ID des fehlerhaften Prozesses: 0x10c0 Startzeit der fehlerhaften Anwendung: 0xiw5mp.exe0 Pfad der fehlerhaften Anwendung: iw5mp.exe1 Pfad des fehlerhaften Moduls: iw5mp.exe2 Berichtskennung: iw5mp.exe3 Error: (11/10/2013 07:02:25 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel: 0x4f186c8f Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0xffff3f80 ID des fehlerhaften Prozesses: 0x880 Startzeit der fehlerhaften Anwendung: 0xiw5mp.exe0 Pfad der fehlerhaften Anwendung: iw5mp.exe1 Pfad des fehlerhaften Moduls: iw5mp.exe2 Berichtskennung: iw5mp.exe3 Error: (11/10/2013 00:58:58 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: WoulClass.vshost.exe, Version: 11.0.50727.1, Zeitstempel: 0x5011d446 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677 Ausnahmecode: 0xe0434f4d Fehleroffset: 0x000000000000940d ID des fehlerhaften Prozesses: 0x%9 Startzeit der fehlerhaften Anwendung: 0xWoulClass.vshost.exe0 Pfad der fehlerhaften Anwendung: WoulClass.vshost.exe1 Pfad des fehlerhaften Moduls: WoulClass.vshost.exe2 Berichtskennung: WoulClass.vshost.exe3 Error: (11/10/2013 00:58:47 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: WoulClass.vshost.exe, Version: 11.0.50727.1, Zeitstempel: 0x5011d446 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677 Ausnahmecode: 0xe0434f4d Fehleroffset: 0x000000000000940d ID des fehlerhaften Prozesses: 0x%9 Startzeit der fehlerhaften Anwendung: 0xWoulClass.vshost.exe0 Pfad der fehlerhaften Anwendung: WoulClass.vshost.exe1 Pfad des fehlerhaften Moduls: WoulClass.vshost.exe2 Berichtskennung: WoulClass.vshost.exe3 Error: (11/03/2013 09:52:42 PM) (Source: Application Hang) (User: ) Description: Programm iw5mp.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 560 Startzeit: 01ced8d68fca516b Endzeit: 38 Anwendungspfad: C:\Users\Admin\Downloads\Teknogods 2.7.1.2\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exe Berichts-ID: df0dbe24-44c9-11e3-95d6-001bfcfb8327 Error: (10/28/2013 11:52:29 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (10/28/2013 11:52:29 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. System errors: ============= Error: (11/24/2013 10:53:42 AM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Error: (11/24/2013 10:52:26 AM) (Source: Service Control Manager) (User: ) Description: Dienst "SecureUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/24/2013 10:51:26 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Utility ChestService" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/24/2013 10:51:26 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Update WebConnect" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/24/2013 10:51:17 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Wsys Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/24/2013 10:51:17 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "WinZiper service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/23/2013 10:27:08 AM) (Source: Service Control Manager) (User: ) Description: Dienst "SecureUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/23/2013 10:26:08 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Utility ChestService" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/23/2013 10:26:08 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Update WebConnect" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/23/2013 10:25:59 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Wsys Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (11/18/2013 01:10:17 AM) (Source: IMFservice)(User: ) Description: Das Handle ist ungültig Error: (11/18/2013 01:10:17 AM) (Source: IMFservice)(User: ) Description: Das Handle ist ungültig Error: (11/10/2013 11:52:02 PM) (Source: Application Error)(User: ) Description: iw5mp.exe0.0.0.04f186c8funknown0.0.0.000000000c0000005ffff3fa433001cede66d2662730C:\Users\Admin\Downloads\cod mw3\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exeunknownb6270760-4a5a-11e3-9172-001bfcfb8327 Error: (11/10/2013 11:47:10 PM) (Source: Application Error)(User: ) Description: iw5mp.exe0.0.0.04f186c8fnvd3dum.dll9.18.13.204951c40fa2c0000005004af57a10c001cede6570685656C:\Users\Admin\Downloads\cod mw3\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exeC:\Windows\system32\nvd3dum.dll081bb54f-4a5a-11e3-9172-001bfcfb8327 Error: (11/10/2013 07:02:25 PM) (Source: Application Error)(User: ) Description: iw5mp.exe0.0.0.04f186c8funknown0.0.0.000000000c0000005ffff3f8088001cede3ef2a128a2C:\Users\Admin\Downloads\cod mw3\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exeunknown40a9e580-4a32-11e3-9172-001bfcfb8327 Error: (11/10/2013 00:58:58 AM) (Source: Application Error)(User: ) Description: WoulClass.vshost.exe11.0.50727.15011d446KERNELBASE.dll6.1.7601.1822951fb1677e0434f4d000000000000940d Error: (11/10/2013 00:58:47 AM) (Source: Application Error)(User: ) Description: WoulClass.vshost.exe11.0.50727.15011d446KERNELBASE.dll6.1.7601.1822951fb1677e0434f4d000000000000940d Error: (11/03/2013 09:52:42 PM) (Source: Application Hang)(User: ) Description: iw5mp.exe0.0.0.056001ced8d68fca516b38C:\Users\Admin\Downloads\Teknogods 2.7.1.2\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exedf0dbe24-44c9-11e3-95d6-001bfcfb8327 Error: (10/28/2013 11:52:29 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Admin\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe Error: (10/28/2013 11:52:29 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Users\Admin\Downloads\SoftonicDownloader_fuer_winrar.exe ==================== Memory info =========================== Percentage of memory in use: 56% Total physical RAM: 4095.18 MB Available physical RAM: 1770.45 MB Total Pagefile: 8188.54 MB Available Pagefile: 5518.29 MB Total Virtual: 8192 MB Available Virtual: 8191.78 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.99 GB) (Free:153.12 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D13C098D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
24.11.2013, 12:53 | #2 | |
/// TB-Ausbilder | _GETWINDOWINFO-TrojanerMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Zitat:
Schritt 1 Scan mit Combofix
Schritt 2 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte poste mit deiner nächsten Antwort
|
24.11.2013, 13:17 | #3 |
| _GETWINDOWINFO-Trojaner Danke für die schnelle Antwort.
__________________Eine Frage bleibt noch offen: Reicht es eine Verknüpfung der Programme auf dem Desktop zu erstellen, oder muss das ganze Programm am Desktop sein? |
24.11.2013, 13:28 | #4 | |
/// TB-Ausbilder | _GETWINDOWINFO-TrojanerZitat:
Programme direkt auf dem Desktop speichern! Ich verstehe nicht, warum Leute immer ein Problem damit haben, die Programme auf dem Desktop zu speichern, ist doch das Einfachste der Welt... Zudem entfernen wir am Ende der Bereinigung alle Tools mit einem Schlag, aber das klappt halt nur, wenn sich die Tools auf dem Desktop befinden. |
24.11.2013, 14:33 | #5 |
| _GETWINDOWINFO-Trojaner Danke für die ersten Infos Matthias. Hier kommen alle von dir angeforderten .txt Dateien. Combifix.txt Code:
ATTFilter ComboFix 13-11-23.02 - Admin 24.11.2013 13:25:32.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.43.1031.18.4095.2125 [GMT 1:00] ausgeführt von:: c:\users\Admin\Desktop\ComboFix.exe SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\protected c:\users\Admin\AppData\Roaming\dclogs c:\users\Admin\AppData\Roaming\dclogs\2013-11-10-1.dc c:\windows\SysWow64\frapsvid.dll . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_WsysSvc . . ((((((((((((((((((((((( Dateien erstellt von 2013-10-24 bis 2013-11-24 )))))))))))))))))))))))))))))) . . 2013-11-24 12:32 . 2013-11-24 12:32 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-11-24 10:56 . 2013-11-24 10:56 -------- d-----w- C:\FRST 2013-11-23 12:43 . 2013-11-24 09:52 -------- d-----w- c:\users\Admin\AppData\Roaming\Windows Net Data 2013-11-23 12:43 . 2013-11-23 12:43 -------- d-----w- c:\users\Admin\AppData\Local\Tempf72101802004da32e7f86b1d7a0eeae3 2013-11-23 12:43 . 2013-11-23 12:43 -------- d-----w- c:\users\Admin\ChromeExtensions 2013-11-23 12:43 . 2013-11-23 12:43 -------- d-----w- c:\users\Admin\AppData\Local\Temp8bed7913ae785723085e8a147597e773 2013-11-22 15:25 . 2013-11-22 15:25 15855568 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-11-22 15:25 . 2013-11-22 15:25 9480328 ----a-w- c:\windows\SysWow64\nvopencl.dll 2013-11-22 15:25 . 2013-11-22 15:25 11374520 ----a-w- c:\windows\system32\nvopencl.dll 2013-11-22 15:25 . 2013-11-22 15:25 30344480 ----a-w- c:\windows\system32\nvoglv64.dll 2013-11-22 15:25 . 2013-11-22 15:25 22933792 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2013-11-22 15:25 . 2013-11-08 03:12 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{492276FF-1DAE-4362-9D2D-D00A517BFA72}\mpengine.dll 2013-11-14 17:51 . 2013-10-12 06:35 2706432 ----a-w- c:\windows\system32\mshtml.tlb 2013-11-14 17:07 . 2013-10-05 20:25 1474048 ----a-w- c:\windows\system32\crypt32.dll 2013-11-14 17:07 . 2013-10-05 19:57 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-11-14 17:07 . 2013-09-28 01:09 497152 ----a-w- c:\windows\system32\drivers\afd.sys 2013-11-12 17:20 . 2013-05-22 17:49 32600 ----a-w- c:\windows\system32\SmartDefragBootTime.exe 2013-11-12 17:16 . 2013-11-12 17:16 883928 ----a-w- c:\windows\system32\drivers\Rt64win7.sys 2013-11-12 17:16 . 2013-11-12 17:16 74456 ----a-w- c:\windows\system32\RtNicProp64.dll 2013-11-12 17:16 . 2013-11-12 17:16 108760 ----a-w- c:\windows\system32\RTNUninst64.dll 2013-11-12 17:11 . 2013-11-12 17:11 1884448 ----a-w- c:\windows\system32\nvdispco6433158.dll 2013-11-12 17:11 . 2013-11-12 17:11 1511712 ----a-w- c:\windows\system32\nvdispgenco6433158.dll 2013-11-12 17:07 . 2013-05-22 17:49 17720 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys 2013-11-12 17:00 . 2013-11-19 15:57 -------- d-----w- c:\programdata\ProductData 2013-11-12 17:00 . 2013-11-12 17:00 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} 2013-11-12 17:00 . 2013-11-19 15:57 -------- d-----w- c:\programdata\IObit 2013-11-12 17:00 . 2013-11-12 17:07 -------- d-----w- c:\users\Admin\AppData\Roaming\IObit 2013-11-12 17:00 . 2013-11-22 15:18 -------- d-----w- c:\program files (x86)\IObit 2013-11-04 20:41 . 2013-11-04 20:42 -------- d-----w- c:\program files (x86)\Audio Recorder Pro 2013-11-03 20:52 . 2013-11-03 20:52 -------- d-----w- c:\users\Admin\AppData\Local\TeknoGods_TotalKillaz.eu 2013-10-27 20:31 . 2013-10-27 20:31 -------- d-----w- c:\program files (x86)\SimilarSites 2013-10-27 20:30 . 2013-10-27 20:30 -------- d-----w- c:\users\Admin\AppData\Roaming\SimilarSites 2013-10-27 15:57 . 2013-11-12 17:00 -------- d-----w- c:\users\Admin\AppData\Roaming\Apple Computer 2013-10-27 11:47 . 2013-10-27 11:47 -------- d-----w- c:\programdata\IBUpdaterService 2013-10-27 11:47 . 2013-10-27 11:47 -------- d-----w- c:\users\Admin\AppData\Roaming\SpeedTestAnalysis 2013-10-27 11:47 . 2013-10-27 11:48 -------- d-----w- c:\users\Admin\AppData\Local\Smartbar 2013-10-27 11:01 . 2013-10-27 11:01 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll 2013-10-27 11:01 . 2013-10-27 11:01 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll 2013-10-27 11:01 . 2013-10-27 11:01 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll 2013-10-27 11:01 . 2013-10-27 11:01 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll 2013-10-27 11:01 . 2013-10-27 11:01 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll 2013-10-27 11:01 . 2013-10-27 11:01 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll 2013-10-27 11:01 . 2013-10-27 11:01 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll 2013-10-27 11:01 . 2013-10-27 11:01 -------- d-----w- c:\programdata\Apple Computer 2013-10-27 10:59 . 2013-10-27 10:59 -------- d-----w- c:\program files (x86)\Common Files\Apple 2013-10-27 10:59 . 2013-10-27 10:59 -------- d-----w- c:\users\Admin\AppData\Local\Apple 2013-10-27 10:59 . 2013-10-27 10:59 -------- d-----w- c:\programdata\Apple 2013-10-27 10:43 . 2008-01-30 17:36 90112 ----a-w- c:\windows\unvise32.exe 2013-10-27 10:40 . 2013-10-27 10:40 -------- d-----w- c:\program files (x86)\REVisionEffects 2013-10-26 12:44 . 2013-10-26 14:03 -------- d-----w- c:\users\Admin\AppData\Local\LooksBuilder 2013-10-26 11:28 . 2013-10-26 11:28 -------- d-----w- c:\programdata\Red Giant 2013-10-26 11:28 . 2013-10-26 11:28 -------- d-----w- c:\program files (x86)\Red Giant Link 2013-10-26 11:28 . 2013-10-26 11:28 -------- d-----w- c:\program files (x86)\LooksBuilder 2013-10-26 11:28 . 2013-10-26 11:28 -------- d-----w- c:\program files (x86)\Red Giant 2013-10-26 11:28 . 2013-10-08 13:33 4890624 ----a-w- c:\windows\system32\LS3Renderer_x64.dll 2013-10-26 11:28 . 2013-10-26 11:32 -------- d-----w- c:\programdata\RedGiant . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-11-22 15:25 . 2009-07-13 21:59 18286416 ----a-w- c:\windows\system32\nvwgf2umx.dll 2013-11-22 15:24 . 2009-06-10 20:37 15212336 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2013-11-22 15:24 . 2013-07-08 09:22 3067560 ----a-w- c:\windows\system32\nvapi64.dll 2013-11-22 15:24 . 2013-07-08 09:22 2695200 ----a-w- c:\windows\SysWow64\nvapi.dll 2013-11-14 17:48 . 2013-10-21 14:41 82896128 ----a-w- c:\windows\system32\MRT.exe 2013-11-11 04:50 . 2012-10-19 19:14 267936 ------w- c:\windows\system32\MpSigStub.exe 2013-10-23 08:20 . 2013-07-08 09:23 6669600 ----a-w- c:\windows\system32\nvcpl.dll 2013-10-23 08:20 . 2013-07-08 09:23 3489568 ----a-w- c:\windows\system32\nvsvc64.dll 2013-10-23 08:20 . 2013-07-08 09:23 922912 ----a-w- c:\windows\system32\nvvsvc.exe 2013-10-23 08:20 . 2013-07-08 09:23 63776 ----a-w- c:\windows\system32\nvshext.dll 2013-10-23 08:20 . 2013-07-08 09:23 219424 ----a-w- c:\windows\system32\nvmctray.dll 2013-10-21 15:02 . 2013-10-21 15:02 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-10-21 15:02 . 2013-10-21 15:02 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-10-21 15:02 . 2013-10-21 15:02 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-10-21 15:02 . 2013-10-21 15:02 81408 ----a-w- c:\windows\system32\icardie.dll 2013-10-21 15:02 . 2013-10-21 15:02 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-10-21 15:02 . 2013-10-21 15:02 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-10-21 15:02 . 2013-10-21 15:02 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-10-21 15:02 . 2013-10-21 15:02 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-10-21 15:02 . 2013-10-21 15:02 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-10-21 15:02 . 2013-10-21 15:02 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-10-21 15:02 . 2013-10-21 15:02 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-10-21 15:02 . 2013-10-21 15:02 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-10-21 15:02 . 2013-10-21 15:02 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-10-21 15:02 . 2013-10-21 15:02 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-10-21 15:02 . 2013-10-21 15:02 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-10-21 15:02 . 2013-10-21 15:02 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-10-21 15:02 . 2013-10-21 15:02 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-10-21 15:02 . 2013-10-21 15:02 441856 ----a-w- c:\windows\system32\html.iec 2013-10-21 15:02 . 2013-10-21 15:02 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-10-21 15:02 . 2013-10-21 15:02 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-10-21 15:02 . 2013-10-21 15:02 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-10-21 15:02 . 2013-10-21 15:02 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-10-21 15:02 . 2013-10-21 15:02 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-10-21 15:02 . 2013-10-21 15:02 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-10-21 15:02 . 2013-10-21 15:02 235008 ----a-w- c:\windows\system32\url.dll 2013-10-21 15:02 . 2013-10-21 15:02 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-10-21 15:02 . 2013-10-21 15:02 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-10-21 15:02 . 2013-10-21 15:02 216064 ----a-w- c:\windows\system32\msls31.dll 2013-10-21 15:02 . 2013-10-21 15:02 197120 ----a-w- c:\windows\system32\msrating.dll 2013-10-21 15:02 . 2013-10-21 15:02 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-10-21 15:02 . 2013-10-21 15:02 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-10-21 15:02 . 2013-10-21 15:02 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-10-21 15:02 . 2013-10-21 15:02 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-10-21 15:02 . 2013-10-21 15:02 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-10-21 15:02 . 2013-10-21 15:02 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-10-21 15:02 . 2013-10-21 15:02 149504 ----a-w- c:\windows\system32\occache.dll 2013-10-21 15:02 . 2013-10-21 15:02 144896 ----a-w- c:\windows\system32\wextract.exe 2013-10-21 15:02 . 2013-10-21 15:02 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-10-21 15:02 . 2013-10-21 15:02 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-10-21 15:02 . 2013-10-21 15:02 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-10-21 15:02 . 2013-10-21 15:02 13824 ----a-w- c:\windows\system32\mshta.exe 2013-10-21 15:02 . 2013-10-21 15:02 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-10-21 15:02 . 2013-10-21 15:02 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-10-21 15:02 . 2013-10-21 15:02 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-10-21 15:02 . 2013-10-21 15:02 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-10-21 15:02 . 2013-10-21 15:02 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-10-21 15:02 . 2013-10-21 15:02 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-10-21 15:02 . 2013-10-21 15:02 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-10-21 15:02 . 2013-10-21 15:02 102912 ----a-w- c:\windows\system32\inseng.dll 2013-10-21 14:57 . 2013-10-21 14:57 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2013-10-21 14:57 . 2013-10-21 14:57 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2013-10-21 14:57 . 2013-10-21 14:57 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-10-21 14:57 . 2013-10-21 14:57 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-10-21 14:57 . 2013-10-21 14:57 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-10-21 14:57 . 2013-10-21 14:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 3928064 ----a-w- c:\windows\system32\d2d1.dll 2013-10-21 14:57 . 2013-10-21 14:57 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-10-21 14:57 . 2013-10-21 14:57 363008 ----a-w- c:\windows\system32\dxgi.dll 2013-10-21 14:57 . 2013-10-21 14:57 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2013-10-21 14:57 . 2013-10-21 14:57 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-10-21 14:57 . 2013-10-21 14:57 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 296960 ----a-w- c:\windows\system32\d3d10core.dll 2013-10-21 14:57 . 2013-10-21 14:57 293376 ----a-w- c:\windows\SysWow64\dxgi.dll 2013-10-21 14:57 . 2013-10-21 14:57 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2013-10-21 14:57 . 2013-10-21 14:57 2565120 ----a-w- c:\windows\system32\d3d10warp.dll 2013-10-21 14:57 . 2013-10-21 14:57 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-10-21 14:57 . 2013-10-21 14:57 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2013-10-21 14:57 . 2013-10-21 14:57 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2013-10-21 14:57 . 2013-10-21 14:57 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-10-21 14:57 . 2013-10-21 14:57 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2013-10-21 14:57 . 2013-10-21 14:57 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll 2013-10-21 14:57 . 2013-10-21 14:57 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll 2013-10-21 14:57 . 2013-10-21 14:57 1988096 ----a-w- c:\windows\SysWow64\d3d10warp.dll 2013-10-21 14:57 . 2013-10-21 14:57 194560 ----a-w- c:\windows\system32\d3d10_1.dll 2013-10-21 14:57 . 2013-10-21 14:57 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll 2013-10-21 14:57 . 2013-10-21 14:57 1682432 ----a-w- c:\windows\system32\XpsPrint.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}] 2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-10-21 20549280] "Browser Infrastructure Helper"="c:\users\Admin\AppData\Local\Smartbar\Application\SnapDo.exe" [2013-08-04 21024] "BitTorrent"="c:\program files (x86)\BitTorrent\BitTorrent.exe" [2012-11-24 1279384] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-09-03 2237328] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240] "IObit Malware Fighter"="c:\program files (x86)\IObit\IObit Malware Fighter\IMF.exe" [2013-08-16 1549120] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Advanced SystemCare 7"="c:\program files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" [2013-11-11 2283808] . c:\users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ net.lnk - c:\users\Admin\AppData\Roaming\Windows Net Data\net.exe [2013-11-23 709120] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice] @="Service" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Sweetpacks Communicator"=c:\program files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "HP Software Update"=c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SecureUpdateSvc;SecureUpdate;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 Update WebConnect;Update WebConnect;c:\program files (x86)\WebConnect\updateWebConnect.exe;c:\program files (x86)\WebConnect\updateWebConnect.exe [x] R2 UtilityChest_49Service;Utility ChestService;c:\progra~2\UTILIT~2\bar\1.bin\49barsvc.exe;c:\progra~2\UTILIT~2\bar\1.bin\49barsvc.exe [x] R2 winzipersvc;WinZiper service;c:\program files (x86)\WinZipper\winzipersvc.exe;c:\program files (x86)\WinZipper\winzipersvc.exe [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x] R3 Rockusb;Driver for Rockusb Device;c:\windows\system32\DRIVERS\rockusb.sys;c:\windows\SYSNATIVE\DRIVERS\rockusb.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssudserd.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [x] R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x] S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 AdvancedSystemCareService7;Advanced SystemCare Service 7;c:\program files (x86)\IObit\Advanced SystemCare 7\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [x] S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x] S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x] S2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x] S2 tor;Tor Win32 Service;c:\program files (x86)\Tor\tor.exe;c:\program files (x86)\Tor\tor.exe [x] S3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-11-17 19:02 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-11-24 c:\windows\Tasks\Driver Booster Update.job - c:\program files (x86)\IObit\Driver Booster\AutoUpdate.exe [2013-11-22 10:12] . 2013-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-27 16:49] . 2013-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-27 16:49] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}] 2013-11-22 15:20 2486592 ----a-w- c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2013-08-30 08:01 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2013-08-30 08:01 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2013-08-30 08:01 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512] "Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-03 1028896] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-06-13 472984] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013 uDefault_Search_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q= mDefault_Search_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q= mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q= mSearch Bar = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q= uCustomizeSearch = hxxp://www.google.com uSearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013 mCustomizeSearch = hxxp://www.google.com mSearchAssistant = hxxp://www.google.com IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000 Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = 10.0.0.138 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{310D38FE-EB4C-467C-8781-B7C2AEB7847D} - c:\program files (x86)\Speed Test Analysis\ScriptHost.dll Toolbar-{cf67755f-9265-449c-87cf-b945519e073b} - c:\program files (x86)\UtilityChest_49\bar\1.bin\49bar.dll Wow6432Node-HKLM-Run-QuickTime Task - c:\program files (x86)\QuickTime\QTTask.exe Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe AddRemove-Mozilla Firefox 23.0.1 (x86 de) - c:\program files (x86)\Mozilla Firefox\uninstall\helper.exe AddRemove-MozillaMaintenanceService - c:\program files (x86)\Mozilla Maintenance Service\uninstall.exe AddRemove-PunkBusterSvc - c:\ubisoft\Ghost Recon Online\PDC-Live\pbsvc_gro.exe AddRemove-Speed Test Analysis - c:\program files (x86)\Speed Test Analysis\uninst.exe AddRemove-Sweet Home 3D_is1 - c:\program files (x86)\Sweet Home 3D\unins000.exe AddRemove-WinZipper - c:\program files (x86)\WinZipper\eUninstall.exe AddRemove-MyFreeCodec - c:\program files (x86)\MyFree Codec\1.0b beta\uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,80,df,39,0f,52,40,3a,42,98,8f,03,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,80,df,39,0f,52,40,3a,42,98,8f,03,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe c:\windows\SysWOW64\PnkBstrA.exe . ************************************************************************** . Zeit der Fertigstellung: 2013-11-24 13:38:59 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-11-24 12:38 . Vor Suchlauf: 12 Verzeichnis(se), 200.647.741.440 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 216.885.616.640 Bytes frei . - - End Of File - - 957696A4995BC4BBD1FAA39476DEA6E3 A36C5E4F47E84449FF07ED3517B43A31 Adwcleaner[S1].txt Code:
ATTFilter # AdwCleaner v3.013 - Bericht erstellt am 24/11/2013 um 13:43:14 # Updated 24/11/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Admin - PC # Gestartet von : C:\Users\Admin\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : Update WebConnect [#] Dienst Gelöscht : winzipersvc ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\IBUpdaterService Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Ordner Gelöscht : C:\Program Files (x86)\SimilarSites Ordner Gelöscht : C:\Users\Admin\AppData\Local\Smartbar Ordner Gelöscht : C:\Users\Admin\AppData\LocalLow\Smartbar Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\OpenCandy Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\SimilarSites Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\Windows Net Data Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\speedtestanalysis@SpeedAnalysis.com Datei Gelöscht : C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk Datei Gelöscht : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\bingp.xml Datei Gelöscht : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\Web Search.xml Datei Gelöscht : C:\Windows\System32\Tasks\Desk 365 RunAsStdUser ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\AddonsFramework.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ButtonSite.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHost.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bho Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{19975B78-1907-4DD6-A437-4C48120F46A4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9317-C08A-444A-9482-62080DD851AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7C28CEF1-A4A6-4B6A-8B97-C44F1267753C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : HKCU\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\smartbarbackup Schlüssel Gelöscht : HKCU\Software\smartbarlog Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\Software\hdcode Schlüssel Gelöscht : HKLM\Software\Myfree Codec Schlüssel Gelöscht : HKLM\Software\winzipersvc Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winzipper Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\237AA359BFA99C94484AF769ACA080AD Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\237AA359BFA99C94484AF769ACA080AD ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16736 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default] -\\ Mozilla Firefox v23.0.1 (de) [ Datei : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\prefs.js ] Zeile gelöscht : user_pref("browser.search.defaultenginename", "Web Search"); Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search"); Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013|hxxp://www.gi[...] Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false); Zeile gelöscht : user_pref("extensions.helperbar.Visibility", true); Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "at"); Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "snapdoocyb"); Zeile gelöscht : user_pref("extensions.helperbar.installationid", "96e1573f-e7e4-9f36-0509-dd0e99161bc7"); Zeile gelöscht : user_pref("extensions.helperbar.installdate", "27/10/2013"); Zeile gelöscht : user_pref("extensions.helperbar.publisher", "snapdoocyb"); Zeile gelöscht : user_pref("extensions.searchads.insertDomains", "{\"search.snapdo.com\":1,\"superhqporn.com\":1,\"cdncache1-a.akamaihd.net\":1}"); Zeile gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&installDate=27/10/2013&q="); Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=nt&installDate=27/10/2013"); -\\ Google Chrome v31.0.1650.57 [ Datei : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : icon_url Gelöscht : search_url Gelöscht : keyword Gelöscht : urls_to_restore_on_startup ************************* AdwCleaner[R1].txt - [14294 octets] - [24/11/2013 13:42:31] AdwCleaner[S1].txt - [13028 octets] - [24/11/2013 13:43:14] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [13089 octets] ########## JRT.txt Code:
ATTFilter Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Professional x64 Ran by Admin on 24.11.2013 at 13:48:16,13 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Main\\Start Page ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{48A789BF-F6D6-4930-9C8B-77855A63EDE1} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r706-n-bf_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r706-n-bf_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r706-n-bf_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r706-n-bf_RASMANCS Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{26681076-2DF8-44B1-900B-06D059B96AA0} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48A789BF-F6D6-4930-9C8B-77855A63EDE1} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Program Files (x86)\secure speed dial" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 24.11.2013 at 14:25:54,51 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Danke schon mal für die Hilfe. |
25.11.2013, 16:12 | #6 |
/// TB-Ausbilder | _GETWINDOWINFO-Trojaner Servus, Schritt 1 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 2 Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
Bitte poste mit deiner nächsten Antwort
|
26.11.2013, 16:17 | #7 |
| _GETWINDOWINFO-Trojaner Hallo, Ich nutz mal hier die Gelegenheit um dir vielmals zu danken, da das ja eigentlich keine Selbstverständlichkeit ist, dass solche Dienstleistungen gratis angeboten werden. Was ich hier so im Forum lese, dass sich Leute nach 12 Stunden aufregen immer noch keine Antwort bekommen zu haben, ist ja eine Frechheit. Ihr könntet genauso gut Geld für die Hilfe verlangen. Also von mir kommt da denke ich eine Spende rein, auch wenn es nur ein paar Euros sein werden. Logdatei Zoek: Code:
ATTFilter Zoek.exe Version 4.0.0.5 Updated 24-November-2013 Tool run by Admin on 25.11.2013 at 19:06:19,29. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Admin\Desktop\zoek.exe [Script inserted] ==== System Restore Info ====================== 25.11.2013 19:07:20 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} deleted successfully HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{cf67755f-9265-449c-87cf-b945519e073b} deleted successfully HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{cf67755f-9265-449c-87cf-b945519e073b} deleted successfully HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{310D38FE-EB4C-467C-8781-B7C2AEB7847D} deleted successfully HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{310D38FE-EB4C-467C-8781-B7C2AEB7847D} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{cf67755f-9265-449c-87cf-b945519e073b} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{310D38FE-EB4C-467C-8781-B7C2AEB7847D} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{310D38FE-EB4C-467C-8781-B7C2AEB7847D} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{31ad400d-1b06-4e33-a59a-90c2c140cba0} deleted successfully HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{cf67755f-9265-449c-87cf-b945519e073b} deleted successfully HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{310D38FE-EB4C-467C-8781-B7C2AEB7847D} deleted successfully HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{48A789BF-F6D6-4930-9C8B-77855A63EDE1} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{cf67755f-9265-449c-87cf-b945519e073b} deleted successfully ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UtilityChest_49Service deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\UtilityChest_49Service deleted successfully ==== FireFox Fix ====================== Deleted from C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\prefs.js: user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.useDBForOrder", true); Added to C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.com"); user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.newtab.url", "hxxp://www.google.com/"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default user.js not found ---- Lines toggle removed from prefs.js ---- user_pref("extensions.toggle.admin", false); user_pref("extensions.toggle.aflt", "orgnl"); user_pref("extensions.toggle.appId", "{EE5558C0-C65E-4EF7-8C52-39632E6A21F3}"); user_pref("extensions.toggle.autoRvrt", "false"); user_pref("extensions.toggle.cid", "adfaa7a7"); user_pref("extensions.toggle.dfltLng", "en"); user_pref("extensions.toggle.dfltSrch", true); user_pref("extensions.toggle.dnsErr", true); user_pref("extensions.toggle.excTlbr", true); user_pref("extensions.toggle.ffxUnstlRst", false); user_pref("extensions.toggle.hmpg", true); user_pref("extensions.toggle.hmpgUrl", "hxxp://search.toggle.com/?lang=en&cid=adfaa7a7"); user_pref("extensions.toggle.hpOld0", "https://www.google.at/"); user_pref("extensions.toggle.id", "1a05b559000000000000001bfcfb8327"); user_pref("extensions.toggle.instlDay", "15760"); user_pref("extensions.toggle.instlRef", ""); user_pref("extensions.toggle.kw_url", "hxxp://search.toggle.com/?lang=en&cid=adfaa7a7&q="); user_pref("extensions.toggle.newTab", true); user_pref("extensions.toggle.newTabUrl", "hxxp://search.toggle.com/?lang=en&cid=adfaa7a7"); user_pref("extensions.toggle.prdct", "toggle"); user_pref("extensions.toggle.prtnrId", "toggle"); user_pref("extensions.toggle.rvrt", "true"); user_pref("extensions.toggle.smplGrp", "none"); user_pref("extensions.toggle.tlbrId", "base"); user_pref("extensions.toggle.tlbrSrchUrl", "hxxp://search.toggle.com/?lang={dfltLng}&cid={cid}&q="); user_pref("extensions.toggle.vrsn", "1.8.12.7"); user_pref("extensions.toggle.vrsni", "1.8.12.7"); user_pref("extensions.toggle.vrsnTs", "1.8.12.711:01:32"); ---- Lines speedtestanalysis removed from prefs.js ---- user_pref("extensions.speedtestanalysis@SpeedAnalysis.com.id", "\"d7b5ae02-e81b-caca-611b-8eba259e2fac\""); user_pref("extensions.speedtestanalysis@SpeedAnalysis.com.mzID", "69"); user_pref("extensions.speedtestanalysis@SpeedAnalysis.com.uuid", "\"14eb5848-4250-11e3-8099-0025901ef77c\""); ---- Lines speedtestanalysis modified from prefs.js ---- user_pref("extensions.enabledAddons", "speedtestanalysis%40SpeedAnalysis.com:1.0.0.5,speeddial%40instair.net:1.4.1,%7B96e1573f-e7e4-9f36-0509-dd0e9916 user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program ---- Lines SpeedAnalysis modified from prefs.js ---- user_pref("extensions.enabledAddons", "disabled%40SpeedAnalysis.com:1.0.0.5,speeddial%40instair.net:1.4.1,%7B96e1573f-e7e4-9f36-0509-dd0e99161bc7%7D:1 user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program ---- FireFox user.js and prefs.js backups ---- prefs__1941_.backup ==== Deleting Files \ Folders ====================== C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\speedtestanalysis@SpeedAnalysis.com not found C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\speedtestanalysis@SpeedAnalysis.com not found "C:\Windows\Installer\131f08.msi" not found C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} deleted C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} deleted C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted C:\Users\Admin\ChromeExtensions deleted C:\User Data\Default\Extensions deleted C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis deleted C:\Users\Admin\AppData\Local\avgchrome deleted C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx deleted C:\user.js deleted C:\Windows\Launcher.exe deleted C:\Windows\SysWow64\searchplugins deleted C:\Windows\SysWow64\Extensions deleted C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\jetpack deleted C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\staged deleted "C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\toggle.xml" deleted ==== Firefox Extensions ====================== ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default - Undetermined - C:\Program Files (x86)\IObit Apps Toolbar\FF - Amazon-Icon - %ProfilePath%\extensions\amazon-icon@giga.de - Advanced SystemCare Surfing Protection - %ProfilePath%\extensions\ascsurfingprotection@iobit.com - HDvid Codec - %ProfilePath%\extensions\hdvc@hdvc.com - AD Block - %ProfilePath%\extensions\searchads@instair.net - AccelerateTab - %ProfilePath%\extensions\speeddial@instair.net - WebSite Recommendation - %ProfilePath%\extensions\WebSiteRecommendation@weliketheweb.com - Snap.Do - %ProfilePath%\extensions\{96e1573f-e7e4-9f36-0509-dd0e99161bc7} ==== Firefox Plugins ====================== Profilepath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default 4BF70B35B943BD73BD6E13EB7C1BA4B3 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll - Shockwave Flash AE7B288233C212C62CD544BF768C45E6 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll - Shockwave for Director / Shockwave for Director FFF2362F6B4A46D4BC1D147E79A7547B - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll - Nexon Game Controller 2C82D753EF779945977C82A3908DA20A - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.90.5 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Deleted Firefox Extensions ====================== C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\speeddial@instair.net deleted C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\{96e1573f-e7e4-9f36-0509-dd0e99161bc7} deleted C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\hdvc@hdvc.com deleted ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions kckgnnipheglejoddfhekdjpbdbinhmb - C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis\SpeedTestAnalysis.crx[] mkcedibhemacmilmkpndpkoidlnmgngg - C:\Users\Admin\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx[] nfengeggddojhakldhlpjdlddgkkjkdd - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx[12.10.2013 13:04] Price Alarm - Admin - Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab Speed Test Analysis - Admin - Default\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb Amazon-Icon - Admin - Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg Advanced SystemCare Surfing Protection - Admin - Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd Speed Test Analysis - Admin - Profile 1\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb Amazon-Icon - Admin - Profile 1\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg Advanced SystemCare Surfing Protection - Admin - Profile 1\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd ==== Chrome Fix ====================== C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab deleted successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fmlgoencnlndpglbocajlimaikjohmab_0.localstorage deleted successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fmlgoencnlndpglbocajlimaikjohmab_0.localstorage-journal deleted successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb deleted successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb deleted successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kckgnnipheglejoddfhekdjpbdbinhmb_0.localstorage deleted successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg deleted successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013" "Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Use Search Asst"="yes" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s" "Default"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s" "Default"="hxxp://www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s" "Default"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "CustomizeSearch"="hxxp://www.google.com" "SearchAssistant"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "CustomizeSearch"="hxxp://www.google.com" "SearchAssistant"="hxxp://www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026" "Default_Search_URL"="hxxp://www.google.com" "Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=" "CustomizeSearch"="hxxp://www.google.com" "SearchAssistant"="hxxp://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{006ee092-9658-4fd6-bd8e-a21a348e59f5}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://www.google.com" "Use Search Asst"="no" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "CustomizeSearch"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" "SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "CustomizeSearch"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" "SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "CustomizeSearch"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" "SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {006ee092-9658-4fd6-bd8e-a21a348e59f5} Web Search Url="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Reset Google Chrome ====================== C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\237AA359BFA99C94484AF769ACA080AD deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7E09412E-7A0E-4C61-B304-888C760F61D4} deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\E21490E7E0A716C43B4088C867F0164D deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesAirMessage deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPreload deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KPeerNexonEU deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Overwolf deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Utility Chest Home Page Guard 64 bit deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MC9QY34B will be deleted at reboot C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VPX4PAEL will be deleted at reboot C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2VIDXTY will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\jgb2a5vb.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Application Cache\Cache emptied successfully C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache is not empty, a reboot is needed ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Admin\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MC9QY34B" not found "C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VPX4PAEL" not found "C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2VIDXTY" not found "C:\Users\Admin\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\SDRQWGNG\empire-s.assets.zgncdn.com" not found "C:\Users\Admin\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\SDRQWGNG\synd.travelplus.tv" not found ==== EOF on 25.11.2013 at 21:54:45,42 ====================== Logdatei Mbam: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.25.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16428 Admin :: PC [Administrator] Schutz: Aktiviert 25.11.2013 18:56:57 mbam-log-2013-11-25 (18-56-57).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 233873 Laufzeit: 4 Minute(n), Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 1 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Windows\Installer\131f08.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\bd5bdd.msi (PUP.Optional.SmartBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\User Data\Default\Extensions\newtab.crx (PUP.Optional.Elex.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Btw: Wenn wir schon dabei sind: Könntest du mir vielleicht ein paar Softwares vorschlagen (wenn möglich kostenfrei), die solchen Problemen effizient vorbeugen? Was benutzt du so? Vielleicht irgendein Programm, dass den Computer nicht all zu sehr belastet, da ich mit meiner 8800 GTS und nem AMD Quad-Core Prozessor nicht ganz zeitgemäß ausgestattet bin :-D Gestern war alles wie gewollt und heute ist die Snap.do Startseite wieder da... Hast du irgendwas hilfreiches gegen diese Sotfware? |
26.11.2013, 19:33 | #8 |
/// TB-Ausbilder | _GETWINDOWINFO-Trojaner Servus, Wir spüren die letzten Reste auf, damit wir sie später entfernen können: Schritt 1 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. Schritt 2 Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit) | SystemLook (64 bit)
In welchem Browser ist die snap.do Seite wieder aufgetaucht? Wie läuft der Rechner derzeit? Bitte poste mit deiner nächsten Antwort
|
01.12.2013, 10:25 | #9 |
/// TB-Ausbilder | _GETWINDOWINFO-Trojaner Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
Themen zu _GETWINDOWINFO-Trojaner |
amazon-icon, branding, browser, darkcomet, darkcomet rat, defender, driver booster, excel, flash player, getwindowinfo, google, internet, internet exlorer, internet explorer, mozilla, newtab, plug-in, pup.optional.elex.a, pup.optional.smartbar.a, pup.optional.snapdo, pup.optional.sweetim, realtek, richtlinie, schutz, services.exe, smartbar, svchost.exe, trojaner, vcredist |