|
Plagegeister aller Art und deren Bekämpfung: Phisingseite im neuen Tab im Browser? Australian brewing company?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
21.12.2013, 05:29 | #1 |
| Phisingseite im neuen Tab im Browser? Australian brewing company? Hallo, ich habe ein Problem. Meine Software warnt mich vor Phishingversuchen. Daher würde ich gerne Hilfe von Euch bekommen. Es gehen manchmal zusätzliche Tabs in allen Internetbrowsern auf wenn ich eine Zeit lang surfe ohne das ich irgendwas anklicke. Meistens ist es dieser Link, der dann von meinem Norton AntiVirus gemeldet wird. static.australianbrewingcompany.com/ng/?z=1&ilmernzkvtaztus=0022FB010E18C566&pu=&s=D-chrome&nm=ilmernzkvtaztus&t= Für eine Hilfe wäre ich sehr dankbar. Beste Grüße Wissl Anbei die geforderten Daten: Defrogger wurde im Disable-modus benutzt und es erfolgte nur der Hinweis Finished. hier das Log dazu: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 04:01 on 21/12/2013 (Wissem) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-12-2013 02 Ran by Wissem (administrator) on VAIO on 21-12-2013 04:05:38 Running from C:\Users\Wissem\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Realtek Semiconductor) C:\Windows\RTKAUDIOSERVICE.EXE (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Symantec Corporation) C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\nst.exe (Sony Corporation) C:\Program Files\sony\Network Utility\NSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) C:\Program Files\sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Sony Corporation) C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\nst.exe (Symantec Corporation) C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sony Corporation) C:\Program Files\sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files\sony\Marketing Tools\MarketingTools.exe (Sony Corporation) C:\Program Files\sony\VAIO Power Management\SPMgr.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sony Corporation) C:\Program Files\sony\Network Utility\LANUtil.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Samsung Electronics) C:\Program Files\Samsung\Kies\KiesAirMessage.exe (Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Dropbox, Inc.) C:\Users\Wissem\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Sony Corporation) C:\Program Files\sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\sony\VAIO Update\VUAgent.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6295552 2008-10-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2007-03-10] (Synaptics, Inc.) HKLM\...\Run: [ISBMgr.exe] - C:\Program Files\sony\ISB Utility\ISBMgr.exe [317280 2008-04-03] (Sony Corporation) HKLM\...\Run: [MarketingTools] - C:\Program Files\sony\Marketing Tools\MarketingTools.exe [24576 2013-01-21] (Sony Corporation) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] () HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Skytel] - C:\Windows\SkyTel.exe [1826816 2008-10-17] (Realtek Semiconductor Corp.) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-04-23] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [BlueStacks Agent] - C:\Program Files\BlueStacks\HD-Agent.exe [601928 2013-07-04] (BlueStack Systems, Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: igfxdev.dll [X] Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll (Sony Corporation) HKCU\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [270336 2008-11-05] (Sony Corporation) HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1561968 2013-04-23] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe [578560 2013-03-20] (Samsung Electronics) HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844168 2013-06-04] (Samsung) HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) HKU\Gast\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) Startup: C:\Users\Wissem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Wissem\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=10&cc=&mi=56cac5660000000000000022fb010e18 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.sonystyle-europe.com?csint=140016340 hxxp://www.club-vaio.com/vbc/ebay/index.html hxxp://www.club-vaio.com/vbc HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.sonystyle-europe.com?csint=140016340 hxxp://www.club-vaio.com/vbc/ebay/index.html hxxp://www.club-vaio.com/vbc HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com SearchScopes: HKLM - DefaultScope {D645DA1C-3672-4AE1-AD32-6ADE02A88FD2} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta= SearchScopes: HKLM - {D645DA1C-3672-4AE1-AD32-6ADE02A88FD2} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta= SearchScopes: HKCU - DefaultScope {A77706B0-D6C9-40EF-9833-2FABCC21BF88} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=56cac5660000000000000022fb010e18&r=77 SearchScopes: HKCU - {A77706B0-D6C9-40EF-9833-2FABCC21BF88} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=56cac5660000000000000022fb010e18&r=77 SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=IDSSNAV&chn=retail&geo=DE&ver=2013&locale=de_DE&gct=sb&qsrc=2869 SearchScopes: HKCU - {D645DA1C-3672-4AE1-AD32-6ADE02A88FD2} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=&rlz=1I7SNYK_de BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\coieplg.dll (Symantec Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\coieplg.dll (Symantec Corporation) Toolbar: HKCU - Norton Identity Safe Toolbar - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\coieplg.dll (Symantec Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default FF user.js: detected! => C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @soe.sony.com/installer,version=1.0.3 - C:\Users\Wissem\AppData\LocalLow\Sony Online Entertainment\npsoe.dll () FF SearchPlugin: C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default\searchplugins\softonic.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.5.0.67\coFFPlgn\ FF Extension: Norton Identity Safe Toolbar - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.5.0.67\coFFPlgn\ FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff\ FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\IPSFF Chrome: ======= CHR HomePage: hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=48&cc=&mi=56cac5660000000000000022fb010e18 CHR DefaultSearchKeyword: google.de CHR DefaultSearchProvider: Google CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultNewTabURL: {google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Norton Identity Safe) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nppllibpnmahfaklnpggkibhkapjkeob\2013.2.1.33_0\npcoplgn.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.110.21) - C:\Windows\system32\npDeployJava1.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Google Docs) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (CnC TA Script Collection) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmhpmdclklpgfcpoiomjofgfagenmgeo\1.2.8.49_0 CHR Extension: (Google Wallet) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR Extension: (Norton Identity Protection) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nppllibpnmahfaklnpggkibhkapjkeob\2014.6.2.3_0 CHR Extension: (Gmail) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [nppllibpnmahfaklnpggkibhkapjkeob] - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\Exts\Chrome.crx ========================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2008-08-01] (ArcSoft Inc.) S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [393032 2013-07-04] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [384840 2013-07-04] (BlueStack Systems, Inc.) S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 NAV; C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation) R2 NCO; C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\diMaster.dll [567600 2013-10-03] (Symantec Corporation) R2 NSUService; C:\Program Files\sony\Network Utility\NSUService.exe [303104 2008-11-05] (Sony Corporation) S3 SOHDBSvr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [72856 2012-03-06] (Sony Corporation) S3 SOHPlMgr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [93336 2012-03-06] (Sony Corporation) R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-03-05] (Sony Corporation) R2 VAIO Event Service; C:\Program Files\sony\VAIO Event Service\VESMgr.exe [203624 2008-12-09] (Sony Corporation) R2 VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [411488 2008-09-05] (Sony Corporation) R2 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [480624 2009-09-16] (Sony Corporation) R3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-03-05] (Sony Corporation) R3 VUAgent; C:\Program Files\sony\VAIO Update\VUAgent.exe [1020976 2013-08-01] (Sony Corporation) R2 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-03-05] (Sony Corporation) S3 MSCSPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe" [x] S3 SPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe" [x] ==================== Drivers (Whitelisted) ==================== R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.) R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20131203.001\BHDrvx86.sys [1098968 2013-12-03] (Symantec Corporation) R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [63816 2013-07-04] (BlueStack Systems) R1 ccSet_NAV; C:\Windows\system32\drivers\NAV\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation) R1 ccSet_NST; C:\Windows\system32\drivers\NST\7DE06000.01B\ccSetx86.sys [127064 2013-09-27] (Symantec Corporation) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-11-21] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-11-21] (Symantec Corporation) R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20131220.001\IDSvix86.sys [394456 2013-12-13] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20131220.008\NAVENG.SYS [93272 2013-12-18] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20131220.008\NAVEX15.SYS [1612376 2013-12-18] (Symantec Corporation) R3 SRTSP; C:\Windows\System32\Drivers\NAV\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NAV\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NAV\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NAV\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NAV\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation) R1 SYMTDIv; C:\Windows\System32\Drivers\NAV\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation) S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] S3 igfx; system32\DRIVERS\igdkmd32.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S4 UIUSys; system32\DRIVERS\UIUSYS.SYS [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-21 04:05 - 2013-12-21 04:05 - 00021543 _____ C:\Users\Wissem\Desktop\FRST.txt 2013-12-21 04:05 - 2013-12-21 04:05 - 00000000 ____D C:\FRST 2013-12-21 04:00 - 2013-12-21 04:01 - 00000474 _____ C:\Users\Wissem\Desktop\defogger_disable.log 2013-12-21 04:00 - 2013-12-21 04:00 - 00000000 _____ C:\Users\Wissem\defogger_reenable 2013-12-21 03:57 - 2013-12-21 03:57 - 00377856 _____ C:\Users\Wissem\Desktop\gmer_2.1.19163.exe 2013-12-21 03:56 - 2013-12-21 03:57 - 01325858 _____ (Farbar) C:\Users\Wissem\Desktop\FRST.exe 2013-12-21 03:55 - 2013-12-21 03:55 - 00050477 _____ C:\Users\Wissem\Desktop\Defogger.exe 2013-12-12 22:11 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 22:11 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 22:11 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 22:11 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 22:11 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 22:11 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 22:11 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-12 22:11 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 22:11 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-12 22:11 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-12 22:11 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 22:11 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-12 22:11 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 22:11 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-12 22:11 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 22:11 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 17:24 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-12 17:24 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-12 17:24 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-12 17:24 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 17:24 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 17:24 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 17:24 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 17:24 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-12 17:24 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 17:24 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\Users\Gast\AppData\Roaming\ArcSoft 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\ProgramData\ArcSoft 2013-11-28 23:04 - 2013-11-29 18:20 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Skype 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ___RD C:\Program Files\Skype 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-11-28 23:03 - 2013-11-28 23:03 - 35095200 _____ (Skype Technologies S.A.) C:\Users\Gast\Downloads\Skype611SetupFull.exe 2013-11-23 22:12 - 2013-11-23 22:12 - 00564736 _____ C:\Users\Wissem\Desktop\6.Std 2013 EurR.ppt ==================== One Month Modified Files and Folders ======= 2013-12-21 04:06 - 2013-06-04 18:27 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Dropbox 2013-12-21 04:05 - 2013-12-21 04:05 - 00021543 _____ C:\Users\Wissem\Desktop\FRST.txt 2013-12-21 04:05 - 2013-12-21 04:05 - 00000000 ____D C:\FRST 2013-12-21 04:04 - 2013-01-21 00:42 - 01854272 _____ C:\Windows\WindowsUpdate.log 2013-12-21 04:01 - 2013-12-21 04:00 - 00000474 _____ C:\Users\Wissem\Desktop\defogger_disable.log 2013-12-21 04:00 - 2013-12-21 04:00 - 00000000 _____ C:\Users\Wissem\defogger_reenable 2013-12-21 04:00 - 2013-01-21 02:49 - 00000000 ____D C:\Users\Wissem 2013-12-21 03:57 - 2013-12-21 03:57 - 00377856 _____ C:\Users\Wissem\Desktop\gmer_2.1.19163.exe 2013-12-21 03:57 - 2013-12-21 03:56 - 01325858 _____ (Farbar) C:\Users\Wissem\Desktop\FRST.exe 2013-12-21 03:55 - 2013-12-21 03:55 - 00050477 _____ C:\Users\Wissem\Desktop\Defogger.exe 2013-12-21 03:55 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-21 03:55 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-21 03:26 - 2013-01-27 19:37 - 00000000 ____D C:\Users\Wissem\AppData\Local\CrashDumps 2013-12-21 01:34 - 2013-01-24 04:37 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-21 01:08 - 2013-10-23 11:08 - 00000296 _____ C:\Windows\Tasks\DigitalSite.job 2013-12-21 00:48 - 2013-01-24 04:39 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-21 00:26 - 2013-10-16 00:02 - 00000000 ____D C:\Users\Wissem\Desktop\VerfR I 2013-12-21 00:12 - 2013-10-23 12:08 - 00000092 _____ C:\Users\Wissem\AppData\Roaming\WB.CFG 2013-12-21 00:12 - 2013-10-23 12:08 - 00000006 _____ C:\Users\Wissem\AppData\Roaming\WBPU-TTL.DAT 2013-12-21 00:01 - 2013-04-20 10:41 - 00000000 ____D C:\Users\Wissem\Desktop\Europarecht 2013-12-20 16:14 - 2013-06-04 18:31 - 00000000 ___RD C:\Users\Wissem\Dropbox 2013-12-20 16:13 - 2013-01-24 04:39 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-20 16:12 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-20 07:27 - 2006-11-02 14:01 - 00032518 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-19 01:40 - 2013-06-04 18:31 - 00000922 _____ C:\Users\Wissem\Desktop\Dropbox.lnk 2013-12-19 01:40 - 2013-06-04 18:28 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-12-18 16:19 - 2008-01-21 03:47 - 00365810 _____ C:\Windows\PFRO.log 2013-12-17 19:12 - 2013-01-21 02:49 - 00002032 _____ C:\Users\Wissem\AppData\Local\d3d9caps.dat 2013-12-13 04:21 - 2006-11-02 13:47 - 00395888 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-13 04:18 - 2008-10-23 12:25 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-12 22:19 - 2013-01-21 01:02 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-12 22:15 - 2013-07-19 02:01 - 00000000 ____D C:\Windows\system32\MRT 2013-12-12 22:12 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-10 18:57 - 2013-01-24 04:37 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-10 18:57 - 2013-01-24 04:37 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-10 18:57 - 2013-01-21 02:49 - 00000000 ____D C:\Users\Wissem\AppData\Local\Adobe 2013-12-09 13:35 - 2013-01-21 03:54 - 00000000 ____D C:\Users\Wissem\AppData\Local\Microsoft Help 2013-12-09 00:10 - 2013-11-06 17:58 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-09 00:10 - 2013-01-21 04:23 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-11-29 18:20 - 2013-11-28 23:04 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Skype 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\Users\Gast\AppData\Roaming\ArcSoft 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\ProgramData\ArcSoft 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ___RD C:\Program Files\Skype 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-11-28 23:04 - 2013-01-22 03:04 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Skype 2013-11-28 23:04 - 2013-01-21 01:20 - 00000000 ____D C:\ProgramData\Skype 2013-11-28 23:03 - 2013-11-28 23:03 - 35095200 _____ (Skype Technologies S.A.) C:\Users\Gast\Downloads\Skype611SetupFull.exe 2013-11-23 22:12 - 2013-11-23 22:12 - 00564736 _____ C:\Users\Wissem\Desktop\6.Std 2013 EurR.ppt 2013-11-21 19:14 - 2013-04-16 05:01 - 00000000 ____D C:\Users\Wissem\Desktop\wiss Hausi 2013-11-21 12:08 - 2013-11-20 17:17 - 00011427 _____ C:\Users\Wissem\Documents\Notenliste Hadjseyd ZRecht II.xlsx Some content of TEMP: ==================== C:\Users\Wissem\AppData\Local\Temp\FileSystemView.dll C:\Users\Wissem\AppData\Local\Temp\gf5nbe4a.dll C:\Users\Wissem\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\ply7cf_y.dll C:\Users\Wissem\AppData\Local\Temp\VzCdb.dll C:\Users\Wissem\AppData\Local\Temp\VzCdbCtrl.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-20 16:19 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-12-2013 02 Ran by Wissem at 2013-12-21 04:06:28 Running from C:\Users\Wissem\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Norton AntiVirus (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton AntiVirus (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} ==================== Installed Programs ====================== 2007 Microsoft Office system (Version: 12.0.6612.1000) 3GP to MP3 Converter AAVUpdateManager (Version: 18.00.0000) Adobe Flash Player 11 Plugin (Version: 11.9.900.170) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8) ArcSoft Magic-i Visual Effects 2 (Version: 2.0.1.39) ArcSoft WebCam Companion 2 ATI Catalyst Install Manager (Version: 3.0.710.0) Big Fish Games Spiel-Suite BlueStacks App Player (Version: 0.7.15.909) BlueStacks Notification Center (Version: 0.7.15.909) Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1) Catalyst Control Center - Branding (Version: 1.00.0000) Catalyst Control Center Core Implementation (Version: 2008.0717.2343.40629) Catalyst Control Center Graphics Full Existing (Version: 2008.0717.2343.40629) Catalyst Control Center Graphics Full New (Version: 2008.0717.2343.40629) Catalyst Control Center Graphics Light (Version: 2008.0717.2343.40629) Catalyst Control Center Graphics Previews Common (Version: 2008.0717.2343.40629) Catalyst Control Center Graphics Previews Vista (Version: 2008.0717.2343.40629) Catalyst Control Center InstallProxy (Version: 2008.0717.2343.40629) Catalyst Control Center InstallProxy (Version: 2009.0515.32.42252) Catalyst Control Center Localization Chinese Standard (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Chinese Traditional (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Czech (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Danish (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Dutch (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Finnish (Version: 2008.0717.2343.40629) Catalyst Control Center Localization French (Version: 2008.0717.2343.40629) Catalyst Control Center Localization German (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Greek (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Hungarian (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Italian (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Japanese (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Korean (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Norwegian (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Polish (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Portuguese (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Russian (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Spanish (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Swedish (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Thai (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Turkish (Version: 2008.0717.2343.40629) CCC Help Chinese Standard (Version: 2008.0717.2342.40629) CCC Help Chinese Traditional (Version: 2008.0717.2342.40629) CCC Help Danish (Version: 2008.0717.2342.40629) CCC Help Dutch (Version: 2008.0717.2342.40629) CCC Help English (Version: 2008.0717.2342.40629) CCC Help Finnish (Version: 2008.0717.2342.40629) CCC Help French (Version: 2008.0717.2342.40629) CCC Help German (Version: 2008.0717.2342.40629) CCC Help Greek (Version: 2008.0717.2342.40629) CCC Help Hungarian (Version: 2008.0717.2342.40629) CCC Help Italian (Version: 2008.0717.2342.40629) CCC Help Japanese (Version: 2008.0717.2342.40629) CCC Help Korean (Version: 2008.0717.2342.40629) CCC Help Norwegian (Version: 2008.0717.2342.40629) CCC Help Polish (Version: 2008.0717.2342.40629) CCC Help Portuguese (Version: 2008.0717.2342.40629) CCC Help Russian (Version: 2008.0717.2342.40629) CCC Help Spanish (Version: 2008.0717.2342.40629) CCC Help Swedish (Version: 2008.0717.2342.40629) CCC Help Thai (Version: 2008.0717.2342.40629) CCC Help Turkish (Version: 2008.0717.2342.40629) ccc-utility (Version: 2008.0717.2343.40629) CDBurnerXP (Version: 4.5.0.3717) Click to Disc (Version: 1.2.73.04270) Click to Disc Editor (Version: 2.0.02) Click to Disc Editor (Version: 2.0.03.04150) Clone Wars Dropbox (HKCU Version: 2.4.10) EVEREST Home Edition v2.20 (Version: 2.20) Free YouTube to MP3 Converter version 3.12.16.1030 (Version: 3.12.16.1030) Google Chrome (Version: 31.0.1650.63) Google Earth (Version: 4.2.205.5730) Google Talk (remove only) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Update Helper (Version: 1.3.22.3) HDAUDIO SoftV92 Data Fax Modem with SmartCP Intel PROSet Wireless Intel(R) PROSet/Wireless WiFi-Software (Version: 12.04.3000) Java 7 Update 45 (Version: 7.0.450) Java Auto Updater (Version: 2.1.9.8) Me&My VAIO (Version: 1.0.0.11140) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320) Microsoft Office 2003 Web Components (Version: 11.0.8003.0) Microsoft Office 2007 Primary Interop Assemblies (Version: 12.0.4518.1014) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Professional Hybrid 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Small Business Connectivity Components (Version: 2.0.7024.0) Microsoft Office Suite Activation Assistant (Version: 2.9) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00) Microsoft SQL Server Native Client (Version: 9.00.5000.00) Microsoft SQL Server VSS Writer (Version: 9.00.5000.00) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Mozilla Firefox 25.0 (x86 de) (Version: 25.0) Mozilla Maintenance Service (Version: 25.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Music Transfer (Version: 1.2.00.17290) MyFreeCodec Norton AntiVirus (Version: 20.4.0.40) Norton Identity Safe (Version: 2014.6.0.27) OpenMG Secure Module 5.4.00 (Version: 5.4.00.04020) Picasa 3 (Version: 3.9) Primo (Version: 1.00.0000) Realtek High Definition Audio Driver (Version: 6.0.1.5653) Roxio Central Audio (Version: 3.7.0) Roxio Central Copy (Version: 3.7.0) Roxio Central Core (Version: 3.7.0) Roxio Central Data (Version: 3.7.0) Roxio Central Tools (Version: 3.7.0) Roxio Easy Media Creator 10 LJ (Version: 10.1) Roxio Easy Media Creator Home (Version: 10.1.296) Samsung Kies (Version: 2.5.2.13021_10) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.23.0) Setting Utility Series (Version: 4.2.0.10150) Skins (Version: 2008.0717.2343.40629) Skype™ 6.11 (Version: 6.11.102) SOE Web Installer (HKCU Version: 1.0.3.171) Software Info for Me&My VAIO (Version: 1.0.0.09110) Sony Home Network Library (Version: 1.4.5.15070) Sony Picture Utility (Version: 3.3.01.09300) Sony Video Shared Library (Version: 3.5.00) Steuer-Spar-Erklärung 2013 (Version: 18.09) Synaptics Pointing Device Driver (Version: 9.1.13.0) TeamSpeak 3 Client (HKCU Version: 3.0.10) Unterstützung für VAIO-Präsentation (Version: 1.1.0.08250) Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition Update for Video Converter Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Outlook 2007 Help (KB963677) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) VAIO Content Folder Setting (Version: 2.1.0.08260) VAIO Content Folder Watcher (Version: 1.0.01.09030) VAIO Content Metadata Intelligent Analyzing Manager (Version: 3.6.1.12010) VAIO Content Metadata Manager Settings (Version: 3.6.0.09240) VAIO Content Metadata XML Interface Library (Version: 3.6.0.09080) VAIO Control Center (Version: 3.2.0.09120) VAIO Data Restore Tool (Version: 1.0.04.01170) VAIO DVD Menu Data Basic (Version: 1.0.00.08130) VAIO Energie Verwaltung (Version: 3.2.0.10060) VAIO Entertainment Platform (Version: 3.4.1.15040) VAIO Event Service (Version: 4.2.1.12090) VAIO Launcher (Version: 2.2.0.09090) VAIO Marketing Tools VAIO Media plus (Version: 1.2.0.10230) VAIO Media plus (Version: 1.4.5.15070) VAIO Media plus Opening Movie (Version: 1.2.0.09100) VAIO Movie Story (Version: 1.3.01.08060) VAIO Movie Story Template Data (Version: 1.3.00.06120) VAIO MusicBox (Version: 2.1.1.09160) VAIO MusicBox Sample Music (Version: 1.1.00.14140) VAIO Original Function Settings (Version: 2.0.2.02240) VAIO Original Funktion Einstellungen (Version: 2.0.2.02240) VAIO Smart Network (Version: 2.2.0.11050) VAIO Update (Version: 6.3.0.08010) VAIO Wallpaper Contents (Version: 1.3.0.10310) VU5x86 (Version: 1.1.0) Wartung Samsung ML-1660 Series WinDVD for VAIO (Version: 8.0-B9.602) ==================== Restore Points ========================= 24-10-2013 19:43:05 Geplanter Prüfpunkt 29-10-2013 22:11:41 Geplanter Prüfpunkt 06-11-2013 00:50:08 Geplanter Prüfpunkt 06-11-2013 19:55:05 Geplanter Prüfpunkt 12-11-2013 01:13:14 TuneUp Utilities 2014 wird entfernt 12-11-2013 01:14:58 TuneUp Utilities 2014 (de-DE) wird entfernt 13-11-2013 02:00:57 Windows Update 13-11-2013 14:47:58 Windows Update 15-11-2013 02:00:41 Windows Update 16-11-2013 21:03:16 Geplanter Prüfpunkt 19-11-2013 00:23:36 Geplanter Prüfpunkt 26-11-2013 13:14:33 Geplanter Prüfpunkt 30-11-2013 10:42:34 Geplanter Prüfpunkt 04-12-2013 08:00:56 Geplanter Prüfpunkt 11-12-2013 07:56:36 Geplanter Prüfpunkt 12-12-2013 21:08:04 Geplanter Prüfpunkt 12-12-2013 21:09:47 Windows Update ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {04DFB7BD-5867-4389-B63D-C0AB042407FA} - System32\Tasks\Sony Corporation\VAIO Update\Launch Application => C:\Program Files\sony\VAIO Update\ShellExeProxy.exe [2013-08-01] (Sony Corporation) Task: {155594D3-648B-4112-B258-C74DB3DBDC99} - System32\Tasks\Norton Identity Safe\Norton Error Processor => C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\symerr.exe [2013-06-04] (Symantec Corporation) Task: {1AF9966D-09F6-4474-9666-398A2684D9CD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {35E9BD17-5783-485D-81D9-215292D5FE95} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-24] (Google Inc.) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {60E57A9C-D41F-46E7-B5EB-CCAFA6026F92} - System32\Tasks\Norton AntiVirus\Norton Error Processor => C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\symerr.exe [2013-06-04] (Symantec Corporation) Task: {65C743DE-31DA-4525-A1CC-6E27F20774A0} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\sony\VAIO Update\VUSR.exe [2013-08-01] (Sony Corporation) Task: {83D5229C-E418-4286-92A1-8BEE7DC88554} - System32\Tasks\SONY\Me&My VAIO\Me&My VAIO => C:\Program Files\Sony\Me&My VAIO\QLGuide.exe Task: {915CAC06-0A5E-40E7-B0D6-38AEF1192F44} - System32\Tasks\Norton Identity Safe\Norton Error Analyzer => C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\symerr.exe [2013-06-04] (Symantec Corporation) Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries Task: {B411CF98-2625-4141-BD75-DEC337143999} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\wscstub.exe [2013-06-04] (Symantec Corporation) Task: {C73D5AE1-53EA-4F1F-AEE1-67C90A26F6FD} - System32\Tasks\Norton AntiVirus\Norton Error Analyzer => C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\symerr.exe [2013-06-04] (Symantec Corporation) Task: {D8615B64-6D0F-48BE-8166-A7CD33168A19} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\sony\VAIO Update\VAIOUpdt.exe [2013-08-01] (Sony Corporation) Task: {D86D3C58-5C96-4943-8CA7-B78D87D79A39} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-24] (Google Inc.) Task: {DF7FC274-B63D-42DB-8AC9-FF733C6F2276} - System32\Tasks\DigitalSite => C:\Users\Wissem\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] () Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\Wissem\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2008-10-23 19:48 - 2009-05-14 22:22 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll 2013-10-11 02:46 - 2013-10-11 02:46 - 01899520 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\59ee5862c051127ed695e125f1e3cb1a\Kies.UI.ni.dll 2013-08-14 18:52 - 2013-08-14 18:52 - 00079360 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\c0fbbc04960625be85b6275ebeb00cb2\Kies.MVVM.ni.dll 2013-08-14 18:53 - 2013-08-14 18:53 - 00080896 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ZipStore\1dd23f0d663e85fd7471859147b682e7\ZipStore.ni.dll 2013-08-14 18:53 - 2013-08-14 18:53 - 00187904 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\2cb652c9e0d3ece998b8622920a463d3\Kies.Common.DeviceServiceLib.Interface.ni.dll 2013-10-11 02:47 - 2013-10-11 02:47 - 00355840 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePhoto\048885ddaa4310795d59f8306203038f\DevicePhoto.ni.dll 2013-10-11 02:47 - 2013-10-11 02:47 - 00300544 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceVideo\0a90338c405d94cc87736c9c687a8e0d\DeviceVideo.ni.dll 2013-10-11 02:47 - 2013-10-11 02:47 - 00614912 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePodcast\75e03182c72ff271ec666a1520ef1014\DevicePodcast.ni.dll 2013-08-14 18:54 - 2013-08-14 18:54 - 00307200 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DummyStorePlugin\aab2f72c4ff4d4516918d856a101b7c6\DummyStorePlugin.ni.dll 2013-08-14 18:54 - 2013-08-14 18:54 - 17554944 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\3adf7b0ea0d7f23db2f5024776a42166\Kies.Theme.ni.dll 2013-10-11 02:47 - 2013-10-11 02:47 - 00580096 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\0f66aea003566f420cf9e472b60d6116\Kies.Common.DeviceServiceLib.FileService.ni.dll 2013-07-11 10:48 - 2013-07-11 10:48 - 00045568 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\b2b18bdc2d90d3aab43a09b1a188150a\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.ni.dll 2013-10-11 02:47 - 2013-10-11 02:47 - 00995328 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceCommonLib\1b30a74c76d2f03f46c4311225d2fb89\DeviceCommonLib.ni.dll 2013-08-14 18:53 - 2013-08-14 18:53 - 00232960 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\c5efe841e2998c266e0f5e29bed04b55\ASF_cSharpAPI.ni.dll 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Wissem\AppData\Roaming\Dropbox\bin\libcef.dll 2013-12-05 03:45 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-05 03:45 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-05 03:45 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll 2013-12-05 03:45 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-05 03:45 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-05 03:45 - 2013-12-04 03:48 - 13586896 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/21/2013 03:18:38 AM) (Source: Application Error) (User: ) Description: Fehlerhafte Anwendung ssp7msm.exe, Version 1.1.0.12, Zeitstempel 0x4e11d0ae, fehlerhaftes Modul ssp7msm.exe, Version 1.1.0.12, Zeitstempel 0x4e11d0ae, Ausnahmecode 0xc0000005, Fehleroffset 0x00043bed, Prozess-ID 0x1760, Anwendungsstartzeit ssp7msm.exe0. Error: (12/20/2013 04:12:54 PM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (12/20/2013 04:12:54 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/20/2013 04:12:53 PM) (Source: BstHdAndroidSvc) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (12/20/2013 01:58:28 AM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (12/20/2013 01:58:28 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/20/2013 01:58:24 AM) (Source: BstHdAndroidSvc) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (12/19/2013 07:34:49 PM) (Source: EventSystem) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (12/18/2013 04:19:31 PM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (12/18/2013 04:19:29 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/20/2013 04:12:54 PM) (Source: Service Control Manager) (User: ) Description: BlueStacks Android Service%%1064 Error: (12/20/2013 04:12:54 PM) (Source: Service Control Manager) (User: ) Description: DgiVecp%%2 Error: (12/20/2013 04:12:54 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (12/20/2013 01:58:28 AM) (Source: Service Control Manager) (User: ) Description: BlueStacks Android Service%%1064 Error: (12/20/2013 01:58:28 AM) (Source: Service Control Manager) (User: ) Description: DgiVecp%%2 Error: (12/20/2013 01:58:28 AM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (12/18/2013 04:19:29 PM) (Source: Service Control Manager) (User: ) Description: BlueStacks Android Service%%1064 Error: (12/18/2013 04:19:29 PM) (Source: Service Control Manager) (User: ) Description: DgiVecp%%2 Error: (12/18/2013 04:19:29 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (12/17/2013 05:38:29 PM) (Source: Service Control Manager) (User: ) Description: BlueStacks Android Service%%1064 Microsoft Office Sessions: ========================= Error: (04/22/2013 08:37:22 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 77256 seconds with 5340 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2013-12-21 04:05:52.841 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-21 04:05:52.715 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-21 04:05:52.576 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-21 04:05:52.394 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-21 04:05:47.508 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20131203.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-21 04:05:47.387 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20131203.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-21 04:05:47.266 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20131203.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-21 04:05:47.142 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20131203.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-05 22:02:40.857 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20131022.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-11-05 22:02:40.654 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20131022.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 56% Total physical RAM: 3038.13 MB Available physical RAM: 1336.47 MB Total Pagefile: 6279.29 MB Available Pagefile: 4371 MB Total Virtual: 2047.88 MB Available Virtual: 1896.57 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:288.28 GB) (Free:148.39 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Removable) (Total:1.89 GB) (Free:0.78 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: AD9C10E4) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=288 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 2 GB) (Disk ID: 00000000) Partition 1: (Not Active) - (Size=2 GB) - (Type=0E) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-12-21 05:09:57 Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.FB4O 298,09GB Running: gmer_2.1.19163.exe; Driver: C:\Users\Wissem\AppData\Local\Temp\pxldypog.sys ---- System - GMER 2.1 ---- SSDT 893CE598 ZwAlertResumeThread SSDT 893CE630 ZwAlertThread SSDT 893CEC30 ZwAllocateVirtualMemory SSDT 88B904D0 ZwAlpcConnectPort SSDT 88DDDF90 ZwAssignProcessToJobObject SSDT 893CE3C0 ZwCreateMutant SSDT 88DDDD88 ZwCreateSymbolicLinkObject SSDT 893CEEC8 ZwCreateThread SSDT 893CE0A8 ZwDebugActiveProcess SSDT 893CED30 ZwDuplicateObject SSDT 893CEB20 ZwFreeVirtualMemory SSDT 893CE468 ZwImpersonateAnonymousToken SSDT 893CE500 ZwImpersonateThread SSDT 88BA2C00 ZwLoadDriver SSDT 893CEA68 ZwMapViewOfSection SSDT 893CE328 ZwOpenEvent SSDT 893CEE40 ZwOpenProcess SSDT 893CECB8 ZwOpenProcessToken SSDT 893CE1F8 ZwOpenSection SSDT 893CEDB8 ZwOpenThread SSDT 88DDDEE8 ZwProtectVirtualMemory SSDT 893CE6C8 ZwResumeThread SSDT 893CE890 ZwSetContextThread SSDT 893CE928 ZwSetInformationProcess SSDT 893CE140 ZwSetSystemInformation SSDT 893CE290 ZwSuspendProcess SSDT 893CE760 ZwSuspendThread SSDT 8916C2A8 ZwTerminateProcess SSDT 893CE7F8 ZwTerminateThread SSDT 893CE9D0 ZwUnmapViewOfSection SSDT 893CEBA8 ZwWriteVirtualMemory SSDT 88DDDE30 ZwCreateThreadEx ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!KeSetEvent + 11D 820C3768 8 Bytes [98, E5, 3C, 89, 30, E6, 3C, ...] .text ntkrnlpa.exe!KeSetEvent + 131 820C377C 4 Bytes [30, EC, 3C, 89] {XOR AH, CH; CMP AL, 0x89} .text ntkrnlpa.exe!KeSetEvent + 13D 820C3788 4 Bytes [D0, 04, B9, 88] .text ntkrnlpa.exe!KeSetEvent + 191 820C37DC 4 Bytes [90, DF, DD, 88] .text ntkrnlpa.exe!KeSetEvent + 1F5 820C3840 4 Bytes [C0, E3, 3C, 89] .text ... .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9140F000, 0x24DFB2, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ntdll.dll!NtTerminateThread 77105394 5 Bytes JMP 00020050 .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!OpenSCManagerA + 125 767D2EB8 7 Bytes JMP 003A0768 .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!CloseServiceHandle + AA 767D834F 7 Bytes JMP 003A0210 .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!AreAllAccessesGranted + 3FD 767F9EAF 7 Bytes JMP 003A05A0 .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!CreateServiceW + FF 767F9FB3 7 Bytes JMP 003A012C .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!ControlService + C1 767FA079 7 Bytes JMP 003A084C .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!I_ScGetCurrentGroupStateW + 8F 76836629 7 Bytes JMP 003A03D8 .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!ControlServiceExA + 10E 7683673C 7 Bytes JMP 003A0048 .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!SetServiceObjectSecurity + FB 76836DD4 7 Bytes JMP 003A0684 .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!ChangeServiceConfigA + 1A3 76836F7C 7 Bytes JMP 003A04BC .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!ChangeServiceConfig2W + BB 7683729C 2 Bytes JMP 003A02F4 .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] ADVAPI32.dll!ChangeServiceConfig2W + BE 7683729F 4 Bytes [B6, 89, EB, F9] {MOV DH, 0x89; JMP 0xfffffffd} .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] USER32.dll!FindWindowA + 1BF 75769F35 7 Bytes JMP 003A0A12 .text C:\Users\Wissem\Desktop\gmer_2.1.19163.exe[172] USER32.dll!RecordShutdownReason + 36A 757AB7BE 7 Bytes JMP 003A0930 .text C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[5460] ntdll.dll!DbgBreakPoint 770E878E 1 Byte [C3] ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys AttachedDevice \Driver\tdx \Device\Tcp SYMTDIV.SYS AttachedDevice \Driver\tdx \Device\Udp SYMTDIV.SYS AttachedDevice \Driver\tdx \Device\RawIp SYMTDIV.SYS AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys ---- EOF - GMER 2.1 ---- |
21.12.2013, 10:49 | #2 |
/// the machine /// TB-Ausbilder | Phisingseite im neuen Tab im Browser? Australian brewing company? hi,
__________________Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
21.12.2013, 18:12 | #3 |
| Phisingseite im neuen Tab im Browser? Australian brewing company? Danke, dass du mir hilfst.
__________________So. 1.Schritt: Malware spuckt das aus Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.12.21.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Wissem :: VAIO [Administrator] 21.12.2013 16:32:37 mbam-log-2013-12-21 (16-32-37).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 235396 Laufzeit: 16 Minute(n), 8 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DigitalSite (PUP.Optional.DigitalSites.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 4 C:\Users\Wissem\AppData\Roaming\DigitalSite\UpdateProc (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\AppData\Roaming\OpenCandy\37B0B18711BC42FA9F6576141CF69BF4 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\AppData\Roaming\OpenCandy\EDFEBE4077DB40CE99055735E01DDD76 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 11 C:\Users\Wissem\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe (PUP.Optional.DigitalSites.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\AppData\Local\Temp\is1590112554\4955247_stp.EXE (PUP.Optional.PricePeep.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\Downloads\Live_Soccer_TV.exe (PUP.Optional.iBryte) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\Downloads\nicht bestätigt 797467.crdownload (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\Downloads\plugin.exe (MSIL.Solimba) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\AppData\Roaming\DigitalSite\UpdateProc\config.dat (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\AppData\Roaming\DigitalSite\UpdateProc\prod.dat (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\AppData\Roaming\DigitalSite\UpdateProc\STTL.DAT (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\AppData\Roaming\DigitalSite\UpdateProc\TTL.DAT (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\AppData\Roaming\OpenCandy\37B0B18711BC42FA9F6576141CF69BF4\Setupsft_chr_p1v7.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Wissem\AppData\Roaming\OpenCandy\EDFEBE4077DB40CE99055735E01DDD76\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) 2.Schritt: AdwCleaner, da hab ich zwei Dateien. Die erste ist eine R0 Datei, die zweite die S0 Datei. AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.015 - Bericht erstellt am 21/12/2013 um 17:35:20 # Updated 10/12/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Wissem - VAIO # Gestartet von : C:\Users\Wissem\Desktop\adwcleaner.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default\searchplugins\softonic.xml Datei Gefunden : C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default\user.js Datei Gefunden : C:\Windows\System32\Tasks\digitalsite Datei Gefunden : C:\Windows\Tasks\digitalsite.job Ordner Gefunden C:\Program Files\myfree codec Ordner Gefunden C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Ordner Gefunden C:\Users\Wissem\AppData\LocalLow\Softonic Ordner Gefunden C:\Users\Wissem\AppData\Roaming\digitalsite Ordner Gefunden C:\Users\Wissem\AppData\Roaming\dvdvideosoftiehelpers ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\dsiteproducts Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyFreeCodec Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Schlüssel Gefunden : HKCU\Software\Myfree Codec Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\digitalsite Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF7FC274-B63D-42DB-8AC9-FF733C6F2276} Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200 Schlüssel Gefunden : HKLM\Software\Myfree Codec Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}] ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16526 Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=10&cc=&mi=56cac5660000000000000022fb010e18 -\\ Mozilla Firefox v25.0 (de) [ Datei : C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default\prefs.js ] Zeile gefunden : user_pref("extensions.Softonic.admin", false); Zeile gefunden : user_pref("extensions.Softonic.aflt", "OC"); Zeile gefunden : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}"); Zeile gefunden : user_pref("extensions.Softonic.autoRvrt", "false"); Zeile gefunden : user_pref("extensions.Softonic.dfltLng", "de"); Zeile gefunden : user_pref("extensions.Softonic.dfltSrch", true); Zeile gefunden : user_pref("extensions.Softonic.dnsErr", true); Zeile gefunden : user_pref("extensions.Softonic.excTlbr", false); Zeile gefunden : user_pref("extensions.Softonic.ffxUnstlRst", false); Zeile gefunden : user_pref("extensions.Softonic.hmpg", true); Zeile gefunden : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=56cac5660000000000000022fb010e18"); Zeile gefunden : user_pref("extensions.Softonic.id", "56cac5660000000000000022fb010e18"); Zeile gefunden : user_pref("extensions.Softonic.instlDay", "16021"); Zeile gefunden : user_pref("extensions.Softonic.instlRef", "MOY00621"); Zeile gefunden : user_pref("extensions.Softonic.newTab", true); Zeile gefunden : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=56cac5660000000000000022fb010e18"); Zeile gefunden : user_pref("extensions.Softonic.prdct", "Softonic"); Zeile gefunden : user_pref("extensions.Softonic.prtnrId", "softonic"); Zeile gefunden : user_pref("extensions.Softonic.rvrt", "false"); Zeile gefunden : user_pref("extensions.Softonic.smplGrp", "none"); Zeile gefunden : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); Zeile gefunden : user_pref("extensions.Softonic.tlbrId", "opencandy2013"); Zeile gefunden : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=56cac5660000000000000022fb010e18&q="); Zeile gefunden : user_pref("extensions.Softonic.vrsn", "1.8.21.14"); Zeile gefunden : user_pref("extensions.Softonic.vrsnTs", "1.8.21.142:11:55"); Zeile gefunden : user_pref("extensions.Softonic.vrsni", "1.8.21.14"); -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gefunden : homepage [ Datei : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [6153 octets] - [21/12/2013 17:35:20] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [6213 octets] ########## [/CODE] AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.015 - Bericht erstellt am 21/12/2013 um 17:37:58 # Updated 10/12/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Wissem - VAIO # Gestartet von : C:\Users\Wissem\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Ordner Gelöscht : C:\Program Files\myfree codec Ordner Gelöscht : C:\Users\Wissem\AppData\LocalLow\Softonic Ordner Gelöscht : C:\Users\Wissem\AppData\Roaming\digitalsite Ordner Gelöscht : C:\Users\Wissem\AppData\Roaming\dvdvideosoftiehelpers Datei Gelöscht : C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default\searchplugins\softonic.xml Datei Gelöscht : C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default\user.js Datei Gelöscht : C:\Windows\Tasks\digitalsite.job Datei Gelöscht : C:\Windows\System32\Tasks\digitalsite ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}] [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DF7FC274-B63D-42DB-8AC9-FF733C6F2276} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF7FC274-B63D-42DB-8AC9-FF733C6F2276} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Schlüssel Gelöscht : HKCU\Software\dsiteproducts Schlüssel Gelöscht : HKCU\Software\Myfree Codec Schlüssel Gelöscht : HKLM\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyFreeCodec Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16526 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v25.0 (de) [ Datei : C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default\prefs.js ] Zeile gelöscht : user_pref("extensions.Softonic.admin", false); Zeile gelöscht : user_pref("extensions.Softonic.aflt", "OC"); Zeile gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}"); Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "de"); Zeile gelöscht : user_pref("extensions.Softonic.dfltSrch", true); Zeile gelöscht : user_pref("extensions.Softonic.dnsErr", true); Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false); Zeile gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false); Zeile gelöscht : user_pref("extensions.Softonic.hmpg", true); Zeile gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=56cac5660000000000000022fb010e18"); Zeile gelöscht : user_pref("extensions.Softonic.id", "56cac5660000000000000022fb010e18"); Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "16021"); Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00621"); Zeile gelöscht : user_pref("extensions.Softonic.newTab", true); Zeile gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=56cac5660000000000000022fb010e18"); Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic"); Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic"); Zeile gelöscht : user_pref("extensions.Softonic.rvrt", "false"); Zeile gelöscht : user_pref("extensions.Softonic.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "opencandy2013"); Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=56cac5660000000000000022fb010e18&q="); Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.21.14"); Zeile gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.21.142:11:55"); Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.21.14"); -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : homepage [ Datei : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [6293 octets] - [21/12/2013 17:35:20] AdwCleaner[S0].txt - [6168 octets] - [21/12/2013 17:37:58] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6228 octets] ########## [/CODE] 3.Schritt: Junkware Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows Vista (TM) Home Premium x86 Ran by Wissem on 21.12.2013 at 17:48:31,22 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A77706B0-D6C9-40EF-9833-2FABCC21BF88} ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 21.12.2013 at 17:51:55,39 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-12-2013 02 Ran by Wissem (administrator) on VAIO on 21-12-2013 17:55:25 Running from C:\Users\Wissem\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Realtek Semiconductor) C:\Windows\RTKAUDIOSERVICE.EXE (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Symantec Corporation) C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\nst.exe (Sony Corporation) C:\Program Files\sony\Network Utility\NSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Symantec Corporation) C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\nst.exe (Sony Corporation) C:\Program Files\sony\VAIO Power Management\SPMgr.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sony Corporation) C:\Program Files\sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files\sony\Marketing Tools\MarketingTools.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sony Corporation) C:\Program Files\sony\Network Utility\LANUtil.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Samsung Electronics) C:\Program Files\Samsung\Kies\KiesAirMessage.exe (Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Dropbox, Inc.) C:\Users\Wissem\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Sony Corporation) C:\Program Files\sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\sony\VAIO Update\VUAgent.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6295552 2008-10-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2007-03-10] (Synaptics, Inc.) HKLM\...\Run: [ISBMgr.exe] - C:\Program Files\sony\ISB Utility\ISBMgr.exe [317280 2008-04-03] (Sony Corporation) HKLM\...\Run: [MarketingTools] - C:\Program Files\sony\Marketing Tools\MarketingTools.exe [24576 2013-01-21] (Sony Corporation) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] () HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Skytel] - C:\Windows\SkyTel.exe [1826816 2008-10-17] (Realtek Semiconductor Corp.) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-04-23] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [BlueStacks Agent] - C:\Program Files\BlueStacks\HD-Agent.exe [601928 2013-07-04] (BlueStack Systems, Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: igfxdev.dll [X] Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll (Sony Corporation) HKCU\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [270336 2008-11-05] (Sony Corporation) HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1561968 2013-04-23] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe [578560 2013-03-20] (Samsung Electronics) HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844168 2013-06-04] (Samsung) HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) HKU\Gast\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) Startup: C:\Users\Wissem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Wissem\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.sonystyle-europe.com?csint=140016340 hxxp://www.club-vaio.com/vbc/ebay/index.html hxxp://www.club-vaio.com/vbc HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.sonystyle-europe.com?csint=140016340 hxxp://www.club-vaio.com/vbc/ebay/index.html hxxp://www.club-vaio.com/vbc HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {D645DA1C-3672-4AE1-AD32-6ADE02A88FD2} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta= SearchScopes: HKCU - {D645DA1C-3672-4AE1-AD32-6ADE02A88FD2} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=&rlz=1I7SNYK_de BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\coieplg.dll (Symantec Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\coieplg.dll (Symantec Corporation) Toolbar: HKCU - Norton Identity Safe Toolbar - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\coieplg.dll (Symantec Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @soe.sony.com/installer,version=1.0.3 - C:\Users\Wissem\AppData\LocalLow\Sony Online Entertainment\npsoe.dll () FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.5.0.67\coFFPlgn\ FF Extension: Norton Identity Safe Toolbar - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.5.0.67\coFFPlgn\ FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\IPSFF Chrome: ======= CHR HomePage: hxxp://www.google.com CHR DefaultSearchKeyword: google.de CHR DefaultSearchProvider: Google CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultNewTabURL: {google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Norton Identity Safe) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nppllibpnmahfaklnpggkibhkapjkeob\2013.2.1.33_0\npcoplgn.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.110.21) - C:\Windows\system32\npDeployJava1.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Google Docs) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (CnC TA Script Collection) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmhpmdclklpgfcpoiomjofgfagenmgeo\1.2.8.49_0 CHR Extension: (Google Wallet) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR Extension: (Norton Identity Protection) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nppllibpnmahfaklnpggkibhkapjkeob\2014.6.2.3_0 CHR Extension: (Gmail) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [nppllibpnmahfaklnpggkibhkapjkeob] - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\Exts\Chrome.crx ========================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2008-08-01] (ArcSoft Inc.) S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [393032 2013-07-04] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [384840 2013-07-04] (BlueStack Systems, Inc.) S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 NAV; C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation) R2 NCO; C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\diMaster.dll [567600 2013-10-03] (Symantec Corporation) R2 NSUService; C:\Program Files\sony\Network Utility\NSUService.exe [303104 2008-11-05] (Sony Corporation) S3 SOHDBSvr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [72856 2012-03-06] (Sony Corporation) S3 SOHPlMgr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [93336 2012-03-06] (Sony Corporation) R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-03-05] (Sony Corporation) R2 VAIO Event Service; C:\Program Files\sony\VAIO Event Service\VESMgr.exe [203624 2008-12-09] (Sony Corporation) R2 VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [411488 2008-09-05] (Sony Corporation) R2 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [480624 2009-09-16] (Sony Corporation) R3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-03-05] (Sony Corporation) R3 VUAgent; C:\Program Files\sony\VAIO Update\VUAgent.exe [1020976 2013-08-01] (Sony Corporation) R2 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-03-05] (Sony Corporation) S3 MSCSPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe" [x] S3 SPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe" [x] ==================== Drivers (Whitelisted) ==================== R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.) R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20131203.001\BHDrvx86.sys [1098968 2013-12-03] (Symantec Corporation) R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [63816 2013-07-04] (BlueStack Systems) R1 ccSet_NAV; C:\Windows\system32\drivers\NAV\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation) R1 ccSet_NST; C:\Windows\system32\drivers\NST\7DE06000.01B\ccSetx86.sys [127064 2013-09-27] (Symantec Corporation) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-12-18] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-11-21] (Symantec Corporation) R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20131220.001\IDSvix86.sys [394456 2013-12-13] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20131220.008\NAVENG.SYS [93272 2013-12-18] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20131220.008\NAVEX15.SYS [1612376 2013-12-18] (Symantec Corporation) R3 SRTSP; C:\Windows\System32\Drivers\NAV\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NAV\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NAV\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NAV\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NAV\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation) R1 SYMTDIv; C:\Windows\System32\Drivers\NAV\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation) S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] S3 igfx; system32\DRIVERS\igdkmd32.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S4 UIUSys; system32\DRIVERS\UIUSYS.SYS [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-21 17:51 - 2013-12-21 17:51 - 00000782 _____ C:\Users\Wissem\Desktop\JRT.txt 2013-12-21 17:35 - 2013-12-21 17:38 - 00000000 ____D C:\AdwCleaner 2013-12-21 16:27 - 2013-12-21 16:27 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Malwarebytes 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-21 16:27 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-12-21 16:24 - 2013-12-21 16:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Wissem\Desktop\mbam-setup-1.75.0.1300.exe 2013-12-21 16:24 - 2013-12-21 16:24 - 01226750 _____ C:\Users\Wissem\Desktop\adwcleaner.exe 2013-12-21 16:24 - 2013-12-21 16:24 - 01034531 _____ (Thisisu) C:\Users\Wissem\Desktop\JRT.exe 2013-12-21 05:09 - 2013-12-21 05:09 - 00008820 _____ C:\Users\Wissem\Desktop\Gmer.txt 2013-12-21 04:06 - 2013-12-21 04:14 - 00028685 _____ C:\Users\Wissem\Desktop\Addition.txt 2013-12-21 04:05 - 2013-12-21 17:55 - 00020040 _____ C:\Users\Wissem\Desktop\FRST.txt 2013-12-21 04:05 - 2013-12-21 04:05 - 00000000 ____D C:\FRST 2013-12-21 04:00 - 2013-12-21 04:01 - 00000474 _____ C:\Users\Wissem\Desktop\defogger_disable.log 2013-12-21 04:00 - 2013-12-21 04:00 - 00000000 _____ C:\Users\Wissem\defogger_reenable 2013-12-21 03:57 - 2013-12-21 03:57 - 00377856 _____ C:\Users\Wissem\Desktop\gmer_2.1.19163.exe 2013-12-21 03:56 - 2013-12-21 03:57 - 01325858 _____ (Farbar) C:\Users\Wissem\Desktop\FRST.exe 2013-12-21 03:55 - 2013-12-21 03:55 - 00050477 _____ C:\Users\Wissem\Desktop\Defogger.exe 2013-12-12 22:11 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 22:11 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 22:11 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 22:11 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 22:11 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 22:11 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 22:11 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-12 22:11 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 22:11 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-12 22:11 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-12 22:11 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 22:11 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-12 22:11 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 22:11 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-12 22:11 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 22:11 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 17:24 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-12 17:24 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-12 17:24 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-12 17:24 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 17:24 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 17:24 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 17:24 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 17:24 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-12 17:24 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 17:24 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\Users\Gast\AppData\Roaming\ArcSoft 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\ProgramData\ArcSoft 2013-11-28 23:04 - 2013-11-29 18:20 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Skype 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ___RD C:\Program Files\Skype 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-11-28 23:03 - 2013-11-28 23:03 - 35095200 _____ (Skype Technologies S.A.) C:\Users\Gast\Downloads\Skype611SetupFull.exe 2013-11-23 22:12 - 2013-11-23 22:12 - 00564736 _____ C:\Users\Wissem\Desktop\6.Std 2013 EurR.ppt ==================== One Month Modified Files and Folders ======= 2013-12-21 17:55 - 2013-12-21 04:05 - 00020040 _____ C:\Users\Wissem\Desktop\FRST.txt 2013-12-21 17:55 - 2013-06-04 18:27 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Dropbox 2013-12-21 17:51 - 2013-12-21 17:51 - 00000782 _____ C:\Users\Wissem\Desktop\JRT.txt 2013-12-21 17:48 - 2013-01-24 17:55 - 00000000 ____D C:\Windows\ERUNT 2013-12-21 17:48 - 2013-01-24 04:39 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-21 17:47 - 2013-01-21 00:42 - 01891705 _____ C:\Windows\WindowsUpdate.log 2013-12-21 17:44 - 2013-06-04 18:31 - 00000000 ___RD C:\Users\Wissem\Dropbox 2013-12-21 17:40 - 2013-01-24 04:39 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-21 17:40 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-21 17:39 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-21 17:39 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-21 17:38 - 2013-12-21 17:35 - 00000000 ____D C:\AdwCleaner 2013-12-21 17:38 - 2006-11-02 14:01 - 00032518 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-21 17:34 - 2013-01-24 04:37 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-21 17:23 - 2008-01-21 03:47 - 00370036 _____ C:\Windows\PFRO.log 2013-12-21 17:13 - 2006-11-02 12:18 - 00000000 ___RD C:\Windows\Offline Web Pages 2013-12-21 16:27 - 2013-12-21 16:27 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Malwarebytes 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-21 16:24 - 2013-12-21 16:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Wissem\Desktop\mbam-setup-1.75.0.1300.exe 2013-12-21 16:24 - 2013-12-21 16:24 - 01226750 _____ C:\Users\Wissem\Desktop\adwcleaner.exe 2013-12-21 16:24 - 2013-12-21 16:24 - 01034531 _____ (Thisisu) C:\Users\Wissem\Desktop\JRT.exe 2013-12-21 05:09 - 2013-12-21 05:09 - 00008820 _____ C:\Users\Wissem\Desktop\Gmer.txt 2013-12-21 04:14 - 2013-12-21 04:06 - 00028685 _____ C:\Users\Wissem\Desktop\Addition.txt 2013-12-21 04:05 - 2013-12-21 04:05 - 00000000 ____D C:\FRST 2013-12-21 04:01 - 2013-12-21 04:00 - 00000474 _____ C:\Users\Wissem\Desktop\defogger_disable.log 2013-12-21 04:00 - 2013-12-21 04:00 - 00000000 _____ C:\Users\Wissem\defogger_reenable 2013-12-21 04:00 - 2013-01-21 02:49 - 00000000 ____D C:\Users\Wissem 2013-12-21 03:57 - 2013-12-21 03:57 - 00377856 _____ C:\Users\Wissem\Desktop\gmer_2.1.19163.exe 2013-12-21 03:57 - 2013-12-21 03:56 - 01325858 _____ (Farbar) C:\Users\Wissem\Desktop\FRST.exe 2013-12-21 03:55 - 2013-12-21 03:55 - 00050477 _____ C:\Users\Wissem\Desktop\Defogger.exe 2013-12-21 03:26 - 2013-01-27 19:37 - 00000000 ____D C:\Users\Wissem\AppData\Local\CrashDumps 2013-12-21 00:26 - 2013-10-16 00:02 - 00000000 ____D C:\Users\Wissem\Desktop\VerfR I 2013-12-21 00:12 - 2013-10-23 12:08 - 00000092 _____ C:\Users\Wissem\AppData\Roaming\WB.CFG 2013-12-21 00:12 - 2013-10-23 12:08 - 00000006 _____ C:\Users\Wissem\AppData\Roaming\WBPU-TTL.DAT 2013-12-21 00:01 - 2013-04-20 10:41 - 00000000 ____D C:\Users\Wissem\Desktop\Europarecht 2013-12-19 01:40 - 2013-06-04 18:31 - 00000922 _____ C:\Users\Wissem\Desktop\Dropbox.lnk 2013-12-19 01:40 - 2013-06-04 18:28 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-12-17 19:12 - 2013-01-21 02:49 - 00002032 _____ C:\Users\Wissem\AppData\Local\d3d9caps.dat 2013-12-13 04:21 - 2006-11-02 13:47 - 00395888 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-13 04:18 - 2008-10-23 12:25 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-12 22:19 - 2013-01-21 01:02 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-12 22:15 - 2013-07-19 02:01 - 00000000 ____D C:\Windows\system32\MRT 2013-12-12 22:12 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-10 18:57 - 2013-01-24 04:37 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-10 18:57 - 2013-01-24 04:37 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-10 18:57 - 2013-01-21 02:49 - 00000000 ____D C:\Users\Wissem\AppData\Local\Adobe 2013-12-09 13:35 - 2013-01-21 03:54 - 00000000 ____D C:\Users\Wissem\AppData\Local\Microsoft Help 2013-12-09 00:10 - 2013-11-06 17:58 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-09 00:10 - 2013-01-21 04:23 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-11-29 18:20 - 2013-11-28 23:04 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Skype 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\Users\Gast\AppData\Roaming\ArcSoft 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\ProgramData\ArcSoft 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ___RD C:\Program Files\Skype 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-11-28 23:04 - 2013-01-22 03:04 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Skype 2013-11-28 23:04 - 2013-01-21 01:20 - 00000000 ____D C:\ProgramData\Skype 2013-11-28 23:03 - 2013-11-28 23:03 - 35095200 _____ (Skype Technologies S.A.) C:\Users\Gast\Downloads\Skype611SetupFull.exe 2013-11-23 22:12 - 2013-11-23 22:12 - 00564736 _____ C:\Users\Wissem\Desktop\6.Std 2013 EurR.ppt 2013-11-21 19:14 - 2013-04-16 05:01 - 00000000 ____D C:\Users\Wissem\Desktop\wiss Hausi 2013-11-21 12:08 - 2013-11-20 17:17 - 00011427 _____ C:\Users\Wissem\Documents\Notenliste Hadjseyd ZRecht II.xlsx Some content of TEMP: ==================== C:\Users\Wissem\AppData\Local\Temp\FileSystemView.dll C:\Users\Wissem\AppData\Local\Temp\gf5nbe4a.dll C:\Users\Wissem\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\ply7cf_y.dll C:\Users\Wissem\AppData\Local\Temp\Quarantine.exe C:\Users\Wissem\AppData\Local\Temp\VzCdb.dll C:\Users\Wissem\AppData\Local\Temp\VzCdbCtrl.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-21 17:46 ==================== End Of Log ============================ So, da bin ich mal gespannt. Was ist das alles? Beste Grüße |
22.12.2013, 07:23 | #4 |
/// the machine /// TB-Ausbilder | Phisingseite im neuen Tab im Browser? Australian brewing company?ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.12.2013, 22:54 | #5 |
| Phisingseite im neuen Tab im Browser? Australian brewing company? Also, hier ist erstmal ESET: (hat um die zwei Stunden gebraucht) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=1c853ae3f387ff4a8eb1ad9966c3fd94 # engine=16364 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-12-22 04:39:45 # local_time=2013-12-22 05:39:45 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=3590 16777213 100 90 14230489 206748571 0 0 # compatibility_mode=5892 16776574 100 95 28701157 225263113 0 0 # scanned=92733 # found=0 # cleaned=0 # scan_time=5259 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=1c853ae3f387ff4a8eb1ad9966c3fd94 # engine=16367 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-12-22 09:30:00 # local_time=2013-12-22 10:30:00 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=3590 16777213 100 90 14247904 206765986 0 0 # compatibility_mode=5892 16776574 100 95 28718572 225280528 0 0 # scanned=180425 # found=0 # cleaned=0 # scan_time=8329 dann haben wir hier checkup.txt (hat wohl nicht funktioniert??????) Code:
ATTFilter UNSUPPORTED OPERATING SYSTEM! ABORTED! FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-12-2013 01 Ran by Wissem (administrator) on VAIO on 22-12-2013 22:50:46 Running from C:\Users\Wissem\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Realtek Semiconductor) C:\Windows\RTKAUDIOSERVICE.EXE (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Symantec Corporation) C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\nst.exe (Sony Corporation) C:\Program Files\sony\Network Utility\NSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Symantec Corporation) C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\nst.exe (Sony Corporation) C:\Program Files\sony\VAIO Power Management\SPMgr.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sony Corporation) C:\Program Files\sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files\sony\Marketing Tools\MarketingTools.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sony Corporation) C:\Program Files\sony\Network Utility\LANUtil.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Samsung Electronics) C:\Program Files\Samsung\Kies\KiesAirMessage.exe (Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Dropbox, Inc.) C:\Users\Wissem\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Sony Corporation) C:\Program Files\sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\sony\VAIO Update\VUAgent.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6295552 2008-10-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2007-03-10] (Synaptics, Inc.) HKLM\...\Run: [ISBMgr.exe] - C:\Program Files\sony\ISB Utility\ISBMgr.exe [317280 2008-04-03] (Sony Corporation) HKLM\...\Run: [MarketingTools] - C:\Program Files\sony\Marketing Tools\MarketingTools.exe [24576 2013-01-21] (Sony Corporation) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] () HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Skytel] - C:\Windows\SkyTel.exe [1826816 2008-10-17] (Realtek Semiconductor Corp.) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-04-23] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [BlueStacks Agent] - C:\Program Files\BlueStacks\HD-Agent.exe [601928 2013-07-04] (BlueStack Systems, Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: igfxdev.dll [X] Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll (Sony Corporation) HKCU\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [270336 2008-11-05] (Sony Corporation) HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1561968 2013-04-23] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe [578560 2013-03-20] (Samsung Electronics) HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844168 2013-06-04] (Samsung) HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) HKU\Gast\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) Startup: C:\Users\Wissem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Wissem\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.sonystyle-europe.com?csint=140016340 hxxp://www.club-vaio.com/vbc/ebay/index.html hxxp://www.club-vaio.com/vbc HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.sonystyle-europe.com?csint=140016340 hxxp://www.club-vaio.com/vbc/ebay/index.html hxxp://www.club-vaio.com/vbc HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {D645DA1C-3672-4AE1-AD32-6ADE02A88FD2} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta= SearchScopes: HKCU - {D645DA1C-3672-4AE1-AD32-6ADE02A88FD2} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=&rlz=1I7SNYK_de BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\coieplg.dll (Symantec Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\coieplg.dll (Symantec Corporation) Toolbar: HKCU - Norton Identity Safe Toolbar - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\coieplg.dll (Symantec Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Wissem\AppData\Roaming\Mozilla\Firefox\Profiles\mi8z95u3.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @soe.sony.com/installer,version=1.0.3 - C:\Users\Wissem\AppData\LocalLow\Sony Online Entertainment\npsoe.dll () FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.5.0.67\coFFPlgn\ FF Extension: Norton Identity Safe Toolbar - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.5.0.67\coFFPlgn\ FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\IPSFF Chrome: ======= CHR HomePage: hxxp://www.google.com CHR DefaultSearchKeyword: google.de CHR DefaultSearchProvider: Google CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultNewTabURL: {google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Norton Identity Safe) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nppllibpnmahfaklnpggkibhkapjkeob\2013.2.1.33_0\npcoplgn.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.110.21) - C:\Windows\system32\npDeployJava1.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Google Docs) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (CnC TA Script Collection) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmhpmdclklpgfcpoiomjofgfagenmgeo\1.2.8.49_0 CHR Extension: (Google Wallet) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR Extension: (Norton Identity Protection) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nppllibpnmahfaklnpggkibhkapjkeob\2014.6.2.3_0 CHR Extension: (Gmail) - C:\Users\Wissem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [nppllibpnmahfaklnpggkibhkapjkeob] - C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\Exts\Chrome.crx ========================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2008-08-01] (ArcSoft Inc.) S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [393032 2013-07-04] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [384840 2013-07-04] (BlueStack Systems, Inc.) S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 NAV; C:\Program Files\Norton AntiVirus\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation) R2 NCO; C:\Program Files\Norton Identity Safe\Engine\2014.6.0.27\diMaster.dll [567600 2013-10-03] (Symantec Corporation) R2 NSUService; C:\Program Files\sony\Network Utility\NSUService.exe [303104 2008-11-05] (Sony Corporation) S3 SOHDBSvr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [72856 2012-03-06] (Sony Corporation) S3 SOHPlMgr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [93336 2012-03-06] (Sony Corporation) R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-03-05] (Sony Corporation) R2 VAIO Event Service; C:\Program Files\sony\VAIO Event Service\VESMgr.exe [203624 2008-12-09] (Sony Corporation) R2 VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [411488 2008-09-05] (Sony Corporation) R2 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [480624 2009-09-16] (Sony Corporation) R3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-03-05] (Sony Corporation) R3 VUAgent; C:\Program Files\sony\VAIO Update\VUAgent.exe [1020976 2013-08-01] (Sony Corporation) R2 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-03-05] (Sony Corporation) S3 MSCSPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe" [x] S3 SPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe" [x] ==================== Drivers (Whitelisted) ==================== R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.) R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20131203.001\BHDrvx86.sys [1098968 2013-12-03] (Symantec Corporation) R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [63816 2013-07-04] (BlueStack Systems) R1 ccSet_NAV; C:\Windows\system32\drivers\NAV\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation) R1 ccSet_NST; C:\Windows\system32\drivers\NST\7DE06000.01B\ccSetx86.sys [127064 2013-09-27] (Symantec Corporation) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-12-18] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-11-21] (Symantec Corporation) R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20131220.001\IDSvix86.sys [394456 2013-12-13] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20131221.006\NAVENG.SYS [93272 2013-12-18] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20131221.006\NAVEX15.SYS [1612376 2013-12-18] (Symantec Corporation) R3 SRTSP; C:\Windows\System32\Drivers\NAV\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NAV\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NAV\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NAV\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NAV\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation) R1 SYMTDIv; C:\Windows\System32\Drivers\NAV\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation) S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] S3 igfx; system32\DRIVERS\igdkmd32.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S4 UIUSys; system32\DRIVERS\UIUSYS.SYS [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-22 22:50 - 2013-12-22 22:50 - 00000000 ____D C:\Users\Wissem\Desktop\FRST-OlderVersion 2013-12-22 22:47 - 2013-12-22 22:47 - 00891200 _____ C:\Users\Wissem\Downloads\SecurityCheck.exe 2013-12-22 16:03 - 2013-12-22 16:03 - 00891200 _____ C:\Users\Wissem\Desktop\SecurityCheck.exe 2013-12-22 16:02 - 2013-12-22 16:02 - 02347384 _____ (ESET) C:\Users\Wissem\Desktop\esetsmartinstaller_enu.exe 2013-12-22 06:54 - 2013-12-22 06:54 - 00347816 _____ (Microsoft Corporation) C:\Users\Wissem\Desktop\MicrosoftFixit.wu.LB.3131111886110948.1.1.Run.exe 2013-12-21 17:51 - 2013-12-21 17:51 - 00000782 _____ C:\Users\Wissem\Desktop\JRT.txt 2013-12-21 17:35 - 2013-12-21 17:38 - 00000000 ____D C:\AdwCleaner 2013-12-21 16:27 - 2013-12-21 16:27 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Malwarebytes 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-21 16:27 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-12-21 16:24 - 2013-12-21 16:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Wissem\Desktop\mbam-setup-1.75.0.1300.exe 2013-12-21 16:24 - 2013-12-21 16:24 - 01226750 _____ C:\Users\Wissem\Desktop\adwcleaner.exe 2013-12-21 16:24 - 2013-12-21 16:24 - 01034531 _____ (Thisisu) C:\Users\Wissem\Desktop\JRT.exe 2013-12-21 05:09 - 2013-12-21 05:09 - 00008820 _____ C:\Users\Wissem\Desktop\Gmer.txt 2013-12-21 04:06 - 2013-12-21 04:14 - 00028685 _____ C:\Users\Wissem\Desktop\Addition.txt 2013-12-21 04:05 - 2013-12-22 22:50 - 00020235 _____ C:\Users\Wissem\Desktop\FRST.txt 2013-12-21 04:05 - 2013-12-22 22:50 - 00000000 ____D C:\FRST 2013-12-21 04:00 - 2013-12-21 04:01 - 00000474 _____ C:\Users\Wissem\Desktop\defogger_disable.log 2013-12-21 04:00 - 2013-12-21 04:00 - 00000000 _____ C:\Users\Wissem\defogger_reenable 2013-12-21 03:57 - 2013-12-21 03:57 - 00377856 _____ C:\Users\Wissem\Desktop\gmer_2.1.19163.exe 2013-12-21 03:56 - 2013-12-22 22:50 - 01061231 _____ (Farbar) C:\Users\Wissem\Desktop\FRST.exe 2013-12-21 03:55 - 2013-12-21 03:55 - 00050477 _____ C:\Users\Wissem\Desktop\Defogger.exe 2013-12-12 22:11 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 22:11 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 22:11 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 22:11 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 22:11 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 22:11 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 22:11 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-12 22:11 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 22:11 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-12 22:11 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-12 22:11 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 22:11 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-12 22:11 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 22:11 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-12 22:11 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 22:11 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 17:24 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-12 17:24 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-12 17:24 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-12 17:24 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 17:24 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 17:24 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 17:24 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 17:24 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-12 17:24 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 17:24 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\Users\Gast\AppData\Roaming\ArcSoft 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\ProgramData\ArcSoft 2013-11-28 23:04 - 2013-11-29 18:20 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Skype 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ___RD C:\Program Files\Skype 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-11-28 23:03 - 2013-11-28 23:03 - 35095200 _____ (Skype Technologies S.A.) C:\Users\Gast\Downloads\Skype611SetupFull.exe 2013-11-23 22:12 - 2013-11-23 22:12 - 00564736 _____ C:\Users\Wissem\Desktop\6.Std 2013 EurR.ppt ==================== One Month Modified Files and Folders ======= 2013-12-22 22:51 - 2013-12-21 04:05 - 00020235 _____ C:\Users\Wissem\Desktop\FRST.txt 2013-12-22 22:50 - 2013-12-22 22:50 - 00000000 ____D C:\Users\Wissem\Desktop\FRST-OlderVersion 2013-12-22 22:50 - 2013-12-21 04:05 - 00000000 ____D C:\FRST 2013-12-22 22:50 - 2013-12-21 03:56 - 01061231 _____ (Farbar) C:\Users\Wissem\Desktop\FRST.exe 2013-12-22 22:48 - 2013-01-24 04:39 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-22 22:47 - 2013-12-22 22:47 - 00891200 _____ C:\Users\Wissem\Downloads\SecurityCheck.exe 2013-12-22 22:42 - 2013-06-04 18:27 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Dropbox 2013-12-22 22:34 - 2013-01-24 04:37 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-22 21:57 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-22 21:57 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-22 20:45 - 2013-01-21 00:42 - 02054014 _____ C:\Windows\WindowsUpdate.log 2013-12-22 16:03 - 2013-12-22 16:03 - 00891200 _____ C:\Users\Wissem\Desktop\SecurityCheck.exe 2013-12-22 16:02 - 2013-12-22 16:02 - 02347384 _____ (ESET) C:\Users\Wissem\Desktop\esetsmartinstaller_enu.exe 2013-12-22 06:54 - 2013-12-22 06:54 - 00347816 _____ (Microsoft Corporation) C:\Users\Wissem\Desktop\MicrosoftFixit.wu.LB.3131111886110948.1.1.Run.exe 2013-12-22 06:49 - 2013-01-24 04:39 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-21 17:51 - 2013-12-21 17:51 - 00000782 _____ C:\Users\Wissem\Desktop\JRT.txt 2013-12-21 17:48 - 2013-01-24 17:55 - 00000000 ____D C:\Windows\ERUNT 2013-12-21 17:44 - 2013-06-04 18:31 - 00000000 ___RD C:\Users\Wissem\Dropbox 2013-12-21 17:40 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-21 17:38 - 2013-12-21 17:35 - 00000000 ____D C:\AdwCleaner 2013-12-21 17:38 - 2006-11-02 14:01 - 00032518 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-21 17:23 - 2008-01-21 03:47 - 00370036 _____ C:\Windows\PFRO.log 2013-12-21 17:23 - 2006-11-02 12:18 - 00000000 ___RD C:\Windows\Offline Web Pages 2013-12-21 16:27 - 2013-12-21 16:27 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Malwarebytes 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-21 16:27 - 2013-12-21 16:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-21 16:24 - 2013-12-21 16:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Wissem\Desktop\mbam-setup-1.75.0.1300.exe 2013-12-21 16:24 - 2013-12-21 16:24 - 01226750 _____ C:\Users\Wissem\Desktop\adwcleaner.exe 2013-12-21 16:24 - 2013-12-21 16:24 - 01034531 _____ (Thisisu) C:\Users\Wissem\Desktop\JRT.exe 2013-12-21 05:09 - 2013-12-21 05:09 - 00008820 _____ C:\Users\Wissem\Desktop\Gmer.txt 2013-12-21 04:14 - 2013-12-21 04:06 - 00028685 _____ C:\Users\Wissem\Desktop\Addition.txt 2013-12-21 04:01 - 2013-12-21 04:00 - 00000474 _____ C:\Users\Wissem\Desktop\defogger_disable.log 2013-12-21 04:00 - 2013-12-21 04:00 - 00000000 _____ C:\Users\Wissem\defogger_reenable 2013-12-21 04:00 - 2013-01-21 02:49 - 00000000 ____D C:\Users\Wissem 2013-12-21 03:57 - 2013-12-21 03:57 - 00377856 _____ C:\Users\Wissem\Desktop\gmer_2.1.19163.exe 2013-12-21 03:55 - 2013-12-21 03:55 - 00050477 _____ C:\Users\Wissem\Desktop\Defogger.exe 2013-12-21 03:26 - 2013-01-27 19:37 - 00000000 ____D C:\Users\Wissem\AppData\Local\CrashDumps 2013-12-21 00:26 - 2013-10-16 00:02 - 00000000 ____D C:\Users\Wissem\Desktop\VerfR I 2013-12-21 00:12 - 2013-10-23 12:08 - 00000092 _____ C:\Users\Wissem\AppData\Roaming\WB.CFG 2013-12-21 00:12 - 2013-10-23 12:08 - 00000006 _____ C:\Users\Wissem\AppData\Roaming\WBPU-TTL.DAT 2013-12-21 00:01 - 2013-04-20 10:41 - 00000000 ____D C:\Users\Wissem\Desktop\Europarecht 2013-12-19 01:40 - 2013-06-04 18:31 - 00000922 _____ C:\Users\Wissem\Desktop\Dropbox.lnk 2013-12-19 01:40 - 2013-06-04 18:28 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-12-17 19:12 - 2013-01-21 02:49 - 00002032 _____ C:\Users\Wissem\AppData\Local\d3d9caps.dat 2013-12-13 04:21 - 2006-11-02 13:47 - 00395888 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-13 04:18 - 2008-10-23 12:25 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-12 22:19 - 2013-01-21 01:02 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-12 22:15 - 2013-07-19 02:01 - 00000000 ____D C:\Windows\system32\MRT 2013-12-12 22:12 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-10 18:58 - 2013-01-21 02:49 - 00000000 ____D C:\Users\Wissem\AppData\Local\Adobe 2013-12-10 18:57 - 2013-01-24 04:37 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-10 18:57 - 2013-01-24 04:37 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-09 13:35 - 2013-01-21 03:54 - 00000000 ____D C:\Users\Wissem\AppData\Local\Microsoft Help 2013-12-09 00:10 - 2013-11-06 17:58 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-09 00:10 - 2013-01-21 04:23 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-11-29 18:20 - 2013-11-28 23:04 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Skype 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\Users\Gast\AppData\Roaming\ArcSoft 2013-11-28 23:06 - 2013-11-28 23:06 - 00000000 ____D C:\ProgramData\ArcSoft 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ___RD C:\Program Files\Skype 2013-11-28 23:04 - 2013-11-28 23:04 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-11-28 23:04 - 2013-01-22 03:04 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Skype 2013-11-28 23:04 - 2013-01-21 01:20 - 00000000 ____D C:\ProgramData\Skype 2013-11-28 23:03 - 2013-11-28 23:03 - 35095200 _____ (Skype Technologies S.A.) C:\Users\Gast\Downloads\Skype611SetupFull.exe 2013-11-23 22:12 - 2013-11-23 22:12 - 00564736 _____ C:\Users\Wissem\Desktop\6.Std 2013 EurR.ppt Some content of TEMP: ==================== C:\Users\Wissem\AppData\Local\Temp\FileSystemView.dll C:\Users\Wissem\AppData\Local\Temp\gf5nbe4a.dll C:\Users\Wissem\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Wissem\AppData\Local\Temp\ply7cf_y.dll C:\Users\Wissem\AppData\Local\Temp\Quarantine.exe C:\Users\Wissem\AppData\Local\Temp\VzCdb.dll C:\Users\Wissem\AppData\Local\Temp\VzCdbCtrl.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-21 17:46 ==================== End Of Log ============================ Also das Problem erscheint grade nicht. Hoffe mein PC ist jetzt wieder gesichert und ich muss mir über phising keine Gedanken machen? Aber was ist das mit Checkup???? Danke schonmal. |
23.12.2013, 19:44 | #6 |
/// the machine /// TB-Ausbilder | Phisingseite im neuen Tab im Browser? Australian brewing company? Securitycheck ignorieren, das ist ne Zicke. Fertig Falls Du Lob oder Kritik loswerden möchtest kannst Du das hier tun Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Phisingseite im neuen Tab im Browser? Australian brewing company? |
25.12.2013, 21:51 | #7 |
| Phisingseite im neuen Tab im Browser? Australian brewing company? Ich danke dir herzlichst und wünsche dir noch rein besinnliches Restweihnachten plus ein guten Rutsch ins neue Jahr. |
26.12.2013, 14:45 | #8 |
/// the machine /// TB-Ausbilder | Phisingseite im neuen Tab im Browser? Australian brewing company? Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Phisingseite im neuen Tab im Browser? Australian brewing company? |
antivirus, bluestacks, branding, browser, device driver, error, flash player, google, home, mp3, msil.solimba, ntdll.dll, plug-in, pup.optional.bundleinstaller.a, pup.optional.digitalsite.a, pup.optional.digitalsites.a, pup.optional.ibryte, pup.optional.opencandy, pup.optional.pricepeep.a, registry, security, server, svchost.exe, symantec, windows |