|
Plagegeister aller Art und deren Bekämpfung: snap.do nicht deinstallierbar windows vistaWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
08.02.2014, 18:50 | #1 |
| snap.do nicht deinstallierbar windows vista Hallo, Ich hatte auf meinem Laptop auf einmal snap.do. Sowohl zu sehen unter Programmen und Funktionen als auch im Browser als Startseite. Obwohl ich des öfteren bereits versucht habe, eine andere Startseite einzustellen. Es fing an mit awesomehp, habe versucht awesomehp zu entfernen, schien auch zu funktionieren (Anleitung von browserdoktor.de) doch dann tauchte zusätzlich auchnoch Snap.do auf. Habe snap.do nach Anleitung von chip versucht zu entfernen, war jedoch nicht möglich. Habe den Verdacht, dass durch awesomehp erst snap.do gekommen ist. Habe nun beides auf meinem Rechner und bin verzweifelt. Wie kann ich beides entgültig entfernen? Ich bin kein Experte mit PC's, sorry falls ich also alles nachfrage. Danke schonmal für Hilfe Lg.: Holly-Blue |
08.02.2014, 19:16 | #2 |
/// the machine /// TB-Ausbilder | snap.do nicht deinstallierbar windows vista hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
08.02.2014, 19:52 | #3 |
| snap.do nicht deinstallierbar windows vista Hi,
__________________habe wie beschrieben die Version gedownloadet und dies sind die Ergebnisse: Musste ich das einfach nur kopieren? frst.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-02-2014 Ran by Bambi (administrator) on BAMBI-PC on 08-02-2014 19:43:47 Running from C:\Users\Bambi\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://splashurl.com/oevqrf3 Download link for 64-Bit Version: hxxp://splashurl.com/p7mksw6 Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://splashurl.com/npm5jht ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TEco.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe () C:\Program Files\SmarThru Office\BackUpSvr.exe () C:\Program Files\SmarThru Office\LegacyLauncher.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Updater) C:\ProgramData\Updater\updater.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (TOSHIBA) C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe (EasyBits Software AS) C:\ProgramData\GameXN\GameXNGO.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (WatchDog) C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe (WatchDog) C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (WatchDog) C:\ProgramData\RHelpers\IeHelper\IeHelper.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\hidfind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (Parallel Lines Development, LLC) C:\ProgramData\InternetUpdater\InternetUpdaterService.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [421888 2007-04-16] (TOSHIBA Electronics, Inc.) HKLM\...\Run: [SVPWUTIL] - C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [438272 2008-11-21] (TOSHIBA) HKLM\...\Run: [KeNotify] - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe [34088 2009-01-13] (TOSHIBA CORPORATION) HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe [1011712 2009-04-23] (TOSHIBA Corporation) HKLM\...\Run: [Google Desktop Search] - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-09-01] (Google) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7289376 2009-03-30] (Realtek Semiconductor) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2009-04-21] (Advanced Micro Devices, Inc.) HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [468320 2009-03-06] (TOSHIBA Corporation) HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [55160 2009-03-09] (TOSHIBA Corporation) HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [503808 2009-03-31] (TOSHIBA Corporation) HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [729088 2009-03-23] (TOSHIBA Corporation) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [184320 2009-03-29] (Alps Electric Co., Ltd.) HKLM\...\Run: [SmartFaceVWatcher] - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [163840 2009-03-24] (TOSHIBA Corporation) HKLM\...\Run: [Teco] - C:\Program Files\TOSHIBA\TECO\Teco.exe [1323008 2009-04-24] (TOSHIBA Corporation) HKLM\...\Run: [ToshibaServiceStation] - C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295736 2011-02-11] (TOSHIBA Corporation) HKLM\...\Run: [TPCHWMsg] - C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe [570736 2009-04-15] (TOSHIBA Corporation) HKLM\...\Run: [NDSTray.exe] - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe [299008 2009-05-12] (TOSHIBA CORPORATION) HKLM\...\Run: [cfFncEnabler.exe] - C:\Program Files\TOSHIBA\ConfigFree\cfFncEnabler.exe [16384 2009-03-24] (Toshiba Corporation) HKLM\...\Run: [TWebCamera] - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2513472 2009-04-16] (TOSHIBA) HKLM\...\Run: [Toshiba TEMPRO] - C:\Program Files\Toshiba TEMPRO\TemproTray.exe [1050072 2010-10-26] (Toshiba Europe GmbH) HKLM\...\Run: [Toshiba Registration] - C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [96144 2009-03-04] (Toshiba Europe GmbH) HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [340520 2010-08-22] (Kaspersky Lab) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-03-30] (Realtek Semiconductor Corp.) HKLM\...\Run: [STO Backup Service] - C:\Program Files\SmarThru Office\BackUpSvr.exe [184320 2009-07-01] () HKLM\...\Run: [STO Launcher Service] - C:\Program Files\SmarThru Office\LegacyLauncher.exe [331776 2009-07-01] () HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\ssmmgr.exe [614400 2009-09-23] () HKLM\...\Run: [] - [X] HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-05-30] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [Updater] - C:\ProgramData\Updater\Updater.exe [486264 2013-12-18] (Updater) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe Winlogon\Notify\klogon: C:\Windows\system32\klogon.dll (Kaspersky Lab) HKU\.DEFAULT\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [6158240 2009-03-16] (TOSHIBA) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3040194652-3351564512-1966064265-1000\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [6158240 2009-03-16] (TOSHIBA) HKU\S-1-5-21-3040194652-3351564512-1966064265-1000\...\Run: [GameXN GO] - C:\ProgramData\GameXN\GameXNGO.exe [347008 2011-09-01] (EasyBits Software AS) HKU\S-1-5-21-3040194652-3351564512-1966064265-1000\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-18] (Updater) HKU\S-1-5-21-3040194652-3351564512-1966064265-1000\...\MountPoints2: {4f185bbd-e8ad-11de-b3e3-0026222f70a8} - D:\.\Kassettenrecorder.exe AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll => C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll [17936 2009-11-17] (Kaspersky Lab) AppInit_DLLs: c:\progra~1\google\google~3\goec62~1.dll => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-09-01] (Google) Startup: C:\Users\Bambi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://splashurl.com/nzqqwb4 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://splashurl.com/pehwg5v HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://splashurl.com/nzqqwb4 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://splashurl.com/pehwg5v HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://splashurl.com/od87e55 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://splashurl.com/od87e55 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://splashurl.com/ok3jybu SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Avira Savings Advisor BHO - {A18A516C-AA41-46A9-92DB-60208917E442} - C:\Program Files\avira\Internet Explorer\avira32.dll () BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://splashurl.com/qfroz6o Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default FF NewTab: hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=TuguuTU&co=DE&userid=2aafde73-17d3-97c3-e54c-63c7ef6a3c1a&searchtype=nt&installDate=06/02/2014 FF Homepage: about:home FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=TuguuTU&co=DE&userid=2aafde73-17d3-97c3-e54c-63c7ef6a3c1a&searchtype=ds&installDate=06/02/2014&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin: @google.com/npPicasa2,version=2.0.0 - C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\awesomehp.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Savings Advisor - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\ciuvo-extension@avira.de [2014-02-05] FF Extension: Snap.Do - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\{2aafde73-17d3-97c3-e54c-63c7ef6a3c1a} [2014-02-06] FF Extension: SnapDo - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\firefox@splashurl.com.xpi [2014-02-06] FF Extension: Extension_Protected - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\jid0-O6MIff3eO5dIGf5Tcv8RsJDKxrs@jetpack.xpi [2014-01-29] FF Extension: Kaspersky URL Advisor - C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2014-01-11] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: [lightningnewtab@gmail.com] - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\extensions\lightningnewtab@gmail.com.xpi FF HKLM\...\Thunderbird\Extensions: [{eea12ec4-729d-4703-bc37-106ce9879ce2}] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt FF Extension: Kaspersky Anti-Spam Extension - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2009-10-26] FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe hxxp://splashurl.com/ok3jybu Chrome: ======= CHR HomePage: hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=TuguuTU&co=DE&userid=2aafde73-17d3-97c3-e54c-63c7ef6a3c1a&searchtype=hp&installDate=06/02/2014 CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=TuguuTU&co=DE&userid=2aafde73-17d3-97c3-e54c-63c7ef6a3c1a&searchtype=hp&installDate=06/02/2014" ], "restore_on_startup" CHR Extension: (YouTube) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-05] CHR Extension: (Avira Sparberater) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cojnmaaohncijldefpkpkkakjonfmgeb [2014-02-05] CHR Extension: (Google-Suche) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-05] CHR Extension: (Re-markit) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcpfhaghaadpjpgocojgnlhjcieeooel [2014-02-05] CHR Extension: (SnapDo) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj [2014-02-06] CHR Extension: (Google Wallet) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-05] CHR Extension: (Google Mail) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-05] CHR Extension: (Lightning speedDial) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkndmigholgfjlniaohblojbhgjbkakn [2014-02-05] CHR HKLM\...\Chrome\Extension: [cojnmaaohncijldefpkpkkakjonfmgeb] - C:\Program Files\avira\Chrome\avira-1.5.14.crx [2013-12-11] CHR HKLM\...\Chrome\Extension: [pkndmigholgfjlniaohblojbhgjbkakn] - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx [2014-01-29] CHR StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://splashurl.com/ok3jybu CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG) R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [340520 2010-08-22] (Kaspersky Lab) R2 camsvc; C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe [20544 2009-04-16] (TOSHIBA) R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION) S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-09-01] (Google) R2 InternetUpdater; C:\ProgramData\InternetUpdater\InternetUpdaterService.exe [45568 2014-01-15] (Parallel Lines Development, LLC) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [235216 2013-09-06] (McAfee, Inc.) R2 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [124368 2010-10-26] (Toshiba Europe GmbH) R3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [54136 2011-02-11] (TOSHIBA Corporation) R2 TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [176128 2009-04-24] (TOSHIBA Corporation) R2 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [73728 2009-03-17] (TOSHIBA Corporation) R2 TPCHSrv; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [656752 2009-04-15] (TOSHIBA Corporation) S2 ca82e1a5; "C:\Windows\system32\rundll32.exe" "c:\progra~1\optimi~1\OptProCrashSvc.dll",ServiceMain ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-18] (Avira Operations GmbH & Co. KG) R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [128016 2009-09-01] (Kaspersky Lab) R0 klbg; C:\Windows\System32\drivers\klbg.sys [36880 2009-10-14] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [311312 2009-11-17] (Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [21520 2009-09-14] (Kaspersky Lab) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [19472 2009-10-02] (Kaspersky Lab) R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [25896 2008-05-07] (COMPAL ELECTRONIC INC.) R3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [22272 2009-03-18] (TOSHIBA Corporation) R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [154272 2008-11-11] (Realtek Semiconductor Corp.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-18] (Avira GmbH) R2 TVALZFL; C:\Windows\System32\DRIVERS\TVALZFL.sys [12920 2009-03-20] (TOSHIBA Corporation) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-08 19:43 - 2014-02-08 19:44 - 00024616 _____ () C:\Users\Bambi\Downloads\FRST.txt 2014-02-08 19:43 - 2014-02-08 19:43 - 00000000 ____D () C:\FRST 2014-02-08 19:38 - 2014-02-08 19:38 - 01136640 _____ (Farbar) C:\Users\Bambi\Downloads\FRST.exe 2014-02-08 12:00 - 2014-02-08 12:00 - 00000000 ____D () C:\ProgramData\InternetUpdater 2014-02-06 16:33 - 2014-02-06 22:04 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Mobogenie 2014-02-06 16:33 - 2014-02-06 16:52 - 00000000 ____D () C:\Users\Bambi\AppData\Local\cache 2014-02-06 16:33 - 2014-02-06 16:33 - 00002029 _____ () C:\Users\Bambi\Desktop\Search.lnk 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\Documents\Mobogenie 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\newnext.me 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\genienext 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\.android 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 _____ () C:\Users\Bambi\daemonprocess.txt 2014-02-05 18:53 - 2014-02-05 18:53 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\Avira 2014-02-05 18:47 - 2014-02-05 18:53 - 00000000 ____D () C:\Program Files\Avira 2014-02-05 18:47 - 2014-02-05 18:47 - 00001812 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-02-05 18:47 - 2014-02-05 18:47 - 00000000 ____D () C:\ProgramData\Avira 2014-02-05 18:47 - 2013-12-18 09:32 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-02-05 18:47 - 2013-12-18 09:32 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-02-05 18:47 - 2013-12-18 09:32 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-02-05 18:47 - 2013-12-18 09:32 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2014-02-04 22:01 - 2014-02-04 22:01 - 00000000 ____D () C:\ProgramData\Websteroids 2014-02-04 21:44 - 2014-02-04 21:44 - 01166132 _____ () C:\Users\Bambi\Downloads\adwcleaner-3.018.exe 2014-02-02 20:35 - 2014-02-02 20:35 - 00000000 ____D () C:\ProgramData\Updater 2014-02-02 20:35 - 2014-02-02 20:35 - 00000000 ____D () C:\ProgramData\RHelpers 2014-02-02 20:34 - 2014-02-07 23:33 - 00000000 ____D () C:\AdwCleaner 2014-02-02 20:33 - 2014-02-02 20:33 - 00000000 ____D () C:\Users\Bambi\Downloads\AdwCleaner_TSV43DG5U 2014-01-29 18:28 - 2014-01-29 18:28 - 00000879 _____ () C:\Users\Bambi\Desktop\Continue VuuPC Installation.lnk 2014-01-29 18:19 - 2014-02-06 16:30 - 00001719 _____ () C:\Users\Bambi\Desktop\Sync Folder.lnk 2014-01-29 18:18 - 2014-02-06 22:23 - 00000000 ____D () C:\Program Files\SupTab 2014-01-29 18:18 - 2014-02-04 21:41 - 00000000 ____D () C:\ProgramData\WPM 2014-01-29 18:18 - 2014-02-02 20:20 - 00000000 ____D () C:\ProgramData\IePluginService 2014-01-15 14:12 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-01-15 14:12 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-15 14:12 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-15 14:12 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-15 14:11 - 2014-01-15 14:12 - 00005315 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-01-12 18:39 - 2014-01-12 18:39 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Macromedia 2014-01-11 15:50 - 2014-01-11 15:50 - 00000000 ____D () C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-02-08 19:44 - 2014-02-08 19:43 - 00024616 _____ () C:\Users\Bambi\Downloads\FRST.txt 2014-02-08 19:43 - 2014-02-08 19:43 - 00000000 ____D () C:\FRST 2014-02-08 19:38 - 2014-02-08 19:38 - 01136640 _____ (Farbar) C:\Users\Bambi\Downloads\FRST.exe 2014-02-08 19:36 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-08 19:36 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-08 19:35 - 2011-09-01 21:19 - 00000000 ____D () C:\ProgramData\GameXN 2014-02-08 19:16 - 2012-07-14 19:10 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-08 18:57 - 2010-02-16 21:19 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-08 18:43 - 2009-08-13 12:28 - 01843987 _____ () C:\Windows\WindowsUpdate.log 2014-02-08 16:03 - 2011-06-11 14:14 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\go 2014-02-08 13:24 - 2012-03-26 20:03 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cd0b832a3e8c5c.job 2014-02-08 12:00 - 2014-02-08 12:00 - 00000000 ____D () C:\ProgramData\InternetUpdater 2014-02-07 23:48 - 2008-01-21 08:16 - 01475854 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-07 23:45 - 2009-10-26 22:12 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-02-07 23:40 - 2008-01-21 03:47 - 00583236 _____ () C:\Windows\PFRO.log 2014-02-07 23:40 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-07 23:39 - 2006-11-02 14:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-07 23:33 - 2014-02-02 20:34 - 00000000 ____D () C:\AdwCleaner 2014-02-06 22:23 - 2014-01-29 18:18 - 00000000 ____D () C:\Program Files\SupTab 2014-02-06 22:04 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Mobogenie 2014-02-06 20:20 - 2009-10-26 21:39 - 00020480 _____ () C:\Users\Bambi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-02-06 16:52 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\cache 2014-02-06 16:33 - 2014-02-06 16:33 - 00002029 _____ () C:\Users\Bambi\Desktop\Search.lnk 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\Documents\Mobogenie 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\newnext.me 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\genienext 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\.android 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 _____ () C:\Users\Bambi\daemonprocess.txt 2014-02-06 16:33 - 2009-10-26 20:12 - 00000000 ____D () C:\Users\Bambi 2014-02-06 16:30 - 2014-01-29 18:19 - 00001719 _____ () C:\Users\Bambi\Desktop\Sync Folder.lnk 2014-02-05 18:53 - 2014-02-05 18:53 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\Avira 2014-02-05 18:53 - 2014-02-05 18:47 - 00000000 ____D () C:\Program Files\Avira 2014-02-05 18:47 - 2014-02-05 18:47 - 00001812 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-02-05 18:47 - 2014-02-05 18:47 - 00000000 ____D () C:\ProgramData\Avira 2014-02-04 22:16 - 2012-07-14 19:10 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-04 22:16 - 2012-07-14 19:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-04 22:01 - 2014-02-04 22:01 - 00000000 ____D () C:\ProgramData\Websteroids 2014-02-04 21:44 - 2014-02-04 21:44 - 01166132 _____ () C:\Users\Bambi\Downloads\adwcleaner-3.018.exe 2014-02-04 21:41 - 2014-01-29 18:18 - 00000000 ____D () C:\ProgramData\WPM 2014-02-04 21:39 - 2013-03-17 13:23 - 00000811 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-02-02 20:58 - 2010-01-10 14:00 - 00000924 _____ () C:\Users\Bambi\Desktop\Internet Explorer.lnk 2014-02-02 20:43 - 2012-08-03 23:49 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft 2014-02-02 20:35 - 2014-02-02 20:35 - 00000000 ____D () C:\ProgramData\Updater 2014-02-02 20:35 - 2014-02-02 20:35 - 00000000 ____D () C:\ProgramData\RHelpers 2014-02-02 20:33 - 2014-02-02 20:33 - 00000000 ____D () C:\Users\Bambi\Downloads\AdwCleaner_TSV43DG5U 2014-02-02 20:20 - 2014-01-29 18:18 - 00000000 ____D () C:\ProgramData\IePluginService 2014-01-30 10:59 - 2010-09-01 21:01 - 00000680 _____ () C:\Users\Bambi\AppData\Local\d3d9caps.dat 2014-01-29 18:28 - 2014-01-29 18:28 - 00000879 _____ () C:\Users\Bambi\Desktop\Continue VuuPC Installation.lnk 2014-01-29 18:17 - 2013-03-05 14:40 - 00002130 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-29 18:17 - 2009-10-26 20:35 - 00001156 _____ () C:\Users\Bambi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-16 12:22 - 2013-09-03 19:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-16 12:18 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-01-15 14:15 - 2013-11-02 15:55 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-15 14:12 - 2014-01-15 14:11 - 00005315 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-01-15 14:12 - 2012-06-27 13:05 - 00000000 ____D () C:\Program Files\Java 2014-01-12 18:39 - 2014-01-12 18:39 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Macromedia 2014-01-12 18:38 - 2009-10-26 21:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Adobe 2014-01-12 12:02 - 2013-03-17 13:22 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-01-11 15:50 - 2014-01-11 15:50 - 00000000 ____D () C:\Program Files\Mozilla Firefox Some content of TEMP: ==================== C:\Users\Bambi\AppData\Local\Temp\ApnStub.exe C:\Users\Bambi\AppData\Local\Temp\avgnt.exe C:\Users\Bambi\AppData\Local\Temp\BackupSetup.exe C:\Users\Bambi\AppData\Local\Temp\contentDATs.exe C:\Users\Bambi\AppData\Local\Temp\drm_dialogs.dll C:\Users\Bambi\AppData\Local\Temp\drm_dyndata_7410004.dll C:\Users\Bambi\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Bambi\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Bambi\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Bambi\AppData\Local\Temp\ICReinstall_Setup.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u17-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u19-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u20-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u21-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\ndqqarkn.dll C:\Users\Bambi\AppData\Local\Temp\NEW5D61.tmp.exe C:\Users\Bambi\AppData\Local\Temp\NEWF711.tmp.exe C:\Users\Bambi\AppData\Local\Temp\nsb8DB4.exe C:\Users\Bambi\AppData\Local\Temp\nsbA21F.exe C:\Users\Bambi\AppData\Local\Temp\nsg1D09.exe C:\Users\Bambi\AppData\Local\Temp\nsg75C0.exe C:\Users\Bambi\AppData\Local\Temp\nsl3BA1.exe C:\Users\Bambi\AppData\Local\Temp\nsq5643.exe C:\Users\Bambi\AppData\Local\Temp\pcspeedmaxsetup.exe C:\Users\Bambi\AppData\Local\Temp\Quarantine.exe C:\Users\Bambi\AppData\Local\Temp\Refresh.exe C:\Users\Bambi\AppData\Local\Temp\SecurityScan_Release.exe C:\Users\Bambi\AppData\Local\Temp\setup.exe C:\Users\Bambi\AppData\Local\Temp\setup{D6921DE2-4509-4629-A14A-5755138AA61A}.exe C:\Users\Bambi\AppData\Local\Temp\SkypeSetup.exe C:\Users\Bambi\AppData\Local\Temp\TEMPRO_2.3.1.exe C:\Users\Bambi\AppData\Local\Temp\vcredist_x86.exe C:\Users\Bambi\AppData\Local\Temp\_is5234.exe C:\Users\Bambi\AppData\Local\Temp\_is5A8E.exe C:\Users\Bambi\AppData\Local\Temp\_prgorxj.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-07 23:49 ==================== End Of Log ============================ und addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 07-02-2014 Ran by Bambi at 2014-02-08 19:44:54 Running from C:\Users\Bambi\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Enabled - Out of date) {56547CC9-C9B2-849D-8FEF-A496150D6A06} AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Kaspersky Internet Security (Enabled - Up to date) {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} FW: Kaspersky Internet Security (Enabled) {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D} ==================== Installed Programs ====================== Activation Assistant for the 2007 Microsoft Office suites (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 12 ActiveX (Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Reader 9.5.5 - Deutsch (Version: 9.5.5 - Adobe Systems Incorporated) Age of Empires III (Version: 1.00.0000 - Microsoft Game Studios) Age of Empires III (Version: 1.00.0000 - Microsoft Game Studios) Hidden ALPS Touch Pad Driver (Version: 7.2.302.105 - ALPS ELECTRIC CO., LTD.) Apple Application Support (Version: 2.1.9 - Apple Inc.) Apple Mobile Device Support (Version: 5.2.0.6 - Apple Inc.) Apple Software Update (Version: 2.1.3.127 - Apple Inc.) ATI Catalyst Install Manager (Version: 3.0.723.0 - ATI Technologies, Inc.) Avira Free Antivirus (Version: 14.0.2.344 - Avira) Avira Savings Advisor (Version: 1.5.14 - Avira) Bonjour (Version: 3.0.0.10 - Apple Inc.) Catalyst Control Center - Branding (Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (Version: 2009.0421.2132.36832 - ATI) Hidden Catalyst Control Center Graphics Full Existing (Version: 2009.0421.2132.36832 - ATI) Hidden Catalyst Control Center Graphics Full New (Version: 2009.0421.2132.36832 - ATI) Hidden Catalyst Control Center Graphics Light (Version: 2009.0421.2132.36832 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (Version: 2009.0421.2132.36832 - ATI) Hidden Catalyst Control Center InstallProxy (Version: 2009.0421.2132.36832 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (Version: 2009.0421.2132.36832 - ATI) Hidden CCC Help Chinese Standard (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Chinese Traditional (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Czech (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Danish (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Dutch (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help English (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Finnish (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help French (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help German (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Greek (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Hungarian (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Italian (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Japanese (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Korean (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Norwegian (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Polish (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Portuguese (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Russian (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Spanish (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Swedish (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Thai (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Turkish (Version: 2009.0421.2131.36832 - ATI) Hidden ccc-core-static (Version: 2009.0421.2132.36832 - Ihr Firmenname) Hidden ccc-utility (Version: 2009.0421.2132.36832 - ATI) Hidden Compatibility Pack für 2007 Office System (Version: 12.0.4518.1014 - Microsoft Corporation) Free YouTube to MP3 Converter version 3.11.26.706 (Version: 3.11.26.706 - DVDVideoSoft Ltd.) GameXN GO (HKCU Version: - GameXN AS) Google Chrome (Version: 32.0.1700.102 - Google Inc.) Google Desktop (Version: 5.9.1005.12335 - Google) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden Google Toolbar for Internet Explorer (Version: 7.5.4805.320 - Google Inc.) Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden Intel® Matrix Storage Manager (Version: - Intel Corporation) Internet Updater (Version: 2.6.57 - Parallel Lines Development, LLC) <==== ATTENTION Java 7 Update 51 (Version: 7.0.510 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Kaspersky Internet Security 2010 (Version: 9.0.0.736 - Kaspersky Lab) Kaspersky Internet Security 2010 (Version: 9.0.0.736 - Kaspersky Lab) Hidden McAfee Security Scan Plus (Version: 3.8.130.10 - McAfee, Inc.) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Home and Student 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Word 2000 SR-1 (Version: 9.00.3821 - Microsoft Corporation) Microsoft Works (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla) Mozilla Maintenance Service (Version: 26.0 - Mozilla) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) myphotobook 3.65 (Version: 3.65 - myphotobook) Picasa 2 (Version: 2.0 - Google, Inc.) PlayReady PC runtime (Version: 1 - Microsoft Corporation) Readiris Pro 10 (Version: - ) Realtek 8136 8168 8169 Ethernet Driver (Version: 1.00.0004 - Realtek) Realtek High Definition Audio Driver (Version: 6.0.1.5821 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (Version: 6.0.6000.20132 - Realtek Semiconductor Corp.) Samsung SCX-4x25 Series (Version: - Samsung Electronics CO.,LTD) Skins (Version: 2009.0421.2132.36832 - ATI) Hidden Skype Toolbars (Version: 1.0.4051 - Skype Technologies S.A.) SmarThru Office (Version: 2.0 - Samsung) SmarThru Office PC Fax (Version: - ) Snap.Do (Version: 10.206.1.14585 - ReSoft Ltd.) <==== ATTENTION Snap.Do Engine (HKCU Version: 10.206.1.14585 - ReSoft Ltd.) <==== ATTENTION Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0 - Adobe Systems Incorporated) TOSHIBA Assist (Version: 2.01.10 - TOSHIBA) TOSHIBA Benutzerhandbücher (Version: 7.40 - TOSHIBA) TOSHIBA ConfigFree (Version: 7.4.9 - TOSHIBA Corporation) TOSHIBA Disc Creator (Version: 2.0.1.3 - TOSHIBA Corporation) TOSHIBA DVD PLAYER (Version: 3.00.1.04-A - TOSHIBA Corporation) TOSHIBA eco Utility (Version: 1.0.3.0 - TOSHIBA Corporation) TOSHIBA eco Utility (Version: 1.0.3.0 - TOSHIBA Corporation) Hidden TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00 - Toshiba) TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00 - Toshiba) Hidden TOSHIBA Face Recognition (Version: 3.0.5.32 - TOSHIBA Corporation) TOSHIBA Face Recognition (Version: 3.0.5.32 - TOSHIBA Corporation) Hidden TOSHIBA Flash Cards Support Utility (Version: 1.63.0.3C - TOSHIBA CORPORATION) TOSHIBA Flash Cards Support Utility (Version: 1.63.0.3C - TOSHIBA CORPORATION) Hidden TOSHIBA Hardware Setup (Version: 1.63.0.6C - TOSHIBA CORPORATION) TOSHIBA Hardware Setup (Version: 1.63.0.6C - TOSHIBA CORPORATION) Hidden TOSHIBA HDD/SSD Alert (Version: 3.0.0.1 - TOSHIBA Corporation) TOSHIBA HDD/SSD Alert (Version: 3.0.0.1 - TOSHIBA Corporation) Hidden Toshiba Online Product Information (Version: 2.06.0000 - TOSHIBA) TOSHIBA PC Health Monitor (Version: 1.3.2.0 - TOSHIBA Corporation) TOSHIBA Recovery Disc Creator (Version: 2.0.0.2 - TOSHIBA) TOSHIBA Recovery Disk Creator Reminder (Version: 1.00.0017 - TOSHIBA) TOSHIBA Recovery Disk Creator Reminder (Version: 1.00.0017 - TOSHIBA) Hidden TOSHIBA SD Memory Utilities (Version: 1.8.1.6 - TOSHIBA) TOSHIBA Service Station (Version: 2.2.9 - TOSHIBA) TOSHIBA Supervisor Password (Version: 1.63.0.3C - TOSHIBA CORPORATION) Hidden TOSHIBA Supervisorkennwort (Version: 1.63.0.3C - TOSHIBA CORPORATION) Toshiba TEMPRO (Version: 2.31 - Toshiba Europe GmbH) TOSHIBA Value Added Package (Version: 1.2.8 - TOSHIBA Corporation) TOSHIBA Value Added Package (Version: 1.2.8 - TOSHIBA Corporation) Hidden TOSHIBA Web Camera Application (Version: 1.0.1.8 - TOSHIBA Corporation) TRORDCLauncher (Version: 1.0.0.6 - TOSHIBA) TRORDCLauncher (Version: 1.0.0.6 - TOSHIBA) Hidden Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3 - Microsoft Corporation) Update for Office 2007 (KB934528) (Version: - ) Update for Office System 2007 Setup (KB929722) (Version: - ) Update Installer for WildTangent Games App (Version: - WildTangent) Hidden Updater (Version: 2.6.53 - Creative Island Media, LLC) <==== ATTENTION Utility Common Driver (Version: 1.0.50.22C - TOSHIBA) Hidden WildTangent Games App (Toshiba Games) (Version: 4.0.5.14 - WildTangent) WildTangent-Spiele (Version: 1.0.0.71 - WildTangent) ==================== Restore Points ========================= 02-11-2013 14:51:35 Installed Java 7 Update 45 25-11-2013 16:22:54 Windows Update 05-12-2013 22:25:07 Geplanter Prüfpunkt 14-12-2013 12:09:35 Geplanter Prüfpunkt 15-12-2013 02:00:14 Windows Update 15-12-2013 17:58:17 Geplanter Prüfpunkt 21-12-2013 16:20:22 Geplanter Prüfpunkt 11-01-2014 15:26:15 Geplanter Prüfpunkt 15-01-2014 13:10:22 Installed Java 7 Update 51 16-01-2014 11:15:28 Windows Update 06-02-2014 21:05:34 Removed Snap.Do 06-02-2014 21:13:31 Removed Snap.Do 06-02-2014 21:18:55 Removed Snap.Do 06-02-2014 21:40:21 Removed Snap.Do 07-02-2014 21:55:45 Removed Snap.Do 07-02-2014 22:03:30 Removed Snap.Do 07-02-2014 22:08:39 Removed Snap.Do 07-02-2014 22:10:14 Removed Snap.Do 07-02-2014 22:14:34 Removed Snap.Do 07-02-2014 22:19:31 Removed Snap.Do 08-02-2014 17:29:00 Removed Skype Toolbars ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {013D6924-A574-489D-B1B2-876DD2E22E66} - System32\Tasks\GoogleUpdateTaskMachineCore1cd0b832a3e8c5c => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-16] (Google Inc.) Task: {1A1388F4-3E9E-432C-8FA0-C73254006951} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-16] (Google Inc.) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {6EACA9B3-2365-44F1-96E5-DA1A30FF8920} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {83C7B9F1-D39B-4250-BCA0-05C312ADBFF9} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {AAD27565-19A6-4F1B-AFFB-53E8410560E3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-04] (Adobe Systems Incorporated) Task: {B5B99628-5DC8-46B3-BD4E-5D73409C00D0} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Bambi => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation) Task: {DD33E915-BE60-436C-9EFB-CFE8834BEE51} - System32\Tasks\aviraSWU => Cscript.exe "C:\Program Files\avira\Internet Explorer\swu.vbs" Task: {E387948B-F15E-4122-96C1-B548D3F0D6E8} - System32\Tasks\{13A0BC14-19D9-41BF-9DCD-75C133B0EF2F} => C:\Program Files\Skype\Phone\Skype.exe Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EB023A36-CF47-46B6-989B-E5A12EFFFAA1} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {EC6D3A62-61AD-4D40-ABCD-C09B862C8176} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-16] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cd0b832a3e8c5c.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2009-08-13 12:32 - 2009-04-21 21:05 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll 2009-01-30 21:11 - 2009-01-30 21:11 - 00073728 _____ () C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll 2009-06-09 10:27 - 2010-09-01 17:19 - 00034816 _____ () C:\Program Files\Google\Google Desktop Search\gzlib.dll 2009-03-07 13:15 - 2009-03-07 13:15 - 07005496 _____ () C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll 2008-07-14 10:37 - 2008-07-14 10:37 - 00095544 _____ () C:\Program Files\TOSHIBA\FlashCards\TWarnMsg\TWarnMsg.dll 2009-06-09 10:13 - 2006-10-10 11:44 - 00009728 _____ () C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll 2009-03-12 18:08 - 2009-03-12 18:08 - 00049152 _____ () C:\Program Files\Toshiba\PCDiag\NotifyPCD.dll 2006-10-07 11:57 - 2006-10-07 11:57 - 00053248 _____ () C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll 2006-12-01 17:55 - 2006-12-01 17:55 - 00009216 _____ () C:\Program Files\Toshiba\TBS\NotifyTBS.dll 2009-04-24 10:39 - 2009-04-24 10:39 - 00516096 _____ () C:\Program Files\TOSHIBA\TECO\TecoPower.dll 2011-04-11 20:10 - 2009-07-01 08:21 - 00077824 _____ () C:\Program Files\SmarThru Office\ProductConfigurator.dll 2011-04-11 20:10 - 2009-07-01 08:16 - 00434176 _____ () C:\Program Files\SmarThru Office\ConfigurationManager.dll 2011-04-11 20:10 - 2009-07-01 08:15 - 00031744 _____ () C:\Program Files\SmarThru Office\STOSearchHelper.dll 2011-04-11 20:10 - 2009-07-01 08:18 - 00143360 _____ () C:\Program Files\SmarThru Office\WindowsDesktopSearch.dll 2011-04-11 20:10 - 2009-07-01 08:19 - 00208896 _____ () C:\Program Files\SmarThru Office\CABFilesWrapper.dll 2011-04-11 20:10 - 2009-07-01 08:16 - 00151552 _____ () C:\Program Files\SmarThru Office\STOCategoryHelper.dll 2009-08-13 12:34 - 2009-08-13 12:34 - 00014848 _____ () C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll 2009-01-30 09:41 - 2009-01-30 09:41 - 00016384 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll 2009-08-13 12:34 - 2009-08-13 12:34 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2014-01-11 15:50 - 2014-01-11 15:50 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-02-06 16:33 - 2013-12-12 08:55 - 00099096 _____ () C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\extensions\{2aafde73-17d3-97c3-e54c-63c7ef6a3c1a}\components\SmartbarFireFoxRemotePlugin_26.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:373E1720 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/08/2014 07:35:26 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1156607 Error: (02/08/2014 07:35:26 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1156607 Error: (02/08/2014 07:35:26 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/08/2014 07:16:19 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 8705 Error: (02/08/2014 07:16:19 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 8705 Error: (02/08/2014 07:16:19 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/08/2014 07:16:14 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4103 Error: (02/08/2014 07:16:14 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 4103 Error: (02/08/2014 07:16:14 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/08/2014 07:16:12 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2418 System errors: ============= Error: (02/07/2014 11:44:33 PM) (Source: Service Control Manager) (User: ) Description: 30000Microsoft .NET Framework NGEN v4.0.30319_X86 Error: (02/07/2014 11:42:19 PM) (Source: Service Control Manager) (User: ) Description: DgiVecp%%20 Error: (02/07/2014 11:42:19 PM) (Source: Service Control Manager) (User: ) Description: 30000Optimizer Pro Crash Monitor Error: (02/07/2014 11:42:19 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (02/06/2014 10:01:49 PM) (Source: Service Control Manager) (User: ) Description: DgiVecp%%20 Error: (02/06/2014 10:01:49 PM) (Source: Service Control Manager) (User: ) Description: 30000Optimizer Pro Crash Monitor Error: (02/06/2014 10:01:49 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (02/06/2014 09:49:23 PM) (Source: Service Control Manager) (User: ) Description: DgiVecp%%20 Error: (02/06/2014 09:49:23 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (02/06/2014 08:17:07 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-02-08 19:44:13.309 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\klmouflt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 19:44:12.857 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\klmouflt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 19:44:12.389 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\klmouflt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 19:44:11.921 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\klmouflt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 19:44:11.250 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\klif.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 19:44:10.829 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\klif.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 19:44:10.361 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\klif.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 19:44:09.924 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\klif.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-04-26 21:38:23.920 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-04-26 21:38:23.842 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 60% Total physical RAM: 3035.93 MB Available physical RAM: 1198.12 MB Total Pagefile: 6283.65 MB Available Pagefile: 4065.37 MB Total Virtual: 2047.88 MB Available Virtual: 1897.27 MB ==================== Drives ================================ Drive c: (Vista) (Fixed) (Total:186.31 GB) (Free:116.84 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: (Data) (Fixed) (Total:184.84 GB) (Free:155.21 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 373 GB) (Disk ID: 7878FC96) Partition 1: (Not Active) - (Size=1 GB) - (Type=27) Partition 2: (Active) - (Size=186 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=185 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
09.02.2014, 16:40 | #4 |
/// the machine /// TB-Ausbilder | snap.do nicht deinstallierbar windows vista Perfekt Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.02.2014, 18:35 | #5 |
| snap.do nicht deinstallierbar windows vista hi, habe getan, was ich tun sollte, bin etwas schockiert was da alles gefunden wurde. Als ob der lappi komplett verseucht ist.. ich bin dir sehr dankbar für deine Hilfe. Hier die Ergebnisse: Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.09.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Bambi :: BAMBI-PC [Administrator] 09.02.2014 17:22:06 mbam-log-2014-02-09 (17-22-06).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 239374 Laufzeit: 19 Minute(n), 44 Sekunde(n) Infizierte Speicherprozesse: 5 C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe (PUP.Optional.SearchDonkey.A) -> 5156 -> Löschen bei Neustart. C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe (PUP.Optional.SearchDonkey.A) -> 5564 -> Löschen bei Neustart. C:\ProgramData\RHelpers\IeHelper\IeHelper.exe (PUP.Optional.SearchDonkey.A) -> 5724 -> Löschen bei Neustart. C:\ProgramData\InternetUpdater\InternetUpdaterService.exe (PUP.Optional.InternetUpdaterService.A) -> 4748 -> Löschen bei Neustart. C:\ProgramData\Updater\updater.exe (Trojan.Agent) -> 1952 -> Löschen bei Neustart. Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 8 HKLM\SYSTEM\CurrentControlSet\Services\InternetUpdater (PUP.Optional.InternetUpdaterService.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C} (PUP.Optional.WebSteroids.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6} (PUP.Optional.DynConIE.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} (PUP.Optional.SupTab.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetUpdater (PUP.Optional.InternetUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Google\Chrome\Extensions\pkndmigholgfjlniaohblojbhgjbkakn (PUP.Optional.NewTab.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SYSTEM\CurrentControlSet\Services\ca82e1a5 (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\Software\awesomehpSoftware (PUP.Optional.Awesomehp.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 4 HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Updater (Trojan.Agent) -> Daten: C:\ProgramData\Updater\updater.exe -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Updater (Trojan.Agent) -> Daten: C:\ProgramData\Updater\Updater.exe -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Mozilla\Firefox\Extensions|lightningnewtab@gmail.com (PUP.Optional.Lightning.A) -> Daten: C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\extensions\lightningnewtab@gmail.com.xpi -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SYSTEM\CurrentControlSet\Services\InternetUpdater|ImagePath (PUP.Optional.InternetUpdater.A) -> Daten: "C:\ProgramData\InternetUpdater\InternetUpdaterService.exe" -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 10 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page (PUP.Optional.Snapdo) -> Bösartig: (pending Gut: (pending -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.Awesomehp.A) -> Bösartig: (pending Gut: (pending -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (PUP.Optional.Snapdo) -> Bösartig: (pending Gut: (pending -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (PUP.Optional.Snapdo) -> Bösartig: (pending Gut: (pending -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|SearchAssistant (PUP.Optional.Snapdo) -> Bösartig: (pending Gut: (pending -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command| (PUP.Optional.Awesomehp.A) -> Bösartig: ("C:\Program Files\Mozilla Firefox\firefox.exe" pending Gut: (firefox.exe) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command| (PUP.Optional.Awesomehp.A) -> Bösartig: ("C:\Program Files\Google\Chrome\Application\chrome.exe" pending Gut: (Chrome.exe) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command| (PUP.Optional.Awesomehp.A) -> Bösartig: (C:\Program Files\Internet Explorer\iexplore.exe pending Gut: (iexplore.exe) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (PUP.Optional.Awesomehp.A) -> Bösartig: (hxxp://splashurl.com/q9d2jdq) Gut: (pending -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\Software\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.Awesomehp.A) -> Bösartig: (pending Gut: (pending -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 10 C:\ProgramData\InternetUpdater (PUP.Optional.InternetUpdater.A) -> Löschen bei Neustart. C:\Users\Bambi\AppData\Local\Temp\CT3323737 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\RHelpers (PUP.Optional.Searchagent) -> Löschen bei Neustart. C:\ProgramData\RHelpers\ChromeHelper (PUP.Optional.Searchagent) -> Löschen bei Neustart. C:\ProgramData\RHelpers\FirefoxHelper (PUP.Optional.Searchagent) -> Löschen bei Neustart. C:\ProgramData\RHelpers\IeHelper (PUP.Optional.Searchagent) -> Löschen bei Neustart. C:\Users\Bambi\AppData\Roaming\newnext.me (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Roaming\newnext.me\cache (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\IePluginService (PUP.Optional.IePluginService.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\IePluginService\update (PUP.Optional.IePluginService.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 42 C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe (PUP.Optional.SearchDonkey.A) -> Löschen bei Neustart. C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe (PUP.Optional.SearchDonkey.A) -> Löschen bei Neustart. C:\ProgramData\RHelpers\IeHelper\IeHelper.exe (PUP.Optional.SearchDonkey.A) -> Löschen bei Neustart. C:\ProgramData\InternetUpdater\InternetUpdaterService.exe (PUP.Optional.InternetUpdaterService.A) -> Löschen bei Neustart. C:\Users\Bambi\AppData\Local\Temp\ICReinstall_Setup.exe (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\awh4E46.tmp (PUP.Optional.Amonetize.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\awh5181.tmp (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\bhs4957.tmp (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\bhs9D9C.tmp (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\bhsD032.tmp (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\nsb8DB4.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\nsbA21F.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\nsg1D09.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\nsg75C0.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\nsl3BA1.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\nsq5643.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\android\android.exe (Trojan.Android.NSD) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\6aab3acf-a2c8-40d1-a13f-532b7d61fdb5\android.exe (Trojan.Android.NSD) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\6aab3acf-a2c8-40d1-a13f-532b7d61fdb5\spidentifierimpl.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\715eb07c-c64b-463e-9f47-4db9a7834a92\software\Installer.exe (PUP.Optional.Linkury.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\s2b4\Setup.exe (PUP.Optional.InternetUpdaterService.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\s410\Setup.exe (PUP.Optional.InternetUpdaterService.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\s49o\Setup.exe (PUP.Optional.InternetUpdaterService.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\f8971b73-49dd-48a8-acb8-6738d5bb8a71\android.exe (Trojan.Android.NSD) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\f8971b73-49dd-48a8-acb8-6738d5bb8a71\software\AndroidSetup.exe (Trojan.Android.NSD) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\f8971b73-49dd-48a8-acb8-6738d5bb8a71\software\OptimizerPro.exe (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\f8971b73-49dd-48a8-acb8-6738d5bb8a71\software\Re-markit_2040-2081.exe (PUP.Optional.AdLyrics) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\nsk8AF3\SpSetup.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\fullpackage_temp1391015804\package1.zip (PUP.Optional.SkyTech.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\fullpackage_temp1391015804\QQBrowserFrame.dll (PUP.Optional.SkyTech.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Temp\fullpackage_temp1391015804\tmp\SupTab.exe (PUP.Optional.SupTab.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\91db687.msi (PUP.Optional.SmartBar) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Mozilla Firefox\browser\searchplugins\awesomehp.xml (PUP.Optional.Awesomehp.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx (PUP.Optional.NewTab.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\InternetUpdater\InternetUpdater.ico (PUP.Optional.InternetUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\InternetUpdater\app.dat (PUP.Optional.InternetUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\InternetUpdater\data.dat (PUP.Optional.InternetUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\InternetUpdater\InternetUpdaterService.exe.config (PUP.Optional.InternetUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\InternetUpdater\Uninstall.exe (PUP.Optional.InternetUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Updater\updater.exe (Trojan.Agent) -> Löschen bei Neustart. C:\Users\Bambi\AppData\Local\Temp\CT3323737\ddt.csf (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\IePluginService\update\conf (PUP.Optional.IePluginService.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) adwcleaner: Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 09/02/2014 um 18:03:01 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Bambi - BAMBI-PC # Gestartet von : C:\Users\Bambi\Desktop\adwcleaner-3.018.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Bambi\AppData\Local\Temp\Smartbar ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\smartbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DynConIE ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16526 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\prefs.js ] Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false); Zeile gelöscht : user_pref("extensions.helperbar.LastHiddenTime", 23197621); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", true); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false); Zeile gelöscht : user_pref("extensions.helperbar.Visibility", false); Zeile gelöscht : user_pref("extensions.helperbar.lastExternalJsUpdate", "1391914878409"); -\\ Google Chrome v32.0.1700.102 [ Datei : C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [13046 octets] - [02/02/2014 20:40:51] AdwCleaner[R1].txt - [1331 octets] - [04/02/2014 21:47:37] AdwCleaner[R2].txt - [7710 octets] - [06/02/2014 21:53:30] AdwCleaner[R3].txt - [2156 octets] - [07/02/2014 23:31:02] AdwCleaner[R4].txt - [2072 octets] - [09/02/2014 17:58:56] AdwCleaner[S0].txt - [12195 octets] - [02/02/2014 20:42:56] AdwCleaner[S1].txt - [1392 octets] - [04/02/2014 21:55:34] AdwCleaner[S2].txt - [7638 octets] - [06/02/2014 21:55:21] AdwCleaner[S3].txt - [2219 octets] - [07/02/2014 23:33:19] AdwCleaner[S4].txt - [1995 octets] - [09/02/2014 18:03:01] ########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [2055 octets] ########## JRT.exe: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.1 (02.04.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by Bambi on 09.02.2014 at 18:19:55,59 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\browsers protector Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\radiorage_4j browser plugin loader Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL\\Default Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\searchURL\\Default ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\{58bd07eb-0ee0-4df0-8121-dc9b693373df} Successfully deleted the following from C:\Users\Bambi\AppData\Roaming\mozilla\firefox\profiles\aswdx0tm.default\prefs.js user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=TuguuTU&co=DE&userid=2aafde73-17d3-97c3-e54c-63c7ef6a3c1a&searchtype=nt&installDate=06/02/2014"); user_pref("extensions.helperbar.SmartbarDisabled", false); user_pref("extensions.helperbar.SmartbarStateMinimaized", false); user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=TuguuTU&co=DE&userid=2aafde73-17d3-97c3-e54c-63c7ef6a3c1a&searchtype=ds&installDate=06/02/2014&q="); Emptied folder: C:\Users\Bambi\AppData\Roaming\mozilla\firefox\profiles\aswdx0tm.default\minidumps [7 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 09.02.2014 at 18:27:01,55 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und nochmal neu FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-02-2014 02 Ran by Bambi (administrator) on BAMBI-PC on 09-02-2014 18:32:56 Running from C:\Users\Bambi\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://splashurl.com/q48acgw Download link for 64-Bit Version: hxxp://splashurl.com/pnhk53f Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://splashurl.com/qhwxjug ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (AMD) C:\Windows\system32\atiesrxx.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TEco.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe () C:\Program Files\SmarThru Office\BackUpSvr.exe () C:\Program Files\SmarThru Office\LegacyLauncher.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (TOSHIBA) C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe (EasyBits Software AS) C:\ProgramData\GameXN\GameXNGO.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [421888 2007-04-16] (TOSHIBA Electronics, Inc.) HKLM\...\Run: [SVPWUTIL] - C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [438272 2008-11-21] (TOSHIBA) HKLM\...\Run: [KeNotify] - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe [34088 2009-01-13] (TOSHIBA CORPORATION) HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe [1011712 2009-04-23] (TOSHIBA Corporation) HKLM\...\Run: [Google Desktop Search] - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-09-01] (Google) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7289376 2009-03-30] (Realtek Semiconductor) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2009-04-21] (Advanced Micro Devices, Inc.) HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [468320 2009-03-06] (TOSHIBA Corporation) HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [55160 2009-03-09] (TOSHIBA Corporation) HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [503808 2009-03-31] (TOSHIBA Corporation) HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [729088 2009-03-23] (TOSHIBA Corporation) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [184320 2009-03-29] (Alps Electric Co., Ltd.) HKLM\...\Run: [SmartFaceVWatcher] - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [163840 2009-03-24] (TOSHIBA Corporation) HKLM\...\Run: [Teco] - C:\Program Files\TOSHIBA\TECO\Teco.exe [1323008 2009-04-24] (TOSHIBA Corporation) HKLM\...\Run: [ToshibaServiceStation] - C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295736 2011-02-11] (TOSHIBA Corporation) HKLM\...\Run: [TPCHWMsg] - C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe [570736 2009-04-15] (TOSHIBA Corporation) HKLM\...\Run: [NDSTray.exe] - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe [299008 2009-05-12] (TOSHIBA CORPORATION) HKLM\...\Run: [cfFncEnabler.exe] - C:\Program Files\TOSHIBA\ConfigFree\cfFncEnabler.exe [16384 2009-03-24] (Toshiba Corporation) HKLM\...\Run: [TWebCamera] - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2513472 2009-04-16] (TOSHIBA) HKLM\...\Run: [Toshiba TEMPRO] - C:\Program Files\Toshiba TEMPRO\TemproTray.exe [1050072 2010-10-26] (Toshiba Europe GmbH) HKLM\...\Run: [Toshiba Registration] - C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [96144 2009-03-04] (Toshiba Europe GmbH) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-03-30] (Realtek Semiconductor Corp.) HKLM\...\Run: [STO Backup Service] - C:\Program Files\SmarThru Office\BackUpSvr.exe [184320 2009-07-01] () HKLM\...\Run: [STO Launcher Service] - C:\Program Files\SmarThru Office\LegacyLauncher.exe [331776 2009-07-01] () HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\ssmmgr.exe [614400 2009-09-23] () HKLM\...\Run: [] - [X] HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-05-30] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKLM\...\Run: [avp] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [340520 2010-08-22] (Kaspersky Lab) Winlogon\Notify\klogon: C:\Windows\system32\klogon.dll (Kaspersky Lab) HKU\.DEFAULT\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [6158240 2009-03-16] (TOSHIBA) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3040194652-3351564512-1966064265-1000\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [6158240 2009-03-16] (TOSHIBA) HKU\S-1-5-21-3040194652-3351564512-1966064265-1000\...\Run: [GameXN GO] - C:\ProgramData\GameXN\GameXNGO.exe [347008 2011-09-01] (EasyBits Software AS) HKU\S-1-5-21-3040194652-3351564512-1966064265-1000\...\MountPoints2: {4f185bbd-e8ad-11de-b3e3-0026222f70a8} - D:\.\Kassettenrecorder.exe AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\google\google~3\goec62~1.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll => C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll [17936 2009-11-17] (Kaspersky Lab) Startup: C:\Users\Bambi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://splashurl.com/q9d2jdq StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Avira Savings Advisor BHO - {A18A516C-AA41-46A9-92DB-60208917E442} - C:\Program Files\avira\Internet Explorer\avira32.dll () BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://splashurl.com/ncc5xz6 Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin: @google.com/npPicasa2,version=2.0.0 - C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Savings Advisor - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\ciuvo-extension@avira.de [2014-02-05] FF Extension: Snap.Do - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\{2aafde73-17d3-97c3-e54c-63c7ef6a3c1a} [2014-02-06] FF Extension: SnapDo - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\firefox@splashurl.com.xpi [2014-02-06] FF Extension: Extension_Protected - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\jid0-O6MIff3eO5dIGf5Tcv8RsJDKxrs@jetpack.xpi [2014-01-29] FF Extension: Kaspersky URL Advisor - C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2014-01-11] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Thunderbird\Extensions: [{eea12ec4-729d-4703-bc37-106ce9879ce2}] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt FF Extension: Kaspersky Anti-Spam Extension - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2009-10-26] FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR HomePage: hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=TuguuTU&co=DE&userid=2aafde73-17d3-97c3-e54c-63c7ef6a3c1a&searchtype=hp&installDate=06/02/2014 CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=TuguuTU&co=DE&userid=2aafde73-17d3-97c3-e54c-63c7ef6a3c1a&searchtype=hp&installDate=06/02/2014" ], "restore_on_startup" CHR Extension: (YouTube) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-05] CHR Extension: (Avira Sparberater) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cojnmaaohncijldefpkpkkakjonfmgeb [2014-02-05] CHR Extension: (Google-Suche) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-05] CHR Extension: (Re-markit) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcpfhaghaadpjpgocojgnlhjcieeooel [2014-02-05] CHR Extension: (SnapDo) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj [2014-02-06] CHR Extension: (Google Wallet) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-05] CHR Extension: (Google Mail) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-05] CHR Extension: (Lightning speedDial) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkndmigholgfjlniaohblojbhgjbkakn [2014-02-05] CHR HKLM\...\Chrome\Extension: [cojnmaaohncijldefpkpkkakjonfmgeb] - C:\Program Files\avira\Chrome\avira-1.5.14.crx [2013-12-11] CHR StartMenuInternet: Google Chrome - Chrome.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG) R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [340520 2010-08-22] (Kaspersky Lab) R2 camsvc; C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe [20544 2009-04-16] (TOSHIBA) R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION) S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-09-01] (Google) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [235216 2013-09-06] (McAfee, Inc.) R2 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [124368 2010-10-26] (Toshiba Europe GmbH) R3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [54136 2011-02-11] (TOSHIBA Corporation) R2 TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [176128 2009-04-24] (TOSHIBA Corporation) R2 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [73728 2009-03-17] (TOSHIBA Corporation) R2 TPCHSrv; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [656752 2009-04-15] (TOSHIBA Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-18] (Avira Operations GmbH & Co. KG) R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [128016 2009-09-01] (Kaspersky Lab) R0 klbg; C:\Windows\System32\drivers\klbg.sys [36880 2009-10-14] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [311312 2009-11-17] (Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [21520 2009-09-14] (Kaspersky Lab) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [19472 2009-10-02] (Kaspersky Lab) R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [25896 2008-05-07] (COMPAL ELECTRONIC INC.) R3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [22272 2009-03-18] (TOSHIBA Corporation) R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [154272 2008-11-11] (Realtek Semiconductor Corp.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-18] (Avira GmbH) R2 TVALZFL; C:\Windows\System32\DRIVERS\TVALZFL.sys [12920 2009-03-20] (TOSHIBA Corporation) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-09 18:32 - 2014-02-09 18:33 - 00021359 _____ () C:\Users\Bambi\Desktop\FRST.txt 2014-02-09 18:32 - 2014-02-09 18:32 - 00000000 ____D () C:\Users\Bambi\Desktop\FRST-OlderVersion 2014-02-09 18:27 - 2014-02-09 18:27 - 00002132 _____ () C:\Users\Bambi\Desktop\JRT.txt 2014-02-09 18:19 - 2014-02-09 18:19 - 01037530 _____ (Thisisu) C:\Users\Bambi\Downloads\JRT.exe 2014-02-09 18:19 - 2014-02-09 18:19 - 00000000 ____D () C:\Windows\ERUNT 2014-02-09 17:08 - 2014-02-09 17:08 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\Malwarebytes 2014-02-09 17:06 - 2014-02-09 17:06 - 00000871 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-09 17:06 - 2014-02-09 17:06 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-09 17:06 - 2014-02-09 17:06 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-09 17:06 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-09 17:01 - 2014-02-09 17:01 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Bambi\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-08 19:44 - 2014-02-08 19:48 - 00025370 _____ () C:\Users\Bambi\Downloads\Addition.txt 2014-02-08 19:43 - 2014-02-09 18:32 - 00000000 ____D () C:\FRST 2014-02-08 19:43 - 2014-02-08 19:48 - 00037516 _____ () C:\Users\Bambi\Downloads\FRST.txt 2014-02-08 19:38 - 2014-02-09 18:32 - 01138688 _____ (Farbar) C:\Users\Bambi\Desktop\FRST.exe 2014-02-06 16:33 - 2014-02-06 22:04 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Mobogenie 2014-02-06 16:33 - 2014-02-06 16:52 - 00000000 ____D () C:\Users\Bambi\AppData\Local\cache 2014-02-06 16:33 - 2014-02-06 16:33 - 00002029 _____ () C:\Users\Bambi\Desktop\Search.lnk 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\Documents\Mobogenie 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\genienext 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\.android 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 _____ () C:\Users\Bambi\daemonprocess.txt 2014-02-05 18:53 - 2014-02-05 18:53 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\Avira 2014-02-05 18:47 - 2014-02-05 18:53 - 00000000 ____D () C:\Program Files\Avira 2014-02-05 18:47 - 2014-02-05 18:47 - 00001812 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-02-05 18:47 - 2014-02-05 18:47 - 00000000 ____D () C:\ProgramData\Avira 2014-02-05 18:47 - 2013-12-18 09:32 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-02-05 18:47 - 2013-12-18 09:32 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-02-05 18:47 - 2013-12-18 09:32 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-02-05 18:47 - 2013-12-18 09:32 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2014-02-04 22:01 - 2014-02-04 22:01 - 00000000 ____D () C:\ProgramData\Websteroids 2014-02-04 21:44 - 2014-02-04 21:44 - 01166132 _____ () C:\Users\Bambi\Desktop\adwcleaner-3.018.exe 2014-02-02 20:35 - 2014-02-09 17:51 - 00000000 ____D () C:\ProgramData\Updater 2014-02-02 20:34 - 2014-02-09 18:03 - 00000000 ____D () C:\AdwCleaner 2014-02-02 20:33 - 2014-02-02 20:33 - 00000000 ____D () C:\Users\Bambi\Downloads\AdwCleaner_TSV43DG5U 2014-01-29 18:28 - 2014-01-29 18:28 - 00000879 _____ () C:\Users\Bambi\Desktop\Continue VuuPC Installation.lnk 2014-01-29 18:19 - 2014-02-06 16:30 - 00001719 _____ () C:\Users\Bambi\Desktop\Sync Folder.lnk 2014-01-29 18:18 - 2014-02-06 22:23 - 00000000 ____D () C:\Program Files\SupTab 2014-01-29 18:18 - 2014-02-04 21:41 - 00000000 ____D () C:\ProgramData\WPM 2014-01-15 14:12 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-01-15 14:12 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-15 14:12 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-15 14:12 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-15 14:11 - 2014-01-15 14:12 - 00005315 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-01-12 18:39 - 2014-01-12 18:39 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Macromedia 2014-01-11 15:50 - 2014-01-11 15:50 - 00000000 ____D () C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-02-09 18:33 - 2014-02-09 18:32 - 00021359 _____ () C:\Users\Bambi\Desktop\FRST.txt 2014-02-09 18:32 - 2014-02-09 18:32 - 00000000 ____D () C:\Users\Bambi\Desktop\FRST-OlderVersion 2014-02-09 18:32 - 2014-02-08 19:43 - 00000000 ____D () C:\FRST 2014-02-09 18:32 - 2014-02-08 19:38 - 01138688 _____ (Farbar) C:\Users\Bambi\Desktop\FRST.exe 2014-02-09 18:30 - 2011-09-01 21:19 - 00000000 ____D () C:\ProgramData\GameXN 2014-02-09 18:27 - 2014-02-09 18:27 - 00002132 _____ () C:\Users\Bambi\Desktop\JRT.txt 2014-02-09 18:19 - 2014-02-09 18:19 - 01037530 _____ (Thisisu) C:\Users\Bambi\Downloads\JRT.exe 2014-02-09 18:19 - 2014-02-09 18:19 - 00000000 ____D () C:\Windows\ERUNT 2014-02-09 18:16 - 2012-07-14 19:10 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-09 18:14 - 2008-01-21 08:16 - 01475854 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-09 18:10 - 2009-10-26 22:12 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-02-09 18:08 - 2012-03-26 20:03 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cd0b832a3e8c5c.job 2014-02-09 18:07 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-09 18:07 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-09 18:07 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-09 18:06 - 2009-08-13 12:28 - 01922900 _____ () C:\Windows\WindowsUpdate.log 2014-02-09 18:06 - 2006-11-02 14:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-09 18:03 - 2014-02-02 20:34 - 00000000 ____D () C:\AdwCleaner 2014-02-09 17:58 - 2010-02-16 21:19 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-09 17:55 - 2011-06-11 14:14 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\go 2014-02-09 17:51 - 2014-02-02 20:35 - 00000000 ____D () C:\ProgramData\Updater 2014-02-09 17:51 - 2008-01-21 03:47 - 00596184 _____ () C:\Windows\PFRO.log 2014-02-09 17:51 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\ShellNew 2014-02-09 17:08 - 2014-02-09 17:08 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\Malwarebytes 2014-02-09 17:06 - 2014-02-09 17:06 - 00000871 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-09 17:06 - 2014-02-09 17:06 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-09 17:06 - 2014-02-09 17:06 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-09 17:01 - 2014-02-09 17:01 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Bambi\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-08 19:48 - 2014-02-08 19:44 - 00025370 _____ () C:\Users\Bambi\Downloads\Addition.txt 2014-02-08 19:48 - 2014-02-08 19:43 - 00037516 _____ () C:\Users\Bambi\Downloads\FRST.txt 2014-02-06 22:23 - 2014-01-29 18:18 - 00000000 ____D () C:\Program Files\SupTab 2014-02-06 22:04 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Mobogenie 2014-02-06 20:20 - 2009-10-26 21:39 - 00020480 _____ () C:\Users\Bambi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-02-06 16:52 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\cache 2014-02-06 16:33 - 2014-02-06 16:33 - 00002029 _____ () C:\Users\Bambi\Desktop\Search.lnk 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\Documents\Mobogenie 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\genienext 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\.android 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 _____ () C:\Users\Bambi\daemonprocess.txt 2014-02-06 16:33 - 2009-10-26 20:12 - 00000000 ____D () C:\Users\Bambi 2014-02-06 16:30 - 2014-01-29 18:19 - 00001719 _____ () C:\Users\Bambi\Desktop\Sync Folder.lnk 2014-02-05 18:53 - 2014-02-05 18:53 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\Avira 2014-02-05 18:53 - 2014-02-05 18:47 - 00000000 ____D () C:\Program Files\Avira 2014-02-05 18:47 - 2014-02-05 18:47 - 00001812 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-02-05 18:47 - 2014-02-05 18:47 - 00000000 ____D () C:\ProgramData\Avira 2014-02-04 22:16 - 2012-07-14 19:10 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-04 22:16 - 2012-07-14 19:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-04 22:01 - 2014-02-04 22:01 - 00000000 ____D () C:\ProgramData\Websteroids 2014-02-04 21:44 - 2014-02-04 21:44 - 01166132 _____ () C:\Users\Bambi\Desktop\adwcleaner-3.018.exe 2014-02-04 21:41 - 2014-01-29 18:18 - 00000000 ____D () C:\ProgramData\WPM 2014-02-04 21:39 - 2013-03-17 13:23 - 00000811 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-02-02 20:58 - 2010-01-10 14:00 - 00000924 _____ () C:\Users\Bambi\Desktop\Internet Explorer.lnk 2014-02-02 20:43 - 2012-08-03 23:49 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft 2014-02-02 20:33 - 2014-02-02 20:33 - 00000000 ____D () C:\Users\Bambi\Downloads\AdwCleaner_TSV43DG5U 2014-01-30 10:59 - 2010-09-01 21:01 - 00000680 _____ () C:\Users\Bambi\AppData\Local\d3d9caps.dat 2014-01-29 18:28 - 2014-01-29 18:28 - 00000879 _____ () C:\Users\Bambi\Desktop\Continue VuuPC Installation.lnk 2014-01-29 18:17 - 2013-03-05 14:40 - 00002130 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-29 18:17 - 2009-10-26 20:35 - 00001156 _____ () C:\Users\Bambi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-16 12:22 - 2013-09-03 19:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-16 12:18 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-01-15 14:15 - 2013-11-02 15:55 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-15 14:12 - 2014-01-15 14:11 - 00005315 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-01-15 14:12 - 2012-06-27 13:05 - 00000000 ____D () C:\Program Files\Java 2014-01-12 18:39 - 2014-01-12 18:39 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Macromedia 2014-01-12 18:38 - 2009-10-26 21:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Adobe 2014-01-12 12:02 - 2013-03-17 13:22 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-01-11 15:50 - 2014-01-11 15:50 - 00000000 ____D () C:\Program Files\Mozilla Firefox Some content of TEMP: ==================== C:\Users\Bambi\AppData\Local\Temp\ApnStub.exe C:\Users\Bambi\AppData\Local\Temp\avgnt.exe C:\Users\Bambi\AppData\Local\Temp\BackupSetup.exe C:\Users\Bambi\AppData\Local\Temp\contentDATs.exe C:\Users\Bambi\AppData\Local\Temp\drm_dialogs.dll C:\Users\Bambi\AppData\Local\Temp\drm_dyndata_7410004.dll C:\Users\Bambi\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Bambi\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Bambi\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u17-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u19-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u20-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u21-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\ndqqarkn.dll C:\Users\Bambi\AppData\Local\Temp\NEW5D61.tmp.exe C:\Users\Bambi\AppData\Local\Temp\NEWF711.tmp.exe C:\Users\Bambi\AppData\Local\Temp\pcspeedmaxsetup.exe C:\Users\Bambi\AppData\Local\Temp\Quarantine.exe C:\Users\Bambi\AppData\Local\Temp\Refresh.exe C:\Users\Bambi\AppData\Local\Temp\SecurityScan_Release.exe C:\Users\Bambi\AppData\Local\Temp\setup.exe C:\Users\Bambi\AppData\Local\Temp\setup{D6921DE2-4509-4629-A14A-5755138AA61A}.exe C:\Users\Bambi\AppData\Local\Temp\SkypeSetup.exe C:\Users\Bambi\AppData\Local\Temp\TEMPRO_2.3.1.exe C:\Users\Bambi\AppData\Local\Temp\vcredist_x86.exe C:\Users\Bambi\AppData\Local\Temp\_is5234.exe C:\Users\Bambi\AppData\Local\Temp\_is5A8E.exe C:\Users\Bambi\AppData\Local\Temp\_prgorxj.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-09 18:14 ==================== End Of Log ============================ |
10.02.2014, 16:16 | #6 |
/// the machine /// TB-Ausbilder | snap.do nicht deinstallierbar windows vistaESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> snap.do nicht deinstallierbar windows vista |
10.02.2014, 18:08 | #7 |
| snap.do nicht deinstallierbar windows vista habe gemacht was ich sollte. Eset: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3bb21a835f949745bbd6ec180a35d3dc # engine=17015 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-10 04:48:16 # local_time=2014-02-10 05:48:16 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=1799 16775165 100 95 24537 4698921 17286 0 # compatibility_mode=5892 16776574 100 95 119739199 229583624 0 0 # scanned=206990 # found=7 # cleaned=0 # scan_time=4283 sh=9ABE489AF3684ABB96AB39F112768F69C83D0F8E ft=1 fh=f7fcd12f54d4e5cc vn="a variant of Win32/SpeedingUpMyPC application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptimizerPro.exe.vir" sh=2F367F244D08950211E4C05FB8EF8E0959BB773A ft=1 fh=20d3e0bbdedcd685 vn="a variant of Win32/AdWare.SpeedingUpMyPC.D application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptProLauncher.exe.vir" sh=E5DB01AF8C7541396D4C619A55B7B664281A5375 ft=1 fh=97edb4dad52fbf6e vn="a variant of Win32/Adware.SpeedingUpMyPC.C application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptProSmartScan.exe.vir" sh=37FF9AF0A4A175AFF14252C3FFA6CCC03A24ACBD ft=1 fh=ff3435be19cccc9e vn="a variant of Win32/SpeedingUpMyPC.F application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\PC Speed Maximizer\PCSpeedMaximizer.exe.vir" sh=6380D624D576DCE34CC8B57180386AF4F19029C1 ft=1 fh=d481267c321a5b3a vn="a variant of Win32/SpeedingUpMyPC.F application" ac=I fn="C:\Users\Bambi\AppData\Local\Temp\pcspeedmaxsetup.exe" sh=DB5E4E4F64BAA359255F230C658BE286E266892A ft=1 fh=cc4c339215781df4 vn="multiple threats" ac=I fn="C:\Users\Bambi\AppData\Local\Temp\{195B3CE0-E607-4012-AECA-87DC78335AE6}\setup.exe" sh=7DA03FE50F18A181427D27D85BDB7FC8AB97BE0E ft=1 fh=5dba62ca4dfb06de vn="multiple threats" ac=I fn="C:\Users\Bambi\AppData\Local\Temp\{A9C633A0-2BC8-45A1-B866-714EA59C32F7}\setup.exe" security scan: Code:
ATTFilter UNSUPPORTED OPERATING SYSTEM! ABORTED! FRST: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-02-2014 02 Ran by Bambi (administrator) on BAMBI-PC on 10-02-2014 18:05:34 Running from C:\Users\Bambi\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://splashurl.com/k4ypypw Download link for 64-Bit Version: hxxp://splashurl.com/kvg5gkx Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://splashurl.com/ny2mklj ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (AMD) C:\Windows\system32\atiesrxx.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TEco.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe () C:\Program Files\SmarThru Office\BackUpSvr.exe () C:\Program Files\SmarThru Office\LegacyLauncher.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (TOSHIBA) C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe (EasyBits Software AS) C:\ProgramData\GameXN\GameXNGO.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [421888 2007-04-16] (TOSHIBA Electronics, Inc.) HKLM\...\Run: [SVPWUTIL] - C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [438272 2008-11-21] (TOSHIBA) HKLM\...\Run: [KeNotify] - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe [34088 2009-01-13] (TOSHIBA CORPORATION) HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe [1011712 2009-04-23] (TOSHIBA Corporation) HKLM\...\Run: [Google Desktop Search] - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-09-01] (Google) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7289376 2009-03-30] (Realtek Semiconductor) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2009-04-21] (Advanced Micro Devices, Inc.) HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [468320 2009-03-06] (TOSHIBA Corporation) HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [55160 2009-03-09] (TOSHIBA Corporation) HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [503808 2009-03-31] (TOSHIBA Corporation) HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [729088 2009-03-23] (TOSHIBA Corporation) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [184320 2009-03-29] (Alps Electric Co., Ltd.) HKLM\...\Run: [SmartFaceVWatcher] - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [163840 2009-03-24] (TOSHIBA Corporation) HKLM\...\Run: [Teco] - C:\Program Files\TOSHIBA\TECO\Teco.exe [1323008 2009-04-24] (TOSHIBA Corporation) HKLM\...\Run: [ToshibaServiceStation] - C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295736 2011-02-11] (TOSHIBA Corporation) HKLM\...\Run: [TPCHWMsg] - C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe [570736 2009-04-15] (TOSHIBA Corporation) HKLM\...\Run: [NDSTray.exe] - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe [299008 2009-05-12] (TOSHIBA CORPORATION) HKLM\...\Run: [cfFncEnabler.exe] - C:\Program Files\TOSHIBA\ConfigFree\cfFncEnabler.exe [16384 2009-03-24] (Toshiba Corporation) HKLM\...\Run: [TWebCamera] - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2513472 2009-04-16] (TOSHIBA) HKLM\...\Run: [Toshiba TEMPRO] - C:\Program Files\Toshiba TEMPRO\TemproTray.exe [1050072 2010-10-26] (Toshiba Europe GmbH) HKLM\...\Run: [Toshiba Registration] - C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [96144 2009-03-04] (Toshiba Europe GmbH) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-03-30] (Realtek Semiconductor Corp.) HKLM\...\Run: [STO Backup Service] - C:\Program Files\SmarThru Office\BackUpSvr.exe [184320 2009-07-01] () HKLM\...\Run: [STO Launcher Service] - C:\Program Files\SmarThru Office\LegacyLauncher.exe [331776 2009-07-01] () HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\ssmmgr.exe [614400 2009-09-23] () HKLM\...\Run: [] - [X] HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-05-30] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe Winlogon\Notify\klogon: C:\Windows\system32\klogon.dll (Kaspersky Lab) HKU\.DEFAULT\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [6158240 2009-03-16] (TOSHIBA) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3040194652-3351564512-1966064265-1000\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [6158240 2009-03-16] (TOSHIBA) HKU\S-1-5-21-3040194652-3351564512-1966064265-1000\...\Run: [GameXN GO] - C:\ProgramData\GameXN\GameXNGO.exe [347008 2011-09-01] (EasyBits Software AS) HKU\S-1-5-21-3040194652-3351564512-1966064265-1000\...\MountPoints2: {4f185bbd-e8ad-11de-b3e3-0026222f70a8} - D:\.\Kassettenrecorder.exe AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\google\google~3\goec62~1.dll => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-09-01] (Google) Startup: C:\Users\Bambi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://splashurl.com/khpf96g StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Avira Savings Advisor BHO - {A18A516C-AA41-46A9-92DB-60208917E442} - C:\Program Files\avira\Internet Explorer\avira32.dll () BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://splashurl.com/lc6soxh Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin: @google.com/npPicasa2,version=2.0.0 - C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Savings Advisor - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\ciuvo-extension@avira.de [2014-02-05] FF Extension: Snap.Do - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\{2aafde73-17d3-97c3-e54c-63c7ef6a3c1a} [2014-02-06] FF Extension: SnapDo - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\firefox@splashurl.com.xpi [2014-02-06] FF Extension: Extension_Protected - C:\Users\Bambi\AppData\Roaming\Mozilla\Firefox\Profiles\aswdx0tm.default\Extensions\jid0-O6MIff3eO5dIGf5Tcv8RsJDKxrs@jetpack.xpi [2014-01-29] FF Extension: Kaspersky URL Advisor - C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2014-01-11] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Thunderbird\Extensions: [{eea12ec4-729d-4703-bc37-106ce9879ce2}] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt FF Extension: Kaspersky Anti-Spam Extension - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2009-10-26] FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR HomePage: hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=TuguuTU&co=DE&userid=2aafde73-17d3-97c3-e54c-63c7ef6a3c1a&searchtype=hp&installDate=06/02/2014 CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=TuguuTU&co=DE&userid=2aafde73-17d3-97c3-e54c-63c7ef6a3c1a&searchtype=hp&installDate=06/02/2014" ], "restore_on_startup" CHR Extension: (YouTube) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-05] CHR Extension: (Avira Sparberater) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cojnmaaohncijldefpkpkkakjonfmgeb [2014-02-05] CHR Extension: (Google-Suche) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-05] CHR Extension: (Re-markit) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcpfhaghaadpjpgocojgnlhjcieeooel [2014-02-05] CHR Extension: (SnapDo) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj [2014-02-06] CHR Extension: (Google Wallet) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-05] CHR Extension: (Google Mail) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-05] CHR Extension: (Lightning speedDial) - C:\Users\Bambi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkndmigholgfjlniaohblojbhgjbkakn [2014-02-05] CHR HKLM\...\Chrome\Extension: [cojnmaaohncijldefpkpkkakjonfmgeb] - C:\Program Files\avira\Chrome\avira-1.5.14.crx [2013-12-11] CHR StartMenuInternet: Google Chrome - Chrome.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG) R3 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [340520 2010-08-22] (Kaspersky Lab) R2 camsvc; C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe [20544 2009-04-16] (TOSHIBA) R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION) S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-09-01] (Google) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [235216 2013-09-06] (McAfee, Inc.) R2 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [124368 2010-10-26] (Toshiba Europe GmbH) R3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [54136 2011-02-11] (TOSHIBA Corporation) R2 TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [176128 2009-04-24] (TOSHIBA Corporation) R2 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [73728 2009-03-17] (TOSHIBA Corporation) R2 TPCHSrv; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [656752 2009-04-15] (TOSHIBA Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-18] (Avira Operations GmbH & Co. KG) R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [128016 2009-09-01] (Kaspersky Lab) R0 klbg; C:\Windows\System32\drivers\klbg.sys [36880 2009-10-14] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [311312 2009-11-17] (Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [21520 2009-09-14] (Kaspersky Lab) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [19472 2009-10-02] (Kaspersky Lab) R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [25896 2008-05-07] (COMPAL ELECTRONIC INC.) R3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [22272 2009-03-18] (TOSHIBA Corporation) R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [154272 2008-11-11] (Realtek Semiconductor Corp.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-18] (Avira GmbH) R2 TVALZFL; C:\Windows\System32\DRIVERS\TVALZFL.sys [12920 2009-03-20] (TOSHIBA Corporation) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-10 16:28 - 2014-02-10 16:28 - 00987425 _____ () C:\Users\Bambi\Desktop\SecurityCheck.exe 2014-02-10 16:25 - 2014-02-10 16:25 - 02347384 _____ (ESET) C:\Users\Bambi\Downloads\esetsmartinstaller_enu.exe 2014-02-09 18:32 - 2014-02-10 18:05 - 00021259 _____ () C:\Users\Bambi\Desktop\FRST.txt 2014-02-09 18:32 - 2014-02-09 18:32 - 00000000 ____D () C:\Users\Bambi\Desktop\FRST-OlderVersion 2014-02-09 18:27 - 2014-02-09 18:27 - 00002132 _____ () C:\Users\Bambi\Desktop\JRT.txt 2014-02-09 18:19 - 2014-02-09 18:19 - 01037530 _____ (Thisisu) C:\Users\Bambi\Downloads\JRT.exe 2014-02-09 18:19 - 2014-02-09 18:19 - 00000000 ____D () C:\Windows\ERUNT 2014-02-09 17:08 - 2014-02-09 17:08 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\Malwarebytes 2014-02-09 17:06 - 2014-02-09 17:06 - 00000871 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-09 17:06 - 2014-02-09 17:06 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-09 17:06 - 2014-02-09 17:06 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-09 17:06 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-09 17:01 - 2014-02-09 17:01 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Bambi\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-08 19:44 - 2014-02-08 19:48 - 00025370 _____ () C:\Users\Bambi\Downloads\Addition.txt 2014-02-08 19:43 - 2014-02-10 18:05 - 00000000 ____D () C:\FRST 2014-02-08 19:43 - 2014-02-08 19:48 - 00037516 _____ () C:\Users\Bambi\Downloads\FRST.txt 2014-02-08 19:38 - 2014-02-09 18:32 - 01138688 _____ (Farbar) C:\Users\Bambi\Desktop\FRST.exe 2014-02-06 16:33 - 2014-02-06 22:04 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Mobogenie 2014-02-06 16:33 - 2014-02-06 16:52 - 00000000 ____D () C:\Users\Bambi\AppData\Local\cache 2014-02-06 16:33 - 2014-02-06 16:33 - 00002029 _____ () C:\Users\Bambi\Desktop\Search.lnk 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\Documents\Mobogenie 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\genienext 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\.android 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 _____ () C:\Users\Bambi\daemonprocess.txt 2014-02-05 18:53 - 2014-02-05 18:53 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\Avira 2014-02-05 18:47 - 2014-02-05 18:53 - 00000000 ____D () C:\Program Files\Avira 2014-02-05 18:47 - 2014-02-05 18:47 - 00001812 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-02-05 18:47 - 2014-02-05 18:47 - 00000000 ____D () C:\ProgramData\Avira 2014-02-05 18:47 - 2013-12-18 09:32 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-02-05 18:47 - 2013-12-18 09:32 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-02-05 18:47 - 2013-12-18 09:32 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-02-05 18:47 - 2013-12-18 09:32 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2014-02-04 22:01 - 2014-02-04 22:01 - 00000000 ____D () C:\ProgramData\Websteroids 2014-02-04 21:44 - 2014-02-04 21:44 - 01166132 _____ () C:\Users\Bambi\Desktop\adwcleaner-3.018.exe 2014-02-02 20:35 - 2014-02-09 17:51 - 00000000 ____D () C:\ProgramData\Updater 2014-02-02 20:34 - 2014-02-09 18:03 - 00000000 ____D () C:\AdwCleaner 2014-02-02 20:33 - 2014-02-02 20:33 - 00000000 ____D () C:\Users\Bambi\Downloads\AdwCleaner_TSV43DG5U 2014-01-29 18:28 - 2014-01-29 18:28 - 00000879 _____ () C:\Users\Bambi\Desktop\Continue VuuPC Installation.lnk 2014-01-29 18:19 - 2014-02-06 16:30 - 00001719 _____ () C:\Users\Bambi\Desktop\Sync Folder.lnk 2014-01-29 18:18 - 2014-02-06 22:23 - 00000000 ____D () C:\Program Files\SupTab 2014-01-29 18:18 - 2014-02-04 21:41 - 00000000 ____D () C:\ProgramData\WPM 2014-01-15 14:12 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-01-15 14:12 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-15 14:12 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-15 14:12 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-15 14:11 - 2014-01-15 14:12 - 00005315 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-01-12 18:39 - 2014-01-12 18:39 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Macromedia 2014-01-11 15:50 - 2014-01-11 15:50 - 00000000 ____D () C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-02-10 18:05 - 2014-02-09 18:32 - 00021259 _____ () C:\Users\Bambi\Desktop\FRST.txt 2014-02-10 18:05 - 2014-02-08 19:43 - 00000000 ____D () C:\FRST 2014-02-10 17:59 - 2011-09-01 21:19 - 00000000 ____D () C:\ProgramData\GameXN 2014-02-10 17:57 - 2010-02-16 21:19 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-10 17:16 - 2012-07-14 19:10 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-10 16:55 - 2009-08-13 12:28 - 01975922 _____ () C:\Windows\WindowsUpdate.log 2014-02-10 16:29 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-10 16:29 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-10 16:28 - 2014-02-10 16:28 - 00987425 _____ () C:\Users\Bambi\Desktop\SecurityCheck.exe 2014-02-10 16:25 - 2014-02-10 16:25 - 02347384 _____ (ESET) C:\Users\Bambi\Downloads\esetsmartinstaller_enu.exe 2014-02-10 16:09 - 2011-06-11 14:14 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\go 2014-02-10 12:57 - 2012-03-26 20:03 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cd0b832a3e8c5c.job 2014-02-09 18:32 - 2014-02-09 18:32 - 00000000 ____D () C:\Users\Bambi\Desktop\FRST-OlderVersion 2014-02-09 18:32 - 2014-02-08 19:38 - 01138688 _____ (Farbar) C:\Users\Bambi\Desktop\FRST.exe 2014-02-09 18:27 - 2014-02-09 18:27 - 00002132 _____ () C:\Users\Bambi\Desktop\JRT.txt 2014-02-09 18:19 - 2014-02-09 18:19 - 01037530 _____ (Thisisu) C:\Users\Bambi\Downloads\JRT.exe 2014-02-09 18:19 - 2014-02-09 18:19 - 00000000 ____D () C:\Windows\ERUNT 2014-02-09 18:14 - 2008-01-21 08:16 - 01475854 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-09 18:10 - 2009-10-26 22:12 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-02-09 18:07 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-09 18:06 - 2006-11-02 14:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-09 18:03 - 2014-02-02 20:34 - 00000000 ____D () C:\AdwCleaner 2014-02-09 17:51 - 2014-02-02 20:35 - 00000000 ____D () C:\ProgramData\Updater 2014-02-09 17:51 - 2008-01-21 03:47 - 00596184 _____ () C:\Windows\PFRO.log 2014-02-09 17:51 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\ShellNew 2014-02-09 17:08 - 2014-02-09 17:08 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\Malwarebytes 2014-02-09 17:06 - 2014-02-09 17:06 - 00000871 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-09 17:06 - 2014-02-09 17:06 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-09 17:06 - 2014-02-09 17:06 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-09 17:01 - 2014-02-09 17:01 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Bambi\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-08 19:48 - 2014-02-08 19:44 - 00025370 _____ () C:\Users\Bambi\Downloads\Addition.txt 2014-02-08 19:48 - 2014-02-08 19:43 - 00037516 _____ () C:\Users\Bambi\Downloads\FRST.txt 2014-02-06 22:23 - 2014-01-29 18:18 - 00000000 ____D () C:\Program Files\SupTab 2014-02-06 22:04 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Mobogenie 2014-02-06 20:20 - 2009-10-26 21:39 - 00020480 _____ () C:\Users\Bambi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-02-06 16:52 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\cache 2014-02-06 16:33 - 2014-02-06 16:33 - 00002029 _____ () C:\Users\Bambi\Desktop\Search.lnk 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\Documents\Mobogenie 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\genienext 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 ____D () C:\Users\Bambi\.android 2014-02-06 16:33 - 2014-02-06 16:33 - 00000000 _____ () C:\Users\Bambi\daemonprocess.txt 2014-02-06 16:33 - 2009-10-26 20:12 - 00000000 ____D () C:\Users\Bambi 2014-02-06 16:30 - 2014-01-29 18:19 - 00001719 _____ () C:\Users\Bambi\Desktop\Sync Folder.lnk 2014-02-05 18:53 - 2014-02-05 18:53 - 00000000 ____D () C:\Users\Bambi\AppData\Roaming\Avira 2014-02-05 18:53 - 2014-02-05 18:47 - 00000000 ____D () C:\Program Files\Avira 2014-02-05 18:47 - 2014-02-05 18:47 - 00001812 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-02-05 18:47 - 2014-02-05 18:47 - 00000000 ____D () C:\ProgramData\Avira 2014-02-04 22:16 - 2012-07-14 19:10 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-04 22:16 - 2012-07-14 19:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-04 22:01 - 2014-02-04 22:01 - 00000000 ____D () C:\ProgramData\Websteroids 2014-02-04 21:44 - 2014-02-04 21:44 - 01166132 _____ () C:\Users\Bambi\Desktop\adwcleaner-3.018.exe 2014-02-04 21:41 - 2014-01-29 18:18 - 00000000 ____D () C:\ProgramData\WPM 2014-02-04 21:39 - 2013-03-17 13:23 - 00000811 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-02-02 20:58 - 2010-01-10 14:00 - 00000924 _____ () C:\Users\Bambi\Desktop\Internet Explorer.lnk 2014-02-02 20:43 - 2012-08-03 23:49 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft 2014-02-02 20:33 - 2014-02-02 20:33 - 00000000 ____D () C:\Users\Bambi\Downloads\AdwCleaner_TSV43DG5U 2014-01-30 10:59 - 2010-09-01 21:01 - 00000680 _____ () C:\Users\Bambi\AppData\Local\d3d9caps.dat 2014-01-29 18:28 - 2014-01-29 18:28 - 00000879 _____ () C:\Users\Bambi\Desktop\Continue VuuPC Installation.lnk 2014-01-29 18:17 - 2013-03-05 14:40 - 00002130 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-29 18:17 - 2009-10-26 20:35 - 00001156 _____ () C:\Users\Bambi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-16 12:22 - 2013-09-03 19:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-16 12:18 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-01-15 14:15 - 2013-11-02 15:55 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-15 14:12 - 2014-01-15 14:11 - 00005315 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-01-15 14:12 - 2012-06-27 13:05 - 00000000 ____D () C:\Program Files\Java 2014-01-12 18:39 - 2014-01-12 18:39 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Macromedia 2014-01-12 18:38 - 2009-10-26 21:33 - 00000000 ____D () C:\Users\Bambi\AppData\Local\Adobe 2014-01-12 12:02 - 2013-03-17 13:22 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-01-11 15:50 - 2014-01-11 15:50 - 00000000 ____D () C:\Program Files\Mozilla Firefox Some content of TEMP: ==================== C:\Users\Bambi\AppData\Local\Temp\ApnStub.exe C:\Users\Bambi\AppData\Local\Temp\avgnt.exe C:\Users\Bambi\AppData\Local\Temp\BackupSetup.exe C:\Users\Bambi\AppData\Local\Temp\contentDATs.exe C:\Users\Bambi\AppData\Local\Temp\drm_dialogs.dll C:\Users\Bambi\AppData\Local\Temp\drm_dyndata_7410004.dll C:\Users\Bambi\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Bambi\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Bambi\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u17-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u19-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u20-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u21-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Bambi\AppData\Local\Temp\ndqqarkn.dll C:\Users\Bambi\AppData\Local\Temp\NEW5D61.tmp.exe C:\Users\Bambi\AppData\Local\Temp\NEWF711.tmp.exe C:\Users\Bambi\AppData\Local\Temp\pcspeedmaxsetup.exe C:\Users\Bambi\AppData\Local\Temp\Quarantine.exe C:\Users\Bambi\AppData\Local\Temp\Refresh.exe C:\Users\Bambi\AppData\Local\Temp\SecurityScan_Release.exe C:\Users\Bambi\AppData\Local\Temp\setup.exe C:\Users\Bambi\AppData\Local\Temp\setup{D6921DE2-4509-4629-A14A-5755138AA61A}.exe C:\Users\Bambi\AppData\Local\Temp\SkypeSetup.exe C:\Users\Bambi\AppData\Local\Temp\TEMPRO_2.3.1.exe C:\Users\Bambi\AppData\Local\Temp\vcredist_x86.exe C:\Users\Bambi\AppData\Local\Temp\_is5234.exe C:\Users\Bambi\AppData\Local\Temp\_is5A8E.exe C:\Users\Bambi\AppData\Local\Temp\_prgorxj.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-10 06:16 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- Es ist beides noch da...sowohl awesome hp, als auch snap.do.. ich starte gleich den Pc neu, aber ob das hilft? Nein es hat nicht geholfen, war der security scan so richtig? Geändert von Holly-Blue (10.02.2014 um 18:35 Uhr) |
11.02.2014, 16:30 | #8 |
/// the machine /// TB-Ausbilder | snap.do nicht deinstallierbar windows vista Wo siehst du beides noch?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.02.2014, 21:09 | #9 |
| snap.do nicht deinstallierbar windows vista Hi, snap.do ist bei mozilla firefox zu sehen, oben links neben den vorwärts und rückwärts pfeilen und bei programme und Funktionen. Awesomehp ist die Startseite bei google chrome, aber das benutzen wir nicht. Beim internet explorer ist es weg. Kann ich google chrome deinstallieren wenn ich es nicht benutze? Lg. Holly-Blue |
12.02.2014, 18:13 | #10 |
/// the machine /// TB-Ausbilder | snap.do nicht deinstallierbar windows vista Ja, aber ebenso Firefox deinstallieren, keine Daten behalten, neu installieren. Dann bitte mitteilen wo es noch Probleme gibt.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.02.2014, 21:23 | #11 |
| snap.do nicht deinstallierbar windows vista so, firefox deinstalliert, lässt sich jetzt aber nichtmehr neu installieren (hä?) Snap.do kann ich nicht deinstallieren, es kommt eine Nachricht: the feature you are trying to use is on a network resource that is unavailable. Click OK to try again, or enter an alternate path to a folder containing the installation package 'installer.msi' in the box below. snap.do engine lässt sich auch nicht deinstallieren. Grüße Holly-Blue |
13.02.2014, 21:44 | #12 |
/// the machine /// TB-Ausbilder | snap.do nicht deinstallierbar windows vista Revo Uninstaller - Download - Filepony Versuchs mal damit.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.02.2014, 19:41 | #13 |
| snap.do nicht deinstallierbar windows vista Das kann ich auch nicht downloaden. Ich kann garnichts mehr runterladen. Weder firefox noch revo. Was ist denn aufeinmal los`? |
15.02.2014, 18:04 | #14 |
/// the machine /// TB-Ausbilder | snap.do nicht deinstallierbar windows vista Lade Dir Revo bitte woanders, mit nem Stick auf den Rechner und dann alles deinstallieren was weg kann. DAnn bitte ein frisches FRST Log.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.02.2014, 22:25 | #15 |
| snap.do nicht deinstallierbar windows vista mach ich, muss mir nur einen stick organisieren, dann meld ich mich sofort Lg |