|
Plagegeister aller Art und deren Bekämpfung: browser.newtab.url ändert sich selbstständig auf "search.conduit.com"Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
19.02.2014, 15:16 | #1 |
| browser.newtab.url ändert sich selbstständig auf "search.conduit.com" Guten Tag zusammen, ich habe seit nun schon ca. 1 Woche das Problem, das sich die browser.newtab.url immer wieder von "google.de" auf "search.conduit.com" ändert. Das ist nicht nur nervig sondern, wie ich bereits gelesen habe, ein Virus o.ä.. Nun wollte ich einmal fragen, was man den dagegen machen kann. Mein Antiviren Programm hat übrigens nichts ausgespuckt. (Avast! Free) Vielen Dank schonmal, Robin |
19.02.2014, 15:50 | #2 |
/// the machine /// TB-Ausbilder | browser.newtab.url ändert sich selbstständig auf "search.conduit.com" hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
19.02.2014, 17:46 | #3 |
| browser.newtab.url ändert sich selbstständig auf "search.conduit.com" FRST:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2014 Ran by Robin (administrator) on ROBIN-PC on 19-02-2014 17:41:56 Running from C:\Users\Robin\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) D:\Program Files\AVAST Software\Avast\AvastSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (ICQ) C:\Users\Robin\AppData\Roaming\ICQM\icq.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe () C:\Program Files (x86)\Zapp\WConnectorProductivity.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Skype Technologies S.A.) D:\Program Files (x86)\Skype\Phone\Skype.exe () C:\Windows\SysWOW64\PnkBstrA.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE (Smartbar) C:\Users\Robin\AppData\Local\Smartbar\Application\Shopop.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () D:\Program Files\Hear\Hear.exe (TeamViewer GmbH) D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (AVAST Software) D:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Conduit) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (Conduit) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe (Conduit) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (File Type Advisor) C:\Program Files (x86)\File Type Advisor\fileadvisor.exe (SEIKO EPSON CORPORATION) C:\Windows\system32\spool\DRIVERS\x64\3\E_IARNHAE.EXE () D:\Program Files (x86)\Steam\steamapps\common\rust\rust.exe (Valve Corporation) D:\Program Files (x86)\Steam\GameOverlayUI.exe (Mozilla Corporation) D:\Program Files\Waterfox\waterfox.exe (Mozilla Corporation) D:\Program Files\Waterfox\plugin-container.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [BCSSync] - D:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - D:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - D:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2014-02-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] - D:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-03] (AVAST Software) HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3813712 2014-02-04] (LogMeIn Inc.) HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2013-08-12] (Microsoft Corporation) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [DAEMON Tools Lite] - D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [icq] - C:\Users\Robin\AppData\Roaming\ICQM\icq.exe [28698984 2013-08-06] (ICQ) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Steam] - D:\Program Files (x86)\Steam\steam.exe [1824000 2014-02-11] (Valve Corporation) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Google Update*] - [X] <===== ATTENTION (ZeroAccess rootkit hidden path) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Skype] - D:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Facebook Update] - C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-01-19] (Facebook Inc.) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [EPLTarget\P0000000000000001] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Browser Infrastructure Helper] - C:\Users\Robin\AppData\Local\Smartbar\Application\Shopop.exe [21040 2013-12-31] (Smartbar) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Robin\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\MountPoints2: {41b2eb50-fde3-11e2-8e7d-bc5ff48acc01} - H:\cdstart.exe HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\MountPoints2: {52ebdb9a-fd50-11e2-8ecc-806e6f6e6963} - F:\start.exe HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\MountPoints2: {93b25906-fd4d-11e2-af92-806e6f6e6963} - F:\SETUP.EXE AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [1351456 2014-02-06] (Conduit) AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [1047328 2014-02-06] (Conduit) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q= HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&SSPV= HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA1AB3F2ADF98CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q= HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q= StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=66807&st=bs&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&q={searchTerms} SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=66807&st=bs&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&q={searchTerms} SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&q={searchTerms}&SSPV= SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&q={searchTerms}&SSPV= SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=66807&st=bs&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&q={searchTerms} SearchScopes: HKCU - {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms} BHO: Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files\Zapp\IE\Zapp.dll (Simply Tech LTD.) BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Shopop WidgetEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Java\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Java\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files (x86)\Zapp\IE\Zapp.dll (Simply Tech LTD.) BHO-x32: Shopop WidgetEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files\Zapp\IE\Zapp.dll (Simply Tech LTD.) Toolbar: HKLM - Shopop Widget - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files (x86)\Zapp\IE\Zapp.dll (Simply Tech LTD.) Toolbar: HKLM-x32 - Shopop Widget - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5 07 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 07 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870 FF NewTab: hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552 FF SelectedSearchEngine: Google FF Homepage: hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&SSPV= FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1))%20%7B%20return%20'PROXY%20nq-us07.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000%3B%20PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000%3B%20PROXY%20nq-us05.personalitycores.com%3A8000%3B%20PROXY%20nq-us04.personalitycores.com%3A8000%3B%20PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us10.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - D:\Java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - D:\Java\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.3 - D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - D:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - D:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Robin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Robin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\searchplugins\search_engine.xml FF Extension: Zapp - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\{70ba6a57-dc09-4a3e-bbe1-dfb10af77244} [2014-02-15] FF Extension: No Name - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-12-19] FF Extension: No Name - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\langpack-de@firefox.mozilla.org.xpi [2014-02-05] FF Extension: No Name - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - D:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - D:\Program Files\AVAST Software\Avast\WebRep\FF [2013-08-27] FF StartMenuInternet: FIREFOX.EXE - D:\Program Files\Mozilla Firefox\firefox.exe ==================== Services (Whitelisted) ================= R2 avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-03] (AVAST Software) R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2360608 2014-02-06] (Conduit) R2 Hamachi2Svc; D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2222416 2014-02-04] (LogMeIn Inc.) S3 Microsoft SharePoint Workspace Audit Service; D:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [30969208 2010-03-25] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-09] () S2 SkypeUpdate; D:\Program Files (x86)\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies) R2 TeamViewer8; D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [4308320 2013-08-07] (TeamViewer GmbH) S2 WinkHandler; C:\Program Files (x86)\Iminent\WinkHandler.exe [X] S2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\ \...\???\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess) ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-03] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-23] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-23] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-03] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-03] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-03] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-16] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-05] (DT Soft Ltd) S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) R3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] () R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-19 17:41 - 2014-02-19 17:42 - 00026078 _____ () C:\Users\Robin\Desktop\FRST.txt 2014-02-19 17:41 - 2014-02-19 17:41 - 02153472 _____ (Farbar) C:\Users\Robin\Desktop\FRST64.exe 2014-02-19 17:41 - 2014-02-19 17:41 - 00000000 ____D () C:\FRST 2014-02-18 22:40 - 2014-02-18 22:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\My Games 2014-02-18 22:28 - 2014-02-18 22:28 - 00000221 _____ () C:\Users\Robin\Desktop\Sid Meier's Civilization V - Demo.url 2014-02-18 21:23 - 2014-02-18 21:23 - 00006477 _____ () C:\Users\Robin\AppData\Local\recently-used.xbel 2014-02-16 17:01 - 2014-02-16 17:01 - 00000000 ____D () C:\Users\Robin\.MCTranscodingSDK 2014-02-16 17:00 - 2014-02-16 17:05 - 00000000 ____D () C:\Users\Public\Documents\Lightworks 2014-02-16 17:00 - 2014-02-16 17:00 - 00000000 ____D () C:\ProgramData\Geevs 2014-02-15 22:44 - 2014-02-15 22:46 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Systweak 2014-02-15 22:44 - 2014-02-15 22:44 - 00000000 ____D () C:\Users\Robin\AppData\Local\Smartbar 2014-02-15 22:44 - 2013-08-22 18:36 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe 2014-02-15 22:19 - 2014-02-15 22:29 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\SimplyTech 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files\Zapp 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Zapp 2014-02-15 21:59 - 2014-02-04 06:36 - 00033864 _____ () C:\Windows\Launcher.exe 2014-02-15 21:18 - 2014-02-15 21:18 - 00015130 _____ () C:\Users\Robin\Documents\Mein Film.wlmp 2014-02-15 20:34 - 2014-02-15 20:52 - 591803806 _____ () C:\Users\Robin\Desktop\template.avi 2014-02-15 20:34 - 2014-02-15 20:52 - 591803806 _____ () C:\Users\Robin\Desktop\A_template.avi 2014-02-15 19:16 - 2014-02-16 22:37 - 00000000 ____D () C:\Users\Robin\Desktop\INTRO TEMPLATE BY RenttuArts 2014-02-13 15:28 - 2014-02-13 15:28 - 00000000 ____D () C:\Windows\SysWOW64\SearchProtect 2014-02-12 22:45 - 2014-02-12 22:45 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-02-10 19:33 - 2014-02-10 19:33 - 00000934 _____ () C:\Users\Robin\Desktop\Landwirtschafts Simulator 2013 .lnk 2014-02-10 17:26 - 2014-02-10 17:26 - 00000000 ____D () C:\Users\Robin\AppData\Local\EdgeOfReality 2014-02-10 16:08 - 2014-02-10 16:08 - 00000222 _____ () C:\Users\Robin\Desktop\Loadout.url 2014-02-09 22:33 - 2014-02-14 23:32 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\vlc 2014-02-09 22:33 - 2014-02-09 22:33 - 00001184 _____ () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk 2014-02-09 22:33 - 2014-02-09 22:33 - 00000757 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-02-09 17:25 - 2014-02-09 17:25 - 00000836 _____ () C:\Users\Public\Desktop\Prime Time.lnk 2014-02-05 18:57 - 2014-02-17 22:31 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.minecraft 2014-02-04 16:51 - 2014-02-04 16:51 - 00003012 _____ () C:\Windows\System32\Tasks\{29949044-F7D7-4E68-B9CE-644E4CFDA5BB} 2014-02-03 20:36 - 2014-02-03 20:36 - 00001648 _____ () C:\Users\Robin\Desktop\Euro Truck Simulator 2.lnk 2014-02-03 18:45 - 2014-02-03 18:45 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run 2014-02-03 18:44 - 2014-02-03 18:44 - 00000000 ____D () C:\2-click run 2014-02-03 18:40 - 2014-02-13 15:29 - 00000000 ____D () C:\Program Files (x86)\SearchProtect 2014-02-03 18:40 - 2014-02-03 18:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\SearchProtect 2014-01-30 16:10 - 2014-01-30 16:10 - 00012834 _____ () C:\Users\Robin\Desktop\Anno2070.lnk 2014-01-30 16:02 - 2014-01-30 16:02 - 00001468 _____ () C:\Users\Robin\Desktop\Flight Simulator X.lnk 2014-01-29 20:02 - 2014-01-29 20:02 - 00038960 _____ () C:\Windows\SysWOW64\RGBAcodec.dll 2014-01-28 21:01 - 2014-02-16 17:46 - 00000000 ___RD () C:\Users\Robin\Desktop\Aufnehmzeug 2014-01-26 21:29 - 2013-12-19 21:33 - 30372640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 22960416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 12645664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-01-26 21:29 - 2013-12-19 21:33 - 11605752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 11554264 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 09700224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 09657464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00882464 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00879392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00852768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00847648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00357152 _____ () C:\Windows\system32\NvIFROpenGL.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00314656 _____ () C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-01-26 21:29 - 2013-11-28 14:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-01-26 21:29 - 2013-11-28 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-01-26 21:29 - 2013-11-22 09:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-01-26 21:26 - 2013-12-27 19:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-01-26 21:26 - 2013-12-27 19:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-01-26 01:00 - 2014-02-19 12:06 - 00005694 _____ () C:\Windows\setupact.log 2014-01-26 01:00 - 2014-01-26 01:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-01-25 17:52 - 2014-01-25 17:52 - 00000000 ____D () C:\Users\Robin\.cache 2014-01-25 15:28 - 2014-01-26 17:48 - 03276780 _____ () C:\Users\Robin\Desktop\Schülerpraktikumsbericht.pptx ==================== One Month Modified Files and Folders ======= 2014-02-19 17:42 - 2014-02-19 17:41 - 00026078 _____ () C:\Users\Robin\Desktop\FRST.txt 2014-02-19 17:41 - 2014-02-19 17:41 - 02153472 _____ (Farbar) C:\Users\Robin\Desktop\FRST64.exe 2014-02-19 17:41 - 2014-02-19 17:41 - 00000000 ____D () C:\FRST 2014-02-19 17:40 - 2013-08-05 17:20 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Skype 2014-02-19 17:25 - 2014-01-19 20:20 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000UA.job 2014-02-19 17:06 - 2013-12-05 14:50 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-19 16:51 - 2013-08-04 23:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-19 12:43 - 2013-08-24 11:43 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor 2014-02-19 12:15 - 2013-12-18 20:45 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\newnext.me 2014-02-19 12:14 - 2009-07-14 05:45 - 00015760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-19 12:14 - 2009-07-14 05:45 - 00015760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-19 12:12 - 2009-07-14 18:58 - 00699394 _____ () C:\Windows\system32\perfh007.dat 2014-02-19 12:12 - 2009-07-14 18:58 - 00149534 _____ () C:\Windows\system32\perfc007.dat 2014-02-19 12:12 - 2009-07-14 06:13 - 01620346 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-19 12:07 - 2014-01-06 16:45 - 00000000 ____D () C:\Users\Robin\AppData\Local\LogMeIn Hamachi 2014-02-19 12:07 - 2013-08-17 09:34 - 00000000 ____D () C:\Users\Robin\AppData\Local\Adobe 2014-02-19 12:07 - 2013-08-05 09:42 - 00124616 _____ () C:\Users\Robin\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-19 12:06 - 2014-01-26 01:00 - 00005694 _____ () C:\Windows\setupact.log 2014-02-19 12:06 - 2013-12-05 14:50 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-19 12:06 - 2013-08-04 22:49 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-19 12:06 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-19 12:06 - 2009-07-14 05:45 - 05108968 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-18 22:40 - 2014-02-18 22:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\My Games 2014-02-18 22:40 - 2013-10-21 15:35 - 00000000 ____D () C:\Users\Robin\Documents\My Games 2014-02-18 22:40 - 2013-08-05 23:41 - 00435159 _____ () C:\Windows\DirectX.log 2014-02-18 22:28 - 2014-02-18 22:28 - 00000221 _____ () C:\Users\Robin\Desktop\Sid Meier's Civilization V - Demo.url 2014-02-18 21:46 - 2013-08-07 20:08 - 00000000 ____D () C:\Users\Robin\Documents\Euro Truck Simulator 2 2014-02-18 21:23 - 2014-02-18 21:23 - 00006477 _____ () C:\Users\Robin\AppData\Local\recently-used.xbel 2014-02-18 21:23 - 2013-08-05 23:05 - 00000000 ____D () C:\Users\Robin\AppData\Local\gtk-2.0 2014-02-18 21:23 - 2013-08-05 23:03 - 00000000 ____D () C:\Users\Robin\.gimp-2.8 2014-02-18 20:25 - 2014-01-19 20:20 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000Core.job 2014-02-18 20:00 - 2013-08-04 22:39 - 01377138 _____ () C:\Windows\WindowsUpdate.log 2014-02-17 22:31 - 2014-02-05 18:57 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.minecraft 2014-02-16 22:37 - 2014-02-15 19:16 - 00000000 ____D () C:\Users\Robin\Desktop\INTRO TEMPLATE BY RenttuArts 2014-02-16 19:27 - 2013-08-05 18:32 - 00007602 _____ () C:\Users\Robin\AppData\Local\Resmon.ResmonCfg 2014-02-16 17:46 - 2014-01-28 21:01 - 00000000 ___RD () C:\Users\Robin\Desktop\Aufnehmzeug 2014-02-16 17:05 - 2014-02-16 17:00 - 00000000 ____D () C:\Users\Public\Documents\Lightworks 2014-02-16 17:01 - 2014-02-16 17:01 - 00000000 ____D () C:\Users\Robin\.MCTranscodingSDK 2014-02-16 17:01 - 2013-08-04 22:37 - 00000000 ____D () C:\Users\Robin 2014-02-16 17:00 - 2014-02-16 17:00 - 00000000 ____D () C:\ProgramData\Geevs 2014-02-16 10:27 - 2013-08-05 09:37 - 00125194 _____ () C:\Windows\PFRO.log 2014-02-15 22:46 - 2014-02-15 22:44 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Systweak 2014-02-15 22:45 - 2013-12-18 20:45 - 00000000 ____D () C:\Users\Robin\AppData\Local\Mobogenie 2014-02-15 22:45 - 2013-12-18 20:45 - 00000000 ____D () C:\Program Files (x86)\Mobogenie 2014-02-15 22:45 - 2013-08-04 22:37 - 00000000 ___RD () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-15 22:44 - 2014-02-15 22:44 - 00000000 ____D () C:\Users\Robin\AppData\Local\Smartbar 2014-02-15 22:44 - 2013-12-18 20:45 - 00000000 ____D () C:\Users\Robin\AppData\Local\genienext 2014-02-15 22:29 - 2014-02-15 22:19 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-02-15 22:28 - 2013-11-12 18:16 - 00000000 ____D () C:\Program Files\Adobe 2014-02-15 22:19 - 2013-08-17 09:34 - 00000000 ____D () C:\ProgramData\Adobe 2014-02-15 22:19 - 2013-08-04 23:29 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Adobe 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\SimplyTech 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files\Zapp 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Zapp 2014-02-15 21:18 - 2014-02-15 21:18 - 00015130 _____ () C:\Users\Robin\Documents\Mein Film.wlmp 2014-02-15 20:52 - 2014-02-15 20:34 - 591803806 _____ () C:\Users\Robin\Desktop\template.avi 2014-02-15 20:52 - 2014-02-15 20:34 - 591803806 _____ () C:\Users\Robin\Desktop\A_template.avi 2014-02-15 15:29 - 2013-12-25 21:24 - 02346186 _____ () C:\Users\Robin\Desktop\TechnicLauncher.exe 2014-02-15 15:29 - 2013-10-26 18:16 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.technic 2014-02-14 23:32 - 2014-02-09 22:33 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\vlc 2014-02-13 15:29 - 2014-02-03 18:40 - 00000000 ____D () C:\Program Files (x86)\SearchProtect 2014-02-13 15:28 - 2014-02-13 15:28 - 00000000 ____D () C:\Windows\SysWOW64\SearchProtect 2014-02-12 22:45 - 2014-02-12 22:45 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-02-12 21:01 - 2013-12-05 14:50 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-12 21:01 - 2013-12-05 14:50 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-12 15:45 - 2013-08-27 17:24 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-02-10 19:33 - 2014-02-10 19:33 - 00000934 _____ () C:\Users\Robin\Desktop\Landwirtschafts Simulator 2013 .lnk 2014-02-10 17:26 - 2014-02-10 17:26 - 00000000 ____D () C:\Users\Robin\AppData\Local\EdgeOfReality 2014-02-10 16:08 - 2014-02-10 16:08 - 00000222 _____ () C:\Users\Robin\Desktop\Loadout.url 2014-02-09 22:33 - 2014-02-09 22:33 - 00001184 _____ () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk 2014-02-09 22:33 - 2014-02-09 22:33 - 00000757 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-02-09 17:25 - 2014-02-09 17:25 - 00000836 _____ () C:\Users\Public\Desktop\Prime Time.lnk 2014-02-04 22:51 - 2013-08-04 23:29 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-04 22:51 - 2013-08-04 23:29 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-04 22:51 - 2013-08-04 23:29 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-04 16:51 - 2014-02-04 16:51 - 00003012 _____ () C:\Windows\System32\Tasks\{29949044-F7D7-4E68-B9CE-644E4CFDA5BB} 2014-02-04 06:36 - 2014-02-15 21:59 - 00033864 _____ () C:\Windows\Launcher.exe 2014-02-03 22:18 - 2013-08-05 23:55 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\uTorrent 2014-02-03 20:36 - 2014-02-03 20:36 - 00001648 _____ () C:\Users\Robin\Desktop\Euro Truck Simulator 2.lnk 2014-02-03 19:03 - 2013-08-27 17:24 - 00001040 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-03 19:02 - 2014-01-16 21:19 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-03 19:02 - 2013-08-27 17:24 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-03 19:02 - 2013-08-27 17:24 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-03 19:02 - 2013-08-27 17:24 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-03 19:02 - 2013-08-27 17:24 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-03 19:02 - 2013-08-27 17:24 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-03 18:45 - 2014-02-03 18:45 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run 2014-02-03 18:44 - 2014-02-03 18:44 - 00000000 ____D () C:\2-click run 2014-02-03 18:40 - 2014-02-03 18:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\SearchProtect 2014-01-30 16:38 - 2013-11-24 15:58 - 00000781 _____ () C:\Users\Robin\Desktop\TransportGigant.lnk 2014-01-30 16:10 - 2014-01-30 16:10 - 00012834 _____ () C:\Users\Robin\Desktop\Anno2070.lnk 2014-01-30 16:03 - 2013-08-30 22:11 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Virtuali 2014-01-30 16:03 - 2013-08-30 22:11 - 00000000 ____D () C:\ProgramData\Virtuali 2014-01-30 16:02 - 2014-01-30 16:02 - 00001468 _____ () C:\Users\Robin\Desktop\Flight Simulator X.lnk 2014-01-29 20:02 - 2014-01-29 20:02 - 00038960 _____ () C:\Windows\SysWOW64\RGBAcodec.dll 2014-01-27 19:49 - 2013-11-21 22:33 - 00000000 ____D () C:\Users\Robin\AppData\Local\Microsoft Games 2014-01-26 21:30 - 2013-08-04 22:49 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-01-26 17:48 - 2014-01-25 15:28 - 03276780 _____ () C:\Users\Robin\Desktop\Schülerpraktikumsbericht.pptx 2014-01-26 01:00 - 2014-01-26 01:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-01-25 17:52 - 2014-01-25 17:52 - 00000000 ____D () C:\Users\Robin\.cache 2014-01-21 03:53 - 2013-11-02 10:54 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-01-21 03:53 - 2013-11-02 10:54 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll ZeroAccess: C:\Users\Robin\AppData\Local\Google\Desktop\Install ZeroAccess: C:\Program Files (x86)\Google\Desktop\Install Some content of TEMP: ==================== C:\Users\Robin\AppData\Local\Temp\BackupSetup.exe C:\Users\Robin\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\Robin\AppData\Local\Temp\DownloadManager.exe C:\Users\Robin\AppData\Local\Temp\nssCDB.exe C:\Users\Robin\AppData\Local\Temp\nssD78.exe C:\Users\Robin\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Robin\AppData\Local\Temp\SearchProtectINT.exe C:\Users\Robin\AppData\Local\Temp\sqlite3.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender LastRegBack: 2014-02-19 12:50 ==================== End Of Log ============================ Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-02-2014 Ran by Robin at 2014-02-19 17:42:19 Running from C:\Users\Robin\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== µTorrent (HKCU Version: 3.3.2.30488 - BitTorrent Inc.) 4Videosoft MKV Video Converter 5.0.8 (x32 Version: - ) Adobe After Effects CC (x32 Version: 12.2.1 - Adobe Systems Incorporated) Adobe Creative Cloud (x32 Version: 2.4.1.351 - Adobe Systems Incorporated) Adobe Flash Player 12 ActiveX (x32 Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03 - Adobe Systems Incorporated) AMD Catalyst Install Manager (Version: 3.0.868.0 - Advanced Micro Devices, Inc.) ANNO 2070 (x32 Version: 1.0.0.0 - Ubisoft) Apple Application Support (x32 Version: 2.3.4 - Apple Inc.) Apple Mobile Device Support (Version: 6.1.0.13 - Apple Inc.) Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.) AppPublisherURL=hxxp://www.rtl-primetime.de/ AppVersion=1.0) avast! Free Antivirus (x32 Version: 9.0.2013 - Avast Software) Battlefield Heroes (x32 Version: - EA Digital illusions) Bonjour (Version: 3.0.0.10 - Apple Inc.) Cinema 4D version R12 (x32 Version: R12 - Salat Production) CL-Eye Driver (x32 Version: 5.3.0.0341 - Code Laboratories, Inc.) Crazy Taxi (x32 Version: - ) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (x32 Version: 4.47.1.0333 - Disc Soft Ltd) Die Siedler 7 (x32 Version: 1.02.1221 - Ubisoft) Die Sims™ 3 (x32 Version: 1.63.4 - Electronic Arts) Die Sims™ 3 Into the Future (x32 Version: 21.0.150 - Electronic Arts) Die Sims™ 3 Late Night (x32 Version: 6.0.81 - Electronic Arts) Die Sims™ 3 Lebensfreude (x32 Version: 8.0.152 - Electronic Arts) Die Sims™ 3 Reiseabenteuer (x32 Version: 2.0.86 - Electronic Arts) Die Sims™ 3 Traumkarrieren (x32 Version: 4.0.87 - Electronic Arts) Easy MP3 Cutter 3.0 (x32 Version: - ManiacTools.com) EPSON SX430 Series Printer Uninstall (Version: - SEIKO EPSON Corporation) Etron USB3.0 Host Controller (x32 Version: 0.115 - Etron Technology) Etron USB3.0 Host Controller (x32 Version: 0.115 - Etron Technology) Hidden Euro Truck Simulator 2 (x32 Version: 1.4.8 - SCS Software) Euro Truck Simulator 2 v1.7.1 (DLC Going East) (x32 Version: 1.7.1 - Friends in War) Facebook Video Calling 2.0.0.447 (x32 Version: 2.0.447 - Skype Limited) File Type Advisor 1.0 (x32 Version: - filetypeadvisor.com) FileEdit (HKCU Version: 1.0.0.7 - FileEdit) FileZilla Client 3.7.3 (x32 Version: 3.7.3 - Tim Kosse) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fraps (remove only) (x32 Version: - ) Free M4a to MP3 Converter 8.0 (x32 Version: - ManiacTools.com) Free YouTube Download version 3.2.11.812 (x32 Version: 3.2.11.812 - DVDVideoSoft Ltd.) FSDreamTeam GSX 1.7.9.8 (x32 Version: - ) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden GIGABYTE OC_GURU II (x32 Version: 1.37.0000 - GIGABYTE Technology Co.,Ltd.) GIGABYTE OC_GURU II (x32 Version: 1.37.0000 - GIGABYTE Technology Co.,Ltd.) Hidden GIMP 2.8.6 (Version: 2.8.6 - The GIMP Team) Google Earth Plug-in (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden Grand Theft Auto IV (x32 Version: 1.00.0000 - Rockstar Games) Hear (Version: - Joesoft) HomepageFIX 2013 (x32 Version: Aktuelle Version - IN MEDIA KG) ICQ 8.1 (build 6337) (HKCU Version: 8.1.6337.0 - Mail.Ru) IndustrieGigant 2 (x32 Version: - UIG GmbH) InterActual Player (x32 Version: - ) iTunes (Version: 11.0.5.5 - Apple Inc.) Java 7 Update 51 (64-bit) (Version: 7.0.510 - Oracle) Just Flight - Traffic X (x32 Version: 1.00.000 - Just Flight) Landwirtschafts Simulator 2013 (x32 Version: 1.0 - GIANTS Software) Lightworks (x32 Version: 11.5.0.0 - Lightworks) Loadout (x32 Version: - Edge of Reality) LogMeIn Hamachi (x32 Version: 2.2.0.130 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.130 - LogMeIn, Inc.) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft Age of Empires II Trial Version (x32 Version: - ) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Flight Simulator X (x32 Version: 10.0.61355.0 - Microsoft Game Studios) Hidden Microsoft Flight Simulator X Service Pack 1 (x32 Version: 10.0.61355.0 - Microsoft Game Studios) Hidden Microsoft Flight Simulator X Service Pack 2 (x32 Version: 10.0.61472.0 - Microsoft Game Studios) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (x32 Version: 3.5.67.0 - Microsoft Corporation) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0 - Microsoft Corp.) Microsoft XNA Framework Redistributable 4.0 (x32 Version: 4.0.20823.0 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0 - Mozilla) Mozilla Firefox 26.0 (x86 de) (HKCU Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 25.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 Parser und SDK (x32 Version: 4.20.9818.0 - Microsoft Corporation) Notepad++ (x32 Version: 6.4.5 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 332.21 (Version: 332.21 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 332.21 (Version: 332.21 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2 (Version: 1.8.2 - NVIDIA Corporation) NVIDIA Grafiktreiber 332.21 (Version: 332.21 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.142.992 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3221 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 332.21 (Version: 332.21 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (Version: 1.2.20 - NVIDIA Corporation) Origin (x32 Version: 9.1.10.2728 - Electronic Arts, Inc.) outobox (Version: 2013.12.07.011955 - outobox) <==== ATTENTION Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Prime Time (x32 Version: - RTL Playtainment Prison Architect (x32 Version: - Introversion Software) PunkBuster Services (x32 Version: 0.990 - Even Balance, Inc.) QuickTime (x32 Version: 7.74.80.86 - Apple Inc.) RCT3 Soaked (x32 Version: 1.00.000 - ) Realtek Ethernet Controller Driver (x32 Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6873 - Realtek Semiconductor Corp.) ReelSmart Motion Blur 4, After Effects-compatible plugin set (x32 Version: - ) RollerCoaster Tycoon 3 (x32 Version: 1.00.000 - ) Rust (x32 Version: - Facepunch Studios) Search Protect (x32 Version: 2.10.20.64 - Conduit) <==== ATTENTION SHIELD Streaming (Version: 1.7.306 - NVIDIA Corporation) Hidden Shopop (x32 Version: 10.203.68.14274 - My Pop Shop Ltd.) <==== ATTENTION Sid Meier's Civilization V - Demo (x32 Version: - Firaxis Games) SimCity™ (x32 Version: 1.0.0.0 - Electronic Arts) Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) Source SDK Base 2007 (x32 Version: - Valve) Steam (x32 Version: 1.0.0.0 - Valve Corporation) TeamSpeak 3 Client (Version: 3.0.11 - TeamSpeak Systems GmbH) TeamViewer 8 (x32 Version: 8.0.20202 - TeamViewer) TG-MOD (x32 Version: 0.32 - -) Train Simulator 2014 (x32 Version: - RailSimulator.com) TransportGigant (x32 Version: 1.3.0 - JoWooD Productions Software AG) TransportGigant: Down Under (x32 Version: 2.10 - JoWooD Productions Software AG) Ubisoft Game Launcher (x32 Version: 1.0.0.0 - UBISOFT) Unity Web Player (HKCU Version: - Unity Technologies ApS) Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1 - Microsoft Corporation) Vegas Pro 12.0 (64-bit) (Version: 12.0.670 - Sony) VLC media player 2.1.3 (Version: 2.1.3 - VideoLAN) Waterfox 26.0 (x64 en-US) (Version: 26.0 - Mozilla) Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden WinRAR 4.20 (64-Bit) (Version: 4.20.0 - win.rar GmbH) Wireless Systems Manager (x32 Version: 4.0.85 - Sennheiser electronic) World of Tanks (x32 Version: - Wargaming.net) World of Warplanes (x32 Version: - Wargaming.net) World Series Of Poker (x32 Version: - ) WorldPainter 1.5.0 (Version: 1.5.0 - pepsoft.org) Zapp 5.7 (x32 Version: 5.7 - Zapp) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {03873767-33A9-471F-B34A-5449C8182409} - System32\Tasks\{97B51F7E-61B9-4818-B97D-DA0C55020521} => D:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {05524248-BAAE-45F2-B7E8-1FDC7B75D8E1} - System32\Tasks\{5576FB1A-EA81-4DB0-9370-2EB35F3519C8} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe Task: {227C430F-E696-498D-B219-8A42D828ABAE} - System32\Tasks\{4DFC705A-3CA5-4287-BE1E-395DAEF79BD6} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe Task: {229E415C-E81E-4FC4-8F5C-3AA21EF0E243} - System32\Tasks\{56D1DA53-B247-4305-994B-D9BF5130DE61} => D:\Program Files (x86)\TransportGigant\transportgiant.exe [2004-10-28] (JoWooD Productions Software AG) Task: {24842094-8928-485B-9AF9-F6A11550677E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-04] (Adobe Systems Incorporated) Task: {248D936E-C7FE-4368-B2C0-68030AC26A38} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000UA => C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-19] (Facebook Inc.) Task: {249DE304-F23B-42B4-9D30-D20BF2AF2653} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-05] (Google Inc.) Task: {2E09AC7E-AB29-4BA1-812F-CDAE097A8066} - System32\Tasks\Browser Updater\Zapp Browser Updater => C:\Program Files (x86)\Zapp\tbupdater.exe Task: {393A9A7A-118B-4E59-9B98-E9629F2D7843} - System32\Tasks\{7B17E059-F7D4-4361-A07B-E745123DC8D5} => D:\Program Files (x86)\TransportGigant\transportgiant.exe [2004-10-28] (JoWooD Productions Software AG) Task: {57604AB5-7B2B-44E2-8B33-F69933632486} - System32\Tasks\avast! Emergency Update => D:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-02-03] (AVAST Software) Task: {5F165A9D-2B23-4018-8E44-1A5EC506E4C4} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] () Task: {77C23E79-380E-4E29-BCB6-370909E92EC8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-05] (Google Inc.) Task: {787437D7-B900-44B4-9EDF-EA1B10001115} - System32\Tasks\{B79F3902-4091-4930-A573-E4A090A0A7E1} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe Task: {7CD884B1-F48C-4C5E-AF4B-35B543E76346} - System32\Tasks\{A5A1D7B4-1739-4954-815E-E58981842E7D} => D:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {81FA4FB1-64A2-4B5B-85DD-CFEBE1D21B5E} - System32\Tasks\FileAdvisorCheck => C:\Program Files (x86)\File Type Advisor\file-type-advisor.exe [2013-07-12] (filetypeadvisor.com ) Task: {87E2AF4D-A960-414F-A871-8FBD259E947E} - System32\Tasks\{B39D9B38-9D41-410C-B032-985E9205FFA9} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe Task: {8C9786BD-E15A-4422-BC50-C4A717186593} - System32\Tasks\{DEA2DC23-3805-47F4-A4CF-509889A050F7} => D:\Program Files (x86)\TransportGigant\transportgiant.exe [2004-10-28] (JoWooD Productions Software AG) Task: {94ACFFF0-2504-433F-A8B9-510C39FFE683} - System32\Tasks\{0B0793EA-DF9D-4F35-9ABB-ECA9F8E6E909} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe Task: {9BEAD541-DD5D-4E2F-962A-62872BCBC274} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000Core => C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-19] (Facebook Inc.) Task: {AF5F6EFE-7E50-4979-BC7D-3AE1597D9B73} - System32\Tasks\{3FAB98F2-BDEC-47EE-A57D-51285D12C184} => D:\Program Files (x86)\TransportGigant\transportgiant.exe [2004-10-28] (JoWooD Productions Software AG) Task: {B0338402-4979-4D02-988C-04D25ABA9BB9} - System32\Tasks\{741CDDD5-0EFC-4FEA-800B-EF6E75535219} => D:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {BCBD4C9C-7FD0-4946-9169-CFC8350A1FCC} - System32\Tasks\FileAdvisorUpdate => C:\Program Files (x86)\File Type Advisor\fileadvisor.exe [2013-07-12] (File Type Advisor) Task: {C3A401A9-D6A8-43F0-BA39-D190CE281869} - System32\Tasks\{BBBD1780-C0FF-4C5C-B2D8-7DB612F06A3D} => C:\Program Files (x86)\Terraria\Terraria.exe Task: {CB52A3AF-8201-4406-B194-13FDC5865C31} - System32\Tasks\{29949044-F7D7-4E68-B9CE-644E4CFDA5BB} => D:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe [2013-08-17] (Sony DADC Austria AG) Task: {D542AB36-D07C-4D3F-9A5E-F4302F4E4B52} - System32\Tasks\{4530D85B-3038-4F3A-A223-2608EB0CCCEE} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe Task: {F1B6A710-99D9-499E-986D-28307E626B2B} - System32\Tasks\{88AA7E58-581B-4365-B920-437A052D9500} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe Task: {FEC68702-49D6-4691-808C-EE3AA92F35AA} - System32\Tasks\{FA1A5B05-1D9B-4464-B2F7-CC8D12CB791A} => D:\Program Files (x86)\TransportGigant\transportgiant.exe [2004-10-28] (JoWooD Productions Software AG) Task: {FF36824C-7BCA-4FD1-A209-0A32FD4A0EB0} - System32\Tasks\SystemSockets\SystemSockets => C:\Program Files (x86)\Zapp\WConnectorProductivity.exe [2014-01-09] () Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000Core.job => C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000UA.job => C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-04 22:49 - 2013-12-19 19:53 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2010-01-30 01:40 - 2010-01-30 01:40 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () D:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2014-02-15 21:59 - 2014-01-09 08:16 - 00034376 _____ () C:\Program Files (x86)\Zapp\WConnectorProductivity.exe 2013-10-09 23:11 - 2013-10-09 23:20 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-16 21:16 - 2011-11-28 20:47 - 03174024 _____ () D:\Program Files\Hear\Hear.exe 2014-01-05 11:34 - 2014-01-21 03:56 - 00093472 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\gamecaster64.dll 2014-01-05 11:34 - 2014-01-21 03:56 - 00874784 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\twitchsdk64.dll 2014-01-15 11:02 - 2014-01-15 11:02 - 04697456 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe 2014-02-17 19:01 - 2014-02-17 19:01 - 18204416 _____ () D:\Program Files (x86)\Steam\steamapps\common\rust\rust.exe 2014-02-05 21:03 - 2013-12-07 19:09 - 07350272 _____ () D:\Program Files\Waterfox\mozjs.dll 2013-12-11 13:51 - 2013-12-11 13:51 - 22332808 _____ () C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll 2014-02-19 12:08 - 2014-02-19 09:01 - 02181120 _____ () D:\Program Files\AVAST Software\Avast\defs\14021900\algo.dll 2013-08-06 07:51 - 2013-08-06 07:51 - 00851456 _____ () C:\Users\Robin\AppData\Roaming\ICQM\ICQ\dll\YLUSBTEL.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-01-08 11:51 - 2013-12-12 23:19 - 00142848 _____ () D:\Program Files (x86)\Steam\libavresample-1.dll 2014-01-08 11:51 - 2013-11-05 02:12 - 00890592 _____ () D:\Program Files (x86)\Steam\libavutil-52.dll 2013-07-01 07:20 - 2014-01-11 00:33 - 00717312 _____ () D:\Program Files (x86)\Steam\SDL2.dll 2013-07-26 13:46 - 2014-01-27 20:02 - 01138088 _____ () D:\Program Files (x86)\Steam\bin\chromehtml.DLL 2013-07-15 13:32 - 2014-01-11 00:33 - 20625832 _____ () D:\Program Files (x86)\Steam\bin\libcef.dll 2013-06-14 14:49 - 2013-06-15 00:49 - 01100800 _____ () D:\Program Files (x86)\Steam\bin\avcodec-53.dll 2013-06-14 14:49 - 2013-06-15 00:49 - 00124416 _____ () D:\Program Files (x86)\Steam\bin\avutil-51.dll 2013-06-14 14:49 - 2013-06-15 00:49 - 00192000 _____ () D:\Program Files (x86)\Steam\bin\avformat-53.dll 2010-01-30 01:41 - 2010-01-30 01:41 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-12-31 16:40 - 2013-12-31 16:40 - 00034864 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00064048 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\srau.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00150576 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00112688 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 02151984 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00055856 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\spbl.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00013360 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\siem.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00048688 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\sppsm.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00728112 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00081968 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00014384 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00017456 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00031280 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\srut.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00020528 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\srsbs.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00057392 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00014384 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\srpdm.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00014384 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\sgml.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00053296 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll 2013-12-31 16:38 - 2013-12-31 16:38 - 00048176 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\MACTrackBarLib.dll 2013-12-31 16:38 - 2013-12-31 16:38 - 00026160 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00025648 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll 2013-12-31 16:40 - 2013-12-31 16:40 - 00248368 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\srns.dll 2014-02-11 15:09 - 2014-02-11 15:09 - 32733080 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll 2013-08-07 20:25 - 2013-08-07 20:25 - 00093696 _____ () D:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2013-11-23 13:20 - 2013-11-23 13:20 - 19336120 _____ () D:\Program Files\AVAST Software\Avast\libcef.dll 2014-02-11 15:09 - 2014-02-11 15:09 - 00742808 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libglesv2.dll 2014-02-11 15:09 - 2014-02-11 15:09 - 00136600 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libegl.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:74603393 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/19/2014 00:07:42 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (02/18/2014 09:23:41 PM) (Source: Application Hang) (User: ) Description: Programm gimp-2.8.exe, Version 2.8.6.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2030 Startzeit: 01cf2ce4d4eda417 Endzeit: 3 Anwendungspfad: D:\Program Files\GIMP 2\bin\gimp-2.8.exe Berichts-ID: 8cfb5941-98da-11e3-aa71-bc5ff48acc01 Error: (02/18/2014 06:02:32 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (02/18/2014 05:22:30 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (02/17/2014 10:03:30 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: GTAIV.exe, Version: 1.0.7.0, Zeitstempel: 0x4bd9efbe Name des fehlerhaften Moduls: GTAIV.exe, Version: 1.0.7.0, Zeitstempel: 0x4bd9efbe Ausnahmecode: 0xc0000005 Fehleroffset: 0x001a9346 ID des fehlerhaften Prozesses: 0x22ac Startzeit der fehlerhaften Anwendung: 0xGTAIV.exe0 Pfad der fehlerhaften Anwendung: GTAIV.exe1 Pfad des fehlerhaften Moduls: GTAIV.exe2 Berichtskennung: GTAIV.exe3 Error: (02/17/2014 10:03:29 PM) (Source: .NET Runtime) (User: ) Description: Application: GTAIV.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: exception code c0000005, exception address 01479346 Stack: Error: (02/17/2014 07:01:06 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (02/16/2014 02:11:46 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (02/16/2014 02:09:00 PM) (Source: Application Hang) (User: ) Description: Programm icq.exe, Version 8.1.6337.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 890 Startzeit: 01cf2af9449b775f Endzeit: 22 Anwendungspfad: C:\Users\Robin\AppData\Roaming\ICQM\icq.exe Berichts-ID: Error: (02/16/2014 10:28:06 AM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall System errors: ============= Error: (02/19/2014 01:09:57 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (02/19/2014 00:07:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2147024891 Error: (02/19/2014 00:07:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet: %%-2147024891 Error: (02/19/2014 00:07:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2147024891 Error: (02/19/2014 00:07:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet: %%-2147024891 Error: (02/19/2014 00:06:53 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" wurde mit folgendem Fehler beendet: %%1060 Error: (02/19/2014 00:06:51 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "WinkHandler" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/19/2014 00:06:48 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "IPsec-Richtlinien-Agent" ist von folgendem Dienst abhängig: BFE. Dieser Dienst ist eventuell nicht installiert. Error: (02/19/2014 00:06:48 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "IKE- und AuthIP IPsec-Schlüsselerstellungsmodule" ist von folgendem Dienst abhängig: BFE. Dieser Dienst ist eventuell nicht installiert. Error: (02/18/2014 07:00:29 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Microsoft Office Sessions: ========================= Error: (02/19/2014 00:07:42 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (02/18/2014 09:23:41 PM) (Source: Application Hang)(User: ) Description: gimp-2.8.exe2.8.6.0203001cf2ce4d4eda4173D:\Program Files\GIMP 2\bin\gimp-2.8.exe8cfb5941-98da-11e3-aa71-bc5ff48acc01 Error: (02/18/2014 06:02:32 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (02/18/2014 05:22:30 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (02/17/2014 10:03:30 PM) (Source: Application Error)(User: ) Description: GTAIV.exe1.0.7.04bd9efbeGTAIV.exe1.0.7.04bd9efbec0000005001a934622ac01cf2c22d7738429D:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\GTAIV.exeD:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\GTAIV.exef39f8df8-9816-11e3-82ae-bc5ff48acc01 Error: (02/17/2014 10:03:29 PM) (Source: .NET Runtime)(User: ) Description: Application: GTAIV.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: exception code c0000005, exception address 01479346 Stack: Error: (02/17/2014 07:01:06 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (02/16/2014 02:11:46 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (02/16/2014 02:09:00 PM) (Source: Application Hang)(User: ) Description: icq.exe8.1.6337.089001cf2af9449b775f22C:\Users\Robin\AppData\Roaming\ICQM\icq.exe Error: (02/16/2014 10:28:06 AM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall ==================== Memory info =========================== Percentage of memory in use: 42% Total physical RAM: 8148.74 MB Available physical RAM: 4683.84 MB Total Pagefile: 16295.68 MB Available Pagefile: 10368.85 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:55.8 GB) (Free:4.92 GB) NTFS Drive d: (Speicherpaltte) (Fixed) (Total:465.76 GB) (Free:245.95 GB) NTFS Drive f: (Prime Time) (CDROM) (Total:0.65 GB) (Free:0 GB) CDFS Drive g: (Volume) (Fixed) (Total:1862.89 GB) (Free:1601.87 GB) NTFS Drive h: (LS2013DE) (CDROM) (Total:1.36 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 56 GB) (Disk ID: 57D4B197) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=56 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 8F2F8149) Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 1863 GB) (Disk ID: 331A92D7) Partition: GPT Partition Type ==================== End Of Log ============================ |
20.02.2014, 14:17 | #4 |
/// the machine /// TB-Ausbilder | browser.newtab.url ändert sich selbstständig auf "search.conduit.com" hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.02.2014, 16:14 | #5 |
| browser.newtab.url ändert sich selbstständig auf "search.conduit.com" hi, hab hier die Logfile bzw. die Combofix.txt: Code:
ATTFilter ComboFix 14-02-19.01 - Robin 20.02.2014 16:05:53.2.6 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8149.6689 [GMT 1:00] ausgeführt von:: c:\users\Robin\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . ((((((((((((((((((((((( Dateien erstellt von 2014-01-20 bis 2014-02-20 )))))))))))))))))))))))))))))) . . 2014-02-20 15:09 . 2014-02-20 15:09 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-02-19 16:41 . 2014-02-19 16:42 -------- d-----w- C:\FRST 2014-02-18 21:40 . 2014-02-18 21:40 -------- d-----w- c:\users\Robin\AppData\Local\My Games 2014-02-16 16:01 . 2014-02-16 16:01 -------- d-----w- c:\users\Robin\.MCTranscodingSDK 2014-02-16 16:00 . 2014-02-16 16:00 -------- d-----w- c:\programdata\Geevs 2014-02-15 21:44 . 2014-02-15 21:44 -------- d-----w- c:\users\Robin\AppData\Local\Smartbar 2014-02-15 21:44 . 2014-02-15 21:46 -------- d-----w- c:\users\Robin\AppData\Roaming\Systweak 2014-02-15 21:44 . 2013-08-22 17:36 20312 ----a-w- c:\windows\system32\roboot64.exe 2014-02-15 21:19 . 2014-02-15 21:29 -------- d-----w- c:\program files\Common Files\Adobe 2014-02-15 20:59 . 2014-02-15 20:59 -------- d-----w- c:\program files\Zapp 2014-02-15 20:59 . 2014-02-15 20:59 -------- d-----w- c:\users\Robin\AppData\Roaming\SimplyTech 2014-02-15 20:59 . 2014-02-15 20:59 -------- d-----w- c:\program files (x86)\Zapp 2014-02-15 20:59 . 2014-02-04 05:36 33864 ----a-w- c:\windows\Launcher.exe 2014-02-13 14:28 . 2014-02-13 14:28 -------- d-----w- c:\windows\SysWow64\SearchProtect 2014-02-12 21:45 . 2014-02-12 21:45 312744 ----a-w- c:\windows\system32\javaws.exe 2014-02-12 21:45 . 2014-02-12 21:45 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2014-02-12 21:45 . 2014-02-12 21:45 189352 ----a-w- c:\windows\system32\javaw.exe 2014-02-12 21:45 . 2014-02-12 21:45 189352 ----a-w- c:\windows\system32\java.exe 2014-02-10 16:26 . 2014-02-10 16:26 -------- d-----w- c:\users\Robin\AppData\Local\EdgeOfReality 2014-02-09 21:33 . 2014-02-14 22:32 -------- d-----w- c:\users\Robin\AppData\Roaming\vlc 2014-02-05 17:57 . 2014-02-17 21:31 -------- d-----w- c:\users\Robin\AppData\Roaming\.minecraft 2014-02-03 17:44 . 2014-02-03 17:44 -------- d-----w- C:\2-click run 2014-02-03 17:40 . 2014-02-03 17:40 -------- d-----w- c:\users\Robin\AppData\Local\SearchProtect 2014-01-29 19:02 . 2014-01-29 19:02 38960 ----a-w- c:\windows\SysWow64\RGBAcodec.dll 2014-01-26 20:26 . 2013-12-27 18:42 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys 2014-01-26 20:26 . 2013-12-27 18:42 33056 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll 2014-01-25 16:52 . 2014-01-25 16:52 -------- d-----w- c:\users\Robin\.fontconfig 2014-01-25 16:52 . 2014-01-25 16:52 -------- d-----w- c:\users\Robin\.cache . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-02-04 21:51 . 2013-08-04 22:29 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-02-04 21:51 . 2013-08-04 22:29 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-02-03 18:02 . 2014-01-16 20:19 80184 ----a-w- c:\windows\system32\drivers\aswstm.sys 2014-02-03 18:02 . 2013-08-27 16:24 421704 ----a-w- c:\windows\system32\drivers\aswSP.sys 2014-02-03 18:02 . 2013-08-27 16:24 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2014-02-03 18:02 . 2013-08-27 16:24 334136 ----a-w- c:\windows\system32\aswBoot.exe 2014-02-03 18:02 . 2013-08-27 16:24 1038072 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2014-02-03 18:02 . 2013-08-27 16:24 43152 ----a-w- c:\windows\avastSS.scr 2014-01-21 02:53 . 2013-11-02 09:54 1048152 ----a-w- c:\windows\SysWow64\nvspcap.dll 2014-01-21 02:53 . 2013-11-02 09:54 1179576 ----a-w- c:\windows\system32\nvspcap64.dll 2014-01-16 20:19 . 2013-08-27 16:24 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-12-27 18:42 . 2013-08-04 22:12 35104 ----a-w- c:\windows\system32\nvaudcap64v.dll 2013-12-19 20:33 . 2013-08-04 22:19 18310112 ----a-w- c:\windows\system32\nvwgf2umx.dll 2013-12-19 20:33 . 2013-08-04 22:19 15877216 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-12-19 20:33 . 2013-08-04 21:49 61216 ----a-w- c:\windows\system32\OpenCL.dll 2013-12-19 20:33 . 2013-08-04 21:49 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll 2013-12-19 20:33 . 2013-08-04 21:48 1436528 ----a-w- c:\windows\system32\nvumdshimx.dll 2013-12-19 20:33 . 2013-08-04 21:48 15230352 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2013-12-19 20:33 . 2013-08-04 21:48 3071656 ----a-w- c:\windows\system32\nvapi64.dll 2013-12-19 20:33 . 2013-08-04 21:48 2698272 ----a-w- c:\windows\SysWow64\nvapi.dll 2013-12-19 18:53 . 2013-08-04 21:49 6671648 ----a-w- c:\windows\system32\nvcpl.dll 2013-12-19 18:53 . 2013-08-04 21:49 3490080 ----a-w- c:\windows\system32\nvsvc64.dll 2013-12-19 18:53 . 2013-08-04 21:49 922912 ----a-w- c:\windows\system32\nvvsvc.exe 2013-12-19 18:53 . 2013-08-04 21:49 63776 ----a-w- c:\windows\system32\nvshext.dll 2013-12-19 18:53 . 2013-08-04 21:49 386336 ----a-w- c:\windows\system32\nvmctray.dll 2013-12-19 18:53 . 2013-08-04 21:49 2559776 ----a-w- c:\windows\system32\nvsvcr.dll 2013-12-19 11:20 . 2013-12-19 11:20 590112 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2013-12-19 05:01 . 2013-08-04 21:49 3539040 ----a-w- c:\windows\system32\nvcoproc.bin 2013-12-04 19:32 . 2013-10-09 22:15 282296 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-12-04 19:32 . 2013-10-09 22:12 282296 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-12-04 19:31 . 2013-10-09 22:12 270240 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-11-24 14:58 . 2013-11-24 14:58 10240 ----a-r- c:\users\Robin\AppData\Roaming\Microsoft\Installer\{BAC3B914-9A96-4097-A5C7-7BF0CAD679D3}\IconBAC3B9141.exe 2013-11-24 14:58 . 2013-11-24 14:58 10240 ----a-r- c:\users\Robin\AppData\Roaming\Microsoft\Installer\{BAC3B914-9A96-4097-A5C7-7BF0CAD679D3}\IconBAC3B914.exe 2013-11-23 12:20 . 2013-08-27 16:24 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-11-23 12:20 . 2013-08-27 16:24 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{14264a21-01fa-455f-a9c4-7c8b3d82b6f6}] 2014-02-05 06:38 1103432 ----a-w- c:\program files (x86)\Zapp\IE\Zapp.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}] 2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{14264a21-01fa-455f-a9c4-7c8b3d82b6f6}"= "c:\program files (x86)\Zapp\IE\Zapp.dll" [2014-02-05 1103432] . [HKEY_CLASSES_ROOT\clsid\{14264a21-01fa-455f-a9c4-7c8b3d82b6f6}] [HKEY_CLASSES_ROOT\wtb.Band.1] [HKEY_CLASSES_ROOT\TypeLib\{8ff7f225-ef13-4714-a630-951a331d8189}] [HKEY_CLASSES_ROOT\wtb.Band] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="d:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640] "icq"="c:\users\Robin\AppData\Roaming\ICQM\icq.exe" [2013-08-06 28698984] "Steam"="d:\program files (x86)\Steam\steam.exe" [2014-02-18 1822400] "EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE" [2012-02-29 283232] "Skype"="d:\program files (x86)\Skype\Phone\Skype.exe" [2013-11-14 20584608] "EPLTarget\P0000000000000001"="c:\windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE" [2012-02-29 283232] "Browser Infrastructure Helper"="c:\users\Robin\AppData\Local\Smartbar\Application\Shopop.exe" [2013-12-31 21040] "NextLive"="c:\users\Robin\AppData\Roaming\newnext.me\nengine.dll" [2013-11-14 1283584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576] "BCSSync"="d:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "iTunesHelper"="d:\program files (x86)\iTunes\iTunesHelper.exe" [2013-08-16 152392] "QuickTime Task"="d:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888] "Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2014-02-11 2239376] "AvastUI.exe"="d:\program files\AVAST Software\Avast\AvastUI.exe" [2014-02-03 3767096] "LogMeIn Hamachi Ui"="d:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-02-04 3813712] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ GIGABYTE OC_GURU.lnk - c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe [2013-3-1 21946368] Hear.lnk - d:\program files\Hear\Hear.exe [2014-1-16 3174024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer1"=wdmaud.drv . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 CltMngSvc;Search Protect by Conduit Service;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe [x] R2 SkypeUpdate;Skype Updater;d:\program files (x86)\Skype\Updater\Updater.exe;d:\program files (x86)\Skype\Updater\Updater.exe [x] R2 WinkHandler;WinkHandler;c:\program files (x86)\Iminent\WinkHandler.exe;c:\program files (x86)\Iminent\WinkHandler.exe [x] R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R3 GPCIDrv;GPCIDrv;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TeamViewer8;TeamViewer 8;d:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;d:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 REN2CAP_DRIVER;Hear;c:\windows\system32\drivers\ren2cap.sys;c:\windows\SYSNATIVE\drivers\ren2cap.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2014-02-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-04 21:51] . 2014-02-19 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000Core.job - c:\users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-19 19:20] . 2014-02-19 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000UA.job - c:\users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-19 19:20] . 2014-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-05 13:50] . 2014-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-05 13:50] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2014-02-03 18:02 287280 ----a-w- d:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [BU] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-03-29 13513288] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-01-21 1179576] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-01-21 2234144] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-12-10 472984] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&SSPV= uDefault_Search_URL = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q= mDefault_Search_URL = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q= mStart Page = about:newtab mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q= mSearch Bar = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q= uInternet Settings,ProxyOverride = *.local IE: An OneNote s&enden - d:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105 IE: Nach Microsoft E&xcel exportieren - d:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&SSPV= FF - prefs.js: network.proxy.type - 2 FF - ExtSQL: 2014-02-15 22:59; {70ba6a57-dc09-4a3e-bbe1-dfb10af77244}; c:\users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\extensions\{70ba6a57-dc09-4a3e-bbe1-dfb10af77244} . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-SearchProtect - c:\progra~2\SearchProtect\Main\bin\uninstall.exe AddRemove-{8D914DD2-F3CE-44E4-9498-E7EED093281C}_is1 - c:\program files (x86)\IndustrieGigant 2\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-3062181239-1702867323-3627005284-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{14264a21-01fa-455f-a9c4-7c8b3d82b6f6}] @Denied: (A 2) (Administrators) @Denied: (A 2) (S-1-5-21-3062181239-1702867323-3627005284-1000) "Flags"=dword:00000400 . [HKEY_USERS\S-1-5-21-3062181239-1702867323-3627005284-1000\Software\SecuROM\License information*] "datasecu"=hex:96,02,09,d0,90,fb,34,de,9d,dd,4d,cc,78,d8,15,aa,bb,da,c2,b2,92, 26,4f,a5,ee,85,c0,81,68,9d,00,2c,5b,eb,3a,cc,13,1c,35,39,c0,d4,39,ec,33,11,\ "rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_44_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_44_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-02-20 16:10:19 ComboFix-quarantined-files.txt 2014-02-20 15:10 ComboFix2.txt 2014-02-20 15:03 . Vor Suchlauf: 8.345.473.024 Bytes frei Nach Suchlauf: 8.282.427.392 Bytes frei . - - End Of File - - BE2E0874B2C0AC96ECAC8FD1B232322A A36C5E4F47E84449FF07ED3517B43A31 |
21.02.2014, 11:13 | #6 |
/// the machine /// TB-Ausbilder | browser.newtab.url ändert sich selbstständig auf "search.conduit.com" Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> browser.newtab.url ändert sich selbstständig auf "search.conduit.com" |
21.02.2014, 14:07 | #7 |
| browser.newtab.url ändert sich selbstständig auf "search.conduit.com" Hey, da die Logs zulang geworden wären, musste ich sie als Archiv anfügen. |
22.02.2014, 13:28 | #8 |
/// the machine /// TB-Ausbilder | browser.newtab.url ändert sich selbstständig auf "search.conduit.com" Hi, Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.02.2014, 18:46 | #9 |
| browser.newtab.url ändert sich selbstständig auf "search.conduit.com" Alles klar, hier mal wieder ein paar Logs. ESET: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=6a9cb6dbe43471428acf0a1afa7b1960 # engine=17180 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-22 03:30:00 # local_time=2014-02-22 04:30:00 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 16690806 144712850 0 0 # scanned=430207 # found=8 # cleaned=0 # scan_time=10173 sh=A065922E48E274F827BC8A04091A44632D498373 ft=1 fh=f3684398a5f5cf1b vn="Win64/Conedex.I trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\Google\Desktop\Install\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\9519~1\A535~1\E628~1\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\U\00000008.@.vir" sh=A065922E48E274F827BC8A04091A44632D498373 ft=1 fh=f3684398a5f5cf1b vn="Win64/Conedex.I trojan" ac=I fn="C:\Qoobox\Quarantine\C\Users\Robin\AppData\Local\Google\Desktop\Install\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\2E2F~1\28F0~1\E628~1\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\U\00000008.@.vir" sh=100C1C6DA6C6646025B17197B437512BE4D78FDC ft=1 fh=20804abc5174beae vn="a variant of Win32/Packed.VMProtect.ABD trojan" ac=I fn="D:\2-click run\Euro Truck Simulator 2 v1.7.1 (DLC Going East)\bin\win_x86\steam_api.dll" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\Desktop\Seltene verwendete Datein\Sidler 7\rzr-set7.iso" sh=021C8E26EB086088409ED1A0EA62075D3376A087 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.ABD trojan" ac=I fn="D:\downloads\3DMGAME-Euro.Truck.Simulator.2.Crack.Only-3DM.rar" sh=14DA30021357111CB12267EFD6436C9791EB56F6 ft=1 fh=eb8748adfd5b0218 vn="Win32/AdWare.1ClickDownload.AQ application" ac=I fn="D:\downloads\4videosoft_mkv_video_converter_5_0_8___crack_[timetravel][h33t]_rar.exe" sh=273A2A936AEC8B68DE2329EF69996F616B0D757E ft=1 fh=6e75ff11b16007d4 vn="NSIS/StartPage.CC trojan" ac=I fn="D:\downloads\vlc-2.1.3-win64.exe" sh=E0994EAA49BEEF8898826541740DEEA33025FC55 ft=1 fh=de1440eb80b6f51a vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\Program Files (x86)\Ubisoft\Die Siedler 7\Data\Base\_Dbg\Bin\Release\1911.dll" Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Adobe Flash Player 12.0.0.70 Flash Player out of Date! Adobe Reader XI Mozilla Firefox (25.0) ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-02-2014 01 Ran by Robin (administrator) on ROBIN-PC on 22-02-2014 18:43:11 Running from C:\Users\Robin\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) D:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Program Files (x86)\Zapp\WConnectorProductivity.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (TeamViewer GmbH) D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (ICQ) C:\Users\Robin\AppData\Roaming\ICQM\icq.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE (Skype Technologies S.A.) D:\Program Files (x86)\Skype\Phone\Skype.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE (Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe () D:\Program Files\Hear\Hear.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (AVAST Software) D:\Program Files\AVAST Software\Avast\AvastUI.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (File Type Advisor) C:\Program Files (x86)\File Type Advisor\fileadvisor.exe (Mozilla Corporation) D:\Program Files\Waterfox\waterfox.exe (Mozilla Corporation) D:\Program Files\Waterfox\plugin-container.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [BCSSync] - D:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - D:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - D:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2014-02-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] - D:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-03] (AVAST Software) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3813712 2014-02-04] (LogMeIn Inc.) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [DAEMON Tools Lite] - D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [icq] - C:\Users\Robin\AppData\Roaming\ICQM\icq.exe [28698984 2013-08-06] (ICQ) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Steam] - D:\Program Files (x86)\Steam\steam.exe [1822400 2014-02-20] (Valve Corporation) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Skype] - D:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [EPLTarget\P0000000000000001] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA1AB3F2ADF98CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Java\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Java\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files (x86)\Zapp\IE\Zapp.dll (Simply Tech LTD.) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files (x86)\Zapp\IE\Zapp.dll (Simply Tech LTD.) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870 FF NewTab: google.de FF SelectedSearchEngine: Google FF Homepage: google.de FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*'))%20%7B%20return%20'PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us07.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000%3B%20PROXY%20nq-us05.personalitycores.com%3A8000%3B%20PROXY%20nq-us10.personalitycores.com%3A8000%3B%20PROXY%20nq-us04.personalitycores.com%3A8000%3B%20PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - D:\Java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - D:\Java\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.3 - D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - D:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - D:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Robin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Robin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\searchplugins\search_engine.xml FF Extension: Zapp - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\{70ba6a57-dc09-4a3e-bbe1-dfb10af77244} [2014-02-15] FF Extension: ProxMate - Proxy on steroids! - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-12-19] FF Extension: Deutsch (DE) Language Pack - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\langpack-de@firefox.mozilla.org.xpi [2014-02-05] FF Extension: Adblock Plus - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - D:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - D:\Program Files\AVAST Software\Avast\WebRep\FF [2013-08-27] FF StartMenuInternet: FIREFOX.EXE - D:\Program Files\Mozilla Firefox\firefox.exe ==================== Services (Whitelisted) ================= R2 avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-03] (AVAST Software) R2 Hamachi2Svc; D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2222416 2014-02-04] (LogMeIn Inc.) S3 Microsoft SharePoint Workspace Audit Service; D:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [30969208 2010-03-25] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-09] () S2 SkypeUpdate; D:\Program Files (x86)\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies) R2 TeamViewer8; D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [4308320 2013-08-07] (TeamViewer GmbH) ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-03] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-23] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-23] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-03] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-03] (AVAST Software) S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-03] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-16] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-05] (DT Soft Ltd) S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) R3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] () R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-22 18:40 - 2014-02-22 18:40 - 00987425 _____ () C:\Users\Robin\Desktop\SecurityCheck.exe 2014-02-22 13:38 - 2014-02-22 13:38 - 02347384 _____ (ESET) C:\Users\Robin\Desktop\esetsmartinstaller_enu.exe 2014-02-21 14:06 - 2014-02-21 14:06 - 00026545 _____ () C:\Users\Robin\Desktop\Logfile.zip 2014-02-21 13:56 - 2014-02-22 18:43 - 00000000 ____D () C:\Users\Robin\Desktop\FRST-OlderVersion 2014-02-21 13:55 - 2014-02-21 13:55 - 00000990 _____ () C:\Users\Robin\Desktop\JRT.txt 2014-02-21 13:49 - 2014-02-21 13:49 - 01037734 _____ (Thisisu) C:\Users\Robin\Desktop\JRT.exe 2014-02-21 13:45 - 2014-02-21 13:45 - 00009292 _____ () C:\Users\Robin\Desktop\AdwCleaner[S1].txt 2014-02-21 13:43 - 2014-02-21 13:43 - 01241834 _____ () C:\Users\Robin\Desktop\adwcleaner.exe 2014-02-21 13:33 - 2014-02-21 13:33 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Malwarebytes 2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-21 13:33 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-20 16:10 - 2014-02-20 16:10 - 00023466 _____ () C:\ComboFix.txt 2014-02-20 15:52 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-20 15:52 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-20 15:52 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-20 15:52 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-20 15:52 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-20 15:52 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-20 15:52 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-20 15:52 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-20 15:51 - 2014-02-20 16:10 - 00000000 ____D () C:\Qoobox 2014-02-20 15:51 - 2014-02-20 16:02 - 00000000 ____D () C:\Windows\erdnt 2014-02-20 15:51 - 2014-02-20 15:51 - 05183254 ____R (Swearware) C:\Users\Robin\Desktop\ComboFix.exe 2014-02-19 17:42 - 2014-02-19 17:42 - 00035833 _____ () C:\Users\Robin\Desktop\Addition.txt 2014-02-19 17:41 - 2014-02-22 18:43 - 02154496 _____ (Farbar) C:\Users\Robin\Desktop\FRST64.exe 2014-02-19 17:41 - 2014-02-22 18:43 - 00019788 _____ () C:\Users\Robin\Desktop\FRST.txt 2014-02-19 17:41 - 2014-02-22 18:43 - 00000000 ____D () C:\FRST 2014-02-18 22:40 - 2014-02-18 22:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\My Games 2014-02-18 22:28 - 2014-02-18 22:28 - 00000221 _____ () C:\Users\Robin\Desktop\Sid Meier's Civilization V - Demo.url 2014-02-18 21:23 - 2014-02-18 21:23 - 00006477 _____ () C:\Users\Robin\AppData\Local\recently-used.xbel 2014-02-16 17:01 - 2014-02-16 17:01 - 00000000 ____D () C:\Users\Robin\.MCTranscodingSDK 2014-02-16 17:00 - 2014-02-16 17:05 - 00000000 ____D () C:\Users\Public\Documents\Lightworks 2014-02-16 17:00 - 2014-02-16 17:00 - 00000000 ____D () C:\ProgramData\Geevs 2014-02-15 22:19 - 2014-02-15 22:29 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-02-15 21:59 - 2014-02-21 13:45 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files\Zapp 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Zapp 2014-02-15 21:59 - 2014-02-04 06:36 - 00033864 _____ () C:\Windows\Launcher.exe 2014-02-15 21:18 - 2014-02-15 21:18 - 00015130 _____ () C:\Users\Robin\Documents\Mein Film.wlmp 2014-02-15 20:34 - 2014-02-15 20:52 - 591803806 _____ () C:\Users\Robin\Desktop\template.avi 2014-02-15 20:34 - 2014-02-15 20:52 - 591803806 _____ () C:\Users\Robin\Desktop\A_template.avi 2014-02-15 19:16 - 2014-02-16 22:37 - 00000000 ____D () C:\Users\Robin\Desktop\INTRO TEMPLATE BY RenttuArts 2014-02-12 22:45 - 2014-02-12 22:45 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-02-10 19:33 - 2014-02-10 19:33 - 00000934 _____ () C:\Users\Robin\Desktop\Landwirtschafts Simulator 2013 .lnk 2014-02-10 17:26 - 2014-02-10 17:26 - 00000000 ____D () C:\Users\Robin\AppData\Local\EdgeOfReality 2014-02-10 16:08 - 2014-02-10 16:08 - 00000222 _____ () C:\Users\Robin\Desktop\Loadout.url 2014-02-09 22:33 - 2014-02-14 23:32 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\vlc 2014-02-09 22:33 - 2014-02-09 22:33 - 00000757 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-02-09 17:25 - 2014-02-09 17:25 - 00000836 _____ () C:\Users\Public\Desktop\Prime Time.lnk 2014-02-05 18:57 - 2014-02-22 11:14 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.minecraft 2014-02-04 16:51 - 2014-02-04 16:51 - 00003012 _____ () C:\Windows\System32\Tasks\{29949044-F7D7-4E68-B9CE-644E4CFDA5BB} 2014-02-03 20:36 - 2014-02-03 20:36 - 00001648 _____ () C:\Users\Robin\Desktop\Euro Truck Simulator 2.lnk 2014-02-03 18:45 - 2014-02-03 18:45 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run 2014-02-03 18:44 - 2014-02-03 18:44 - 00000000 ____D () C:\2-click run 2014-01-30 16:10 - 2014-01-30 16:10 - 00012834 _____ () C:\Users\Robin\Desktop\Anno2070.lnk 2014-01-30 16:02 - 2014-01-30 16:02 - 00001468 _____ () C:\Users\Robin\Desktop\Flight Simulator X.lnk 2014-01-29 20:02 - 2014-01-29 20:02 - 00038960 _____ () C:\Windows\SysWOW64\RGBAcodec.dll 2014-01-28 21:01 - 2014-02-16 17:46 - 00000000 ___RD () C:\Users\Robin\Desktop\Aufnehmzeug 2014-01-26 21:29 - 2013-12-19 21:33 - 30372640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 22960416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 12645664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-01-26 21:29 - 2013-12-19 21:33 - 11605752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 11554264 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 09700224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 09657464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00882464 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00879392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00852768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00847648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00357152 _____ () C:\Windows\system32\NvIFROpenGL.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00314656 _____ () C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-01-26 21:29 - 2013-12-19 21:33 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-01-26 21:29 - 2013-11-28 14:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-01-26 21:29 - 2013-11-28 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-01-26 21:29 - 2013-11-22 09:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-01-26 21:26 - 2013-12-27 19:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-01-26 21:26 - 2013-12-27 19:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-01-26 01:00 - 2014-02-22 11:04 - 00007206 _____ () C:\Windows\setupact.log 2014-01-26 01:00 - 2014-01-26 01:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-01-25 17:52 - 2014-01-25 17:52 - 00000000 ____D () C:\Users\Robin\.cache 2014-01-25 15:28 - 2014-01-26 17:48 - 03276780 _____ () C:\Users\Robin\Desktop\Schülerpraktikumsbericht.pptx ==================== One Month Modified Files and Folders ======= 2014-02-22 18:43 - 2014-02-21 13:56 - 00000000 ____D () C:\Users\Robin\Desktop\FRST-OlderVersion 2014-02-22 18:43 - 2014-02-19 17:41 - 02154496 _____ (Farbar) C:\Users\Robin\Desktop\FRST64.exe 2014-02-22 18:43 - 2014-02-19 17:41 - 00019788 _____ () C:\Users\Robin\Desktop\FRST.txt 2014-02-22 18:43 - 2014-02-19 17:41 - 00000000 ____D () C:\FRST 2014-02-22 18:41 - 2013-08-05 17:20 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Skype 2014-02-22 18:40 - 2014-02-22 18:40 - 00987425 _____ () C:\Users\Robin\Desktop\SecurityCheck.exe 2014-02-22 18:06 - 2013-12-05 14:50 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-22 17:51 - 2013-08-04 23:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-22 17:25 - 2014-01-19 20:20 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000UA.job 2014-02-22 15:58 - 2013-08-04 22:39 - 01405874 _____ () C:\Windows\WindowsUpdate.log 2014-02-22 13:41 - 2009-07-14 05:45 - 00015760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-22 13:41 - 2009-07-14 05:45 - 00015760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-22 13:38 - 2014-02-22 13:38 - 02347384 _____ (ESET) C:\Users\Robin\Desktop\esetsmartinstaller_enu.exe 2014-02-22 13:38 - 2009-07-14 18:58 - 00699394 _____ () C:\Windows\system32\perfh007.dat 2014-02-22 13:38 - 2009-07-14 18:58 - 00149534 _____ () C:\Windows\system32\perfc007.dat 2014-02-22 13:38 - 2009-07-14 06:13 - 01620346 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-22 12:43 - 2013-08-24 11:43 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor 2014-02-22 11:14 - 2014-02-05 18:57 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.minecraft 2014-02-22 11:04 - 2014-01-26 01:00 - 00007206 _____ () C:\Windows\setupact.log 2014-02-22 11:04 - 2014-01-06 16:45 - 00000000 ____D () C:\Users\Robin\AppData\Local\LogMeIn Hamachi 2014-02-22 11:04 - 2013-12-05 14:50 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-22 11:04 - 2013-08-17 09:34 - 00000000 ____D () C:\Users\Robin\AppData\Local\Adobe 2014-02-22 11:04 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-22 11:03 - 2013-08-04 22:49 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-21 20:25 - 2014-01-19 20:20 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000Core.job 2014-02-21 14:51 - 2013-08-04 23:29 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-21 14:51 - 2013-08-04 23:29 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-21 14:51 - 2013-08-04 23:29 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-21 14:06 - 2014-02-21 14:06 - 00026545 _____ () C:\Users\Robin\Desktop\Logfile.zip 2014-02-21 13:55 - 2014-02-21 13:55 - 00000990 _____ () C:\Users\Robin\Desktop\JRT.txt 2014-02-21 13:49 - 2014-02-21 13:49 - 01037734 _____ (Thisisu) C:\Users\Robin\Desktop\JRT.exe 2014-02-21 13:48 - 2013-12-19 22:16 - 00000000 ____D () C:\AdwCleaner 2014-02-21 13:47 - 2013-08-27 17:24 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-02-21 13:45 - 2014-02-21 13:45 - 00009292 _____ () C:\Users\Robin\Desktop\AdwCleaner[S1].txt 2014-02-21 13:45 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-02-21 13:43 - 2014-02-21 13:43 - 01241834 _____ () C:\Users\Robin\Desktop\adwcleaner.exe 2014-02-21 13:43 - 2013-11-08 18:53 - 00000000 ____D () C:\Users\Robin\AppData\Local\Apps\2.0 2014-02-21 13:41 - 2013-08-05 09:37 - 00423784 _____ () C:\Windows\PFRO.log 2014-02-21 13:33 - 2014-02-21 13:33 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Malwarebytes 2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-20 16:10 - 2014-02-20 16:10 - 00023466 _____ () C:\ComboFix.txt 2014-02-20 16:10 - 2014-02-20 15:51 - 00000000 ____D () C:\Qoobox 2014-02-20 16:09 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-20 16:03 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-20 16:02 - 2014-02-20 15:51 - 00000000 ____D () C:\Windows\erdnt 2014-02-20 15:55 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-20 15:51 - 2014-02-20 15:51 - 05183254 ____R (Swearware) C:\Users\Robin\Desktop\ComboFix.exe 2014-02-19 17:42 - 2014-02-19 17:42 - 00035833 _____ () C:\Users\Robin\Desktop\Addition.txt 2014-02-19 12:07 - 2013-08-05 09:42 - 00124616 _____ () C:\Users\Robin\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-19 12:06 - 2009-07-14 05:45 - 05108968 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-18 22:40 - 2014-02-18 22:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\My Games 2014-02-18 22:40 - 2013-10-21 15:35 - 00000000 ____D () C:\Users\Robin\Documents\My Games 2014-02-18 22:40 - 2013-08-05 23:41 - 00435159 _____ () C:\Windows\DirectX.log 2014-02-18 22:28 - 2014-02-18 22:28 - 00000221 _____ () C:\Users\Robin\Desktop\Sid Meier's Civilization V - Demo.url 2014-02-18 21:46 - 2013-08-07 20:08 - 00000000 ____D () C:\Users\Robin\Documents\Euro Truck Simulator 2 2014-02-18 21:23 - 2014-02-18 21:23 - 00006477 _____ () C:\Users\Robin\AppData\Local\recently-used.xbel 2014-02-18 21:23 - 2013-08-05 23:05 - 00000000 ____D () C:\Users\Robin\AppData\Local\gtk-2.0 2014-02-18 21:23 - 2013-08-05 23:03 - 00000000 ____D () C:\Users\Robin\.gimp-2.8 2014-02-16 22:37 - 2014-02-15 19:16 - 00000000 ____D () C:\Users\Robin\Desktop\INTRO TEMPLATE BY RenttuArts 2014-02-16 19:27 - 2013-08-05 18:32 - 00007602 _____ () C:\Users\Robin\AppData\Local\Resmon.ResmonCfg 2014-02-16 17:46 - 2014-01-28 21:01 - 00000000 ___RD () C:\Users\Robin\Desktop\Aufnehmzeug 2014-02-16 17:05 - 2014-02-16 17:00 - 00000000 ____D () C:\Users\Public\Documents\Lightworks 2014-02-16 17:01 - 2014-02-16 17:01 - 00000000 ____D () C:\Users\Robin\.MCTranscodingSDK 2014-02-16 17:01 - 2013-08-04 22:37 - 00000000 ____D () C:\Users\Robin 2014-02-16 17:00 - 2014-02-16 17:00 - 00000000 ____D () C:\ProgramData\Geevs 2014-02-15 22:45 - 2013-08-04 22:37 - 00000000 ___RD () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-15 22:29 - 2014-02-15 22:19 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-02-15 22:28 - 2013-11-12 18:16 - 00000000 ____D () C:\Program Files\Adobe 2014-02-15 22:19 - 2013-08-17 09:34 - 00000000 ____D () C:\ProgramData\Adobe 2014-02-15 22:19 - 2013-08-04 23:29 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Adobe 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files\Zapp 2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Zapp 2014-02-15 21:18 - 2014-02-15 21:18 - 00015130 _____ () C:\Users\Robin\Documents\Mein Film.wlmp 2014-02-15 20:52 - 2014-02-15 20:34 - 591803806 _____ () C:\Users\Robin\Desktop\template.avi 2014-02-15 20:52 - 2014-02-15 20:34 - 591803806 _____ () C:\Users\Robin\Desktop\A_template.avi 2014-02-15 15:29 - 2013-12-25 21:24 - 02346186 _____ () C:\Users\Robin\Desktop\TechnicLauncher.exe 2014-02-15 15:29 - 2013-10-26 18:16 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.technic 2014-02-14 23:32 - 2014-02-09 22:33 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\vlc 2014-02-12 22:45 - 2014-02-12 22:45 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-02-12 22:45 - 2014-02-12 22:45 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-02-12 21:01 - 2013-12-05 14:50 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-12 21:01 - 2013-12-05 14:50 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-10 19:33 - 2014-02-10 19:33 - 00000934 _____ () C:\Users\Robin\Desktop\Landwirtschafts Simulator 2013 .lnk 2014-02-10 17:26 - 2014-02-10 17:26 - 00000000 ____D () C:\Users\Robin\AppData\Local\EdgeOfReality 2014-02-10 16:08 - 2014-02-10 16:08 - 00000222 _____ () C:\Users\Robin\Desktop\Loadout.url 2014-02-09 22:33 - 2014-02-09 22:33 - 00000757 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-02-09 17:25 - 2014-02-09 17:25 - 00000836 _____ () C:\Users\Public\Desktop\Prime Time.lnk 2014-02-04 16:51 - 2014-02-04 16:51 - 00003012 _____ () C:\Windows\System32\Tasks\{29949044-F7D7-4E68-B9CE-644E4CFDA5BB} 2014-02-04 06:36 - 2014-02-15 21:59 - 00033864 _____ () C:\Windows\Launcher.exe 2014-02-03 22:18 - 2013-08-05 23:55 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\uTorrent 2014-02-03 20:36 - 2014-02-03 20:36 - 00001648 _____ () C:\Users\Robin\Desktop\Euro Truck Simulator 2.lnk 2014-02-03 19:03 - 2013-08-27 17:24 - 00001040 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-03 19:02 - 2014-01-16 21:19 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-03 19:02 - 2013-08-27 17:24 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-03 19:02 - 2013-08-27 17:24 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-03 19:02 - 2013-08-27 17:24 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-03 19:02 - 2013-08-27 17:24 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-03 19:02 - 2013-08-27 17:24 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-03 18:45 - 2014-02-03 18:45 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run 2014-02-03 18:44 - 2014-02-03 18:44 - 00000000 ____D () C:\2-click run 2014-01-30 16:38 - 2013-11-24 15:58 - 00000781 _____ () C:\Users\Robin\Desktop\TransportGigant.lnk 2014-01-30 16:10 - 2014-01-30 16:10 - 00012834 _____ () C:\Users\Robin\Desktop\Anno2070.lnk 2014-01-30 16:03 - 2013-08-30 22:11 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Virtuali 2014-01-30 16:03 - 2013-08-30 22:11 - 00000000 ____D () C:\ProgramData\Virtuali 2014-01-30 16:02 - 2014-01-30 16:02 - 00001468 _____ () C:\Users\Robin\Desktop\Flight Simulator X.lnk 2014-01-29 20:02 - 2014-01-29 20:02 - 00038960 _____ () C:\Windows\SysWOW64\RGBAcodec.dll 2014-01-27 19:49 - 2013-11-21 22:33 - 00000000 ____D () C:\Users\Robin\AppData\Local\Microsoft Games 2014-01-26 21:30 - 2013-08-04 22:49 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-01-26 17:48 - 2014-01-25 15:28 - 03276780 _____ () C:\Users\Robin\Desktop\Schülerpraktikumsbericht.pptx 2014-01-26 01:00 - 2014-01-26 01:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-01-25 17:52 - 2014-01-25 17:52 - 00000000 ____D () C:\Users\Robin\.cache Some content of TEMP: ==================== C:\Users\Robin\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-19 12:50 ==================== End Of Log ============================ --- --- --- |
23.02.2014, 16:35 | #10 |
/// the machine /// TB-Ausbilder | browser.newtab.url ändert sich selbstständig auf "search.conduit.com" Funde von ESET bitte manuell löschen. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.02.2014, 22:29 | #11 |
| browser.newtab.url ändert sich selbstständig auf "search.conduit.com" Hey, vielen Dank für deine Hilfe, es hat soweit geklappt und ich habe die Programme entfernt. Jedoch habe ich jetzt scheinbar ein anderes Problem, es geht darum das mein Internet, seit dem entfernen, langsamer geworden ist, am meisten fällt es mir bei YT Videos auf, sie laden nicht mehr richtig oder garnicht mehr. Kommt sowas mal vor? Neugestartet habe ich schon 2 mal. Grüße Robin |
24.02.2014, 18:40 | #12 |
/// the machine /// TB-Ausbilder | browser.newtab.url ändert sich selbstständig auf "search.conduit.com" In welchem Browser?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.02.2014, 14:26 | #13 |
| browser.newtab.url ändert sich selbstständig auf "search.conduit.com" Firefox bzw. Waterfox |
26.02.2014, 12:21 | #14 |
/// the machine /// TB-Ausbilder | browser.newtab.url ändert sich selbstständig auf "search.conduit.com" Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu browser.newtab.url ändert sich selbstständig auf "search.conduit.com" |
.com, avast, avast!, frage, fragen, guten, immer wieder, mobogenie, mobogenie entfernen, nichts, nsis/startpage.cc, problem, schonmal, selbstständig, win32/adware.1clickdownload.aq, win32/packed.vmprotect.aaa, win32/packed.vmprotect.abd, win64/conedex.i, woche, zusammen |