|
Plagegeister aller Art und deren Bekämpfung: Google chrome Öffnet 3 Facebook tabs unaufgefordertWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
06.03.2014, 23:00 | #1 |
| Google chrome Öffnet 3 Facebook tabs unaufgefordert Guten tag Ich googel heute schon den ganzen tag, habe aber keine Hilfe gefunden, denn wenn ich den link suche, oder die Problem beschreibung komme ich immer wieder falsch raus. Ich kenne mich garnicht mit dem PC aus und bräuchte darum bitte genaue anleitungen. ich hoffe ihr könnt mir helfen. Also zu meinem Problem. wenn ich Google chrome benutze öffnen sich in unterschiedlichen abständen drei Facebook tabs: https://www.facebook.com/login.php?next=https%3A%2F%2Fwww.facebook.com%2Fdesktop%2Ffbdesktop2%2F https://www.facebook.com/login.php?next=https%3A%2F%2Fwww.facebook.com%2Fdesktop%2Ffbdesktop2%2Ftickerflyout.php https://www.facebook.com/login.php?next=https%3A%2F%2Fwww.facebook.com%2Fdesktop%2Ffbdesktop2%2Fdialog.php wenn google chrome nicht geöffnet ist öffnet es sich selbständig. Ich hoffe hier kann mir mir weiter geholfen werden. Ich füge noch hinzu, dass ich windows 7 benutze und auf anraten eines Boardler den Chromebrowser deinstalliert habe. bevor ich ihn wieder installieren konnte haben sich genau die drei gleichen Tabs im Internet Explorer geöffnet |
06.03.2014, 23:31 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Google chrome Öffnet 3 Facebook tabs unaufgefordert Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
07.03.2014, 00:18 | #3 |
| Google chrome Öffnet 3 Facebook tabs unaufgefordert Ich habe nur einen Virenscan mit avira gemacht und der zeigte 0 viren funde und 0 Maleware funde. kurze frage. was sind logs?
__________________ok. es sind die berichte bzw. befunde, aber da war nix hier die Log von FRST FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-03-2014 Ran by Adioz (administrator) on PC_ADIOZ on 07-03-2014 00:11:48 Running from C:\Users\Adioz\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\Tor\tor.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (PixArt Imaging Incorporation) C:\Windows\PixArt\PAC7302\Monitor.exe () C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\Grid64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [PAC7302_Monitor] - C:\Windows\PixArt\PAC7302\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation) HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641664 2012-04-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-02-20] () HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1648056 2014-01-31] (Ask) HKU\S-1-5-21-500615665-753558739-4272784270-1000\...\Run: [Grid] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe [409600 2011-12-05] () HKU\S-1-5-21-500615665-753558739-4272784270-1000\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-500615665-753558739-4272784270-1000\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2011-12-05] (AMD) HKU\S-1-5-21-500615665-753558739-4272784270-1000\...\Run: [BackgroundContainer] - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Adioz\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun <===== ATTENTION HKU\S-1-5-21-500615665-753558739-4272784270-1000\...\MountPoints2: {ab592903-aa42-11e1-ac41-cfdcf387d17f} - F:\pushinst.exe Startup: C:\Users\Adioz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk ShortcutTarget: Facebook Messenger.lnk -> C:\Users\Adioz\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.holasearch.com/?affID=121962&babsrc=HP_ss&mntrId=DC94001E0B6963B3 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC85D4C96E439CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKLM-x32 - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File URLSearchHook: HKLM-x32 - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=3b583ffd-a4b0-4c02-ac29-9ae843795da7&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=3b583ffd-a4b0-4c02-ac29-9ae843795da7&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=63d67d81-afa5-4772-a646-8497216be752&affid=113129&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=63d67d81-afa5-4772-a646-8497216be752&affid=113129&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://isearch.babylon.com/?q={searchTerms}&affID=121962&babsrc=SP_ss_btis2&mntrId=DC94001E0B6963B3 SearchScopes: HKCU - {39EC5CFA-1343-4F39-B772-BA7E29DD7908} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^VK^DE&apn_uid=e0a0fbf6-97dc-412b-bed8-c40e6ea4b847&apn_sauid=78F31A2D-C4B0-4080-BEC7-B16AD87F2328 SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/mb167/?search={searchTerms}&loc=IB_DS&a=6PQCmBhzF0&i=26 BHO: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll () BHO: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll () BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: holasearch Helper Object - {DFF9B2DA-EF99-4B26-83CB-7058299999D8} - C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll (holasearch.com) Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - Holasearch Toolbar - {C510DFFB-0AFE-484C-BA40-CED5B74C4EEF} - C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchTlbr.dll (holasearch.com) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Adioz\AppData\Roaming\Mozilla\Firefox\Profiles\usxg4nsa.default FF NewTab: hxxp://www.holasearch.com/?affID=121962&babsrc=NT_ss&mntrId=DC94001E0B6963B3 FF SearchEngineOrder.1: Hola Search FF SelectedSearchEngine: Hola Search FF Homepage: hxxp://www.holasearch.com/?affID=121962&babsrc=HP_ss&mntrId=DC94001E0B6963B3 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox [2012-07-03] FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-11-21] FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-06] CHR Extension: (Google Drive) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-06] CHR Extension: (Schalten Sie das Licht) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2014-03-06] CHR Extension: (YouTube) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-06] CHR Extension: (Google-Suche) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-06] CHR Extension: (Web Assistant) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd [2014-03-06] CHR Extension: (hola Toolbar) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla [2014-03-06] CHR Extension: (Stylish) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2014-03-06] CHR Extension: (AdBlock) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-03-06] CHR Extension: (Webseite Blocher (Beta)) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hclgegipaehbigmbhdpfapmjadbaldib [2014-03-06] CHR Extension: (Google Wallet) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-06] CHR Extension: (Blue Space Sunset Chrome Theme) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nndfdjfoclbidmgpmbelcieibgjjfdog [2014-03-06] CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2014-03-06] CHR Extension: (Google Mail) - C:\Users\Adioz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-06] CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [2012-07-03] CHR HKLM-x32\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [2012-07-03] CHR HKLM-x32\...\Chrome\Extension: [fagpjgjmoaccgkkpjeoinehnoaimnbla] - C:\Users\Adioz\AppData\Roaming\BabSolution\CR\hola.crx [2013-05-02] CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-20] (Avira Operations GmbH & Co. KG) S4 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-24] () S4 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [185856 2012-06-25] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-04] (AVM Berlin) S3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-04] (AVM GmbH) S3 PAC7302; C:\Windows\System32\DRIVERS\PAC7302.SYS [527872 2007-11-08] (PixArt Imaging Inc.) S3 PAC7302; C:\Windows\SysWOW64\DRIVERS\PAC7302.SYS [454656 2007-11-08] (PixArt Imaging Inc.) S3 ssudobex; C:\Windows\System32\DRIVERS\ssudobex.sys [203104 2012-09-20] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-07 00:11 - 2014-03-07 00:12 - 00017699 _____ () C:\Users\Adioz\Downloads\FRST.txt 2014-03-07 00:11 - 2014-03-07 00:11 - 00000000 ____D () C:\FRST 2014-03-07 00:09 - 2014-03-07 00:09 - 02156544 _____ (Farbar) C:\Users\Adioz\Downloads\FRST64.exe 2014-03-06 23:07 - 2014-03-06 23:07 - 00003034 _____ () C:\Users\Adioz\Documents\registry.reg 2014-03-06 22:52 - 2014-03-06 22:52 - 00002247 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-06 22:51 - 2014-03-07 00:01 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-06 22:51 - 2014-03-06 23:01 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-06 22:51 - 2014-03-06 22:56 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-06 22:47 - 2014-03-06 22:47 - 00003370 _____ () C:\Windows\System32\Tasks\BackgroundContainer Startup Task 2014-03-06 22:43 - 2014-03-06 22:44 - 38146040 _____ (Google Inc.) C:\Users\Adioz\Downloads\ChromeStandaloneSetup_33.0.1750.146.exe 2014-03-06 12:16 - 2014-03-06 12:16 - 00000000 ____D () C:\Users\Adioz\AppData\Roaming\Malwarebytes 2014-03-06 12:15 - 2014-03-06 12:15 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-06 12:15 - 2014-03-06 12:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-06 12:15 - 2014-03-06 12:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-06 12:15 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-06 12:13 - 2014-03-06 12:14 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Adioz\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-05 16:24 - 2014-03-05 16:24 - 00016602 _____ () C:\Users\Adioz\Documents\Schwarz und weiß.odt 2014-03-01 13:36 - 2014-03-03 03:01 - 00015975 _____ () C:\Users\Adioz\Documents\Pokedex x+y.ods 2014-02-26 21:29 - 2014-02-26 21:29 - 00000000 ____D () C:\Users\Adioz\AppData\Local\Skype 2014-02-26 09:39 - 2014-02-28 00:01 - 01594028 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-12 22:40 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-12 22:40 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-12 22:39 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 22:39 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-12 22:39 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-12 22:39 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-12 22:39 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-12 22:39 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-12 22:39 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-12 22:39 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-12 22:39 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-12 22:39 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-12 22:39 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-12 22:39 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-12 22:39 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-12 22:39 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-12 22:39 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-12 22:39 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-12 22:39 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-12 22:39 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-12 22:39 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-12 22:39 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-12 22:39 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-12 22:39 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-12 22:39 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-12 22:39 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-12 22:39 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-12 22:39 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-12 22:39 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-12 22:39 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-12 22:39 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-12 22:39 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-12 22:39 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-12 22:39 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-12 22:39 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-12 22:39 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-12 22:39 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-12 22:39 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-12 22:39 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-12 22:39 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-12 22:39 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-12 14:45 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-12 14:45 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 14:45 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 14:45 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 14:45 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 14:45 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 14:45 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 14:45 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 14:45 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 14:45 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 14:45 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 14:45 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 14:45 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 14:45 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 14:45 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 14:45 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 14:45 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 14:45 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 14:45 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 14:45 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 14:45 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 14:45 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 14:45 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 14:45 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 14:45 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 14:45 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 14:45 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 14:45 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-09 03:21 - 2014-02-09 03:21 - 00013986 _____ () C:\Users\Adioz\Documents\sandsturm.odt ==================== One Month Modified Files and Folders ======= 2014-03-07 00:12 - 2014-03-07 00:11 - 00017699 _____ () C:\Users\Adioz\Downloads\FRST.txt 2014-03-07 00:11 - 2014-03-07 00:11 - 00000000 ____D () C:\FRST 2014-03-07 00:09 - 2014-03-07 00:09 - 02156544 _____ (Farbar) C:\Users\Adioz\Downloads\FRST64.exe 2014-03-07 00:01 - 2014-03-06 22:51 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-06 23:52 - 2012-05-28 20:13 - 00000000 ____D () C:\Users\Adioz\AppData\Roaming\Skype 2014-03-06 23:40 - 2009-07-14 05:45 - 00016624 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-06 23:40 - 2009-07-14 05:45 - 00016624 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-06 23:26 - 2012-05-24 21:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-06 23:07 - 2014-03-06 23:07 - 00003034 _____ () C:\Users\Adioz\Documents\registry.reg 2014-03-06 23:01 - 2014-03-06 22:51 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-06 22:56 - 2014-03-06 22:51 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-06 22:56 - 2013-05-15 17:46 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-06 22:53 - 2012-10-18 15:46 - 00003818 _____ () C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar 2014-03-06 22:53 - 2012-10-18 15:46 - 00000000 ____D () C:\Program Files (x86)\Ask.com 2014-03-06 22:52 - 2014-03-06 22:52 - 00002247 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-06 22:52 - 2012-05-24 21:28 - 00000000 ____D () C:\Users\Adioz\AppData\Local\Google 2014-03-06 22:51 - 2012-05-24 21:27 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-06 22:47 - 2014-03-06 22:47 - 00003370 _____ () C:\Windows\System32\Tasks\BackgroundContainer Startup Task 2014-03-06 22:47 - 2012-06-06 19:26 - 00000000 ____D () C:\Users\Adioz\AppData\Local\Conduit 2014-03-06 22:47 - 2012-06-06 19:26 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoftTB 2014-03-06 22:44 - 2014-03-06 22:43 - 38146040 _____ (Google Inc.) C:\Users\Adioz\Downloads\ChromeStandaloneSetup_33.0.1750.146.exe 2014-03-06 21:54 - 2012-08-20 11:49 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-500615665-753558739-4272784270-1000UA.job 2014-03-06 16:58 - 2013-06-24 15:09 - 01174808 _____ () C:\Windows\WindowsUpdate.log 2014-03-06 14:28 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-06 14:24 - 2013-01-05 19:55 - 00000000 ____D () C:\Users\Adioz\AppData\Roaming\SearchProtect 2014-03-06 14:24 - 2013-01-05 19:55 - 00000000 ____D () C:\Program Files (x86)\SearchProtect 2014-03-06 12:54 - 2012-08-20 11:49 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-500615665-753558739-4272784270-1000Core.job 2014-03-06 12:16 - 2014-03-06 12:16 - 00000000 ____D () C:\Users\Adioz\AppData\Roaming\Malwarebytes 2014-03-06 12:15 - 2014-03-06 12:15 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-06 12:15 - 2014-03-06 12:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-06 12:15 - 2014-03-06 12:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-06 12:14 - 2014-03-06 12:13 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Adioz\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-05 16:24 - 2014-03-05 16:24 - 00016602 _____ () C:\Users\Adioz\Documents\Schwarz und weiß.odt 2014-03-03 03:01 - 2014-03-01 13:36 - 00015975 _____ () C:\Users\Adioz\Documents\Pokedex x+y.ods 2014-02-28 00:01 - 2014-02-26 09:39 - 01594028 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-28 00:01 - 2009-07-14 18:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-02-28 00:01 - 2009-07-14 18:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-02-28 00:01 - 2009-07-14 06:13 - 01594028 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-26 21:29 - 2014-02-26 21:29 - 00000000 ____D () C:\Users\Adioz\AppData\Local\Skype 2014-02-26 21:29 - 2012-05-28 20:13 - 00000000 ____D () C:\ProgramData\Skype 2014-02-26 21:28 - 2012-05-28 20:13 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-25 07:56 - 2012-05-24 21:52 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-25 07:56 - 2012-05-24 21:52 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-25 07:56 - 2012-05-24 21:52 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-17 23:30 - 2013-08-15 02:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-17 23:27 - 2012-05-30 17:29 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-17 19:40 - 2013-07-05 06:43 - 00000099 _____ () C:\Users\Public\LMDebug.log 2014-02-14 19:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-02-10 22:24 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-09 03:21 - 2014-02-09 03:21 - 00013986 _____ () C:\Users\Adioz\Documents\sandsturm.odt 2014-02-06 13:16 - 2014-02-12 22:39 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-12 22:39 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-12 22:39 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-12 22:39 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-12 22:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-12 22:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-12 22:39 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-12 22:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-12 22:39 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-12 22:39 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-12 22:39 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-12 22:39 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-12 22:39 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-12 22:39 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-12 22:39 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-12 22:39 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-12 22:39 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-12 22:39 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-12 22:39 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-12 22:39 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-12 22:39 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-12 22:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-12 22:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-12 22:39 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-12 22:39 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-12 22:39 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-12 22:39 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-12 22:39 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-12 22:39 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-12 22:39 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-12 22:39 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-12 22:39 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-12 22:39 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-12 22:39 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-12 22:39 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-12 22:39 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-12 22:39 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-12 22:39 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-12 22:39 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Some content of TEMP: ==================== C:\Users\Adioz\AppData\Local\Temp\avgnt.exe C:\Users\Adioz\AppData\Local\Temp\setup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-28 18:41 ==================== End Of Log ============================ --- --- --- und die addition FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-03-2014 Ran by Adioz at 2014-03-07 00:12:35 Running from C:\Users\Adioz\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Reader XI - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 2.00.0002 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.923.1 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{5831C6D6-309D-DBB5-14F7-FEE57086CEE7}) (Version: 8.0.873.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.70405.2224 - Advanced Micro Devices, Inc.) Hidden ASCII Art - Machine 1.2 (HKLM-x32\...\ASCII Art - Machine_is1) (Version: - ) Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.15.31.0 - Ask.com) <==== ATTENTION Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) Avira SearchFree Toolbar plus Web Protection Updater (HKCU\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version: - AVM Berlin) CANYON USB PC CAMERA (HKLM-x32\...\{A59AB961-BE82-41E0-B0FB-648DFA6DDEA4}) (Version: 1.0.20 - ANC) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center (x32 Version: 2012.0405.2205.37728 - Ihr Firmenname) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0405.2205.37728 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.0405.2205.37728 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.0405.2205.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.0405.2204.37728 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.0405.2205.37728 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.18 - Piriform) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.22 - DivX, LLC) DVDVideoSoftTB Toolbar (HKLM-x32\...\DVDVideoSoftTB Toolbar) (Version: 6.8.10.403 - DVDVideoSoftTB) Free YouTube to MP3 Converter version 3.12.1.320 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.1.320 - DVDVideoSoft Ltd.) GIMP 2.8.2 (HKLM\...\GIMP-2_is1) (Version: 2.8.2 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.146 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden hola Chrome Toolbar (HKLM-x32\...\hola Chrome Toolbar) (Version: - hola) holasearch toolbar (HKLM-x32\...\holasearch) (Version: 1.8.16.16 - holasearch) <==== ATTENTION HydraVision (x32 Version: 4.2.220.0 - Advanced Micro Devices, Inc.) Hidden InterActual Player (HKLM-x32\...\InterActual Player) (Version: - ) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden LibreOffice 3.5 (HKLM-x32\...\{28C70D19-6DE9-43EF-BFA3-342F4A11B727}) (Version: 3.5.3.2 - The Document Foundation) LightScribe System Software (HKLM-x32\...\{2FA75B40-17C9-4D22-88CA-80A5D52FAB13}) (Version: 1.18.24.1 - LightScribe) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 23.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 23.0.1 (x86 de)) (Version: 23.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 23.0.1 - Mozilla) Plants vs. Zombies 1.0.4.7924 (by Scar) (HKLM-x32\...\{0DE8527A-FE3E-4FCA-A023-D57EF0B796C9}_is1) (Version: - PopCap Games) Pokemon Online 2.1.0 (HKLM-x32\...\{2C08D7E7-9EE1-4A08-AFE0-745F02DCD6A4}_is1) (Version: - Dreambelievers) Project 64 version 2.1.0.1 (HKLM-x32\...\Project 64_is1) (Version: 2.1.0.1 - ) RGSS-RTP Standard (HKLM-x32\...\{5A9FE525-8B8F-4701-A937-7F6745A4E9C7}) (Version: 1.0.0 - Enterbrain) RPGXP (HKLM-x32\...\{9B34CAC6-738F-4A20-B428-A115C3E3474C}) (Version: 1.0.0 - Enterbrain) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.0.12094_27 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.5.0.12094_27 - Samsung Electronics Co., Ltd.) Hidden Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.15.0 - SAMSUNG Electronics Co., Ltd.) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) SureThing CD Labeler Deluxe Trial (HKLM-x32\...\{4ED7D297-58F7-45C3-A9BA-A7CD6FA0D373}_is1) (Version: 5.2.693.0 - MicroVision Development, Inc.) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.0.1 (HKLM-x32\...\VLC media player) (Version: 2.0.1 - VideoLAN) Web Assistant 2.0.0.462 (HKLM\...\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1) (Version: - IncrediBar) <==== ATTENTION WinRAR 4.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) ==================== Restore Points ========================= 27-02-2014 22:58:29 Windows Update 04-03-2014 12:23:08 Windows Update 06-03-2014 22:04:52 Removed Facebook Messenger 2.1.4814.0 ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1B448685-DC2F-4A64-A31A-EBD7842DF892} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-25] (Adobe Systems Incorporated) Task: {253A3884-ED7F-4B1F-95A8-708899401F11} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2014-01-31] () <==== ATTENTION Task: {2E62D82A-8B25-4F8C-90AF-944F90DF7347} - System32\Tasks\BackgroundContainer Startup Task => Rundll32.exe "C:\Users\Adioz\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun <==== ATTENTION Task: {4C3BB12D-1272-4255-84BC-1941A4EAA530} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-06] (Google Inc.) Task: {53DC7316-C4D0-4DB8-9E5F-48CB89D338EE} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-500615665-753558739-4272784270-1000Core => C:\Users\Adioz\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-20] (Facebook Inc.) Task: {768E89D0-626E-40B5-A436-123DDB0D6410} - System32\Tasks\AdobeFlashPlayerUpdate => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe Task: {796BEFF2-01F0-4097-B3FE-D406229FDF87} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe Task: {81777349-88E1-40C3-BD59-A3E4C035B310} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {822DB7E0-81EC-4255-8E2A-12AD244DA357} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION Task: {B49CAF72-BBA8-4487-9B9E-001635BBFD3C} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect <==== ATTENTION Task: {C9F44B8A-1EA5-4BD0-AE60-E80C0AB2FF06} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-06] (Google Inc.) Task: {F7E2538F-567A-4E45-B827-42A7611FD106} - System32\Tasks\EPUpdater => C:\Users\Adioz\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () <==== ATTENTION Task: {FA2F9804-CED9-4E65-B073-4033B6565F94} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-500615665-753558739-4272784270-1000UA => C:\Users\Adioz\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-20] (Facebook Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-500615665-753558739-4272784270-1000Core.job => C:\Users\Adioz\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-500615665-753558739-4272784270-1000UA.job => C:\Users\Adioz\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-06-28 09:12 - 2013-06-28 09:12 - 00034304 _____ () C:\Windows\System32\ssm1mlm.dll 2013-08-24 13:40 - 2013-08-24 13:40 - 03233806 _____ () C:\Program Files (x86)\Tor\tor.exe 2011-12-05 20:36 - 2011-12-05 20:36 - 00409600 _____ () C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe 2012-04-05 21:00 - 2012-04-05 21:00 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2012-10-27 17:27 - 2012-09-19 18:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2014-03-06 22:52 - 2014-03-02 03:35 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\chrome_elf.dll 2014-03-06 22:52 - 2014-03-02 03:35 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\libglesv2.dll 2014-03-06 22:52 - 2014-03-02 03:35 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\libegl.dll 2014-03-06 22:52 - 2014-03-02 03:35 - 04061000 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\pdf.dll 2014-03-06 22:52 - 2014-03-02 03:35 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll 2014-03-06 22:52 - 2014-03-02 03:35 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AVM WLAN Connection Service => 2 MSCONFIG\Services: CltMngSvc => 2 MSCONFIG\Services: Guard.Mail.ru => 2 MSCONFIG\Services: IBUpdaterService => 2 MSCONFIG\Services: LightScribeService => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: Web Assistant Updater => 2 MSCONFIG\startupfolder: C:^Users^Adioz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk => C:\Windows\pss\Facebook Messenger.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: ApnUpdater => "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" MSCONFIG\startupreg: AVMWlanClient => C:\Program Files (x86)\avmwlanstick\wlangui.exe MSCONFIG\startupreg: Browser Infrastructure Helper => C:\Users\Adioz\AppData\Local\Smartbar\Application\QuickShare.exe startup MSCONFIG\startupreg: DivXMediaServer => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW MSCONFIG\startupreg: Facebook Update => "C:\Users\Adioz\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver MSCONFIG\startupreg: Guard.Mail.ru.gui => "C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe" /gui MSCONFIG\startupreg: ICQ => "C:\Program Files (x86)\ICQ7M\ICQ.exe" silent loginmode=4 MSCONFIG\startupreg: KiesAirMessage => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup MSCONFIG\startupreg: KiesPreload => C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: LightScribe Control Panel => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden MSCONFIG\startupreg: SearchProtect => C:\Users\Adioz\AppData\Roaming\SearchProtect\cltmng.exe MSCONFIG\startupreg: SearchProtectAll => C:\Program Files (x86)\SearchProtect\bin\cltmng.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun ==================== Faulty Device Manager Devices ============= Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Serieller PCI-Anschluss Description: Serieller PCI-Anschluss Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Belkin Drahtlos-A/G Desktop-Netzwerkkarte Description: Belkin Drahtlos-A/G Desktop-Netzwerkkarte Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Atheros Communications Inc. Service: athr Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: PS/2-kompatible Maus Description: PS/2-kompatible Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: PCI-Kommunikationscontroller (einfach) Description: PCI-Kommunikationscontroller (einfach) Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (03/06/2014 09:08:25 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (03/06/2014 02:52:14 PM) (Source: Application Hang) (User: ) Description: Programm Skype.exe, Version 6.14.0.104 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a68 Startzeit: 01cf39401e2bed32 Endzeit: 5 Anwendungspfad: C:\Program Files (x86)\Skype\Phone\Skype.exe Berichts-ID: Error: (03/06/2014 11:37:23 AM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (03/04/2014 02:09:19 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (03/03/2014 05:58:26 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (03/02/2014 10:43:54 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 90080108 Error: (03/02/2014 07:00:08 PM) (Source: Windows Backup) (User: ) Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "G:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)" Error: (03/02/2014 09:29:19 AM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (03/01/2014 10:33:17 AM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (02/28/2014 02:11:14 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: ICQ7.exe, Version: 14.0.0.162, Zeitstempel: 0x4626b2f4 Name des fehlerhaften Moduls: MoveIt.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x4fa119ef Ausnahmecode: 0xc0000005 Fehleroffset: 0x6b01cfde ID des fehlerhaften Prozesses: 0x544 Startzeit der fehlerhaften Anwendung: 0xICQ7.exe0 Pfad der fehlerhaften Anwendung: ICQ7.exe1 Pfad des fehlerhaften Moduls: ICQ7.exe2 Berichtskennung: ICQ7.exe3 System errors: ============= Error: (03/06/2014 10:50:42 PM) (Source: DCOM) (User: PC_Adioz) Description: ComputerstandardLokalAktivierung{000C101C-0000-0000-C000-000000000046}{000C101C-0000-0000-C000-000000000046}PC_AdiozAdiozS-1-5-21-500615665-753558739-4272784270-1000LocalHost (unter Verwendung von LRPC) Error: (03/06/2014 10:50:41 PM) (Source: DCOM) (User: PC_Adioz) Description: ComputerstandardLokalAktivierung{000C101C-0000-0000-C000-000000000046}{000C101C-0000-0000-C000-000000000046}PC_AdiozAdiozS-1-5-21-500615665-753558739-4272784270-1000LocalHost (unter Verwendung von LRPC) Error: (03/06/2014 10:50:36 PM) (Source: DCOM) (User: PC_Adioz) Description: ComputerstandardLokalAktivierung{000C101C-0000-0000-C000-000000000046}{000C101C-0000-0000-C000-000000000046}PC_AdiozAdiozS-1-5-21-500615665-753558739-4272784270-1000LocalHost (unter Verwendung von LRPC) Error: (03/06/2014 02:31:55 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X64 erreicht. Error: (03/06/2014 02:28:42 PM) (Source: Ntfs) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (03/06/2014 11:28:04 AM) (Source: Ntfs) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (03/05/2014 00:11:07 PM) (Source: Ntfs) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (03/04/2014 01:18:29 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Sicherung" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/04/2014 01:18:29 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows-Sicherung erreicht. Error: (03/04/2014 01:18:30 PM) (Source: DCOM) (User: ) Description: 1053sdrsvc{687E55CA-6621-4C41-B9F1-C0EDDC94BB05} Microsoft Office Sessions: ========================= Error: (03/06/2014 09:08:25 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (03/06/2014 02:52:14 PM) (Source: Application Hang)(User: ) Description: Skype.exe6.14.0.104a6801cf39401e2bed325C:\Program Files (x86)\Skype\Phone\Skype.exe Error: (03/06/2014 11:37:23 AM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (03/04/2014 02:09:19 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (03/03/2014 05:58:26 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (03/02/2014 10:43:54 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 90080108 Error: (03/02/2014 07:00:08 PM) (Source: Windows Backup)(User: ) Description: G:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006) Error: (03/02/2014 09:29:19 AM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (03/01/2014 10:33:17 AM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (02/28/2014 02:11:14 PM) (Source: Application Error)(User: ) Description: ICQ7.exe14.0.0.1624626b2f4MoveIt.dll_unloaded0.0.0.04fa119efc00000056b01cfde54401cf348657c77301C:\Users\Adioz\AppData\Local\Temp\{DCB0B39C-E004-460C-82C2-3995609C0EF4}\ICQ7.exeMoveIt.dllcc773cc3-a079-11e3-b48d-001e0b6963b3 ==================== Memory info =========================== Percentage of memory in use: 64% Total physical RAM: 2012.3 MB Available physical RAM: 706.29 MB Total Pagefile: 4024.6 MB Available Pagefile: 1695.67 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:149.04 GB) (Free:95.96 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:0.01 GB) (Free:0 GB) NTFS Drive e: (SUPERNATURAL) (CDROM) (Total:7.01 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 3283CBC4) Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=8 MB) - (Type=07 NTFS) ==================== End Of Log ============================ Geändert von Adioz1994 (07.03.2014 um 00:08 Uhr) |
07.03.2014, 00:31 | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Google chrome Öffnet 3 Facebook tabs unaufgefordertZitat:
Lesestoff: Warum wir Avira nicht mehr empfehlen Avira liefert seit einiger Zeit mit der Standardinstallation die Ask Toolbar mit aus. Diese Toolbar ist Voraussetzung dafür, dass der Webguard zuverlässig funktioniert. Die Ask Toolbar ist dafür bekannt, dass sie das Surfverhalten des Benutzers ausspioniert, um damit in letzter Konsequenz Geld zu verdienen. Daher wird diese Toolbar von uns als "schädlich" eingestuft. Mehr Informationen. Eine Sicherheitsfirma, die dem Benutzer praktisch ungefragt schädliche Software "unterjubelt", scheidet für uns daher aus. Wir empfehlen daher allen Nutzern von Avira aufgrund dieser Geschäftspraktik, der teilweise äußerst schlechten Erkennungsrate und der überaus nervtötenden Werbung Avira zu deinstallieren und auf ein alternatives Produkt auszuweichen. Solltest du dich zu einem Wechsel entscheiden, empfehlen wir dir nach der Deinstallation mit dem Avira-Cleaner alle Reste zu entfernen.
__________________ Logfiles bitte immer in CODE-Tags posten |
07.03.2014, 00:39 | #5 |
| Google chrome Öffnet 3 Facebook tabs unaufgefordert das win 7 ultimate hab ich geschenkt bekommen war also auch umsonst |
07.03.2014, 00:43 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Google chrome Öffnet 3 Facebook tabs unaufgefordert Hoffentlich hat dir nicht jmd. was gecracktes "geschenkt" Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ --> Google chrome Öffnet 3 Facebook tabs unaufgefordert |
07.03.2014, 00:53 | #7 |
| Google chrome Öffnet 3 Facebook tabs unaufgefordert ich wurde von einem boardler mit dem selben Problem angeschrieben. er löste es in dem er den Facebook messenger deinstallierte. das hab ich vor dem FRST scann auch gemacht und seit dem haben sich keine tabs mehr geöffnet. wenn das so bleibt lass ich es gut sein. wenn nicht lad ich mir MBAR runter |
07.03.2014, 00:56 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Google chrome Öffnet 3 Facebook tabs unaufgefordert MBAR ist nicht gedacht um die Probleme zu lösen die "du siehst" Denn es ist ein Anti-Rootkit-Tool und eine Vorsichtsmaßnahme, als routinemäßger Check um annähern sicher zu sein, dass keine richtig fiesen Gäste an Bord sind. Also bitte ich dich zu deinem eigenen Schutz MBAR auszuführen, egal ob du noch sichtbare Probleme hast oder nicht.
__________________ Logfiles bitte immer in CODE-Tags posten |
07.03.2014, 01:03 | #9 |
| Google chrome Öffnet 3 Facebook tabs unaufgefordert ok. habe es mir jetzt mal runtergeladen und lasse es wie in der anleitung laufen. Soll die log-datei wieder hier rein? bzw. kannst du was mit der anfangen? |
07.03.2014, 01:12 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Google chrome Öffnet 3 Facebook tabs unaufgefordert Anleitung richtig lesen. Natprlich muss das Log gepostet werden
__________________ Logfiles bitte immer in CODE-Tags posten |
07.03.2014, 01:15 | #11 |
| Google chrome Öffnet 3 Facebook tabs unaufgefordert ja hab ich bin grad beim scannen. danach cleanup dann neu starten, dann nochmal scannen und je nach erneutem fund noch mal cleanup und neustart |
07.03.2014, 01:18 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Google chrome Öffnet 3 Facebook tabs unaufgefordert Genau so
__________________ Logfiles bitte immer in CODE-Tags posten |
07.03.2014, 01:19 | #13 |
| Google chrome Öffnet 3 Facebook tabs unaufgefordert scan ist fertig. No maleware found *freu* |
07.03.2014, 01:20 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Google chrome Öffnet 3 Facebook tabs unaufgefordert Log bitte trotzdem und immer posten
__________________ Logfiles bitte immer in CODE-Tags posten |
07.03.2014, 01:22 | #15 |
| Google chrome Öffnet 3 Facebook tabs unaufgefordertCode:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1009 www.malwarebytes.org Database version: v2014.03.06.10 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16518 Adioz :: PC_ADIOZ [administrator] 07.03.2014 01:01:06 mbar-log-2014-03-07 (01-01-06).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 229919 Time elapsed: 13 minute(s), 9 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
Themen zu Google chrome Öffnet 3 Facebook tabs unaufgefordert |
3 tabs, abständen, beschreibung, bräuchte, chrome, facebook, falsch, garnicht, gefunde, geholfen, google, google chrome, guten, heute, hilfe, hoffe, https, immer wieder, link, problem, suche, unaufgefordert, unterschiedliche, unterschiedlichen, öffnen |