|
Plagegeister aller Art und deren Bekämpfung: Avira hat ADWARE/installCore.Gen gefundenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
25.03.2014, 13:01 | #1 |
| Avira hat ADWARE/installCore.Gen gefunden Moin zusammen ! Avira hat beim Systemscan ADWARE/insatallCore.gen gefunden und nun macht der Browser von Google Chrom Probleme beim öffnen was kann ich tun ? Bin Laie und habe nicht viel Ahnung die Datei hat Avira in die Quarantäne verschoben Danke für die Hilfe Thomas |
25.03.2014, 13:20 | #2 |
/// the machine /// TB-Ausbilder | Avira hat ADWARE/installCore.Gen gefunden hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
30.03.2014, 06:51 | #3 |
| Avira hat ADWARE/installCore.Gen gefundenFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Tomtom (ATTENTION: The logged in user is not administrator) on INA-PC on 30-03-2014 07:42:00 Running from C:\Users\Tomtom\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-23] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-13] (APN) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\RunOnce: [*Restore] - C:\Windows\System32\rstrui.exe /runonce [296960 2010-11-21] (Microsoft Corporation) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com SearchScopes: HKCU - {4DEA90FF-9F76-48C1-94AE-D6B7D1B4597A} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=33739dff-47ce-4ebf-805e-e8ba57b4217b&apn_sauid=1D243CA1-5603-4649-8F3B-B799F070ACEB BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\Tomtom\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh [2013-09-21] CHR Extension: (Google Wallet) - C:\Users\Tomtom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-21] CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [2014-02-21] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-23] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-23] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-23] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.) R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-18] (Avira Operations GmbH & Co. KG) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-26 09:55 - 2014-03-26 09:55 - 00011224 _____ () C:\Users\Tomtom\Downloads\Addition.txt 2014-03-26 09:54 - 2014-03-30 07:42 - 00005355 _____ () C:\Users\Tomtom\Downloads\FRST.txt 2014-03-26 09:54 - 2014-03-30 07:42 - 00000000 ____D () C:\FRST 2014-03-26 09:52 - 2014-03-26 09:53 - 02157056 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST64.exe 2014-03-26 09:52 - 2014-03-26 09:52 - 01145856 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST.exe 2014-03-25 13:03 - 2014-03-25 13:04 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-25 13:03 - 2014-03-25 13:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-25 13:03 - 2014-03-25 13:03 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-25 13:03 - 2013-04-04 15:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-25 12:42 - 2014-03-25 12:43 - 138607664 _____ () C:\Users\Tomtom\Downloads\avira_free_antivirus_de_14.0.3.350.exe 2014-03-25 12:22 - 2014-03-25 12:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-25 12:12 - 2014-03-25 12:36 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\BabSolution 2014-03-25 12:12 - 2014-03-25 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-25 12:11 - 2014-03-25 12:11 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\AppCloudUpdater 2014-03-25 12:11 - 2014-03-25 12:11 - 00000000 ____D () C:\ProgramData\Babylon 2014-03-20 09:12 - 2014-03-20 09:12 - 00000544 _____ () C:\Users\Tomtom\Downloads\vCard_frau_n._francke_2014-03-20.vcf 2014-03-16 19:51 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-16 19:51 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-16 19:51 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-16 19:51 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-16 19:51 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-16 19:51 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-16 19:51 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-16 19:51 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-16 19:51 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-16 19:51 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-16 19:51 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-16 19:51 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-16 19:51 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-16 19:51 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-16 19:51 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-16 19:51 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-16 19:51 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-16 19:51 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-16 19:51 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-16 19:51 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-16 19:51 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-16 19:51 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-16 19:51 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-16 19:51 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-16 19:51 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-16 19:51 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-16 19:51 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-16 19:51 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-16 19:51 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-16 19:51 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-16 19:51 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-16 19:51 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-16 19:51 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-16 19:51 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-16 19:51 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-16 19:51 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-16 19:51 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-16 19:51 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-16 19:51 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-16 19:51 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-16 19:51 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-16 19:51 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-16 19:51 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-16 19:50 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-16 19:50 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-03-30 07:42 - 2014-03-26 09:54 - 00005355 _____ () C:\Users\Tomtom\Downloads\FRST.txt 2014-03-30 07:42 - 2014-03-26 09:54 - 00000000 ____D () C:\FRST 2014-03-30 07:41 - 2013-02-21 19:52 - 01734854 _____ () C:\Windows\system32\perfh007.dat 2014-03-30 07:41 - 2013-02-21 19:52 - 00473238 _____ () C:\Windows\system32\perfc007.dat 2014-03-30 07:41 - 2013-02-21 12:15 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-30 07:41 - 2009-07-14 07:13 - 00004568 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-30 07:37 - 2013-11-29 15:22 - 00003954 _____ () C:\Windows\setupact.log 2014-03-30 07:37 - 2013-02-21 12:15 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-30 07:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-26 10:15 - 2013-02-21 10:57 - 01179852 _____ () C:\Windows\WindowsUpdate.log 2014-03-26 10:10 - 2013-03-28 10:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-26 09:56 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-26 09:56 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-26 09:55 - 2014-03-26 09:55 - 00011224 _____ () C:\Users\Tomtom\Downloads\Addition.txt 2014-03-26 09:54 - 2013-09-20 20:35 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-26 09:53 - 2014-03-26 09:52 - 02157056 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST64.exe 2014-03-26 09:52 - 2014-03-26 09:52 - 01145856 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST.exe 2014-03-26 09:52 - 2013-02-21 11:55 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-25 14:03 - 2014-02-25 10:05 - 00003238 _____ () C:\Windows\PFRO.log 2014-03-25 13:15 - 2014-02-25 10:08 - 00000000 ____D () C:\Program Files\CyberGhost 5 2014-03-25 13:04 - 2014-03-25 13:03 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-25 13:03 - 2014-03-25 13:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-25 13:03 - 2014-03-25 13:03 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-25 12:45 - 2013-09-20 19:18 - 00002070 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-03-25 12:43 - 2014-03-25 12:42 - 138607664 _____ () C:\Users\Tomtom\Downloads\avira_free_antivirus_de_14.0.3.350.exe 2014-03-25 12:37 - 2014-03-25 12:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-25 12:37 - 2013-02-21 20:08 - 00000000 ____D () C:\Users\Tomtom 2014-03-25 12:36 - 2014-03-25 12:12 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\BabSolution 2014-03-25 12:36 - 2013-02-21 11:02 - 00000000 ____D () C:\Users\Ina 2014-03-25 12:36 - 2010-11-21 09:16 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-25 12:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-03-25 12:12 - 2014-03-25 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-25 12:11 - 2014-03-25 12:11 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\AppCloudUpdater 2014-03-25 12:11 - 2014-03-25 12:11 - 00000000 ____D () C:\ProgramData\Babylon 2014-03-20 09:12 - 2014-03-20 09:12 - 00000544 _____ () C:\Users\Tomtom\Downloads\vCard_frau_n._francke_2014-03-20.vcf 2014-03-20 08:53 - 2013-02-21 12:15 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-20 08:45 - 2009-07-14 06:45 - 00274464 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-12 10:10 - 2013-03-28 10:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 10:10 - 2013-03-28 10:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-01 08:05 - 2014-03-16 19:51 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 07:17 - 2014-03-16 19:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 07:16 - 2014-03-16 19:51 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 06:58 - 2014-03-16 19:51 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 06:52 - 2014-03-16 19:51 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 06:51 - 2014-03-16 19:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 06:42 - 2014-03-16 19:51 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 06:40 - 2014-03-16 19:51 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 06:37 - 2014-03-16 19:51 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 06:33 - 2014-03-16 19:51 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 06:33 - 2014-03-16 19:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 06:32 - 2014-03-16 19:51 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 06:30 - 2014-03-16 19:51 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 06:23 - 2014-03-16 19:51 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 06:17 - 2014-03-16 19:51 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 06:11 - 2014-03-16 19:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 06:02 - 2014-03-16 19:51 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 05:54 - 2014-03-16 19:51 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 05:52 - 2014-03-16 19:51 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 05:51 - 2014-03-16 19:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 05:47 - 2014-03-16 19:51 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 05:43 - 2014-03-16 19:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 05:43 - 2014-03-16 19:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 05:42 - 2014-03-16 19:51 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 05:40 - 2014-03-16 19:51 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 05:38 - 2014-03-16 19:51 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 05:37 - 2014-03-16 19:51 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 05:35 - 2014-03-16 19:51 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 05:18 - 2014-03-16 19:51 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 05:16 - 2014-03-16 19:51 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 05:14 - 2014-03-16 19:51 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 05:10 - 2014-03-16 19:51 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 05:03 - 2014-03-16 19:51 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 05:00 - 2014-03-16 19:51 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 04:57 - 2014-03-16 19:51 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 04:38 - 2014-03-16 19:51 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 04:32 - 2014-03-16 19:51 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 04:27 - 2014-03-16 19:51 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 04:25 - 2014-03-16 19:51 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 04:25 - 2014-03-16 19:51 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Some content of TEMP: ==================== C:\Users\Tomtom\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by Tomtom at 2014-03-26 08:55:03 Running from C:\Users\Tomtom\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) Avira SearchFree Toolbar (HKLM-x32\...\{41564952-412D-5637-00A7-A758B70C0A03}) (Version: 12.10.3.4487 - APN, LLC) Avira SearchFree Toolbar plus Web Protection Updater (HKCU\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.4.37949 - Ask.com) <==== ATTENTION CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.) Google Drive (HKLM-x32\...\{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}) (Version: 1.14.6059.644 - Google, Inc.) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Ravensburger tiptoi (HKLM-x32\...\Ravensburger tiptoi) (Version: - ) ==================== Restore Points ========================= Could not list Restore Points. Check "winmgmt" service or repair WMI. ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ? Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ? Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ? ==================== Loaded Modules (whitelisted) ============= ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (03/26/2014 08:53:40 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (03/26/2014 08:53:40 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (03/26/2014 08:53:40 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (03/26/2014 08:49:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/25/2014 01:04:59 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/25/2014 11:42:02 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (03/25/2014 11:42:02 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (03/25/2014 11:42:02 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (03/25/2014 11:38:53 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/25/2014 11:38:47 AM) (Source: Avira Antivirus) (User: NT-AUTORITÄT) Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet! System errors: ============= Error: (03/25/2014 11:38:47 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Browser-Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1. Error: (03/25/2014 11:38:04 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Browser-Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1. Error: (03/25/2014 10:32:18 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "CyberGhost VPN 5 Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/25/2014 10:32:18 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst CyberGhost VPN 5 Client Service erreicht. Error: (03/20/2014 07:50:41 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Google Update-Dienst (gupdate)" wurde nicht richtig gestartet. Error: (03/20/2014 07:46:24 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "CyberGhost VPN 5 Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/20/2014 07:46:24 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst CyberGhost VPN 5 Client Service erreicht. Error: (03/16/2014 06:42:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "CyberGhost VPN 5 Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/16/2014 06:42:38 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst CyberGhost VPN 5 Client Service erreicht. Error: (03/12/2014 08:56:10 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "CyberGhost VPN 5 Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Microsoft Office Sessions: ========================= Error: (03/26/2014 08:53:40 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (03/26/2014 08:53:40 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (03/26/2014 08:53:40 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (03/26/2014 08:49:41 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/25/2014 01:04:59 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/25/2014 11:42:02 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (03/25/2014 11:42:02 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (03/25/2014 11:42:02 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (03/25/2014 11:38:53 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/25/2014 11:38:47 AM) (Source: Avira Antivirus)(User: NT-AUTORITÄT) Description: 0x0 ==================== Memory info =========================== Percentage of memory in use: 36% Total physical RAM: 3838.36 MB Available physical RAM: 2424.34 MB Total Pagefile: 7674.9 MB Available Pagefile: 6139.95 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:149.04 GB) (Free:121.22 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: () (Fixed) (Total:148.65 GB) (Free:68.53 GB) NTFS ==================== MBR & Partition Table ================== ==================== End Of Log ============================ Ist das das was du brauchst ? |
30.03.2014, 12:54 | #4 |
/// the machine /// TB-Ausbilder | Avira hat ADWARE/installCore.Gen gefunden Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.03.2014, 20:42 | #5 |
| Avira hat ADWARE/installCore.Gen gefunden AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.022 - Bericht erstellt am 30/03/2014 um 21:18:20 # Aktualisiert 13/03/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Ina - INA-PC # Gestartet von : C:\Users\Ina\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v -\\ Google Chrome v33.0.1750.154 [ Datei : C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\preferences ] [ Datei : C:\Users\Tomtom\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1890 octets] - [30/03/2014 20:51:08] AdwCleaner[R1].txt - [1026 octets] - [30/03/2014 21:02:40] AdwCleaner[R2].txt - [1087 octets] - [30/03/2014 21:17:41] AdwCleaner[S0].txt - [1909 octets] - [30/03/2014 20:54:09] AdwCleaner[S1].txt - [1009 octets] - [30/03/2014 21:18:20] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1069 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.3 (03.23.2014:1) OS: Windows 7 Home Premium x64 Ran by Ina on 30.03.2014 at 21:05:30,33 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{093229E6-1008-4B97-A024-624DED0809C2} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Folder] "C:\Users\Ina\appdata\local\apn" ~~~ Chrome Successfully deleted: [Folder] C:\Users\Ina\appdata\local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 30.03.2014 at 21:13:59,06 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware Malwarebytes | Free Anti-Malware & Internet Security Software Suchlauf Datum: 30.03.2014 Suchlauf-Zeit: 20:38:51 Logdatei: mbam.txt Administrator: Ja Version: 2.00.0.1000 Malware Datenbank: v2014.03.30.05 Rootkit Datenbank: v2014.03.27.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Ina Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 256298 Verstrichene Zeit: 11 Min, 28 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Ich hoffe das passt so alles war ein wenig überfordert ! ;-) wenn noch was fehlt einfach bescheid sagen tue mein bestes ! Und nochmal Danke FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Ina (administrator) on INA-PC on 30-03-2014 21:39:34 Running from C:\Users\Ina\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files (x86)\Vidalia Relay Bundle\Vidalia\vidalia.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-23] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKU\S-1-5-21-2501610007-4256825277-2014219784-1001\...\Run: [Vidalia] - C:\Program Files (x86)\Vidalia Relay Bundle\Vidalia\vidalia.exe [6239727 2012-12-02] () HKU\S-1-5-21-2501610007-4256825277-2014219784-1001\...\MountPoints2: {7a9a47db-9c89-11e2-94eb-705ab6893770} - F:\Startme.exe Startup: C:\Users\Ina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk ShortcutTarget: Product Registration.lnk -> C:\Users\Ina\AppData\Local\Temp\is-JGTJF.tmp\ATR1.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Dell Official Site - The Power To Do More | Dell URLSearchHook: HKCU - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.) BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrId=566B00FFB78B0417&affID=127690&tsp=5197 CHR DefaultSearchKeyword: buenosearch.com CHR DefaultSearchProvider: Bueno Search CHR DefaultSearchURL: hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=566B00FFB78B0417&affID=127690&tsp=5197 CHR DefaultNewTabURL: CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Extension: (Google Docs) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-02-21] CHR Extension: (Google Drive) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-02-21] CHR Extension: (YouTube) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-21] CHR Extension: (Google-Suche) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-21] CHR Extension: (Google Wallet) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-03] CHR Extension: (Google Mail) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-21] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-23] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-23] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-23] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-18] (Avira Operations GmbH & Co. KG) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-03-05] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-03-30] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-03-05] (Malwarebytes Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-30 21:39 - 2014-03-30 21:39 - 02157056 _____ (Farbar) C:\Users\Ina\Downloads\FRST64.exe 2014-03-30 21:39 - 2014-03-30 21:39 - 00008003 _____ () C:\Users\Ina\Downloads\FRST.txt 2014-03-30 21:13 - 2014-03-30 21:13 - 00001387 _____ () C:\Users\Ina\Desktop\JRT.txt 2014-03-30 21:05 - 2014-03-30 21:05 - 00000000 ____D () C:\Windows\ERUNT 2014-03-30 21:04 - 2014-03-30 21:05 - 01038974 _____ (Thisisu) C:\Users\Ina\Downloads\JRT.exe 2014-03-30 20:50 - 2014-03-30 21:18 - 00000000 ____D () C:\AdwCleaner 2014-03-30 20:49 - 2014-03-30 20:49 - 01950720 _____ () C:\Users\Ina\Downloads\adwcleaner.exe 2014-03-30 20:44 - 2014-03-30 20:44 - 00001142 _____ () C:\mbam.txt 2014-03-30 19:58 - 2014-03-30 21:21 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-30 19:57 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-30 19:57 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-30 19:56 - 2014-03-30 19:57 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000 (1).exe 2014-03-30 19:56 - 2014-03-30 19:56 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-26 09:55 - 2014-03-26 09:55 - 00011224 _____ () C:\Users\Tomtom\Downloads\Addition.txt 2014-03-26 09:54 - 2014-03-30 21:39 - 00000000 ____D () C:\FRST 2014-03-26 09:54 - 2014-03-30 07:43 - 00021389 _____ () C:\Users\Tomtom\Downloads\FRST.txt 2014-03-26 09:52 - 2014-03-26 09:53 - 02157056 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST64.exe 2014-03-26 09:52 - 2014-03-26 09:52 - 01145856 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST.exe 2014-03-25 13:03 - 2014-03-30 19:57 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-25 13:03 - 2014-03-25 13:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-25 13:03 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-25 12:42 - 2014-03-25 12:43 - 138607664 _____ () C:\Users\Tomtom\Downloads\avira_free_antivirus_de_14.0.3.350.exe 2014-03-25 12:22 - 2014-03-30 19:57 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-25 12:12 - 2014-03-25 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-25 12:11 - 2014-03-25 12:11 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\AppCloudUpdater 2014-03-20 09:12 - 2014-03-20 09:12 - 00000544 _____ () C:\Users\Tomtom\Downloads\vCard_frau_n._francke_2014-03-20.vcf 2014-03-16 19:51 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-16 19:51 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-16 19:51 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-16 19:51 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-16 19:51 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-16 19:51 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-16 19:51 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-16 19:51 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-16 19:51 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-16 19:51 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-16 19:51 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-16 19:51 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-16 19:51 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-16 19:51 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-16 19:51 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-16 19:51 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-16 19:51 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-16 19:51 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-16 19:51 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-16 19:51 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-16 19:51 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-16 19:51 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-16 19:51 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-16 19:51 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-16 19:51 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-16 19:51 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-16 19:51 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-16 19:51 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-16 19:51 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-16 19:51 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-16 19:51 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-16 19:51 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-16 19:51 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-16 19:51 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-16 19:51 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-16 19:51 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-16 19:51 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-16 19:51 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-16 19:51 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-16 19:51 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-16 19:51 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-16 19:51 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-16 19:51 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-16 19:50 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-16 19:50 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-03-30 21:39 - 2014-03-30 21:39 - 02157056 _____ (Farbar) C:\Users\Ina\Downloads\FRST64.exe 2014-03-30 21:39 - 2014-03-30 21:39 - 00008003 _____ () C:\Users\Ina\Downloads\FRST.txt 2014-03-30 21:39 - 2014-03-26 09:54 - 00000000 ____D () C:\FRST 2014-03-30 21:27 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-30 21:27 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-30 21:23 - 2013-02-21 19:52 - 01794022 _____ () C:\Windows\system32\perfh007.dat 2014-03-30 21:23 - 2013-02-21 19:52 - 00492182 _____ () C:\Windows\system32\perfc007.dat 2014-03-30 21:23 - 2013-02-21 10:57 - 01213339 _____ () C:\Windows\WindowsUpdate.log 2014-03-30 21:23 - 2009-07-14 07:13 - 00004568 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-30 21:21 - 2014-03-30 19:58 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-30 21:19 - 2013-11-29 15:22 - 00004178 _____ () C:\Windows\setupact.log 2014-03-30 21:19 - 2013-02-21 12:15 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-30 21:19 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-30 21:18 - 2014-03-30 20:50 - 00000000 ____D () C:\AdwCleaner 2014-03-30 21:13 - 2014-03-30 21:13 - 00001387 _____ () C:\Users\Ina\Desktop\JRT.txt 2014-03-30 21:10 - 2013-03-28 10:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-30 21:05 - 2014-03-30 21:05 - 00000000 ____D () C:\Windows\ERUNT 2014-03-30 21:05 - 2014-03-30 21:04 - 01038974 _____ (Thisisu) C:\Users\Ina\Downloads\JRT.exe 2014-03-30 20:49 - 2014-03-30 20:49 - 01950720 _____ () C:\Users\Ina\Downloads\adwcleaner.exe 2014-03-30 20:44 - 2014-03-30 20:44 - 00001142 _____ () C:\mbam.txt 2014-03-30 20:41 - 2013-02-21 12:15 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-30 20:26 - 2013-02-23 09:21 - 00000000 ____D () C:\Users\Ina\AppData\Local\Vidalia 2014-03-30 19:57 - 2014-03-30 19:56 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000 (1).exe 2014-03-30 19:57 - 2014-03-25 13:03 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-30 19:57 - 2014-03-25 12:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-30 19:57 - 2013-04-05 08:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-30 19:56 - 2014-03-30 19:56 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-30 07:43 - 2014-03-26 09:54 - 00021389 _____ () C:\Users\Tomtom\Downloads\FRST.txt 2014-03-26 09:55 - 2014-03-26 09:55 - 00011224 _____ () C:\Users\Tomtom\Downloads\Addition.txt 2014-03-26 09:54 - 2013-09-20 20:35 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-26 09:53 - 2014-03-26 09:52 - 02157056 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST64.exe 2014-03-26 09:52 - 2014-03-26 09:52 - 01145856 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST.exe 2014-03-26 09:52 - 2013-02-21 11:55 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-25 14:03 - 2014-02-25 10:05 - 00003238 _____ () C:\Windows\PFRO.log 2014-03-25 13:15 - 2014-02-25 10:08 - 00000000 ____D () C:\Program Files\CyberGhost 5 2014-03-25 13:03 - 2014-03-25 13:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-25 12:45 - 2013-09-20 19:18 - 00002070 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-03-25 12:43 - 2014-03-25 12:42 - 138607664 _____ () C:\Users\Tomtom\Downloads\avira_free_antivirus_de_14.0.3.350.exe 2014-03-25 12:37 - 2013-02-21 20:08 - 00000000 ____D () C:\Users\Tomtom 2014-03-25 12:36 - 2013-02-21 11:02 - 00000000 ____D () C:\Users\Ina 2014-03-25 12:36 - 2010-11-21 09:16 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-25 12:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-03-25 12:12 - 2014-03-25 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-25 12:11 - 2014-03-25 12:11 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\AppCloudUpdater 2014-03-20 09:12 - 2014-03-20 09:12 - 00000544 _____ () C:\Users\Tomtom\Downloads\vCard_frau_n._francke_2014-03-20.vcf 2014-03-20 08:53 - 2013-02-21 12:15 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-20 08:45 - 2009-07-14 06:45 - 00274464 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-12 10:10 - 2013-03-28 10:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 10:10 - 2013-03-28 10:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 10:10 - 2013-03-28 10:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-05 09:26 - 2014-03-30 19:57 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-05 09:26 - 2014-03-30 19:57 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-05 09:26 - 2014-03-25 13:03 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-01 08:05 - 2014-03-16 19:51 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 07:17 - 2014-03-16 19:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 07:16 - 2014-03-16 19:51 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 06:58 - 2014-03-16 19:51 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 06:52 - 2014-03-16 19:51 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 06:51 - 2014-03-16 19:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 06:42 - 2014-03-16 19:51 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 06:40 - 2014-03-16 19:51 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 06:37 - 2014-03-16 19:51 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 06:33 - 2014-03-16 19:51 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 06:33 - 2014-03-16 19:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 06:32 - 2014-03-16 19:51 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 06:30 - 2014-03-16 19:51 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 06:23 - 2014-03-16 19:51 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 06:17 - 2014-03-16 19:51 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 06:11 - 2014-03-16 19:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 06:02 - 2014-03-16 19:51 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 05:54 - 2014-03-16 19:51 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 05:52 - 2014-03-16 19:51 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 05:51 - 2014-03-16 19:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 05:47 - 2014-03-16 19:51 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 05:43 - 2014-03-16 19:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 05:43 - 2014-03-16 19:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 05:42 - 2014-03-16 19:51 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 05:40 - 2014-03-16 19:51 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 05:38 - 2014-03-16 19:51 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 05:37 - 2014-03-16 19:51 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 05:35 - 2014-03-16 19:51 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 05:18 - 2014-03-16 19:51 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 05:16 - 2014-03-16 19:51 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 05:14 - 2014-03-16 19:51 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 05:10 - 2014-03-16 19:51 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 05:03 - 2014-03-16 19:51 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 05:00 - 2014-03-16 19:51 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 04:57 - 2014-03-16 19:51 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 04:38 - 2014-03-16 19:51 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 04:32 - 2014-03-16 19:51 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 04:27 - 2014-03-16 19:51 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 04:25 - 2014-03-16 19:51 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 04:25 - 2014-03-16 19:51 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Some content of TEMP: ==================== C:\Users\Ina\AppData\Local\Temp\avgnt.exe C:\Users\Ina\AppData\Local\Temp\mdm_z4_ext_94109768_2572.dll C:\Users\Ina\AppData\Local\Temp\mdm_z4_ext_94502984_3960.dll C:\Users\Ina\AppData\Local\Temp\mdm_z4_ext_96862280_3016.dll C:\Users\Ina\AppData\Local\Temp\Quarantine.exe C:\Users\Tomtom\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-18 11:22 Sorry das fehlte ja noch ! ==================== End Of Log ============================ --- --- --- |
31.03.2014, 13:00 | #6 |
/// the machine /// TB-Ausbilder | Avira hat ADWARE/installCore.Gen gefundenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Avira hat ADWARE/installCore.Gen gefunden |
01.04.2014, 20:20 | #7 |
| Avira hat ADWARE/installCore.Gen gefunden FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Ina (administrator) on INA-PC on 01-04-2014 21:05:45 Running from C:\Users\Ina\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files (x86)\Vidalia Relay Bundle\Vidalia\vidalia.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\Ina\Downloads\FRST64 (1).exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-23] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKU\S-1-5-21-2501610007-4256825277-2014219784-1001\...\Run: [Vidalia] - C:\Program Files (x86)\Vidalia Relay Bundle\Vidalia\vidalia.exe [6239727 2012-12-02] () HKU\S-1-5-21-2501610007-4256825277-2014219784-1001\...\MountPoints2: {7a9a47db-9c89-11e2-94eb-705ab6893770} - F:\Startme.exe Startup: C:\Users\Ina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk ShortcutTarget: Product Registration.lnk -> C:\Users\Ina\AppData\Local\Temp\is-JGTJF.tmp\ATR1.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com URLSearchHook: HKCU - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.) BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrId=566B00FFB78B0417&affID=127690&tsp=5197 CHR DefaultSearchKeyword: buenosearch.com CHR DefaultSearchProvider: Bueno Search CHR DefaultSearchURL: hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=566B00FFB78B0417&affID=127690&tsp=5197 CHR DefaultNewTabURL: CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Extension: (Google Docs) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-02-21] CHR Extension: (Google Drive) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-02-21] CHR Extension: (YouTube) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-21] CHR Extension: (Google-Suche) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-21] CHR Extension: (Google Wallet) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-03] CHR Extension: (Google Mail) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-21] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-23] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-23] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-23] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.) R4 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-18] (Avira Operations GmbH & Co. KG) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-03-05] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-01] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-03-05] (Malwarebytes Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-01 21:05 - 2014-04-01 21:05 - 02157056 _____ (Farbar) C:\Users\Ina\Downloads\FRST64 (1).exe 2014-04-01 20:47 - 2014-04-01 20:48 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (3).exe 2014-04-01 20:44 - 2014-04-01 20:45 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (2).exe 2014-04-01 20:38 - 2014-04-01 20:38 - 00987442 _____ () C:\Users\Ina\Downloads\SecurityCheck.exe 2014-04-01 20:15 - 2014-04-01 20:15 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (1).exe 2014-04-01 19:46 - 2014-04-01 19:46 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-01 19:45 - 2014-04-01 19:45 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu.exe 2014-03-30 21:39 - 2014-04-01 21:05 - 00008051 _____ () C:\Users\Ina\Downloads\FRST.txt 2014-03-30 21:39 - 2014-03-30 21:39 - 02157056 _____ (Farbar) C:\Users\Ina\Downloads\FRST64.exe 2014-03-30 21:05 - 2014-03-30 21:05 - 00000000 ____D () C:\Windows\ERUNT 2014-03-30 21:04 - 2014-03-30 21:05 - 01038974 _____ (Thisisu) C:\Users\Ina\Downloads\JRT.exe 2014-03-30 20:50 - 2014-03-30 21:18 - 00000000 ____D () C:\AdwCleaner 2014-03-30 20:49 - 2014-03-30 20:49 - 01950720 _____ () C:\Users\Ina\Downloads\adwcleaner.exe 2014-03-30 20:44 - 2014-03-30 20:44 - 00001142 _____ () C:\mbam.txt 2014-03-30 19:58 - 2014-04-01 20:36 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-30 19:57 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-30 19:57 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-30 19:56 - 2014-03-30 19:57 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000 (1).exe 2014-03-30 19:56 - 2014-03-30 19:56 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-26 09:55 - 2014-03-26 09:55 - 00011224 _____ () C:\Users\Tomtom\Downloads\Addition.txt 2014-03-26 09:54 - 2014-04-01 21:05 - 00000000 ____D () C:\FRST 2014-03-26 09:54 - 2014-03-30 07:43 - 00021389 _____ () C:\Users\Tomtom\Downloads\FRST.txt 2014-03-26 09:52 - 2014-03-26 09:53 - 02157056 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST64.exe 2014-03-26 09:52 - 2014-03-26 09:52 - 01145856 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST.exe 2014-03-25 13:03 - 2014-03-30 19:57 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-25 13:03 - 2014-03-25 13:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-25 13:03 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-25 12:42 - 2014-03-25 12:43 - 138607664 _____ () C:\Users\Tomtom\Downloads\avira_free_antivirus_de_14.0.3.350.exe 2014-03-25 12:22 - 2014-03-30 19:57 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-25 12:12 - 2014-03-25 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-25 12:11 - 2014-03-25 12:11 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\AppCloudUpdater 2014-03-20 09:12 - 2014-03-20 09:12 - 00000544 _____ () C:\Users\Tomtom\Downloads\vCard_frau_n._francke_2014-03-20.vcf 2014-03-16 19:51 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-16 19:51 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-16 19:51 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-16 19:51 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-16 19:51 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-16 19:51 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-16 19:51 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-16 19:51 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-16 19:51 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-16 19:51 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-16 19:51 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-16 19:51 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-16 19:51 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-16 19:51 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-16 19:51 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-16 19:51 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-16 19:51 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-16 19:51 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-16 19:51 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-16 19:51 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-16 19:51 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-16 19:51 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-16 19:51 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-16 19:51 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-16 19:51 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-16 19:51 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-16 19:51 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-16 19:51 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-16 19:51 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-16 19:51 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-16 19:51 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-16 19:51 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-16 19:51 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-16 19:51 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-16 19:51 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-16 19:51 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-16 19:51 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-16 19:51 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-16 19:51 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-16 19:51 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-16 19:51 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-16 19:51 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-16 19:51 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-16 19:50 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-16 19:50 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-01 21:05 - 2014-04-01 21:05 - 02157056 _____ (Farbar) C:\Users\Ina\Downloads\FRST64 (1).exe 2014-04-01 21:05 - 2014-03-30 21:39 - 00008051 _____ () C:\Users\Ina\Downloads\FRST.txt 2014-04-01 21:05 - 2014-03-26 09:54 - 00000000 ____D () C:\FRST 2014-04-01 20:48 - 2014-04-01 20:47 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (3).exe 2014-04-01 20:45 - 2014-04-01 20:44 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (2).exe 2014-04-01 20:42 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-01 20:42 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-01 20:41 - 2013-02-21 12:15 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-01 20:40 - 2013-02-21 19:52 - 01823606 _____ () C:\Windows\system32\perfh007.dat 2014-04-01 20:40 - 2013-02-21 19:52 - 00501654 _____ () C:\Windows\system32\perfc007.dat 2014-04-01 20:40 - 2009-07-14 07:13 - 00004568 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-01 20:39 - 2013-02-21 10:57 - 01235053 _____ () C:\Windows\WindowsUpdate.log 2014-04-01 20:38 - 2014-04-01 20:38 - 00987442 _____ () C:\Users\Ina\Downloads\SecurityCheck.exe 2014-04-01 20:36 - 2014-03-30 19:58 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-01 20:35 - 2013-02-21 12:15 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-01 20:34 - 2013-11-29 15:22 - 00004290 _____ () C:\Windows\setupact.log 2014-04-01 20:34 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-01 20:15 - 2014-04-01 20:15 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (1).exe 2014-04-01 20:10 - 2013-03-28 10:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-01 19:46 - 2014-04-01 19:46 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-01 19:45 - 2014-04-01 19:45 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu.exe 2014-04-01 19:39 - 2013-02-23 09:21 - 00000000 ____D () C:\Users\Ina\AppData\Local\Vidalia 2014-03-30 21:39 - 2014-03-30 21:39 - 02157056 _____ (Farbar) C:\Users\Ina\Downloads\FRST64.exe 2014-03-30 21:18 - 2014-03-30 20:50 - 00000000 ____D () C:\AdwCleaner 2014-03-30 21:05 - 2014-03-30 21:05 - 00000000 ____D () C:\Windows\ERUNT 2014-03-30 21:05 - 2014-03-30 21:04 - 01038974 _____ (Thisisu) C:\Users\Ina\Downloads\JRT.exe 2014-03-30 20:49 - 2014-03-30 20:49 - 01950720 _____ () C:\Users\Ina\Downloads\adwcleaner.exe 2014-03-30 20:44 - 2014-03-30 20:44 - 00001142 _____ () C:\mbam.txt 2014-03-30 19:57 - 2014-03-30 19:56 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000 (1).exe 2014-03-30 19:57 - 2014-03-25 13:03 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-30 19:57 - 2014-03-25 12:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-30 19:57 - 2013-04-05 08:44 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\Malwarebytes 2014-03-30 19:57 - 2013-04-05 08:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-30 19:56 - 2014-03-30 19:56 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-30 07:43 - 2014-03-26 09:54 - 00021389 _____ () C:\Users\Tomtom\Downloads\FRST.txt 2014-03-26 09:55 - 2014-03-26 09:55 - 00011224 _____ () C:\Users\Tomtom\Downloads\Addition.txt 2014-03-26 09:54 - 2013-09-20 20:35 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-26 09:53 - 2014-03-26 09:52 - 02157056 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST64.exe 2014-03-26 09:52 - 2014-03-26 09:52 - 01145856 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST.exe 2014-03-26 09:52 - 2013-02-21 11:55 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-25 14:03 - 2014-02-25 10:05 - 00003238 _____ () C:\Windows\PFRO.log 2014-03-25 13:15 - 2014-02-25 10:08 - 00000000 ____D () C:\Program Files\CyberGhost 5 2014-03-25 13:03 - 2014-03-25 13:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-25 12:45 - 2013-09-20 19:18 - 00002070 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-03-25 12:43 - 2014-03-25 12:42 - 138607664 _____ () C:\Users\Tomtom\Downloads\avira_free_antivirus_de_14.0.3.350.exe 2014-03-25 12:37 - 2013-02-21 20:08 - 00000000 ____D () C:\Users\Tomtom 2014-03-25 12:36 - 2013-02-21 11:02 - 00000000 ____D () C:\Users\Ina 2014-03-25 12:36 - 2010-11-21 09:16 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-25 12:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-03-25 12:12 - 2014-03-25 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-25 12:11 - 2014-03-25 12:11 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\AppCloudUpdater 2014-03-20 09:12 - 2014-03-20 09:12 - 00000544 _____ () C:\Users\Tomtom\Downloads\vCard_frau_n._francke_2014-03-20.vcf 2014-03-20 08:53 - 2013-02-21 12:15 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-20 08:45 - 2009-07-14 06:45 - 00274464 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-12 10:10 - 2013-03-28 10:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 10:10 - 2013-03-28 10:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 10:10 - 2013-03-28 10:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-05 09:26 - 2014-03-30 19:57 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-05 09:26 - 2014-03-30 19:57 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-05 09:26 - 2014-03-25 13:03 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys Some content of TEMP: ==================== C:\Users\Ina\AppData\Local\Temp\avgnt.exe C:\Users\Ina\AppData\Local\Temp\mdm_z4_ext_94109768_2572.dll C:\Users\Ina\AppData\Local\Temp\mdm_z4_ext_94502984_3960.dll C:\Users\Ina\AppData\Local\Temp\mdm_z4_ext_96862280_3016.dll C:\Users\Ina\AppData\Local\Temp\Quarantine.exe C:\Users\Tomtom\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-18 11:22 ==================== End Of Log ============================ --- --- --- Results of screen317's Security Check version 0.99.80 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Adobe Reader XI Google Chrome 33.0.1750.146 Google Chrome 33.0.1750.154 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Moin ! Das mit dem Online check hat leider nicht geklappt ist immer wieder angehalten und hat nicht weiter gescannt warum kann ich nicht sagen ( weißt ja bin Laie ) :-$ habe es aber 3 mal probiert leider ohne ergebniss. Gruß Thomas |
01.04.2014, 22:56 | #8 |
| Avira hat ADWARE/installCore.Gen gefunden Achso ! Ausserdem macht der Rechner wenn ich den Google Chrom Browser öffnen will nicht den sondern buenosearch oder so ähnlich auf auch da weiß ich nicht warum . Hallo nochmal ! Habe mir eset heruntergeladen und ein scan durchgeführt ( hat lange gedauert ) einmal 26 funde und ein mal 2 funde wollte die logdat hier posten weiß aber nicht wie gruß Thomas FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Ina (administrator) on INA-PC on 01-04-2014 23:27:55 Running from C:\Users\Ina\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe () C:\Program Files (x86)\Vidalia Relay Bundle\Vidalia\vidalia.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-23] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKU\S-1-5-21-2501610007-4256825277-2014219784-1001\...\Run: [Vidalia] - C:\Program Files (x86)\Vidalia Relay Bundle\Vidalia\vidalia.exe [6239727 2012-12-02] () HKU\S-1-5-21-2501610007-4256825277-2014219784-1001\...\MountPoints2: {7a9a47db-9c89-11e2-94eb-705ab6893770} - F:\Startme.exe HKU\S-1-5-21-2501610007-4256825277-2014219784-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Vidalia] - C:\Program Files (x86)\Vidalia Relay Bundle\Vidalia\vidalia.exe [6239727 2012-12-02] () HKU\S-1-5-21-2501610007-4256825277-2014219784-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {7a9a47db-9c89-11e2-94eb-705ab6893770} - F:\Startme.exe Startup: C:\Users\Ina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk ShortcutTarget: Product Registration.lnk -> C:\Users\Ina\AppData\Local\Temp\is-JGTJF.tmp\ATR1.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Dell Official Site - The Power To Do More | Dell URLSearchHook: HKCU - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.) BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-04-01] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-04-01] Chrome: ======= CHR DefaultSearchKeyword: buenosearch.com CHR DefaultSearchProvider: Bueno Search CHR DefaultSearchURL: hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=566B00FFB78B0417&affID=127690&tsp=5197 CHR DefaultNewTabURL: CHR Extension: (Google Wallet) - C:\Users\Ina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-03] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-23] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-23] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-23] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-18] (Avira Operations GmbH & Co. KG) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET) U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-01] (Malwarebytes Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-01 23:27 - 2014-04-01 23:27 - 00001916 _____ () C:\Users\Ina\Desktop\tommy - Verknüpfung.lnk 2014-04-01 23:23 - 2014-04-01 23:23 - 02157056 _____ () C:\Users\Ina\Downloads\FRST64 (6).exe 2014-04-01 23:22 - 2014-04-01 23:22 - 02157056 _____ () C:\Users\Ina\Downloads\FRST64 (5).exe 2014-04-01 23:20 - 2014-04-01 23:20 - 02157056 _____ () C:\Users\Ina\Downloads\FRST64 (4).exe 2014-04-01 23:19 - 2014-04-01 23:19 - 02142536 _____ () C:\Users\Ina\Downloads\FRST64 (3).exe 2014-04-01 23:18 - 2014-04-01 23:18 - 02154152 _____ () C:\Users\Ina\Downloads\FRST64 (2).exe 2014-04-01 22:53 - 2014-04-01 22:53 - 00018634 _____ () C:\Users\Ina\Documents\tommy.xml 2014-04-01 21:38 - 2014-04-01 21:38 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\ESET 2014-04-01 21:38 - 2014-04-01 21:38 - 00000000 ____D () C:\Users\Ina\AppData\Local\ESET 2014-04-01 21:37 - 2014-04-01 21:37 - 00000000 ____D () C:\ProgramData\ESET 2014-04-01 21:37 - 2014-04-01 21:37 - 00000000 ____D () C:\Program Files\ESET 2014-04-01 21:32 - 2014-04-01 21:32 - 01581384 _____ (ESET) C:\Users\Ina\Downloads\eset_smart_security_live_installer_.exe 2014-04-01 21:14 - 2014-04-01 21:14 - 00987442 _____ () C:\Users\Ina\Downloads\SecurityCheck (1).exe 2014-04-01 21:12 - 2014-04-01 21:12 - 00001092 _____ () C:\Users\Ina\Downloads\FRST64 - Verknüpfung.lnk 2014-04-01 21:05 - 2014-04-01 21:05 - 02157056 _____ (Farbar) C:\Users\Ina\Downloads\FRST64 (1).exe 2014-04-01 20:47 - 2014-04-01 20:48 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (3).exe 2014-04-01 20:44 - 2014-04-01 20:45 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (2).exe 2014-04-01 20:38 - 2014-04-01 20:38 - 00987442 _____ () C:\Users\Ina\Downloads\SecurityCheck.exe 2014-04-01 20:15 - 2014-04-01 20:15 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (1).exe 2014-04-01 19:46 - 2014-04-01 19:46 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-01 19:45 - 2014-04-01 19:45 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu.exe 2014-03-30 21:39 - 2014-04-01 23:27 - 00007372 _____ () C:\Users\Ina\Downloads\FRST.txt 2014-03-30 21:39 - 2014-03-30 21:39 - 02157056 _____ (Farbar) C:\Users\Ina\Downloads\FRST64.exe 2014-03-30 21:05 - 2014-03-30 21:05 - 00000000 ____D () C:\Windows\ERUNT 2014-03-30 21:04 - 2014-03-30 21:05 - 01038974 _____ (Thisisu) C:\Users\Ina\Downloads\JRT.exe 2014-03-30 20:50 - 2014-03-30 21:18 - 00000000 ____D () C:\AdwCleaner 2014-03-30 20:49 - 2014-03-30 20:49 - 01950720 _____ () C:\Users\Ina\Downloads\adwcleaner.exe 2014-03-30 20:44 - 2014-03-30 20:44 - 00001142 _____ () C:\mbam.txt 2014-03-30 19:58 - 2014-04-01 23:25 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-30 19:57 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-30 19:57 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-30 19:56 - 2014-03-30 19:57 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000 (1).exe 2014-03-30 19:56 - 2014-03-30 19:56 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-26 09:55 - 2014-03-26 09:55 - 00011224 _____ () C:\Users\Tomtom\Downloads\Addition.txt 2014-03-26 09:54 - 2014-04-01 23:27 - 00000000 ____D () C:\FRST 2014-03-26 09:54 - 2014-03-30 07:43 - 00021389 _____ () C:\Users\Tomtom\Downloads\FRST.txt 2014-03-26 09:52 - 2014-03-26 09:53 - 02157056 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST64.exe 2014-03-26 09:52 - 2014-03-26 09:52 - 01145856 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST.exe 2014-03-25 13:03 - 2014-03-30 19:57 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-25 13:03 - 2014-03-25 13:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-25 13:03 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-25 12:42 - 2014-03-25 12:43 - 138607664 _____ () C:\Users\Tomtom\Downloads\avira_free_antivirus_de_14.0.3.350.exe 2014-03-25 12:22 - 2014-03-30 19:57 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-25 12:12 - 2014-03-25 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-25 12:11 - 2014-03-25 12:11 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\AppCloudUpdater 2014-03-20 09:12 - 2014-03-20 09:12 - 00000544 _____ () C:\Users\Tomtom\Downloads\vCard_frau_n._francke_2014-03-20.vcf 2014-03-16 19:51 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-16 19:51 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-16 19:51 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-16 19:51 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-16 19:51 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-16 19:51 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-16 19:51 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-16 19:51 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-16 19:51 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-16 19:51 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-16 19:51 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-16 19:51 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-16 19:51 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-16 19:51 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-16 19:51 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-16 19:51 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-16 19:51 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-16 19:51 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-16 19:51 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-16 19:51 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-16 19:51 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-16 19:51 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-16 19:51 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-16 19:51 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-16 19:51 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-16 19:51 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-16 19:51 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-16 19:51 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-16 19:51 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-16 19:51 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-16 19:51 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-16 19:51 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-16 19:51 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-16 19:51 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-16 19:51 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-16 19:51 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-16 19:51 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-16 19:51 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-16 19:51 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-16 19:51 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-16 19:51 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-16 19:51 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-16 19:51 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-16 19:50 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-16 19:50 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-01 23:28 - 2014-03-30 21:39 - 00007372 _____ () C:\Users\Ina\Downloads\FRST.txt 2014-04-01 23:27 - 2014-04-01 23:27 - 00001916 _____ () C:\Users\Ina\Desktop\tommy - Verknüpfung.lnk 2014-04-01 23:27 - 2014-03-26 09:54 - 00000000 ____D () C:\FRST 2014-04-01 23:25 - 2014-03-30 19:58 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-01 23:23 - 2014-04-01 23:23 - 02157056 _____ () C:\Users\Ina\Downloads\FRST64 (6).exe 2014-04-01 23:22 - 2014-04-01 23:22 - 02157056 _____ () C:\Users\Ina\Downloads\FRST64 (5).exe 2014-04-01 23:20 - 2014-04-01 23:20 - 02157056 _____ () C:\Users\Ina\Downloads\FRST64 (4).exe 2014-04-01 23:19 - 2014-04-01 23:19 - 02142536 _____ () C:\Users\Ina\Downloads\FRST64 (3).exe 2014-04-01 23:18 - 2014-04-01 23:18 - 02154152 _____ () C:\Users\Ina\Downloads\FRST64 (2).exe 2014-04-01 23:16 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-01 23:16 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-01 23:12 - 2013-02-21 19:52 - 01838398 _____ () C:\Windows\system32\perfh007.dat 2014-04-01 23:12 - 2013-02-21 19:52 - 00506390 _____ () C:\Windows\system32\perfc007.dat 2014-04-01 23:12 - 2009-07-14 07:13 - 00004568 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-01 23:11 - 2013-02-21 19:54 - 00000000 ____D () C:\Windows\Panther 2014-04-01 23:10 - 2013-03-28 10:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-01 23:07 - 2013-02-23 09:21 - 00000000 ____D () C:\Users\Ina\AppData\Local\Vidalia 2014-04-01 23:07 - 2013-02-21 12:15 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-01 23:07 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-01 23:06 - 2013-02-21 10:57 - 01267118 ____N () C:\Windows\WindowsUpdate.log 2014-04-01 22:53 - 2014-04-01 22:53 - 00018634 _____ () C:\Users\Ina\Documents\tommy.xml 2014-04-01 22:41 - 2013-02-21 12:15 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-01 21:38 - 2014-04-01 21:38 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\ESET 2014-04-01 21:38 - 2014-04-01 21:38 - 00000000 ____D () C:\Users\Ina\AppData\Local\ESET 2014-04-01 21:37 - 2014-04-01 21:37 - 00000000 ____D () C:\ProgramData\ESET 2014-04-01 21:37 - 2014-04-01 21:37 - 00000000 ____D () C:\Program Files\ESET 2014-04-01 21:32 - 2014-04-01 21:32 - 01581384 _____ (ESET) C:\Users\Ina\Downloads\eset_smart_security_live_installer_.exe 2014-04-01 21:14 - 2014-04-01 21:14 - 00987442 _____ () C:\Users\Ina\Downloads\SecurityCheck (1).exe 2014-04-01 21:12 - 2014-04-01 21:12 - 00001092 _____ () C:\Users\Ina\Downloads\FRST64 - Verknüpfung.lnk 2014-04-01 21:05 - 2014-04-01 21:05 - 02157056 _____ (Farbar) C:\Users\Ina\Downloads\FRST64 (1).exe 2014-04-01 20:48 - 2014-04-01 20:47 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (3).exe 2014-04-01 20:45 - 2014-04-01 20:44 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (2).exe 2014-04-01 20:38 - 2014-04-01 20:38 - 00987442 _____ () C:\Users\Ina\Downloads\SecurityCheck.exe 2014-04-01 20:15 - 2014-04-01 20:15 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu (1).exe 2014-04-01 19:46 - 2014-04-01 19:46 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-01 19:45 - 2014-04-01 19:45 - 02347384 _____ (ESET) C:\Users\Ina\Downloads\esetsmartinstaller_enu.exe 2014-03-30 21:39 - 2014-03-30 21:39 - 02157056 _____ (Farbar) C:\Users\Ina\Downloads\FRST64.exe 2014-03-30 21:18 - 2014-03-30 20:50 - 00000000 ____D () C:\AdwCleaner 2014-03-30 21:05 - 2014-03-30 21:05 - 00000000 ____D () C:\Windows\ERUNT 2014-03-30 21:05 - 2014-03-30 21:04 - 01038974 _____ (Thisisu) C:\Users\Ina\Downloads\JRT.exe 2014-03-30 20:49 - 2014-03-30 20:49 - 01950720 _____ () C:\Users\Ina\Downloads\adwcleaner.exe 2014-03-30 20:44 - 2014-03-30 20:44 - 00001142 _____ () C:\mbam.txt 2014-03-30 19:57 - 2014-03-30 19:56 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000 (1).exe 2014-03-30 19:57 - 2014-03-25 13:03 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-30 19:57 - 2014-03-25 12:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-30 19:57 - 2013-04-05 08:44 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\Malwarebytes 2014-03-30 19:57 - 2013-04-05 08:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-30 19:56 - 2014-03-30 19:56 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-30 07:43 - 2014-03-26 09:54 - 00021389 _____ () C:\Users\Tomtom\Downloads\FRST.txt 2014-03-26 09:55 - 2014-03-26 09:55 - 00011224 _____ () C:\Users\Tomtom\Downloads\Addition.txt 2014-03-26 09:54 - 2013-09-20 20:35 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-26 09:53 - 2014-03-26 09:52 - 02157056 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST64.exe 2014-03-26 09:52 - 2014-03-26 09:52 - 01145856 _____ (Farbar) C:\Users\Tomtom\Downloads\FRST.exe 2014-03-26 09:52 - 2013-02-21 11:55 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-25 13:15 - 2014-02-25 10:08 - 00000000 ____D () C:\Program Files\CyberGhost 5 2014-03-25 13:03 - 2014-03-25 13:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomtom\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-25 12:45 - 2013-09-20 19:18 - 00002070 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-03-25 12:43 - 2014-03-25 12:42 - 138607664 _____ () C:\Users\Tomtom\Downloads\avira_free_antivirus_de_14.0.3.350.exe 2014-03-25 12:37 - 2013-02-21 20:08 - 00000000 ____D () C:\Users\Tomtom 2014-03-25 12:36 - 2013-02-21 11:02 - 00000000 ____D () C:\Users\Ina 2014-03-25 12:36 - 2010-11-21 09:16 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-25 12:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-03-25 12:12 - 2014-03-25 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-25 12:11 - 2014-03-25 12:11 - 00000000 ____D () C:\Users\Ina\AppData\Roaming\AppCloudUpdater 2014-03-20 09:12 - 2014-03-20 09:12 - 00000544 _____ () C:\Users\Tomtom\Downloads\vCard_frau_n._francke_2014-03-20.vcf 2014-03-20 08:53 - 2013-02-21 12:15 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-20 08:45 - 2009-07-14 06:45 - 00274464 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-12 10:10 - 2013-03-28 10:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 10:10 - 2013-03-28 10:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 10:10 - 2013-03-28 10:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-05 09:26 - 2014-03-30 19:57 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-05 09:26 - 2014-03-30 19:57 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-05 09:26 - 2014-03-25 13:03 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys Some content of TEMP: ==================== C:\Users\Ina\AppData\Local\Temp\avgnt.exe C:\Users\Ina\AppData\Local\Temp\InstHelper.exe C:\Users\Tomtom\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-18 11:22 ==================== End Of Log ============================ --- --- --- --- --- --- hier nochmal das aktuellste FRST Log ! <?xml version="1.0" encoding="UTF-8"?> -<ESET> -<LOG> -<RECORD> <COLUMN NAME="Log">Log</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">Version der Signaturdatenbank: 9623 (20140401)</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">Datum: 01.04.2014 Uhrzeit: 21:58:06</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">Geprüfte Laufwerke, Ordner und Dateien: C:\</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\hiberfil.sys - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\pagefile.sys - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Boot\BCD - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Boot\BCD.LOG - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Avira\AntiVir Desktop\TEMP\scaninfo(1460).tmp - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-18-0-ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-18-0-ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-18-0-ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-19-0-ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-19-0-ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-19-0-ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-20-0-ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-20-0-ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-20-0-ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1001-0-ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1001-0-ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1001-0-ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1003-0-ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1003-0-ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1003-0-ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\Syscache.hve - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\Syscache.hve.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\Syscache.hve.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{1b0550a2-affb-11e3-918e-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{1b0550a3-affb-11e3-918e-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{1b055112-affb-11e3-918e-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{38b96313-b400-11e3-bfb7-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{38b96336-b400-11e3-bfb7-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{3a18ca5c-ad32-11e3-bd12-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{3a18cad8-ad32-11e3-bd12-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{3a18cb24-ad32-11e3-bd12-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863ef2-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863f1f-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863f23-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863f4c-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863f59-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863f5a-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863f69-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863f6b-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863f6c-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863f6d-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{61863f6f-b409-11e3-8746-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{72137f26-a2ed-11e3-9b43-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{72137f4d-a2ed-11e3-9b43-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{75d324d2-b403-11e3-ae9e-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{8471efcb-9df3-11e3-bd7f-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{8471efeb-9df3-11e3-bd7f-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{8471f008-9df3-11e3-bd7f-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{a77be5cf-a9bb-11e3-af44-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{cbe915f4-b833-11e3-87e1-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\System Volume Information\{e986999e-b4ba-11e3-8fa0-705ab6893770}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Avira\AntiVir Desktop\TEMP\scaninfo(1460).tmp - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-18-0-ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-18-0-ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-18-0-ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-19-0-ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-19-0-ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-19-0-ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-20-0-ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-20-0-ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-20-0-ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1001-0-ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1001-0-ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1001-0-ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1003-0-ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1003-0-ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Malwarebytes\ Malwarebytes Anti-Malware \S-1-5-21-2501610007-4256825277-2014219784-1003-0-ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\MSS.log - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\ntuser.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\ntuser.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\ntuser.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\AppData\Local\Microsoft\Windows\UsrClass.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\AppData\Local\Microsoft\Windows\WebCacheLock.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\AppData\Local\Microsoft\Windows\WebCache\V01.log - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.tmp - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\Downloads\zafwSetupWeb_110_000_057 (1).exe = ZIP = CUninstallerZA.exe = NSIS = Script.nsi - Win32/Toolbar.Conduit evtl. unerwünschte Anwendung</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\Downloads\zafwSetupWeb_110_000_057.exe = ZIP = CUninstallerZA.exe = NSIS = Script.nsi - Win32/Toolbar.Conduit evtl. unerwünschte Anwendung</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2 - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\System32\catroot2\edb.log - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - Fehler beim Öffnen [4]</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\Downloads\zafwSetupWeb_110_000_057 (1).exe = ZIP = CUninstallerZA.exe = NSIS = Script.nsi - Win32/Toolbar.Conduit evtl. unerwünschte Anwendung - war Teil des gelöschten Objekts</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">C:\Users\Ina\Downloads\zafwSetupWeb_110_000_057.exe = ZIP = CUninstallerZA.exe = NSIS = Script.nsi - Win32/Toolbar.Conduit evtl. unerwünschte Anwendung - war Teil des gelöschten Objekts</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">Geprüfte Objekte: 89996</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">Erkannte Bedrohungen: 2</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">Anzahl gesäuberter Objekte: 2</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">Abgeschlossen: 22:49:48 Benötigte Zeit: 3102 Sek. (00:51:42)</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log"/> </RECORD> -<RECORD> <COLUMN NAME="Log">Hinweise:</COLUMN> </RECORD> -<RECORD> <COLUMN NAME="Log">[4] Objekt kann nicht geöffnet werden. Möglicherweise in Benutzung durch eine andere Anwendung oder das Betriebssystem.</COLUMN> </RECORD> </LOG> </ESET> |
02.04.2014, 13:58 | #9 |
/// the machine /// TB-Ausbilder | Avira hat ADWARE/installCore.Gen gefunden Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Startup: C:\Users\Ina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk ShortcutTarget: Product Registration.lnk -> C:\Users\Ina\AppData\Local\Temp\is-JGTJF.tmp\ATR1.exe (No File) Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.google.com/chrome/answer/3296214?hl=de
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.04.2014, 20:18 | #10 |
| Avira hat ADWARE/installCore.Gen gefunden Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by Ina at 2014-04-04 21:14:46 Run:1 Running from C:\Users\Ina\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Startup: C:\Users\Ina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk ShortcutTarget: Product Registration.lnk -> C:\Users\Ina\AppData\Local\Temp\is-JGTJF.tmp\ATR1.exe (No File) ***************** C:\Users\Ina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk => Moved successfully. C:\Users\Ina\AppData\Local\Temp\is-JGTJF.tmp\ATR1.exe not found. ==== End of Fixlog ==== War das richtig so ?? Gruß |
05.04.2014, 11:04 | #11 |
/// the machine /// TB-Ausbilder | Avira hat ADWARE/installCore.Gen gefunden Ja Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.04.2014, 22:11 | #12 |
| Avira hat ADWARE/installCore.Gen gefunden Moin ! das mit defogger und Combofix habe ich nicht ganz verstanden ! wo finde ich das denn ob defogger oder Combfix ??? hab irgendwie keine ahnung ! Gruß Thomas |
06.04.2014, 15:54 | #13 |
/// the machine /// TB-Ausbilder | Avira hat ADWARE/installCore.Gen gefunden Haben wir nicht benutzt, mach gleich Delfix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.04.2014, 19:09 | #14 |
| Avira hat ADWARE/installCore.Gen gefunden Moin ! Hab ich gemacht !! Hoffe jetzt geht wider alles . Vielen Dank nochmal . Gruß Thomas |
07.04.2014, 13:50 | #15 |
/// the machine /// TB-Ausbilder | Avira hat ADWARE/installCore.Gen gefunden Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Avira hat ADWARE/installCore.Gen gefunden |
adware/insatallcore.gen, adware/installcore.gen, ahnung, avira, browser, datei, gefunde, google, probleme, quara, quarantäne, systemscan, win32/toolbar.conduit, zusammen, öffnen |