|
Plagegeister aller Art und deren Bekämpfung: Default-SearchWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
27.03.2014, 08:08 | #1 |
| Default-Search hallo...seid kurzen öffnet sich bei mir eine 2.seite wenn ich firefox öffne die sich Default-Search nennt...ich bekomme sie einfach nicht mehr weg..sie scheint sich im hintergrund eingenistet zu haben als ich mir von web.de den mail-check draufgemacht habe...diesen hab ich sofort wieder gelöscht...habe kasperky drauf aber das zeigt mir keinen virenbefall an...merke jedoch das da was nicht stimmt...kann mir da wer helfen?...habe windows 7 drauf gruß paula |
27.03.2014, 08:38 | #2 |
/// the machine /// TB-Ausbilder | Default-Search hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
27.03.2014, 10:18 | #3 |
| Default-SearchCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014 01 Ran by katrin at 2014-03-27 10:12:37 Running from C:\Users\katrin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Anti-Virus (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Anti-Virus (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.) ANNO 2070 (HKLM\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft) CCleaner (HKLM\...\CCleaner) (Version: 4.09 - Piriform) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden ICQ 8.2 (build 6901) (HKCU\...\ICQ) (Version: 8.2.6901.0 - ICQ) Kaspersky Anti-Virus (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Anti-Virus (Version: 14.0.0.4651 - Kaspersky Lab) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 27.0 (x86 de) (HKLM\...\Mozilla Firefox 27.0 (x86 de)) (Version: 27.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0 - Mozilla) Need For Speed™ World (HKLM\...\{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1) (Version: 1.0.0.659 - Electronic Arts) NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.82 - NVIDIA Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.142.992 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (Version: 9.13.0725 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation) NVIDIA ShadowPlay 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.3182 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.82 (Version: 331.82 - NVIDIA Corporation) Hidden NVIDIA Update 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 10.11.15 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.19 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.19 - NVIDIA Corporation) OpenOffice 4.0.1 (HKLM\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5859 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Settings Manager (HKLM\...\Settings Manager) (Version: 5.0.0.11471 - Aztec Media Inc.) SHIELD Streaming (Version: 1.6.85 - NVIDIA Corporation) Hidden Skype™ 6.14 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Ubisoft Game Launcher (HKLM\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) VideoPlayer v2.0.6 (HKLM\...\VideoPlayer) (Version: v2.0.6 - TUGUU SL) <==== ATTENTION ==================== Restore Points ========================= 18-03-2014 02:00:12 Windows Update 20-03-2014 08:05:24 Revo Uninstaller's restore point - Linkey 20-03-2014 08:08:12 Revo Uninstaller's restore point - Securita Scout 20-03-2014 23:20:44 Installed SpyHunter 20-03-2014 23:54:47 Revo Uninstaller's restore point - SpyHunter 20-03-2014 23:55:10 Removed SpyHunter 26-03-2014 17:15:27 Installed SpyHunter 26-03-2014 17:20:38 Revo Uninstaller's restore point - SpyHunter 26-03-2014 17:21:07 Removed SpyHunter ==================== Hosts content: ========================== 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {024A6D31-8AC3-4700-A6CE-3BB741BA8EE0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd) Task: {7ACAE2E0-B6EF-4E6E-9DD7-0AF61F30C9EE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-26] (Adobe Systems Incorporated) Task: {CA99E34A-F4CC-4CD6-9EF2-284F62004770} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2014-03-19 07:33 - 2014-02-06 11:11 - 00485904 _____ () c:\program files\settings manager\systemk\sysapcrt.dll 2013-12-20 00:28 - 2013-11-11 15:26 - 00092448 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\kpcengine.2.3.dll 2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\dblite.dll 2014-03-19 07:33 - 2014-02-06 11:11 - 00019984 _____ () c:\program files\settings manager\systemk\syskldr.dll 2014-03-19 07:33 - 2014-02-06 11:11 - 00019984 _____ () C:\Program Files\Settings Manager\systemk\syskldr.dll 2014-01-03 16:19 - 2014-01-03 16:19 - 00857944 _____ () C:\Users\katrin\AppData\Roaming\ICQM\ICQ\dll\YLUSBTEL.dll 2014-01-08 02:43 - 2014-01-28 07:54 - 03583600 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-03-11 20:12 - 2014-03-26 15:14 - 16276872 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:373E1720 ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/27/2014 06:41:36 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/26/2014 09:40:57 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/26/2014 06:41:54 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/26/2014 06:40:20 AM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (03/26/2014 06:40:20 AM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (03/26/2014 06:40:20 AM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (03/25/2014 09:05:08 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/25/2014 07:47:47 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/24/2014 06:42:36 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/23/2014 10:24:54 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (03/27/2014 06:39:52 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SpyHunter 4 Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (03/26/2014 10:01:58 PM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (03/26/2014 09:39:15 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SpyHunter 4 Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (03/20/2014 02:29:15 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (03/19/2014 07:33:33 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Systemk Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (03/19/2014 07:32:57 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "BUP Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (03/19/2014 06:46:33 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/19/2014 06:46:33 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (03/19/2014 06:46:33 AM) (Source: DCOM) (User: ) Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (03/16/2014 03:15:49 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Microsoft Office Sessions: ========================= Error: (03/27/2014 06:41:36 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/26/2014 09:40:57 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/26/2014 06:41:54 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/26/2014 06:40:20 AM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (03/26/2014 06:40:20 AM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (03/26/2014 06:40:20 AM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (03/25/2014 09:05:08 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/25/2014 07:47:47 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/24/2014 06:42:36 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/23/2014 10:24:54 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2014-03-27 09:23:56.667 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-27 09:23:56.664 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-27 09:23:56.661 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-27 09:23:56.655 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-27 09:23:56.652 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-27 09:23:56.641 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-27 09:23:56.615 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-27 09:23:56.613 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-27 09:23:56.610 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-27 09:23:56.603 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 56% Total physical RAM: 2047.18 MB Available physical RAM: 893.79 MB Total Pagefile: 4094.35 MB Available Pagefile: 2209.42 MB Total Virtual: 2047.88 MB Available Virtual: 1898.38 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:232.79 GB) (Free:186.67 GB) NTFS Drive d: () (Fixed) (Total:149.05 GB) (Free:132.86 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: DCBADCBA) Partition: GPT Partition Type. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: C5E8C5E8) Partition: GPT Partition Type. ==================== End Of Log ============================ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 Ran by katrin (administrator) on KATRIN-PC on 27-03-2014 10:12:01 Running from C:\Users\katrin\Downloads Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Aztec Media Inc.) C:\Program Files\Settings Manager\systemk\SystemkService.exe (Aztec Media Inc.) C:\Program Files\Settings Manager\systemk\SystemkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (Aztec Media Inc.) C:\Program Files\Settings Manager\systemk\systemku.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe (ICQ) C:\Users\katrin\AppData\Roaming\ICQM\icq.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\klwtblfs.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7514656 2009-05-22] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-05-22] (Realtek Semiconductor Corp.) HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap.dll [982232 2013-12-10] (NVIDIA Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [NvBackend] - C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation) HKU\S-1-5-21-430205881-583344909-559689374-1000\...\Run: [icq] - C:\Users\katrin\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-03] (ICQ) HKU\S-1-5-21-430205881-583344909-559689374-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) AppInit_DLLs: C:\PROGRA~1\SETTIN~1\systemk\syskldr.dll => C:\Program Files\Settings Manager\systemk\syskldr.dll [19984 2014-02-06] () HKLM\...\AppCertDlls: [x64] -> c:\program files\settings manager\systemk\x64\sysapcrt.dll HKLM\...\AppCertDlls: [x86] -> c:\program files\settings manager\systemk\sysapcrt.dll [485904 2014-02-06] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x80E8E03300FDCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=291&src=ds&p={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=291&src=ds&p={searchTerms} BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default FF DefaultSearchEngine: Google FF SearchEngineOrder.1: default-search.net FF SelectedSearchEngine: Google FF Homepage: https://apps.facebook.com/forbiddengarden/?fb_source=bookmark|hxxp://www.default-search.net/?sid=476&aid=122&itype=n&ver=11471&tm=291&src=bar FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\katrin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\default-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Settings Manager - C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\Extensions\{19D73812-1701-1B61-CBA2-12A70C87A0B0} [2014-03-19] FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com [2014-03-26] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-03-26] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com [2014-03-26] ========================== Services (Whitelisted) ================= R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14658848 2013-12-10] (NVIDIA Corporation) R2 SystemkService; C:\Program Files\Settings Manager\systemk\SystemkService.exe [3448848 2014-02-06] (Aztec Media Inc.) S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X] S2 SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [X] ==================== Drivers (Whitelisted) ==================== R3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [278528 2011-10-24] (AVEO) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] () R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-03-26] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [94304 2014-03-26] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-03-26] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-03-26] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-03-26] (Kaspersky Lab ZAO) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-05] (NVIDIA Corporation) S3 athr; system32\DRIVERS\athr.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-27 10:12 - 2014-03-27 10:12 - 00011350 _____ () C:\Users\katrin\Downloads\FRST.txt 2014-03-27 10:11 - 2014-03-27 10:12 - 00000000 ____D () C:\FRST 2014-03-27 10:10 - 2014-03-27 10:11 - 01145856 _____ (Farbar) C:\Users\katrin\Downloads\FRST.exe 2014-03-27 00:29 - 2014-03-27 01:07 - 1163986772 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-22_2015_68681.avi 2014-03-27 00:29 - 2014-03-27 00:53 - 605594990 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Familienbande_2014-03-24_2015_68681.avi 2014-03-26 21:51 - 2014-03-26 21:51 - 00001059 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-03-26 21:50 - 2014-03-27 08:56 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-03-26 21:50 - 2014-03-26 22:01 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-03-26 21:50 - 2014-03-26 22:01 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-03-26 21:39 - 2014-03-27 06:40 - 00000336 _____ () C:\Windows\setupact.log 2014-03-26 21:39 - 2014-03-27 06:39 - 00001106 _____ () C:\Windows\PFRO.log 2014-03-26 21:39 - 2014-03-26 21:39 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-26 18:23 - 2014-03-26 18:31 - 243681088 _____ () C:\Users\katrin\Downloads\kav14.0.0.4651abDE_5154.exe 2014-03-26 18:15 - 2014-03-26 18:15 - 00000000 ____D () C:\sh4ldr 2014-03-26 18:13 - 2014-03-26 18:13 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\katrin\Downloads\SpyHunter-Installer.exe 2014-03-25 00:03 - 2014-03-25 00:03 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-03-24 23:54 - 2014-03-24 23:54 - 00001087 _____ () C:\Users\katrin\Desktop\USB2.0 Camera - Verknüpfung.lnk 2014-03-21 19:48 - 2014-03-21 20:59 - 847036712 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Mhysa_Folge30_2014-03-16_2320_68681.avi 2014-03-21 19:48 - 2014-03-21 20:32 - 654863488 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_13_Prozent_2014-03-17_2015_68681.avi 2014-03-21 19:47 - 2014-03-21 20:59 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681(1).avi 2014-03-21 19:47 - 2014-03-21 20:52 - 690707840 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Regen_von_Castamaer_Folge29_2014-03-16_2220_68681.avi 2014-03-21 01:06 - 2014-03-21 01:06 - 00000000 ____D () C:\Users\katrin\Downloads\backups 2014-03-21 01:04 - 2014-03-21 01:04 - 00004313 _____ () C:\Users\katrin\Downloads\hijackthis.log 2014-03-21 01:03 - 2014-03-21 01:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\katrin\Downloads\hijackthis_5833.exe 2014-03-20 20:49 - 2014-03-20 20:49 - 00000105 ____H () C:\Users\katrin\Desktop\.~lock.sicher pw.xls# 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\.mono 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\ProgramData\.mono 2014-03-19 07:33 - 2014-03-27 10:12 - 00000000 ____D () C:\ProgramData\systemk 2014-03-19 07:33 - 2014-03-19 07:33 - 00000000 ____D () C:\Program Files\Settings Manager 2014-03-19 07:26 - 2014-03-19 07:26 - 00648240 _____ (Unity Technologies ApS) C:\Users\katrin\Desktop\UnityWebPlayer_4_2_1_0.exe 2014-03-19 07:05 - 2014-03-19 07:05 - 00389472 _____ (Softonic ) C:\Users\katrin\Downloads\SoftonicDownloader_fuer_unity-web-player.exe 2014-03-18 06:22 - 2014-03-26 22:06 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ___RD () C:\Program Files\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Users\katrin\AppData\Local\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-03-18 00:03 - 2014-03-25 09:34 - 00614400 _____ () C:\Windows\system32\Image20.dat 2014-03-16 18:24 - 2014-03-16 19:04 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681.avi 2014-03-16 18:23 - 2014-03-16 18:52 - 654864400 _____ () C:\Users\katrin\Downloads\Vampire_Diaries_Amara_2014-03-13_2015_68681.avi 2014-03-12 20:46 - 2014-03-12 22:10 - 653618416 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Ein_unvergesslicher_Abend_2014-03-10_2015_68681.avi 2014-03-12 20:45 - 2014-03-12 22:31 - 1158218112 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-08_2015_68681.avi 2014-03-12 20:45 - 2014-03-12 22:27 - 790724896 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Baer_und_die_Jungfrau_hehr_Folge27_2014-03-09_2220_68681.avi 2014-03-12 20:45 - 2014-03-12 22:26 - 762285704 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Die_Zweitgeborenen_Folge28_2014-03-09_2330_68681.avi 2014-03-12 20:45 - 2014-03-12 21:32 - 232655938 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Candace_im_Unglueck_Folge67_2014-03-08_1845_68681.avi 2014-03-12 20:44 - 2014-03-12 21:36 - 381282758 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Teamwork_Folge106_2014-03-08_1820_68681.avi 2014-03-12 20:44 - 2014-03-12 21:21 - 278627650 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Superhelden_Folge41_2014-03-08_1535_68681.avi 2014-03-12 20:43 - 2014-03-12 21:59 - 576686134 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Mission_Marvel_2014-03-08_1550_68681.avi 2014-03-12 20:43 - 2014-03-12 21:29 - 241351188 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Fisch_Phin_Ferb_Folge46_2014-03-08_1635_68681.avi 2014-03-12 06:55 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-12 06:55 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-12 06:55 - 2014-03-01 05:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-12 06:55 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-12 06:55 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-12 06:55 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-12 06:55 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-12 06:55 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-12 06:55 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-12 06:55 - 2014-03-01 04:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-12 06:55 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-12 06:55 - 2014-03-01 04:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-12 06:55 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-12 06:55 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-12 06:55 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-12 06:55 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-12 06:55 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-12 06:55 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-12 06:55 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-12 06:55 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-12 06:54 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-12 06:54 - 2014-03-01 04:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-12 06:54 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-12 06:54 - 2014-02-07 02:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-12 06:54 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-12 06:54 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-12 06:54 - 2014-01-28 03:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll ==================== One Month Modified Files and Folders ======= 2014-03-27 10:12 - 2014-03-27 10:12 - 00011350 _____ () C:\Users\katrin\Downloads\FRST.txt 2014-03-27 10:12 - 2014-03-27 10:11 - 00000000 ____D () C:\FRST 2014-03-27 10:12 - 2014-03-19 07:33 - 00000000 ____D () C:\ProgramData\systemk 2014-03-27 10:12 - 2013-12-19 22:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-27 10:11 - 2014-03-27 10:10 - 01145856 _____ (Farbar) C:\Users\katrin\Downloads\FRST.exe 2014-03-27 09:57 - 2013-12-20 01:16 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\Skype 2014-03-27 08:56 - 2014-03-26 21:50 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-03-27 06:47 - 2009-07-14 05:34 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-27 06:47 - 2009-07-14 05:34 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-27 06:43 - 2013-12-19 22:16 - 01292630 _____ () C:\Windows\WindowsUpdate.log 2014-03-27 06:40 - 2014-03-26 21:39 - 00000336 _____ () C:\Windows\setupact.log 2014-03-27 06:39 - 2014-03-26 21:39 - 00001106 _____ () C:\Windows\PFRO.log 2014-03-27 06:39 - 2013-12-19 22:44 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-03-27 06:39 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-27 01:07 - 2014-03-27 00:29 - 1163986772 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-22_2015_68681.avi 2014-03-27 00:53 - 2014-03-27 00:29 - 605594990 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Familienbande_2014-03-24_2015_68681.avi 2014-03-26 22:06 - 2014-03-18 06:22 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-26 22:06 - 2013-12-20 01:16 - 00000000 ____D () C:\ProgramData\Skype 2014-03-26 22:01 - 2014-03-26 21:50 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-03-26 22:01 - 2014-03-26 21:50 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-03-26 22:01 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2014-03-26 22:01 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2014-03-26 22:01 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2014-03-26 21:51 - 2014-03-26 21:51 - 00001059 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-03-26 21:39 - 2014-03-26 21:39 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-26 18:31 - 2014-03-26 18:23 - 243681088 _____ () C:\Users\katrin\Downloads\kav14.0.0.4651abDE_5154.exe 2014-03-26 18:16 - 2014-01-26 02:26 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP 2014-03-26 18:15 - 2014-03-26 18:15 - 00000000 ____D () C:\sh4ldr 2014-03-26 18:15 - 2014-01-26 02:26 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-03-26 18:13 - 2014-03-26 18:13 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\katrin\Downloads\SpyHunter-Installer.exe 2014-03-26 15:14 - 2013-12-19 22:22 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-03-26 15:14 - 2013-12-19 22:22 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-03-26 15:14 - 2013-12-19 22:21 - 00000000 ____D () C:\Users\katrin\AppData\Local\Adobe 2014-03-25 09:34 - 2014-03-18 00:03 - 00614400 _____ () C:\Windows\system32\Image20.dat 2014-03-25 00:17 - 2013-12-20 12:20 - 00000000 ____D () C:\Users\katrin\AppData\Local\Unity 2014-03-25 00:03 - 2014-03-25 00:03 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-03-24 23:54 - 2014-03-24 23:54 - 00001087 _____ () C:\Users\katrin\Desktop\USB2.0 Camera - Verknüpfung.lnk 2014-03-21 20:59 - 2014-03-21 19:48 - 847036712 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Mhysa_Folge30_2014-03-16_2320_68681.avi 2014-03-21 20:59 - 2014-03-21 19:47 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681(1).avi 2014-03-21 20:52 - 2014-03-21 19:47 - 690707840 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Regen_von_Castamaer_Folge29_2014-03-16_2220_68681.avi 2014-03-21 20:32 - 2014-03-21 19:48 - 654863488 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_13_Prozent_2014-03-17_2015_68681.avi 2014-03-21 01:06 - 2014-03-21 01:06 - 00000000 ____D () C:\Users\katrin\Downloads\backups 2014-03-21 01:04 - 2014-03-21 01:04 - 00004313 _____ () C:\Users\katrin\Downloads\hijackthis.log 2014-03-21 01:04 - 2013-12-19 22:18 - 00000000 ____D () C:\Users\katrin\AppData\Local\VirtualStore 2014-03-21 01:03 - 2014-03-21 01:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\katrin\Downloads\hijackthis_5833.exe 2014-03-20 20:54 - 2014-01-26 03:09 - 00000000 ____D () C:\AdwCleaner 2014-03-20 20:49 - 2014-03-20 20:49 - 00000105 ____H () C:\Users\katrin\Desktop\.~lock.sicher pw.xls# 2014-03-20 06:47 - 2014-01-08 02:43 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-03-19 09:41 - 2014-01-08 02:43 - 00001101 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-19 09:41 - 2013-12-20 00:45 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\.mono 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\ProgramData\.mono 2014-03-19 07:33 - 2014-03-19 07:33 - 00000000 ____D () C:\Program Files\Settings Manager 2014-03-19 07:26 - 2014-03-19 07:26 - 00648240 _____ (Unity Technologies ApS) C:\Users\katrin\Desktop\UnityWebPlayer_4_2_1_0.exe 2014-03-19 07:24 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-03-19 07:05 - 2014-03-19 07:05 - 00389472 _____ (Softonic ) C:\Users\katrin\Downloads\SoftonicDownloader_fuer_unity-web-player.exe 2014-03-18 21:56 - 2011-04-12 02:38 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ___RD () C:\Program Files\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Users\katrin\AppData\Local\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-03-18 03:02 - 2013-12-19 23:35 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-18 03:00 - 2012-01-10 21:50 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-16 19:04 - 2014-03-16 18:24 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681.avi 2014-03-16 18:52 - 2014-03-16 18:23 - 654864400 _____ () C:\Users\katrin\Downloads\Vampire_Diaries_Amara_2014-03-13_2015_68681.avi 2014-03-13 06:38 - 2009-07-14 05:33 - 00295816 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-12 22:31 - 2014-03-12 20:45 - 1158218112 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-08_2015_68681.avi 2014-03-12 22:27 - 2014-03-12 20:45 - 790724896 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Baer_und_die_Jungfrau_hehr_Folge27_2014-03-09_2220_68681.avi 2014-03-12 22:26 - 2014-03-12 20:45 - 762285704 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Die_Zweitgeborenen_Folge28_2014-03-09_2330_68681.avi 2014-03-12 22:10 - 2014-03-12 20:46 - 653618416 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Ein_unvergesslicher_Abend_2014-03-10_2015_68681.avi 2014-03-12 21:59 - 2014-03-12 20:43 - 576686134 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Mission_Marvel_2014-03-08_1550_68681.avi 2014-03-12 21:36 - 2014-03-12 20:44 - 381282758 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Teamwork_Folge106_2014-03-08_1820_68681.avi 2014-03-12 21:32 - 2014-03-12 20:45 - 232655938 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Candace_im_Unglueck_Folge67_2014-03-08_1845_68681.avi 2014-03-12 21:29 - 2014-03-12 20:43 - 241351188 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Fisch_Phin_Ferb_Folge46_2014-03-08_1635_68681.avi 2014-03-12 21:21 - 2014-03-12 20:44 - 278627650 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Superhelden_Folge41_2014-03-08_1535_68681.avi 2014-03-01 05:30 - 2014-03-12 06:55 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 05:11 - 2014-03-12 06:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 05:10 - 2014-03-12 06:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 04:52 - 2014-03-12 06:54 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 04:51 - 2014-03-12 06:55 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 04:47 - 2014-03-12 06:55 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 04:43 - 2014-03-12 06:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 04:43 - 2014-03-12 06:55 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 04:40 - 2014-03-12 06:55 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 04:38 - 2014-03-12 06:55 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 04:38 - 2014-03-12 06:55 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 04:37 - 2014-03-12 06:55 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 04:31 - 2014-03-12 06:55 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 04:25 - 2014-03-12 06:54 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 04:16 - 2014-03-12 06:55 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 04:14 - 2014-03-12 06:55 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 04:03 - 2014-03-12 06:55 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 04:00 - 2014-03-12 06:55 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 03:57 - 2014-03-12 06:54 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 03:32 - 2014-03-12 06:55 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 03:27 - 2014-03-12 06:55 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 03:25 - 2014-03-12 06:55 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-27 11:03 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-02-27 03:04 - 2010-11-20 22:01 - 01593956 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-26 09:30 - 2009-07-14 05:53 - 00032634 _____ () C:\Windows\Tasks\SCHEDLGU.TXT Some content of TEMP: ==================== C:\Users\katrin\AppData\Local\Temp\avgnt.exe C:\Users\katrin\AppData\Local\Temp\SHSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-20 09:49 ==================== End Of Log ============================ --- --- --- |
28.03.2014, 08:53 | #4 |
/// the machine /// TB-Ausbilder | Default-Search Revo Uninstaller - Download - Filepony Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION Mit Revo auch Moderat die Reste entfernen lassen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.03.2014, 12:22 | #5 |
| Default-Search hallo schrauber... Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 28.03.2014 Suchlauf-Zeit: 09:31:56 Logdatei: mbam.txt Administrator: Ja Version: 2.00.0.1000 Malware Datenbank: v2014.03.28.03 Rootkit Datenbank: v2014.03.27.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: katrin Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 211657 Verstrichene Zeit: 9 Min, 47 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 3 PUP.Optional.SystemK.A, C:\Program Files\Settings Manager\systemk\systemku.exe, 2412, Löschen bei Neustart, [b6ed73952754a393c3a06cf64ab715eb] PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\SystemkService.exe, 2308, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8] PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\SystemkService.exe, 2388, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8] Module: 26 PUP.Optional.SystemK.A, C:\Program Files\Settings Manager\systemk\systemk.dll, Löschen bei Neustart, [158e28e0611a0d293f244022f20f33cd], PUP.Optional.SystemK.A, C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\extensions\{19D73812-1701-1B61-CBA2-12A70C87A0B0}\components\SystemKHlpFF27.dll, Löschen bei Neustart, [b7ec33d597e4270f78eb72f045bc1ce4], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\syskldr.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\syskldr.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\syskldr.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], Registrierungsschlüssel: 13 PUP.Optional.Linkey.A, HKU\S-1-5-21-430205881-583344909-559689374-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, In Quarantäne, [4b58e12780fbbc7a7011947149b9837d], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\SYSTEMK\General, In Quarantäne, [eab9c04893e841f519af4c0a4cb6e11f], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\SYSTEMK, In Quarantäne, [8a1931d7e39871c58841094d7f834bb5], PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-5.5, In Quarantäne, [485bbd4b641744f2074a2334bc466a96], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\SettingsManagerIEHelper.DNSGuard, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\SettingsManagerIEHelper.DNSGuard.1, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, HKU\S-1-5-21-430205881-583344909-559689374-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{54739D49-AC03-4C57-9264-C5195596B3A1}, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\CLSID\{E1842850-FB16-4471-B327-7343FBAED55C}, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{93D511B5-143B-4A99-ABFC-B5B78AD0AE1B}, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{AA760BA8-5862-4BC5-9263-4452CBC0B264}, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SystemkService, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Settings Manager, In Quarantäne, [059e4dbbf9821b1beaa982d3f50d28d8], Registrierungswerte: 1 PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\SYSTEMK|browser, ie ff cr, In Quarantäne, [8a1931d7e39871c58841094d7f834bb5] Registrierungsdaten: 1 PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~1\SETTIN~1\systemk\syskldr.dll , Gut: (), Schlecht: (C:\PROGRA~1\SETTIN~1\systemk\syskldr.dll),Ersetzt,[059e4dbbf9821b1beaa982d3f50d28d8] Ordner: 1 PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], Dateien: 14 PUP.Optional.SystemK.A, C:\Program Files\Settings Manager\systemk\systemku.exe, Löschen bei Neustart, [b6ed73952754a393c3a06cf64ab715eb], PUP.Optional.SystemK.A, C:\Program Files\Settings Manager\systemk\systemk.dll, Löschen bei Neustart, [158e28e0611a0d293f244022f20f33cd], PUP.Optional.SystemK.A, C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\extensions\{19D73812-1701-1B61-CBA2-12A70C87A0B0}\components\SystemKHlpFF27.dll, Löschen bei Neustart, [b7ec33d597e4270f78eb72f045bc1ce4], PUP.Optional.Softonic.A, C:\Users\katrin\Downloads\SoftonicDownloader_fuer_unity-web-player.exe, In Quarantäne, [9c0717f1ff7ce5514b29bc5b04fdc23e], PUP.Optional.DefaultSearch.A, C:\Program Files\Mozilla Firefox\browser\searchplugins\default-search.xml, In Quarantäne, [7a2914f473088bab8a3477df2cd69d63], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\favicon.ico, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\Helper.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\Internet Explorer Settings.exe, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\sysapcrt.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\syskldr.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\syskldr_u.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\systemkbho.dll, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\SystemkService.exe, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], PUP.Optional.SettingsManager.A, C:\Program Files\Settings Manager\systemk\Uninstall.exe, Löschen bei Neustart, [059e4dbbf9821b1beaa982d3f50d28d8], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.022 - Bericht erstellt am 28/03/2014 um 09:44:57 # Aktualisiert 13/03/2014 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits) # Benutzername : katrin - KATRIN-PC # Gestartet von : C:\Users\katrin\Downloads\adwcleaner(1).exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Windows\System32\Tasks\SpyHunter4Startup ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\SpyHunter4Startup Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA99E34A-F4CC-4CD6-9EF2-284F62004770} Wert Gefunden : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64] Wert Gefunden : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86] Wert Gefunden : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64] Wert Gefunden : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86] Wert Gefunden : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64] Wert Gefunden : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x86] ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v27.0 (de) [ Datei : C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\prefs.js ] ************************* AdwCleaner[R0].txt - [4036 octets] - [26/01/2014 03:09:28] AdwCleaner[R1].txt - [4253 octets] - [20/03/2014 20:53:30] AdwCleaner[R2].txt - [1621 octets] - [28/03/2014 09:44:57] AdwCleaner[S0].txt - [3770 octets] - [26/01/2014 03:10:58] AdwCleaner[S1].txt - [4144 octets] - [20/03/2014 20:54:28] ########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1801 octets] ########## Code:
ATTFilter Junkware Removal Tool (JRT) by Thisisu Version: 6.1.3 (03.23.2014:1) OS: Windows 7 Ultimate x86 Ran by katrin on 28.03.2014 at 10:46:48,57 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\katrin\appdata\locallow\datamngr" ~~~ FireFox Emptied folder: C:\Users\katrin\AppData\Roaming\mozilla\firefox\profiles\4ui8084u.default\minidumps [115 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 28.03.2014 at 10:54:01,73 Computer was rebooted End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 Ran by katrin (administrator) on KATRIN-PC on 28-03-2014 12:00:19 Running from C:\Users\katrin\Downloads Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (ICQ) C:\Users\katrin\AppData\Roaming\ICQM\icq.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\klwtblfs.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7514656 2009-05-22] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-05-22] (Realtek Semiconductor Corp.) HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap.dll [982232 2013-12-10] (NVIDIA Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [NvBackend] - C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation) HKU\S-1-5-21-430205881-583344909-559689374-1000\...\Run: [icq] - C:\Users\katrin\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-03] (ICQ) HKU\S-1-5-21-430205881-583344909-559689374-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x80E8E03300FDCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=291&src=ds&p={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=291&src=ds&p={searchTerms} BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default FF DefaultSearchEngine: Google FF SearchEngineOrder.1: default-search.net FF SelectedSearchEngine: Google FF Homepage: https://apps.facebook.com/forbiddengarden/?fb_source=bookmark|hxxp://www.default-search.net/?sid=476&aid=122&itype=n&ver=11471&tm=291&src=bar FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\katrin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Settings Manager - C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\Extensions\{19D73812-1701-1B61-CBA2-12A70C87A0B0} [2014-03-19] FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com [2014-03-26] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-03-26] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com [2014-03-26] ========================== Services (Whitelisted) ================= R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14658848 2013-12-10] (NVIDIA Corporation) S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X] S2 SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [X] ==================== Drivers (Whitelisted) ==================== R3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [278528 2011-10-24] (AVEO) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] () R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-03-26] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [94304 2014-03-26] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-03-26] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-03-26] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-03-26] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-03-05] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-03-28] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51416 2014-03-05] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-05] (NVIDIA Corporation) S3 athr; system32\DRIVERS\athr.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-28 10:54 - 2014-03-28 10:54 - 00000857 _____ () C:\Users\katrin\Desktop\JRT.txt 2014-03-28 09:55 - 2014-03-28 09:55 - 01038974 _____ (Thisisu) C:\Users\katrin\Downloads\JRT.exe 2014-03-28 09:44 - 2014-03-28 09:44 - 01950720 _____ () C:\Users\katrin\Downloads\adwcleaner(1).exe 2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\Users\katrin\Desktop\mbam.txt 2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\mbam.txt 2014-03-28 09:21 - 2014-03-28 10:46 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-28 09:21 - 2014-03-28 09:21 - 00001056 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-28 09:21 - 2014-03-28 09:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-03-28 09:21 - 2014-03-05 09:26 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-28 09:21 - 2014-03-05 09:26 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-28 09:21 - 2014-03-05 09:26 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-28 09:19 - 2014-03-28 09:20 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\katrin\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-28 09:09 - 2014-03-28 09:09 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\katrin\Downloads\revosetup95(1).exe 2014-03-27 10:12 - 2014-03-28 12:00 - 00011137 _____ () C:\Users\katrin\Downloads\FRST.txt 2014-03-27 10:12 - 2014-03-27 10:13 - 00018161 _____ () C:\Users\katrin\Downloads\Addition.txt 2014-03-27 10:11 - 2014-03-28 12:00 - 00000000 ____D () C:\FRST 2014-03-27 10:10 - 2014-03-27 10:11 - 01145856 _____ (Farbar) C:\Users\katrin\Downloads\FRST.exe 2014-03-27 00:29 - 2014-03-27 01:07 - 1163986772 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-22_2015_68681.avi 2014-03-27 00:29 - 2014-03-27 00:53 - 605594990 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Familienbande_2014-03-24_2015_68681.avi 2014-03-26 21:51 - 2014-03-26 21:51 - 00001059 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-03-26 21:50 - 2014-03-28 11:01 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-03-26 21:50 - 2014-03-26 22:01 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-03-26 21:50 - 2014-03-26 22:01 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-03-26 21:39 - 2014-03-28 10:45 - 00001176 _____ () C:\Windows\setupact.log 2014-03-26 21:39 - 2014-03-28 09:51 - 00006496 _____ () C:\Windows\PFRO.log 2014-03-26 21:39 - 2014-03-26 21:39 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-26 18:23 - 2014-03-26 18:31 - 243681088 _____ () C:\Users\katrin\Downloads\kav14.0.0.4651abDE_5154.exe 2014-03-26 18:15 - 2014-03-26 18:15 - 00000000 ____D () C:\sh4ldr 2014-03-26 18:13 - 2014-03-26 18:13 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\katrin\Downloads\SpyHunter-Installer.exe 2014-03-25 00:03 - 2014-03-25 00:03 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-03-24 23:54 - 2014-03-24 23:54 - 00001087 _____ () C:\Users\katrin\Desktop\USB2.0 Camera - Verknüpfung.lnk 2014-03-21 19:48 - 2014-03-21 20:59 - 847036712 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Mhysa_Folge30_2014-03-16_2320_68681.avi 2014-03-21 19:48 - 2014-03-21 20:32 - 654863488 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_13_Prozent_2014-03-17_2015_68681.avi 2014-03-21 19:47 - 2014-03-21 20:59 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681(1).avi 2014-03-21 19:47 - 2014-03-21 20:52 - 690707840 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Regen_von_Castamaer_Folge29_2014-03-16_2220_68681.avi 2014-03-21 01:06 - 2014-03-21 01:06 - 00000000 ____D () C:\Users\katrin\Downloads\backups 2014-03-21 01:04 - 2014-03-21 01:04 - 00004313 _____ () C:\Users\katrin\Downloads\hijackthis.log 2014-03-21 01:03 - 2014-03-21 01:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\katrin\Downloads\hijackthis_5833.exe 2014-03-20 20:49 - 2014-03-20 20:49 - 00000105 ____H () C:\Users\katrin\Desktop\.~lock.sicher pw.xls# 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\.mono 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\ProgramData\.mono 2014-03-19 07:33 - 2014-03-28 09:34 - 00000000 ____D () C:\Program Files\Settings Manager 2014-03-19 07:33 - 2014-03-28 09:33 - 00000000 ____D () C:\ProgramData\systemk 2014-03-19 07:26 - 2014-03-19 07:26 - 00648240 _____ (Unity Technologies ApS) C:\Users\katrin\Desktop\UnityWebPlayer_4_2_1_0.exe 2014-03-18 06:22 - 2014-03-26 22:06 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ___RD () C:\Program Files\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Users\katrin\AppData\Local\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-03-18 00:03 - 2014-03-27 11:06 - 00614400 _____ () C:\Windows\system32\Image20.dat 2014-03-16 18:24 - 2014-03-16 19:04 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681.avi 2014-03-16 18:23 - 2014-03-16 18:52 - 654864400 _____ () C:\Users\katrin\Downloads\Vampire_Diaries_Amara_2014-03-13_2015_68681.avi 2014-03-12 20:46 - 2014-03-12 22:10 - 653618416 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Ein_unvergesslicher_Abend_2014-03-10_2015_68681.avi 2014-03-12 20:45 - 2014-03-12 22:31 - 1158218112 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-08_2015_68681.avi 2014-03-12 20:45 - 2014-03-12 22:27 - 790724896 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Baer_und_die_Jungfrau_hehr_Folge27_2014-03-09_2220_68681.avi 2014-03-12 20:45 - 2014-03-12 22:26 - 762285704 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Die_Zweitgeborenen_Folge28_2014-03-09_2330_68681.avi 2014-03-12 20:45 - 2014-03-12 21:32 - 232655938 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Candace_im_Unglueck_Folge67_2014-03-08_1845_68681.avi 2014-03-12 20:44 - 2014-03-12 21:36 - 381282758 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Teamwork_Folge106_2014-03-08_1820_68681.avi 2014-03-12 20:44 - 2014-03-12 21:21 - 278627650 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Superhelden_Folge41_2014-03-08_1535_68681.avi 2014-03-12 20:43 - 2014-03-12 21:59 - 576686134 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Mission_Marvel_2014-03-08_1550_68681.avi 2014-03-12 20:43 - 2014-03-12 21:29 - 241351188 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Fisch_Phin_Ferb_Folge46_2014-03-08_1635_68681.avi 2014-03-12 06:55 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-12 06:55 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-12 06:55 - 2014-03-01 05:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-12 06:55 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-12 06:55 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-12 06:55 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-12 06:55 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-12 06:55 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-12 06:55 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-12 06:55 - 2014-03-01 04:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-12 06:55 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-12 06:55 - 2014-03-01 04:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-12 06:55 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-12 06:55 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-12 06:55 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-12 06:55 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-12 06:55 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-12 06:55 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-12 06:55 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-12 06:55 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-12 06:54 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-12 06:54 - 2014-03-01 04:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-12 06:54 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-12 06:54 - 2014-02-07 02:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-12 06:54 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-12 06:54 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-12 06:54 - 2014-01-28 03:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll ==================== One Month Modified Files and Folders ======= 2014-03-28 12:00 - 2014-03-27 10:12 - 00011137 _____ () C:\Users\katrin\Downloads\FRST.txt 2014-03-28 12:00 - 2014-03-27 10:11 - 00000000 ____D () C:\FRST 2014-03-28 11:46 - 2013-12-20 01:16 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\Skype 2014-03-28 11:12 - 2013-12-19 22:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-28 11:01 - 2014-03-26 21:50 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-03-28 10:54 - 2014-03-28 10:54 - 00000857 _____ () C:\Users\katrin\Desktop\JRT.txt 2014-03-28 10:53 - 2009-07-14 05:34 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-28 10:53 - 2009-07-14 05:34 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-28 10:49 - 2013-12-19 22:16 - 01391233 _____ () C:\Windows\WindowsUpdate.log 2014-03-28 10:46 - 2014-03-28 09:21 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-28 10:45 - 2014-03-26 21:39 - 00001176 _____ () C:\Windows\setupact.log 2014-03-28 10:45 - 2013-12-19 22:44 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-03-28 10:45 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-28 09:55 - 2014-03-28 09:55 - 01038974 _____ (Thisisu) C:\Users\katrin\Downloads\JRT.exe 2014-03-28 09:51 - 2014-03-26 21:39 - 00006496 _____ () C:\Windows\PFRO.log 2014-03-28 09:50 - 2014-01-26 03:09 - 00000000 ____D () C:\AdwCleaner 2014-03-28 09:44 - 2014-03-28 09:44 - 01950720 _____ () C:\Users\katrin\Downloads\adwcleaner(1).exe 2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\Users\katrin\Desktop\mbam.txt 2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\mbam.txt 2014-03-28 09:34 - 2014-03-19 07:33 - 00000000 ____D () C:\Program Files\Settings Manager 2014-03-28 09:34 - 2009-07-14 03:37 - 00000000 __RSD () C:\Windows\Media 2014-03-28 09:33 - 2014-03-19 07:33 - 00000000 ____D () C:\ProgramData\systemk 2014-03-28 09:21 - 2014-03-28 09:21 - 00001056 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-28 09:21 - 2014-03-28 09:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-03-28 09:21 - 2014-01-26 02:53 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-28 09:20 - 2014-03-28 09:19 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\katrin\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-28 09:09 - 2014-03-28 09:09 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\katrin\Downloads\revosetup95(1).exe 2014-03-28 09:09 - 2014-01-26 02:08 - 00001218 _____ () C:\Users\katrin\Desktop\Revo Uninstaller.lnk 2014-03-27 11:06 - 2014-03-18 00:03 - 00614400 _____ () C:\Windows\system32\Image20.dat 2014-03-27 10:13 - 2014-03-27 10:12 - 00018161 _____ () C:\Users\katrin\Downloads\Addition.txt 2014-03-27 10:11 - 2014-03-27 10:10 - 01145856 _____ (Farbar) C:\Users\katrin\Downloads\FRST.exe 2014-03-27 01:07 - 2014-03-27 00:29 - 1163986772 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-22_2015_68681.avi 2014-03-27 00:53 - 2014-03-27 00:29 - 605594990 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Familienbande_2014-03-24_2015_68681.avi 2014-03-26 22:06 - 2014-03-18 06:22 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-26 22:06 - 2013-12-20 01:16 - 00000000 ____D () C:\ProgramData\Skype 2014-03-26 22:01 - 2014-03-26 21:50 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-03-26 22:01 - 2014-03-26 21:50 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-03-26 22:01 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2014-03-26 22:01 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2014-03-26 22:01 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2014-03-26 21:51 - 2014-03-26 21:51 - 00001059 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-03-26 21:39 - 2014-03-26 21:39 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-26 18:31 - 2014-03-26 18:23 - 243681088 _____ () C:\Users\katrin\Downloads\kav14.0.0.4651abDE_5154.exe 2014-03-26 18:16 - 2014-01-26 02:26 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP 2014-03-26 18:15 - 2014-03-26 18:15 - 00000000 ____D () C:\sh4ldr 2014-03-26 18:15 - 2014-01-26 02:26 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-03-26 18:13 - 2014-03-26 18:13 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\katrin\Downloads\SpyHunter-Installer.exe 2014-03-26 15:14 - 2013-12-19 22:22 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-03-26 15:14 - 2013-12-19 22:22 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-03-26 15:14 - 2013-12-19 22:21 - 00000000 ____D () C:\Users\katrin\AppData\Local\Adobe 2014-03-25 00:17 - 2013-12-20 12:20 - 00000000 ____D () C:\Users\katrin\AppData\Local\Unity 2014-03-25 00:03 - 2014-03-25 00:03 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-03-24 23:54 - 2014-03-24 23:54 - 00001087 _____ () C:\Users\katrin\Desktop\USB2.0 Camera - Verknüpfung.lnk 2014-03-21 20:59 - 2014-03-21 19:48 - 847036712 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Mhysa_Folge30_2014-03-16_2320_68681.avi 2014-03-21 20:59 - 2014-03-21 19:47 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681(1).avi 2014-03-21 20:52 - 2014-03-21 19:47 - 690707840 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Regen_von_Castamaer_Folge29_2014-03-16_2220_68681.avi 2014-03-21 20:32 - 2014-03-21 19:48 - 654863488 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_13_Prozent_2014-03-17_2015_68681.avi 2014-03-21 01:06 - 2014-03-21 01:06 - 00000000 ____D () C:\Users\katrin\Downloads\backups 2014-03-21 01:04 - 2014-03-21 01:04 - 00004313 _____ () C:\Users\katrin\Downloads\hijackthis.log 2014-03-21 01:04 - 2013-12-19 22:18 - 00000000 ____D () C:\Users\katrin\AppData\Local\VirtualStore 2014-03-21 01:03 - 2014-03-21 01:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\katrin\Downloads\hijackthis_5833.exe 2014-03-20 20:49 - 2014-03-20 20:49 - 00000105 ____H () C:\Users\katrin\Desktop\.~lock.sicher pw.xls# 2014-03-20 06:47 - 2014-01-08 02:43 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-03-19 09:41 - 2014-01-08 02:43 - 00001101 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-19 09:41 - 2013-12-20 00:45 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\.mono 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\ProgramData\.mono 2014-03-19 07:26 - 2014-03-19 07:26 - 00648240 _____ (Unity Technologies ApS) C:\Users\katrin\Desktop\UnityWebPlayer_4_2_1_0.exe 2014-03-19 07:24 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-03-18 21:56 - 2011-04-12 02:38 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ___RD () C:\Program Files\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Users\katrin\AppData\Local\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-03-18 03:02 - 2013-12-19 23:35 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-18 03:00 - 2012-01-10 21:50 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-16 19:04 - 2014-03-16 18:24 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681.avi 2014-03-16 18:52 - 2014-03-16 18:23 - 654864400 _____ () C:\Users\katrin\Downloads\Vampire_Diaries_Amara_2014-03-13_2015_68681.avi 2014-03-13 06:38 - 2009-07-14 05:33 - 00295816 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-12 22:31 - 2014-03-12 20:45 - 1158218112 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-08_2015_68681.avi 2014-03-12 22:27 - 2014-03-12 20:45 - 790724896 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Baer_und_die_Jungfrau_hehr_Folge27_2014-03-09_2220_68681.avi 2014-03-12 22:26 - 2014-03-12 20:45 - 762285704 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Die_Zweitgeborenen_Folge28_2014-03-09_2330_68681.avi 2014-03-12 22:10 - 2014-03-12 20:46 - 653618416 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Ein_unvergesslicher_Abend_2014-03-10_2015_68681.avi 2014-03-12 21:59 - 2014-03-12 20:43 - 576686134 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Mission_Marvel_2014-03-08_1550_68681.avi 2014-03-12 21:36 - 2014-03-12 20:44 - 381282758 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Teamwork_Folge106_2014-03-08_1820_68681.avi 2014-03-12 21:32 - 2014-03-12 20:45 - 232655938 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Candace_im_Unglueck_Folge67_2014-03-08_1845_68681.avi 2014-03-12 21:29 - 2014-03-12 20:43 - 241351188 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Fisch_Phin_Ferb_Folge46_2014-03-08_1635_68681.avi 2014-03-12 21:21 - 2014-03-12 20:44 - 278627650 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Superhelden_Folge41_2014-03-08_1535_68681.avi 2014-03-05 09:26 - 2014-03-28 09:21 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-05 09:26 - 2014-03-28 09:21 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-05 09:26 - 2014-03-28 09:21 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-01 05:30 - 2014-03-12 06:55 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 05:11 - 2014-03-12 06:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 05:10 - 2014-03-12 06:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 04:52 - 2014-03-12 06:54 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 04:51 - 2014-03-12 06:55 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 04:47 - 2014-03-12 06:55 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 04:43 - 2014-03-12 06:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 04:43 - 2014-03-12 06:55 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 04:40 - 2014-03-12 06:55 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 04:38 - 2014-03-12 06:55 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 04:38 - 2014-03-12 06:55 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 04:37 - 2014-03-12 06:55 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 04:31 - 2014-03-12 06:55 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 04:25 - 2014-03-12 06:54 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 04:16 - 2014-03-12 06:55 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 04:14 - 2014-03-12 06:55 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 04:03 - 2014-03-12 06:55 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 04:00 - 2014-03-12 06:55 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 03:57 - 2014-03-12 06:54 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 03:32 - 2014-03-12 06:55 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 03:27 - 2014-03-12 06:55 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 03:25 - 2014-03-12 06:55 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-27 11:03 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-02-27 03:04 - 2010-11-20 22:01 - 01593956 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-26 09:30 - 2009-07-14 05:53 - 00032634 _____ () C:\Windows\Tasks\SCHEDLGU.TXT Some content of TEMP: ==================== C:\Users\katrin\AppData\Local\Temp\avgnt.exe C:\Users\katrin\AppData\Local\Temp\Quarantine.exe C:\Users\katrin\AppData\Local\Temp\SHSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-20 09:49 ==================== End Of Log ============================ --- --- --- schönes wochenende! |
29.03.2014, 08:29 | #6 |
/// the machine /// TB-Ausbilder | Default-SearchESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Default-Search |
30.03.2014, 01:12 | #7 |
| Default-SearchCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=e3eec5ab2d07004d8fd12613b1ac086c # engine=17679 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-03-29 11:58:02 # local_time=2014-03-30 12:58:02 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 136786 147768673 0 0 # scanned=117768 # found=0 # cleaned=0 # scan_time=3018 Code:
ATTFilter Results of screen317's Security Check version 0.99.80 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Anti-Virus Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` CCleaner Adobe Flash Player 12.0.0.77 Adobe Reader XI Mozilla Firefox (27.0) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Kaspersky Lab Kaspersky Anti-Virus 14.0.0 avp.exe Kaspersky Lab Kaspersky Anti-Virus 14.0.0 avpui.exe Kaspersky Lab Kaspersky Anti-Virus 14.0.0 klwtblfs.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 Ran by katrin (administrator) on KATRIN-PC on 30-03-2014 01:07:53 Running from C:\Users\katrin\Downloads Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (ICQ) C:\Users\katrin\AppData\Roaming\ICQM\icq.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\klwtblfs.exe () C:\Users\katrin\Downloads\SecurityCheck.exe (Microsoft Corporation) C:\Windows\system32\cmd.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7514656 2009-05-22] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-05-22] (Realtek Semiconductor Corp.) HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap.dll [982232 2013-12-10] (NVIDIA Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [NvBackend] - C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation) HKU\S-1-5-21-430205881-583344909-559689374-1000\...\Run: [icq] - C:\Users\katrin\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-03] (ICQ) HKU\S-1-5-21-430205881-583344909-559689374-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x80E8E03300FDCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=291&src=ds&p={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=291&src=ds&p={searchTerms} BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default FF DefaultSearchEngine: Google FF SearchEngineOrder.1: default-search.net FF SelectedSearchEngine: Google FF Homepage: https://apps.facebook.com/forbiddengarden/?fb_source=bookmark|hxxp://www.default-search.net/?sid=476&aid=122&itype=n&ver=11471&tm=291&src=bar FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\katrin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Settings Manager - C:\Users\katrin\AppData\Roaming\Mozilla\Firefox\Profiles\4ui8084u.default\Extensions\{19D73812-1701-1B61-CBA2-12A70C87A0B0} [2014-03-19] FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com [2014-03-26] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-03-26] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com [2014-03-26] ========================== Services (Whitelisted) ================= R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14658848 2013-12-10] (NVIDIA Corporation) S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X] S2 SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [X] ==================== Drivers (Whitelisted) ==================== R3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [278528 2011-10-24] (AVEO) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] () R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-03-26] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [94304 2014-03-26] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-03-26] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-03-26] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-03-26] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-03-05] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-03-30] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51416 2014-03-05] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-05] (NVIDIA Corporation) S3 athr; system32\DRIVERS\athr.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-30 01:04 - 2014-03-30 01:04 - 00987442 _____ () C:\Users\katrin\Downloads\SecurityCheck.exe 2014-03-30 00:05 - 2014-03-30 00:05 - 02347384 _____ (ESET) C:\Users\katrin\Downloads\esetsmartinstaller_enu(1).exe 2014-03-29 00:07 - 2014-03-29 09:20 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\62EC727E.sys 2014-03-28 10:54 - 2014-03-28 10:54 - 00000857 _____ () C:\Users\katrin\Desktop\JRT.txt 2014-03-28 09:55 - 2014-03-28 09:55 - 01038974 _____ (Thisisu) C:\Users\katrin\Downloads\JRT.exe 2014-03-28 09:44 - 2014-03-28 09:44 - 01950720 _____ () C:\Users\katrin\Downloads\adwcleaner(1).exe 2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\Users\katrin\Desktop\mbam.txt 2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\mbam.txt 2014-03-28 09:21 - 2014-03-30 01:06 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-28 09:21 - 2014-03-28 09:21 - 00001056 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-28 09:21 - 2014-03-28 09:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-03-28 09:21 - 2014-03-05 09:26 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-28 09:21 - 2014-03-05 09:26 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-28 09:21 - 2014-03-05 09:26 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-28 09:19 - 2014-03-28 09:20 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\katrin\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-28 09:09 - 2014-03-28 09:09 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\katrin\Downloads\revosetup95(1).exe 2014-03-27 10:12 - 2014-03-30 01:07 - 00011238 _____ () C:\Users\katrin\Downloads\FRST.txt 2014-03-27 10:12 - 2014-03-27 10:13 - 00018161 _____ () C:\Users\katrin\Downloads\Addition.txt 2014-03-27 10:11 - 2014-03-30 01:07 - 00000000 ____D () C:\FRST 2014-03-27 10:10 - 2014-03-27 10:11 - 01145856 _____ (Farbar) C:\Users\katrin\Downloads\FRST.exe 2014-03-27 00:29 - 2014-03-27 01:07 - 1163986772 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-22_2015_68681.avi 2014-03-27 00:29 - 2014-03-27 00:53 - 605594990 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Familienbande_2014-03-24_2015_68681.avi 2014-03-26 21:51 - 2014-03-26 21:51 - 00001059 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-03-26 21:50 - 2014-03-29 23:45 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-03-26 21:50 - 2014-03-26 22:01 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-03-26 21:50 - 2014-03-26 22:01 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-03-26 21:39 - 2014-03-29 09:19 - 00001344 _____ () C:\Windows\setupact.log 2014-03-26 21:39 - 2014-03-28 09:51 - 00006496 _____ () C:\Windows\PFRO.log 2014-03-26 21:39 - 2014-03-26 21:39 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-26 18:23 - 2014-03-26 18:31 - 243681088 _____ () C:\Users\katrin\Downloads\kav14.0.0.4651abDE_5154.exe 2014-03-26 18:15 - 2014-03-26 18:15 - 00000000 ____D () C:\sh4ldr 2014-03-26 18:13 - 2014-03-26 18:13 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\katrin\Downloads\SpyHunter-Installer.exe 2014-03-25 00:03 - 2014-03-25 00:03 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-03-24 23:54 - 2014-03-24 23:54 - 00001087 _____ () C:\Users\katrin\Desktop\USB2.0 Camera - Verknüpfung.lnk 2014-03-21 19:48 - 2014-03-21 20:59 - 847036712 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Mhysa_Folge30_2014-03-16_2320_68681.avi 2014-03-21 19:48 - 2014-03-21 20:32 - 654863488 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_13_Prozent_2014-03-17_2015_68681.avi 2014-03-21 19:47 - 2014-03-21 20:59 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681(1).avi 2014-03-21 19:47 - 2014-03-21 20:52 - 690707840 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Regen_von_Castamaer_Folge29_2014-03-16_2220_68681.avi 2014-03-21 01:06 - 2014-03-21 01:06 - 00000000 ____D () C:\Users\katrin\Downloads\backups 2014-03-21 01:04 - 2014-03-21 01:04 - 00004313 _____ () C:\Users\katrin\Downloads\hijackthis.log 2014-03-21 01:03 - 2014-03-21 01:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\katrin\Downloads\hijackthis_5833.exe 2014-03-20 20:49 - 2014-03-20 20:49 - 00000105 ____H () C:\Users\katrin\Desktop\.~lock.sicher pw.xls# 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\.mono 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\ProgramData\.mono 2014-03-19 07:33 - 2014-03-28 09:34 - 00000000 ____D () C:\Program Files\Settings Manager 2014-03-19 07:33 - 2014-03-28 09:33 - 00000000 ____D () C:\ProgramData\systemk 2014-03-19 07:26 - 2014-03-19 07:26 - 00648240 _____ (Unity Technologies ApS) C:\Users\katrin\Desktop\UnityWebPlayer_4_2_1_0.exe 2014-03-18 06:22 - 2014-03-26 22:06 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ___RD () C:\Program Files\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Users\katrin\AppData\Local\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-03-18 00:03 - 2014-03-27 11:06 - 00614400 _____ () C:\Windows\system32\Image20.dat 2014-03-16 18:24 - 2014-03-16 19:04 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681.avi 2014-03-16 18:23 - 2014-03-16 18:52 - 654864400 _____ () C:\Users\katrin\Downloads\Vampire_Diaries_Amara_2014-03-13_2015_68681.avi 2014-03-12 20:46 - 2014-03-12 22:10 - 653618416 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Ein_unvergesslicher_Abend_2014-03-10_2015_68681.avi 2014-03-12 20:45 - 2014-03-12 22:31 - 1158218112 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-08_2015_68681.avi 2014-03-12 20:45 - 2014-03-12 22:27 - 790724896 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Baer_und_die_Jungfrau_hehr_Folge27_2014-03-09_2220_68681.avi 2014-03-12 20:45 - 2014-03-12 22:26 - 762285704 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Die_Zweitgeborenen_Folge28_2014-03-09_2330_68681.avi 2014-03-12 20:45 - 2014-03-12 21:32 - 232655938 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Candace_im_Unglueck_Folge67_2014-03-08_1845_68681.avi 2014-03-12 20:44 - 2014-03-12 21:36 - 381282758 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Teamwork_Folge106_2014-03-08_1820_68681.avi 2014-03-12 20:44 - 2014-03-12 21:21 - 278627650 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Superhelden_Folge41_2014-03-08_1535_68681.avi 2014-03-12 20:43 - 2014-03-12 21:59 - 576686134 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Mission_Marvel_2014-03-08_1550_68681.avi 2014-03-12 20:43 - 2014-03-12 21:29 - 241351188 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Fisch_Phin_Ferb_Folge46_2014-03-08_1635_68681.avi 2014-03-12 06:55 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-12 06:55 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-12 06:55 - 2014-03-01 05:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-12 06:55 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-12 06:55 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-12 06:55 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-12 06:55 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-12 06:55 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-12 06:55 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-12 06:55 - 2014-03-01 04:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-12 06:55 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-12 06:55 - 2014-03-01 04:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-12 06:55 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-12 06:55 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-12 06:55 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-12 06:55 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-12 06:55 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-12 06:55 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-12 06:55 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-12 06:55 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-12 06:54 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-12 06:54 - 2014-03-01 04:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-12 06:54 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-12 06:54 - 2014-02-07 02:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-12 06:54 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-12 06:54 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-12 06:54 - 2014-01-28 03:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll ==================== One Month Modified Files and Folders ======= 2014-03-30 01:08 - 2014-03-27 10:12 - 00011238 _____ () C:\Users\katrin\Downloads\FRST.txt 2014-03-30 01:07 - 2014-03-27 10:11 - 00000000 ____D () C:\FRST 2014-03-30 01:06 - 2014-03-28 09:21 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-30 01:06 - 2009-07-14 05:34 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-30 01:06 - 2009-07-14 05:34 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-30 01:05 - 2013-12-19 22:16 - 01409491 _____ () C:\Windows\WindowsUpdate.log 2014-03-30 01:04 - 2014-03-30 01:04 - 00987442 _____ () C:\Users\katrin\Downloads\SecurityCheck.exe 2014-03-30 00:42 - 2013-12-20 01:16 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\Skype 2014-03-30 00:12 - 2013-12-19 22:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-30 00:05 - 2014-03-30 00:05 - 02347384 _____ (ESET) C:\Users\katrin\Downloads\esetsmartinstaller_enu(1).exe 2014-03-29 23:45 - 2014-03-26 21:50 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-03-29 09:20 - 2014-03-29 00:07 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\62EC727E.sys 2014-03-29 09:19 - 2014-03-26 21:39 - 00001344 _____ () C:\Windows\setupact.log 2014-03-29 09:18 - 2013-12-19 22:44 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-03-29 09:18 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-28 10:54 - 2014-03-28 10:54 - 00000857 _____ () C:\Users\katrin\Desktop\JRT.txt 2014-03-28 09:55 - 2014-03-28 09:55 - 01038974 _____ (Thisisu) C:\Users\katrin\Downloads\JRT.exe 2014-03-28 09:51 - 2014-03-26 21:39 - 00006496 _____ () C:\Windows\PFRO.log 2014-03-28 09:50 - 2014-01-26 03:09 - 00000000 ____D () C:\AdwCleaner 2014-03-28 09:44 - 2014-03-28 09:44 - 01950720 _____ () C:\Users\katrin\Downloads\adwcleaner(1).exe 2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\Users\katrin\Desktop\mbam.txt 2014-03-28 09:43 - 2014-03-28 09:43 - 00010146 _____ () C:\mbam.txt 2014-03-28 09:34 - 2014-03-19 07:33 - 00000000 ____D () C:\Program Files\Settings Manager 2014-03-28 09:34 - 2009-07-14 03:37 - 00000000 __RSD () C:\Windows\Media 2014-03-28 09:33 - 2014-03-19 07:33 - 00000000 ____D () C:\ProgramData\systemk 2014-03-28 09:21 - 2014-03-28 09:21 - 00001056 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-28 09:21 - 2014-03-28 09:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-03-28 09:21 - 2014-01-26 02:53 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-28 09:20 - 2014-03-28 09:19 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\katrin\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-28 09:09 - 2014-03-28 09:09 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\katrin\Downloads\revosetup95(1).exe 2014-03-28 09:09 - 2014-01-26 02:08 - 00001218 _____ () C:\Users\katrin\Desktop\Revo Uninstaller.lnk 2014-03-27 11:06 - 2014-03-18 00:03 - 00614400 _____ () C:\Windows\system32\Image20.dat 2014-03-27 10:13 - 2014-03-27 10:12 - 00018161 _____ () C:\Users\katrin\Downloads\Addition.txt 2014-03-27 10:11 - 2014-03-27 10:10 - 01145856 _____ (Farbar) C:\Users\katrin\Downloads\FRST.exe 2014-03-27 01:07 - 2014-03-27 00:29 - 1163986772 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-22_2015_68681.avi 2014-03-27 00:53 - 2014-03-27 00:29 - 605594990 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Familienbande_2014-03-24_2015_68681.avi 2014-03-26 22:06 - 2014-03-18 06:22 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-26 22:06 - 2013-12-20 01:16 - 00000000 ____D () C:\ProgramData\Skype 2014-03-26 22:01 - 2014-03-26 21:50 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-03-26 22:01 - 2014-03-26 21:50 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-03-26 22:01 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2014-03-26 22:01 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2014-03-26 22:01 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2014-03-26 21:51 - 2014-03-26 21:51 - 00001059 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-03-26 21:50 - 2014-03-26 21:50 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-03-26 21:39 - 2014-03-26 21:39 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-26 18:31 - 2014-03-26 18:23 - 243681088 _____ () C:\Users\katrin\Downloads\kav14.0.0.4651abDE_5154.exe 2014-03-26 18:16 - 2014-01-26 02:26 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP 2014-03-26 18:15 - 2014-03-26 18:15 - 00000000 ____D () C:\sh4ldr 2014-03-26 18:15 - 2014-01-26 02:26 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-03-26 18:13 - 2014-03-26 18:13 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\katrin\Downloads\SpyHunter-Installer.exe 2014-03-26 15:14 - 2013-12-19 22:22 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-03-26 15:14 - 2013-12-19 22:22 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-03-26 15:14 - 2013-12-19 22:21 - 00000000 ____D () C:\Users\katrin\AppData\Local\Adobe 2014-03-25 00:17 - 2013-12-20 12:20 - 00000000 ____D () C:\Users\katrin\AppData\Local\Unity 2014-03-25 00:03 - 2014-03-25 00:03 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-03-24 23:54 - 2014-03-24 23:54 - 00001087 _____ () C:\Users\katrin\Desktop\USB2.0 Camera - Verknüpfung.lnk 2014-03-21 20:59 - 2014-03-21 19:48 - 847036712 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Mhysa_Folge30_2014-03-16_2320_68681.avi 2014-03-21 20:59 - 2014-03-21 19:47 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681(1).avi 2014-03-21 20:52 - 2014-03-21 19:47 - 690707840 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Regen_von_Castamaer_Folge29_2014-03-16_2220_68681.avi 2014-03-21 20:32 - 2014-03-21 19:48 - 654863488 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_13_Prozent_2014-03-17_2015_68681.avi 2014-03-21 01:06 - 2014-03-21 01:06 - 00000000 ____D () C:\Users\katrin\Downloads\backups 2014-03-21 01:04 - 2014-03-21 01:04 - 00004313 _____ () C:\Users\katrin\Downloads\hijackthis.log 2014-03-21 01:04 - 2013-12-19 22:18 - 00000000 ____D () C:\Users\katrin\AppData\Local\VirtualStore 2014-03-21 01:03 - 2014-03-21 01:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\katrin\Downloads\hijackthis_5833.exe 2014-03-20 20:49 - 2014-03-20 20:49 - 00000105 ____H () C:\Users\katrin\Desktop\.~lock.sicher pw.xls# 2014-03-20 06:47 - 2014-01-08 02:43 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-03-19 09:41 - 2014-01-08 02:43 - 00001101 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-19 09:41 - 2013-12-20 00:45 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\Users\katrin\AppData\Roaming\.mono 2014-03-19 07:34 - 2014-03-19 07:34 - 00000000 ____D () C:\ProgramData\.mono 2014-03-19 07:26 - 2014-03-19 07:26 - 00648240 _____ (Unity Technologies ApS) C:\Users\katrin\Desktop\UnityWebPlayer_4_2_1_0.exe 2014-03-19 07:24 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-03-18 21:56 - 2011-04-12 02:38 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ___RD () C:\Program Files\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Users\katrin\AppData\Local\Skype 2014-03-18 06:22 - 2014-03-18 06:22 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-03-18 03:02 - 2013-12-19 23:35 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-18 03:00 - 2012-01-10 21:50 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-16 19:04 - 2014-03-16 18:24 - 1164877558 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-15_2015_68681.avi 2014-03-16 18:52 - 2014-03-16 18:23 - 654864400 _____ () C:\Users\katrin\Downloads\Vampire_Diaries_Amara_2014-03-13_2015_68681.avi 2014-03-13 06:38 - 2009-07-14 05:33 - 00295816 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-12 22:31 - 2014-03-12 20:45 - 1158218112 _____ () C:\Users\katrin\Downloads\Star_Wars_The_Clone_Wars_2014-03-08_2015_68681.avi 2014-03-12 22:27 - 2014-03-12 20:45 - 790724896 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Der_Baer_und_die_Jungfrau_hehr_Folge27_2014-03-09_2220_68681.avi 2014-03-12 22:26 - 2014-03-12 20:45 - 762285704 _____ () C:\Users\katrin\Downloads\Game_Of_Thrones_Das_Lied_von_Eis_und_F_Die_Zweitgeborenen_Folge28_2014-03-09_2330_68681.avi 2014-03-12 22:10 - 2014-03-12 20:46 - 653618416 _____ () C:\Users\katrin\Downloads\Hart_of_Dixie_Ein_unvergesslicher_Abend_2014-03-10_2015_68681.avi 2014-03-12 21:59 - 2014-03-12 20:43 - 576686134 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Mission_Marvel_2014-03-08_1550_68681.avi 2014-03-12 21:36 - 2014-03-12 20:44 - 381282758 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Teamwork_Folge106_2014-03-08_1820_68681.avi 2014-03-12 21:32 - 2014-03-12 20:45 - 232655938 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Candace_im_Unglueck_Folge67_2014-03-08_1845_68681.avi 2014-03-12 21:29 - 2014-03-12 20:43 - 241351188 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Fisch_Phin_Ferb_Folge46_2014-03-08_1635_68681.avi 2014-03-12 21:21 - 2014-03-12 20:44 - 278627650 _____ () C:\Users\katrin\Downloads\Phineas_und_Ferb_Superhelden_Folge41_2014-03-08_1535_68681.avi 2014-03-05 09:26 - 2014-03-28 09:21 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-05 09:26 - 2014-03-28 09:21 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-05 09:26 - 2014-03-28 09:21 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-01 05:30 - 2014-03-12 06:55 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 05:11 - 2014-03-12 06:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 05:10 - 2014-03-12 06:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 04:52 - 2014-03-12 06:54 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 04:51 - 2014-03-12 06:55 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 04:47 - 2014-03-12 06:55 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 04:43 - 2014-03-12 06:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 04:43 - 2014-03-12 06:55 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 04:40 - 2014-03-12 06:55 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 04:38 - 2014-03-12 06:55 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 04:38 - 2014-03-12 06:55 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 04:37 - 2014-03-12 06:55 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 04:31 - 2014-03-12 06:55 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 04:25 - 2014-03-12 06:54 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 04:16 - 2014-03-12 06:55 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 04:14 - 2014-03-12 06:55 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 04:03 - 2014-03-12 06:55 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 04:00 - 2014-03-12 06:55 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 03:57 - 2014-03-12 06:54 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 03:32 - 2014-03-12 06:55 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 03:27 - 2014-03-12 06:55 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 03:25 - 2014-03-12 06:55 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll Some content of TEMP: ==================== C:\Users\katrin\AppData\Local\Temp\avgnt.exe C:\Users\katrin\AppData\Local\Temp\Quarantine.exe C:\Users\katrin\AppData\Local\Temp\SHSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-20 09:49 ==================== End Of Log ============================ --- --- --- --- --- --- die seite öffnet sich leider noch immer wenn ich das firefox öffne... gruß paula |
30.03.2014, 12:52 | #8 |
/// the machine /// TB-Ausbilder | Default-Search Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.04.2014, 01:42 | #9 |
| Default-Search hallo schrauber...vielen dank es hat geholfen...die seite hat sich nicht mehr geöffnet...vielen vielen dank gruß paula |
01.04.2014, 13:02 | #10 |
/// the machine /// TB-Ausbilder | Default-Search Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |