|
Plagegeister aller Art und deren Bekämpfung: Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
31.03.2014, 14:03 | #1 |
| Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? Hallo ich möchte gerne man Pc Richtig Grundreinigen, nur ich möchte keinen fehler machen. den zu viele programme schaden ja nur bzw. vertragen sich miteinander ja nicht. fals Thema schon gibt könnt ihr mich bitte darauf hinweißen gefunden hab ich leider keins. |
31.03.2014, 14:05 | #2 |
/// TB-Ausbilder | Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ?Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Eine Bereinigung ist immer individuell und speziell auf einen Computer zugeschnitten. Hast du denn Probleme? Wenn ja, welche? Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
31.03.2014, 14:56 | #3 | |
| Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? frst 32:
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by angel (administrator) on ANGEL-PC on 31-03-2014 15:53:59 Running from C:\Users\angel\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Logixoft) C:\ProgramData\rvlkl\rvlkl.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 4\Integrator.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe () C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-979047111-3019266187-3407045396-1000\...\Run: [] - [X] HKU\S-1-5-21-979047111-3019266187-3407045396-1000\...\Run: [GUDelayStartup] - C:\Program Files (x86)\Glary Utilities 4\StartupManager.exe [37152 2014-02-26] (Glarysoft Ltd) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=hp&fr=linkury-tb&installDate=10/01/2014&type=hp1000 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000 SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000 SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1209149.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @zylom.com/ZylomGamesPlayer - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\angel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-03-31] FF Extension: Adblock Plus - C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-19] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-08-07] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-08-07] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-08-07] ==================== Services (Whitelisted) ================= R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) S4 WSWNA1100; C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe [268768 2010-03-22] () ==================== Drivers (Whitelisted) ==================== R0 BootDefragDriver; C:\Windows\System32\drivers\BootDefragDriver.sys [17088 2014-02-26] (Glarysoft Ltd) R3 cleanhlp; C:\EEK\Run\cleanhlp64.sys [57024 2014-03-31] (Emsisoft GmbH) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-31 15:15 - 2014-03-31 15:16 - 00032098 _____ () C:\Users\angel\Downloads\Addition.txt 2014-03-31 15:14 - 2014-03-31 15:54 - 00012598 _____ () C:\Users\angel\Downloads\FRST.txt 2014-03-31 15:12 - 2014-03-31 15:53 - 00000000 ____D () C:\FRST 2014-03-31 15:11 - 2014-03-31 15:11 - 02157056 _____ (Farbar) C:\Users\angel\Downloads\FRST64.exe 2014-03-31 14:10 - 2014-03-31 14:10 - 00000546 _____ () C:\Users\angel\Desktop\Emsisoft Emergency Kit.lnk 2014-03-31 14:09 - 2014-03-31 14:10 - 00000000 ____D () C:\EEK 2014-03-31 14:00 - 2014-03-31 14:03 - 224883568 _____ () C:\Users\angel\Downloads\EmsisoftEmergencyKit.exe 2014-03-31 13:49 - 2014-03-31 13:49 - 01678496 _____ (Skype Technologies S.A.) C:\Users\angel\Downloads\SkypeSetup(1).exe 2014-03-30 23:44 - 2014-03-30 23:44 - 00027423 _____ () C:\Users\angel\Documents\Unbenannt.wma 2014-03-30 23:40 - 2014-03-30 23:40 - 00058853 _____ () C:\Users\angel\Desktop\test.wma 2014-03-30 20:54 - 2014-03-30 23:35 - 00000000 ____D () C:\Users\angel\AppData\Roaming\TS3Client 2014-03-30 20:53 - 2014-03-30 20:53 - 00000967 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-03-30 20:53 - 2014-03-30 20:53 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-03-30 20:48 - 2014-03-30 20:48 - 00613200 _____ (Chip Digital GmbH) C:\Users\angel\Downloads\TeamSpeak 3 64 Bit - CHIP-Downloader.exe 2014-03-29 21:23 - 2014-03-31 14:07 - 00000000 ____D () C:\Users\angel\AppData\Roaming\Skype 2014-03-29 21:23 - 2014-03-31 14:07 - 00000000 ____D () C:\ProgramData\Skype 2014-03-29 21:23 - 2014-03-29 21:23 - 00000000 ____D () C:\Users\angel\AppData\Local\Skype 2014-03-29 21:22 - 2014-03-29 21:22 - 01678496 _____ (Skype Technologies S.A.) C:\Users\angel\Downloads\SkypeSetup.exe 2014-03-29 18:09 - 2014-03-29 18:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-27 08:24 - 2014-03-28 08:21 - 00000000 ____D () C:\ProgramData\rvlkl 2014-03-26 21:01 - 2014-03-27 08:24 - 00000000 ____D () C:\Users\angel\AppData\Roaming\Systweak 2014-03-26 21:01 - 2014-03-26 21:01 - 01411136 _____ (Logixoft) C:\Users\Public\Desktop\rkfree_setup.exe 2014-03-26 21:01 - 2013-07-11 14:49 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe 2014-03-26 20:56 - 2014-03-26 20:56 - 00316480 _____ () C:\Users\angel\Downloads\revealer-keylogger-windows-downloader_de.exe 2014-03-14 10:34 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-14 10:34 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-14 10:34 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-14 10:34 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-14 10:34 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-14 10:34 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-14 10:34 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-14 10:34 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-14 10:34 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-14 10:34 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-14 10:34 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-14 10:34 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-14 10:34 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-14 10:34 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-14 10:34 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-14 10:34 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-14 10:34 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-14 10:34 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-14 10:34 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-14 10:34 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-14 10:34 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-14 10:34 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-14 10:34 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-14 10:34 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-14 10:34 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-14 10:34 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-14 10:34 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-14 10:34 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-14 10:34 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-14 10:34 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-14 10:34 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-14 10:34 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-14 10:34 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-14 10:34 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-14 10:34 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-14 10:34 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-14 10:34 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-14 10:34 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-14 10:34 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-14 10:34 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-14 10:34 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-14 10:34 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-14 10:34 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-14 10:34 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-14 10:33 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-14 10:33 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-14 10:33 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-14 10:33 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-13 21:04 - 2014-03-13 21:05 - 00012488 _____ () C:\Users\angel\Desktop\pizzazeig.odt 2014-03-13 20:58 - 2014-03-13 20:58 - 00007334 _____ () C:\Users\angel\Desktop\OpenDocument Text (neu).odt 2014-03-10 11:45 - 2014-03-10 11:45 - 00000000 ____D () C:\Windows\SysWOW64\Adobe 2014-03-05 11:36 - 2014-03-05 11:36 - 01070496 _____ (Unity Technologies ApS) C:\Users\angel\Downloads\UnityWebPlayer.exe 2014-03-03 12:48 - 2014-03-03 12:48 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-03 12:47 - 2014-03-03 12:47 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-03-03 12:45 - 2014-03-03 12:45 - 04765152 _____ (Piriform Ltd) C:\Users\angel\Downloads\CCleaner_v4.11.4619.exe 2014-03-03 12:45 - 2014-03-03 12:45 - 00001080 _____ () C:\Users\Public\Desktop\Glary Utilities 4.lnk 2014-03-03 12:44 - 2014-03-03 12:44 - 12393008 _____ () C:\Users\angel\Downloads\Glary_Utilities_v4.7.0.96.exe 2014-03-03 12:44 - 2014-02-26 07:17 - 00017088 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\BootDefragDriver.sys ==================== One Month Modified Files and Folders ======= 2014-03-31 15:54 - 2014-03-31 15:14 - 00012598 _____ () C:\Users\angel\Downloads\FRST.txt 2014-03-31 15:53 - 2014-03-31 15:12 - 00000000 ____D () C:\FRST 2014-03-31 15:32 - 2013-09-03 17:02 - 01507773 _____ () C:\Windows\WindowsUpdate.log 2014-03-31 15:19 - 2014-02-26 21:46 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-31 15:16 - 2014-03-31 15:15 - 00032098 _____ () C:\Users\angel\Downloads\Addition.txt 2014-03-31 15:11 - 2014-03-31 15:11 - 02157056 _____ (Farbar) C:\Users\angel\Downloads\FRST64.exe 2014-03-31 14:13 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-31 14:13 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-31 14:12 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-03-31 14:12 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-03-31 14:12 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-31 14:10 - 2014-03-31 14:10 - 00000546 _____ () C:\Users\angel\Desktop\Emsisoft Emergency Kit.lnk 2014-03-31 14:10 - 2014-03-31 14:09 - 00000000 ____D () C:\EEK 2014-03-31 14:07 - 2014-03-29 21:23 - 00000000 ____D () C:\Users\angel\AppData\Roaming\Skype 2014-03-31 14:07 - 2014-03-29 21:23 - 00000000 ____D () C:\ProgramData\Skype 2014-03-31 14:06 - 2013-11-20 17:12 - 00000334 _____ () C:\Windows\Tasks\GlaryInitialize 4.job 2014-03-31 14:05 - 2014-02-16 14:39 - 00010562 _____ () C:\Windows\setupact.log 2014-03-31 14:05 - 2013-11-20 17:12 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 4 2014-03-31 14:05 - 2013-08-07 10:52 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-03-31 14:05 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-31 14:04 - 2014-01-18 11:23 - 00000000 ____D () C:\Users\angel\Documents\a-squared Free 2014-03-31 14:03 - 2014-03-31 14:00 - 224883568 _____ () C:\Users\angel\Downloads\EmsisoftEmergencyKit.exe 2014-03-31 13:49 - 2014-03-31 13:49 - 01678496 _____ (Skype Technologies S.A.) C:\Users\angel\Downloads\SkypeSetup(1).exe 2014-03-31 08:28 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-03-30 23:44 - 2014-03-30 23:44 - 00027423 _____ () C:\Users\angel\Documents\Unbenannt.wma 2014-03-30 23:40 - 2014-03-30 23:40 - 00058853 _____ () C:\Users\angel\Desktop\test.wma 2014-03-30 23:35 - 2014-03-30 20:54 - 00000000 ____D () C:\Users\angel\AppData\Roaming\TS3Client 2014-03-30 20:53 - 2014-03-30 20:53 - 00000967 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-03-30 20:53 - 2014-03-30 20:53 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-03-30 20:48 - 2014-03-30 20:48 - 00613200 _____ (Chip Digital GmbH) C:\Users\angel\Downloads\TeamSpeak 3 64 Bit - CHIP-Downloader.exe 2014-03-30 08:36 - 2014-01-19 19:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 21:23 - 2014-03-29 21:23 - 00000000 ____D () C:\Users\angel\AppData\Local\Skype 2014-03-29 21:22 - 2014-03-29 21:22 - 01678496 _____ (Skype Technologies S.A.) C:\Users\angel\Downloads\SkypeSetup.exe 2014-03-29 18:09 - 2014-03-29 18:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-28 08:21 - 2014-03-27 08:24 - 00000000 ____D () C:\ProgramData\rvlkl 2014-03-27 08:24 - 2014-03-26 21:01 - 00000000 ____D () C:\Users\angel\AppData\Roaming\Systweak 2014-03-26 21:01 - 2014-03-26 21:01 - 01411136 _____ (Logixoft) C:\Users\Public\Desktop\rkfree_setup.exe 2014-03-26 20:56 - 2014-03-26 20:56 - 00316480 _____ () C:\Users\angel\Downloads\revealer-keylogger-windows-downloader_de.exe 2014-03-26 20:42 - 2013-09-15 20:51 - 00000000 ____D () C:\Program Files (x86)\Spyrix Free Keylogger 2014-03-25 09:48 - 2013-09-03 13:17 - 00000000 ____D () C:\Users\angel\AppData\Roaming\DiskDefrag 2014-03-19 00:23 - 2013-08-07 12:42 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-19 00:19 - 2013-08-07 11:08 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-14 13:43 - 2009-07-14 06:45 - 00295432 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-13 21:05 - 2014-03-13 21:04 - 00012488 _____ () C:\Users\angel\Desktop\pizzazeig.odt 2014-03-13 20:58 - 2014-03-13 20:58 - 00007334 _____ () C:\Users\angel\Desktop\OpenDocument Text (neu).odt 2014-03-13 11:51 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-11 20:19 - 2014-02-26 21:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-11 20:19 - 2014-02-26 21:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-11 20:19 - 2014-02-26 21:46 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-10 11:45 - 2014-03-10 11:45 - 00000000 ____D () C:\Windows\SysWOW64\Adobe 2014-03-07 17:04 - 2013-08-07 12:26 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-03-05 11:36 - 2014-03-05 11:36 - 01070496 _____ (Unity Technologies ApS) C:\Users\angel\Downloads\UnityWebPlayer.exe 2014-03-04 09:56 - 2013-08-07 10:28 - 00000000 ____D () C:\Users\angel\AppData\Roaming\HpUpdate 2014-03-04 09:48 - 2014-02-26 21:24 - 00157650 _____ () C:\Windows\PFRO.log 2014-03-03 12:48 - 2014-03-03 12:48 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-03 12:48 - 2013-08-07 11:04 - 00000000 ____D () C:\Users\angel\AppData\Local\Google 2014-03-03 12:48 - 2013-08-07 11:04 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-03 12:47 - 2014-03-03 12:47 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-03-03 12:47 - 2013-08-07 11:07 - 00000000 ____D () C:\Program Files\CCleaner 2014-03-03 12:45 - 2014-03-03 12:45 - 04765152 _____ (Piriform Ltd) C:\Users\angel\Downloads\CCleaner_v4.11.4619.exe 2014-03-03 12:45 - 2014-03-03 12:45 - 00001080 _____ () C:\Users\Public\Desktop\Glary Utilities 4.lnk 2014-03-03 12:45 - 2014-01-07 09:48 - 00002972 _____ () C:\Windows\System32\Tasks\GU4SkipUAC 2014-03-03 12:44 - 2014-03-03 12:44 - 12393008 _____ () C:\Users\angel\Downloads\Glary_Utilities_v4.7.0.96.exe 2014-03-03 12:44 - 2013-11-20 17:12 - 00002630 _____ () C:\Windows\System32\Tasks\GlaryInitialize 4 2014-03-01 08:05 - 2014-03-14 10:34 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 07:17 - 2014-03-14 10:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 07:16 - 2014-03-14 10:34 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 06:58 - 2014-03-14 10:34 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 06:52 - 2014-03-14 10:34 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 06:51 - 2014-03-14 10:34 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 06:42 - 2014-03-14 10:34 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 06:40 - 2014-03-14 10:34 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 06:37 - 2014-03-14 10:34 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 06:33 - 2014-03-14 10:34 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 06:33 - 2014-03-14 10:34 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 06:32 - 2014-03-14 10:34 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 06:30 - 2014-03-14 10:34 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 06:23 - 2014-03-14 10:34 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 06:17 - 2014-03-14 10:34 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 06:11 - 2014-03-14 10:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 06:02 - 2014-03-14 10:34 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 05:54 - 2014-03-14 10:34 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 05:52 - 2014-03-14 10:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 05:51 - 2014-03-14 10:34 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 05:47 - 2014-03-14 10:34 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 05:43 - 2014-03-14 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 05:43 - 2014-03-14 10:34 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 05:42 - 2014-03-14 10:34 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 05:40 - 2014-03-14 10:34 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 05:38 - 2014-03-14 10:34 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 05:37 - 2014-03-14 10:34 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 05:35 - 2014-03-14 10:34 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 05:18 - 2014-03-14 10:34 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 05:16 - 2014-03-14 10:34 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 05:14 - 2014-03-14 10:34 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 05:10 - 2014-03-14 10:34 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 05:03 - 2014-03-14 10:34 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 05:00 - 2014-03-14 10:34 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 04:57 - 2014-03-14 10:34 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 04:38 - 2014-03-14 10:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 04:32 - 2014-03-14 10:34 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 04:27 - 2014-03-14 10:34 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 04:25 - 2014-03-14 10:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 04:25 - 2014-03-14 10:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-21 19:57 ==================== End Of Log ============================ --- --- --- addition: Zitat:
und natürlich bin ich bereit alles zu löschen was muss. ps soll ich sagen welche progamme ich drauf habe ?(also nur die reingungprogramme) |
01.04.2014, 15:08 | #4 | |
/// TB-Ausbilder | Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? Servus, Zitat:
Ich sehe noch einige Adware-Reste, die entfernen werden müssen. Wir beginnen erst mal so: Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 4 Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
Bitte poste mit deiner nächsten Antwort
|
01.04.2014, 19:08 | #5 |
| Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? die Logdatei von AdwCleaner, Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 01/04/2014 um 19:04:52 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : angel - ANGEL-PC # Gestartet von : C:\Users\angel\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\rvlkl Ordner Gelöscht : C:\Windows\SysWOW64\AI_RecycleBin Ordner Gelöscht : C:\Users\angel\AppData\Roaming\OpenCandy Ordner Gelöscht : C:\Users\angel\AppData\Roaming\Systweak Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\rvlkl.lnk Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Windows\System32\Tasks\Browser Updater Datei Gelöscht : C:\Windows\System32\Tasks\ProtectedSearch ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default] -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default\prefs.js ] ************************* AdwCleaner[R0].txt - [980 octets] - [04/01/2014 11:09:01] AdwCleaner[R1].txt - [1100 octets] - [05/01/2014 16:28:47] AdwCleaner[R2].txt - [4205 octets] - [01/04/2014 19:04:09] AdwCleaner[S0].txt - [1040 octets] - [04/01/2014 11:09:55] AdwCleaner[S1].txt - [3008 octets] - [01/04/2014 19:04:52] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3068 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.3 (03.23.2014:1) OS: Windows 7 Home Premium x64 Ran by angel on 01.04.2014 at 19:10:38,72 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\angel\AppData\Roaming\mozilla\firefox\profiles\4qua5mwg.default\minidumps [88 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 01.04.2014 at 19:15:38,63 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 01.04.2014 Suchlauf-Zeit: 19:40:01 Logdatei: Mbam.txt Administrator: Ja Version: 2.00.0.1000 Malware Datenbank: v2014.04.01.06 Rootkit Datenbank: v2014.03.27.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: angel Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 281437 Verstrichene Zeit: 12 Min, 5 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 12 PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[d82870902dd3c13fb6ff4cc3fb096f91] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=hp&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=hp&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[bb450cf4f80852aeece73acbd0346e92] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=hp&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=hp&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[52ae6b959967966ae5dad639ac5814ec] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[7c847b85ca36ad5300d13dc80004f40c] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[39c70ff13ec2b14f4b729877cb39f709] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[9868748cfe02de22e3ef6f96f80cb24e] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[5ca49f61ef11669afdc15fb0bf45dc24] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[808025db936d5ba59440b4514eb67090] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[3cc4bd430af642be318f000f46bec13f] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[7e8208f8f709a759f3e251b4c73d50b0] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[ef117d83dd237090724f9e71f311b54b] PUP.Optional.HelperBar.A, HKU\S-1-5-21-979047111-3019266187-3407045396-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=8327f32b-c329-014a-3be5-295887cd8784&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/01/2014&type=hp1000),Ersetzt,[ad53d03047b95ea2a22ec5406c98e51b] Ordner: 0 (No malicious items detected) Dateien: 13 Keylogger.Logixoft, C:\Users\Public\Desktop\rkfree_setup.exe, In Quarantäne, [8f71f30d6898f40ceb0d53c2dc28e020], PUP.Optional.RegCleanerPro, C:\$Recycle.Bin\S-1-5-21-979047111-3019266187-3407045396-1000\$R2C34L8.exe, In Quarantäne, [39c7a957b44c15eb31ae33cf90713bc5], PUP.Optional.SearchProtect.A, C:\$Recycle.Bin\S-1-5-21-979047111-3019266187-3407045396-1000\$RP6NU9A.exe, In Quarantäne, [7c84dc24dd2315eb8bc673ae35cccb35], PUP.Optional.SearchProtect.A, C:\$Recycle.Bin\S-1-5-21-979047111-3019266187-3407045396-1000\$RJ3O7E1.exe, In Quarantäne, [f40c936d0bf5df21d37e7fa20cf5bc44], PUP.Optional.SearchProtect.A, C:\$Recycle.Bin\S-1-5-21-979047111-3019266187-3407045396-1000\$RQPDRAE.exe, In Quarantäne, [4fb1699752ae6d93aca541e0d130649c], PUP.Optional.SearchProtect.A, C:\$Recycle.Bin\S-1-5-21-979047111-3019266187-3407045396-1000\$RHPQCWU.exe, In Quarantäne, [ee1233cd67992ad62d24cf52fb0622de], PUP.Optional.SearchProtect.A, C:\$Recycle.Bin\S-1-5-21-979047111-3019266187-3407045396-1000\$RL3EJ5N.exe, In Quarantäne, [916f7c84c8387d83440d2ff2e81940c0], PUP.Optional.Conduit.A, C:\$Recycle.Bin\S-1-5-21-979047111-3019266187-3407045396-1000\$RK0C2DU\sp-downloader.exe, In Quarantäne, [10f0bc44bc4440c0413c1400d42dd52b], PUP.Optional.RegCleanerPro, C:\$Recycle.Bin\S-1-5-21-979047111-3019266187-3407045396-1000\$RU2KAOP\RegCleanSetup9.exe, In Quarantäne, [25db748c38c88b7509d64cb65da422de], PUP.Optional.Conduit.A, C:\$Recycle.Bin\S-1-5-21-979047111-3019266187-3407045396-1000\$RDQIIT4\SpSetup.exe, In Quarantäne, [06fa0ef2f10f37c98fb2b85e659c50b0], Trojan.Agent, C:\Windows\SysWOW64\svchosptd.exe, In Quarantäne, [6a96a957af51c43c0e200612bd4739c7], PUP.Optional.BundleInstaller.A, C:\Users\angel\Downloads\revealer-keylogger-windows-downloader_de.exe, In Quarantäne, [748cbb456b951ce41e2851140100da26], PUP.Optional.Simplytech, C:\Windows\Launcher.exe, In Quarantäne, [db25d52b4bb501ffeb77763353b0c13f], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter Zoek.exe v5.0.0.0 Updated 07-March-2014 Tool run by angel on 01.04.2014 at 19:46:50,27. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\angel\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 01.04.2014 19:48:46 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default\prefs.js: user_pref("browser.startup.homepage", "www.google.de"); Added to C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.com"); user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.newtab.url", "hxxp://www.google.com/"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); ProfilePath: C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default user.js not found ---- Lines ask.com removed from prefs.js ---- user_pref("weboftrust.search.ask.display", "Ask.com Web Search"); ---- FireFox user.js and prefs.js backups ---- prefs__1956_.backup ==== Deleting Files \ Folders ====================== C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted C:\PROGRA~2\Yahoo! deleted C:\User Data\Default\Extensions deleted C:\Users\angel\AppData\Roaming\Yahoo! deleted C:\PROGRA~3\Package Cache deleted C:\windows\SysNative\Tasks\Browser Updater deleted C:\Windows\wininit.ini deleted C:\windows\SysNative\tasks\ProtectedSearch deleted "C:\Users\angel\AppData\Local\LumaEmu" deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{F003DA68-8256-4b37-A6C4-350FA04494DF}"="C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt" [07.08.2013 22:37] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "smartwebprinting@hp.com"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [07.08.2013 10:28] ==== Firefox Extensions ====================== ProfilePath: C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default - WOT - %ProfilePath%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default 95812430959AE88CDD0301AB3A71913B - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll - Shockwave Flash 65C1D9F74004E775F9A8598476ABE5EE - C:\Users\angel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player 5174E3BE46B2CCCDAF9CEB5B622CEA9B - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1209149.dll - Shockwave for Director / Shockwave for Director D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17 FC5866F7793AF2CBCD425CC4B8D32A9E - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll - Zylom Plugin 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bddpogknpjlgfpbboediomaiiaecfajn - C:\Program Files (x86)\HomeTab\chrome\HomeTab.crx[] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" "Use Search Asst"="yes" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI] "(Default)"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI] "(Default)"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="" "Default"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "(Default)"="" "Default"="hxxp://www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "CustomizeSearch"="hxxp://www.bing.com/search?q={searchTerms}" "SearchAssistant"="hxxp://www.bing.com/search?q={searchTerms}" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search] "CustomizeSearch"="hxxp://www.bing.com/search?q={searchTerms}" "SearchAssistant"="hxxp://www.bing.com/search?q={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://www.google.com" "SearchAssistant"="hxxp://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://www.google.com" "Use Search Asst"="no" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "CustomizeSearch"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" "SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search] "CustomizeSearch"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" "SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Reset Google Chrome ====================== Nothing found to reset ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bddpogknpjlgfpbboediomaiiaecfajn deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\angel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\angel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8UAWELL6 will be deleted at reboot C:\Users\angel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AUPCC2RR will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\angel\AppData\Local\Mozilla\Firefox\Profiles\4qua5mwg.default\Cache will be emptied at reboot ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache is not empty, a reboot is needed ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=136 folders=40 28803321 bytes) ==== Empty Temp Folders ====================== C:\Users\angel\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\angel\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\angel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8UAWELL6" not found "C:\Users\angel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AUPCC2RR" not found "C:\Users\angel\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\T3F7WLDF\cdn.kaisergames.de" not found "C:\Users\angel\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\T3F7WLDF\moviebox.kinoundco.de" not found "C:\Users\angel\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\T3F7WLDF\www.miniclip.com" not found "C:\Users\angel\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\T3F7WLDF\www.rossmann.de" not found ==== EOF on 01.04.2014 at 20:02:12,24 ====================== 1. frage weiß ja nicht ob noch zu früh ist. aber nachdem die bereingung zu ende. gibt kostenlose progamme die gut sind und zusammen funktionieren ??? die ich benutzen kann ?? und welche progamme sollte ich löschen?? z.b. glary ulities,spybot. usw. ich weiß nicht welche progamme ja gut miteinander funktionieren und den kompletten pc absichern und sicher halten, und dazu den pc nicht lahm macht. UND VIELEN dank für die HILFE . aber das werde ich am ende gerne nochmal sagen ihr seit jetzt schon ein super team Geändert von Mahlec (01.04.2014 um 19:16 Uhr) |
01.04.2014, 19:11 | #6 |
/// TB-Ausbilder | Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? Servus, Wir spüren die letzten Reste auf, damit wir sie später entfernen können: Schritt 1 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu einen Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden zwei Logdateien erzeugt. Poste mir diese. Schritt 2 Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit) | SystemLook (64 bit)
Gibt es noch Probleme mit Malware? Wenn ja, welche? Wie läuft der Rechner derzeit? Bitte poste mit deiner nächsten Antwort
|
01.04.2014, 19:39 | #7 |
| Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? die zwei Logdateien von FRST, FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by angel (administrator) on ANGEL-PC on 01-04-2014 20:28:38 Running from C:\Users\angel\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 4\Integrator.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe () C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.205\deploy\LoLLauncher.exe () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.78\deploy\LolClient.exe (Farbar) C:\Users\angel\Downloads\FRST64(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-979047111-3019266187-3407045396-1000\...\Run: [] - [X] HKU\S-1-5-21-979047111-3019266187-3407045396-1000\...\Run: [GUDelayStartup] - C:\Program Files (x86)\Glary Utilities 4\StartupManager.exe [37152 2014-02-26] (Glarysoft Ltd) ==================== Internet (Whitelisted) ==================== HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default FF NewTab: hxxp://www.google.com/ FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.com FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1209149.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @zylom.com/ZylomGamesPlayer - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\angel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-03-31] FF Extension: Adblock Plus - C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\4qua5mwg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-19] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-08-07] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-08-07] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-08-07] ==================== Services (Whitelisted) ================= R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) S4 WSWNA1100; C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe [268768 2010-03-22] () ==================== Drivers (Whitelisted) ==================== R0 BootDefragDriver; C:\Windows\System32\drivers\BootDefragDriver.sys [17088 2014-02-26] (Glarysoft Ltd) S3 cleanhlp; C:\EEK\Run\cleanhlp64.sys [57024 2014-03-31] (Emsisoft GmbH) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-03-05] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-01] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-03-05] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-01 20:26 - 2014-04-01 20:26 - 02157056 _____ (Farbar) C:\Users\angel\Downloads\FRST64(1).exe 2014-04-01 20:02 - 2014-04-01 20:02 - 00012543 _____ () C:\Users\angel\Desktop\zoek-results.txt 2014-04-01 19:59 - 2014-04-01 19:59 - 00000082 _____ () C:\folders.txt 2014-04-01 19:59 - 2014-04-01 19:46 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-04-01 19:48 - 2014-04-01 20:02 - 00012543 _____ () C:\zoek-results.log 2014-04-01 19:46 - 2014-04-01 19:56 - 00000000 ____D () C:\zoek_backup 2014-04-01 19:46 - 2014-04-01 19:46 - 01285120 _____ () C:\Users\angel\Desktop\zoek.exe 2014-04-01 19:45 - 2014-04-01 19:45 - 00010169 _____ () C:\Users\angel\Desktop\Mbam.txt 2014-04-01 19:24 - 2014-04-01 20:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-01 19:23 - 2014-04-01 19:23 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\angel\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-01 19:23 - 2014-04-01 19:23 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-01 19:23 - 2014-04-01 19:23 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-01 19:23 - 2014-04-01 19:23 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-01 19:23 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-01 19:23 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-01 19:23 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-01 19:17 - 2014-04-01 19:17 - 00000854 _____ () C:\Users\angel\Desktop\JRT2.txt 2014-04-01 19:15 - 2014-04-01 19:15 - 00000854 _____ () C:\Users\angel\Desktop\JRT.txt 2014-04-01 19:10 - 2014-04-01 19:10 - 00000000 ____D () C:\Windows\ERUNT 2014-04-01 19:08 - 2014-04-01 19:08 - 01038974 _____ (Thisisu) C:\Users\angel\Desktop\JRT.exe 2014-04-01 19:06 - 2014-04-01 19:06 - 00003164 _____ () C:\Users\angel\Desktop\AdwCleaner[S1].txt 2014-04-01 19:02 - 2014-04-01 19:02 - 01426178 _____ () C:\Users\angel\Downloads\adwcleaner.exe 2014-04-01 12:32 - 2014-04-01 12:32 - 00094773 _____ () C:\Users\angel\Desktop\startlachen.wma 2014-04-01 12:31 - 2014-04-01 12:31 - 00094773 _____ () C:\Users\angel\Desktop\Unbenannt (2).wma 2014-03-31 15:15 - 2014-03-31 15:54 - 00032211 _____ () C:\Users\angel\Downloads\Addition.txt 2014-03-31 15:14 - 2014-04-01 20:28 - 00012904 _____ () C:\Users\angel\Downloads\FRST.txt 2014-03-31 15:12 - 2014-04-01 20:28 - 00000000 ____D () C:\FRST 2014-03-31 15:11 - 2014-03-31 15:11 - 02157056 _____ (Farbar) C:\Users\angel\Downloads\FRST64.exe 2014-03-31 14:10 - 2014-03-31 14:10 - 00000546 _____ () C:\Users\angel\Desktop\Emsisoft Emergency Kit.lnk 2014-03-31 14:09 - 2014-03-31 14:10 - 00000000 ____D () C:\EEK 2014-03-31 14:00 - 2014-03-31 14:03 - 224883568 _____ () C:\Users\angel\Downloads\EmsisoftEmergencyKit.exe 2014-03-31 13:49 - 2014-03-31 13:49 - 01678496 _____ (Skype Technologies S.A.) C:\Users\angel\Downloads\SkypeSetup(1).exe 2014-03-30 23:44 - 2014-03-30 23:44 - 00027423 _____ () C:\Users\angel\Documents\Unbenannt.wma 2014-03-30 23:40 - 2014-03-30 23:40 - 00058853 _____ () C:\Users\angel\Desktop\test.wma 2014-03-30 20:54 - 2014-03-31 21:47 - 00000000 ____D () C:\Users\angel\AppData\Roaming\TS3Client 2014-03-30 20:53 - 2014-03-30 20:53 - 00000967 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-03-30 20:53 - 2014-03-30 20:53 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-03-30 20:48 - 2014-03-30 20:48 - 00613200 _____ (Chip Digital GmbH) C:\Users\angel\Downloads\TeamSpeak 3 64 Bit - CHIP-Downloader.exe 2014-03-29 21:23 - 2014-03-31 14:07 - 00000000 ____D () C:\Users\angel\AppData\Roaming\Skype 2014-03-29 21:23 - 2014-03-31 14:07 - 00000000 ____D () C:\ProgramData\Skype 2014-03-29 21:23 - 2014-03-29 21:23 - 00000000 ____D () C:\Users\angel\AppData\Local\Skype 2014-03-29 21:22 - 2014-03-29 21:22 - 01678496 _____ (Skype Technologies S.A.) C:\Users\angel\Downloads\SkypeSetup.exe 2014-03-29 18:09 - 2014-03-29 18:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-14 10:34 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-14 10:34 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-14 10:34 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-14 10:34 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-14 10:34 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-14 10:34 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-14 10:34 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-14 10:34 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-14 10:34 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-14 10:34 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-14 10:34 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-14 10:34 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-14 10:34 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-14 10:34 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-14 10:34 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-14 10:34 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-14 10:34 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-14 10:34 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-14 10:34 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-14 10:34 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-14 10:34 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-14 10:34 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-14 10:34 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-14 10:34 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-14 10:34 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-14 10:34 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-14 10:34 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-14 10:34 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-14 10:34 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-14 10:34 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-14 10:34 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-14 10:34 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-14 10:34 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-14 10:34 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-14 10:34 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-14 10:34 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-14 10:34 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-14 10:34 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-14 10:34 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-14 10:34 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-14 10:34 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-14 10:34 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-14 10:34 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-14 10:34 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-14 10:33 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-14 10:33 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-14 10:33 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-14 10:33 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-13 21:04 - 2014-03-13 21:05 - 00012488 _____ () C:\Users\angel\Desktop\pizzazeig.odt 2014-03-13 20:58 - 2014-03-13 20:58 - 00007334 _____ () C:\Users\angel\Desktop\OpenDocument Text (neu).odt 2014-03-10 11:45 - 2014-03-10 11:45 - 00000000 ____D () C:\Windows\SysWOW64\Adobe 2014-03-05 11:36 - 2014-03-05 11:36 - 01070496 _____ (Unity Technologies ApS) C:\Users\angel\Downloads\UnityWebPlayer.exe 2014-03-03 12:48 - 2014-03-03 12:48 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-03 12:47 - 2014-03-03 12:47 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-03-03 12:45 - 2014-03-03 12:45 - 04765152 _____ (Piriform Ltd) C:\Users\angel\Downloads\CCleaner_v4.11.4619.exe 2014-03-03 12:45 - 2014-03-03 12:45 - 00001080 _____ () C:\Users\Public\Desktop\Glary Utilities 4.lnk 2014-03-03 12:44 - 2014-03-03 12:44 - 12393008 _____ () C:\Users\angel\Downloads\Glary_Utilities_v4.7.0.96.exe 2014-03-03 12:44 - 2014-02-26 07:17 - 00017088 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\BootDefragDriver.sys ==================== One Month Modified Files and Folders ======= 2014-04-01 20:28 - 2014-03-31 15:14 - 00012904 _____ () C:\Users\angel\Downloads\FRST.txt 2014-04-01 20:28 - 2014-03-31 15:12 - 00000000 ____D () C:\FRST 2014-04-01 20:26 - 2014-04-01 20:26 - 02157056 _____ (Farbar) C:\Users\angel\Downloads\FRST64(1).exe 2014-04-01 20:19 - 2014-02-26 21:46 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-01 20:08 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-01 20:08 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-01 20:06 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-04-01 20:06 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-04-01 20:06 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-01 20:04 - 2013-09-03 17:02 - 01608171 _____ () C:\Windows\WindowsUpdate.log 2014-04-01 20:02 - 2014-04-01 20:02 - 00012543 _____ () C:\Users\angel\Desktop\zoek-results.txt 2014-04-01 20:02 - 2014-04-01 19:48 - 00012543 _____ () C:\zoek-results.log 2014-04-01 20:02 - 2013-11-20 17:12 - 00000334 _____ () C:\Windows\Tasks\GlaryInitialize 4.job 2014-04-01 20:02 - 2013-11-20 17:12 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 4 2014-04-01 20:01 - 2014-04-01 19:24 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-01 20:00 - 2014-02-26 21:24 - 00161852 _____ () C:\Windows\PFRO.log 2014-04-01 20:00 - 2014-02-16 14:39 - 00011178 _____ () C:\Windows\setupact.log 2014-04-01 20:00 - 2013-08-07 10:52 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-01 20:00 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-01 19:59 - 2014-04-01 19:59 - 00000082 _____ () C:\folders.txt 2014-04-01 19:56 - 2014-04-01 19:46 - 00000000 ____D () C:\zoek_backup 2014-04-01 19:46 - 2014-04-01 19:59 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-04-01 19:46 - 2014-04-01 19:46 - 01285120 _____ () C:\Users\angel\Desktop\zoek.exe 2014-04-01 19:45 - 2014-04-01 19:45 - 00010169 _____ () C:\Users\angel\Desktop\Mbam.txt 2014-04-01 19:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Vss 2014-04-01 19:23 - 2014-04-01 19:23 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\angel\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-01 19:23 - 2014-04-01 19:23 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-01 19:23 - 2014-04-01 19:23 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-01 19:23 - 2014-04-01 19:23 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-01 19:17 - 2014-04-01 19:17 - 00000854 _____ () C:\Users\angel\Desktop\JRT2.txt 2014-04-01 19:15 - 2014-04-01 19:15 - 00000854 _____ () C:\Users\angel\Desktop\JRT.txt 2014-04-01 19:10 - 2014-04-01 19:10 - 00000000 ____D () C:\Windows\ERUNT 2014-04-01 19:08 - 2014-04-01 19:08 - 01038974 _____ (Thisisu) C:\Users\angel\Desktop\JRT.exe 2014-04-01 19:06 - 2014-04-01 19:06 - 00003164 _____ () C:\Users\angel\Desktop\AdwCleaner[S1].txt 2014-04-01 19:04 - 2014-01-04 11:08 - 00000000 ____D () C:\AdwCleaner 2014-04-01 19:02 - 2014-04-01 19:02 - 01426178 _____ () C:\Users\angel\Downloads\adwcleaner.exe 2014-04-01 12:32 - 2014-04-01 12:32 - 00094773 _____ () C:\Users\angel\Desktop\startlachen.wma 2014-04-01 12:31 - 2014-04-01 12:31 - 00094773 _____ () C:\Users\angel\Desktop\Unbenannt (2).wma 2014-04-01 08:54 - 2013-09-03 13:17 - 00000000 ____D () C:\Users\angel\AppData\Roaming\DiskDefrag 2014-03-31 21:47 - 2014-03-30 20:54 - 00000000 ____D () C:\Users\angel\AppData\Roaming\TS3Client 2014-03-31 15:54 - 2014-03-31 15:15 - 00032211 _____ () C:\Users\angel\Downloads\Addition.txt 2014-03-31 15:11 - 2014-03-31 15:11 - 02157056 _____ (Farbar) C:\Users\angel\Downloads\FRST64.exe 2014-03-31 14:10 - 2014-03-31 14:10 - 00000546 _____ () C:\Users\angel\Desktop\Emsisoft Emergency Kit.lnk 2014-03-31 14:10 - 2014-03-31 14:09 - 00000000 ____D () C:\EEK 2014-03-31 14:07 - 2014-03-29 21:23 - 00000000 ____D () C:\Users\angel\AppData\Roaming\Skype 2014-03-31 14:07 - 2014-03-29 21:23 - 00000000 ____D () C:\ProgramData\Skype 2014-03-31 14:04 - 2014-01-18 11:23 - 00000000 ____D () C:\Users\angel\Documents\a-squared Free 2014-03-31 14:03 - 2014-03-31 14:00 - 224883568 _____ () C:\Users\angel\Downloads\EmsisoftEmergencyKit.exe 2014-03-31 13:49 - 2014-03-31 13:49 - 01678496 _____ (Skype Technologies S.A.) C:\Users\angel\Downloads\SkypeSetup(1).exe 2014-03-31 08:28 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-03-30 23:44 - 2014-03-30 23:44 - 00027423 _____ () C:\Users\angel\Documents\Unbenannt.wma 2014-03-30 23:40 - 2014-03-30 23:40 - 00058853 _____ () C:\Users\angel\Desktop\test.wma 2014-03-30 20:53 - 2014-03-30 20:53 - 00000967 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-03-30 20:53 - 2014-03-30 20:53 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-03-30 20:48 - 2014-03-30 20:48 - 00613200 _____ (Chip Digital GmbH) C:\Users\angel\Downloads\TeamSpeak 3 64 Bit - CHIP-Downloader.exe 2014-03-30 08:36 - 2014-01-19 19:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 21:23 - 2014-03-29 21:23 - 00000000 ____D () C:\Users\angel\AppData\Local\Skype 2014-03-29 21:22 - 2014-03-29 21:22 - 01678496 _____ (Skype Technologies S.A.) C:\Users\angel\Downloads\SkypeSetup.exe 2014-03-29 18:09 - 2014-03-29 18:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-26 20:42 - 2013-09-15 20:51 - 00000000 ____D () C:\Program Files (x86)\Spyrix Free Keylogger 2014-03-19 00:23 - 2013-08-07 12:42 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-19 00:19 - 2013-08-07 11:08 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-14 13:43 - 2009-07-14 06:45 - 00295432 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-13 21:05 - 2014-03-13 21:04 - 00012488 _____ () C:\Users\angel\Desktop\pizzazeig.odt 2014-03-13 20:58 - 2014-03-13 20:58 - 00007334 _____ () C:\Users\angel\Desktop\OpenDocument Text (neu).odt 2014-03-13 11:51 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-11 20:19 - 2014-02-26 21:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-11 20:19 - 2014-02-26 21:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-11 20:19 - 2014-02-26 21:46 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-10 11:45 - 2014-03-10 11:45 - 00000000 ____D () C:\Windows\SysWOW64\Adobe 2014-03-07 17:04 - 2013-08-07 12:26 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-03-05 11:36 - 2014-03-05 11:36 - 01070496 _____ (Unity Technologies ApS) C:\Users\angel\Downloads\UnityWebPlayer.exe 2014-03-05 09:26 - 2014-04-01 19:23 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-05 09:26 - 2014-04-01 19:23 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-05 09:26 - 2014-04-01 19:23 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-04 09:56 - 2013-08-07 10:28 - 00000000 ____D () C:\Users\angel\AppData\Roaming\HpUpdate 2014-03-03 12:48 - 2014-03-03 12:48 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-03 12:48 - 2013-08-07 11:04 - 00000000 ____D () C:\Users\angel\AppData\Local\Google 2014-03-03 12:48 - 2013-08-07 11:04 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-03 12:47 - 2014-03-03 12:47 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-03-03 12:47 - 2013-08-07 11:07 - 00000000 ____D () C:\Program Files\CCleaner 2014-03-03 12:45 - 2014-03-03 12:45 - 04765152 _____ (Piriform Ltd) C:\Users\angel\Downloads\CCleaner_v4.11.4619.exe 2014-03-03 12:45 - 2014-03-03 12:45 - 00001080 _____ () C:\Users\Public\Desktop\Glary Utilities 4.lnk 2014-03-03 12:45 - 2014-01-07 09:48 - 00002972 _____ () C:\Windows\System32\Tasks\GU4SkipUAC 2014-03-03 12:44 - 2014-03-03 12:44 - 12393008 _____ () C:\Users\angel\Downloads\Glary_Utilities_v4.7.0.96.exe 2014-03-03 12:44 - 2013-11-20 17:12 - 00002630 _____ () C:\Windows\System32\Tasks\GlaryInitialize 4 ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-21 19:57 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by angel at 2014-04-01 20:29:04 Running from C:\Users\angel\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.9.149 - Adobe Systems, Inc.) Apple Application Support (HKLM-x32\...\{A922C4B7-50E0-4787-A94C-59DBF3C65DBE}) (Version: 3.0 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) BufferChm (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden C4600 (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Destinations (x32 Version: 140.0.77.000 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) Die Sims™ 3 Einfach tierisch (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts) Die Sims™ 3 Reiseabenteuer (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden Free YouTube to iPhone Converter version 2.12.20.1230 (HKLM-x32\...\Free YouTube to iPhone Converter_is1) (Version: 2.12.20.1230 - DVDVideoSoft Ltd.) Glary Utilities 4.7 (HKLM-x32\...\Glary Utilities 4) (Version: 4.7.0.96 - Glarysoft Ltd) GPBaseService2 (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Photosmart C4600 All-In-One Driver Software 14.0 Rel. 5 (HKLM\...\{1E1746EF-F5BF-4677-8F30-04FE399130DA}) (Version: 14.0 - HP) HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HP Update (HKLM-x32\...\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.001 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden HPProductAssistant (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden ipswDownloader 2.0 (HKLM-x32\...\ipswDownloader) (Version: 2.0 - Sergey 'iOrange' Kudlay) iTunes (HKLM\...\{0D924CB2-2EA4-4044-BAF7-770202D6BD0D}) (Version: 11.1.4.62 - Apple Inc.) Java 7 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417025FF}) (Version: 7.0.250 - Oracle) Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Logitech SetPoint 6.61 (HKLM\...\sp6) (Version: 6.61.15 - Logitech) Malwarebytes Anti-Malware Version 2.00.0.1000 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 - Malwarebytes Corporation) MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.4.304.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1 - Nokia) Hidden Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1 - Nokia) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) NETGEAR WNA1100 wireless USB 2.0 adapter (HKLM-x32\...\{A2AE9709-283B-4B48-AA34-729C070A62FB}) (Version: 1.0.0.133 - NETGEAR) Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia) Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.8.48.0 - Nokia) Nokia Suite (x32 Version: 3.8.48.0 - Nokia) Hidden NVIDIA 3D Vision Controller-Treiber 320.49 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 320.49 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 320.49 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 320.49 - NVIDIA Corporation) NVIDIA GeForce Experience 1.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.5 - NVIDIA Corporation) NVIDIA Grafiktreiber 320.49 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 320.49 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.124.810 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.0604 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0604 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2049 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 320.49 (Version: 320.49 - NVIDIA Corporation) Hidden NVIDIA Update 4.11.9 (Version: 4.11.9 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 4.11.9 - NVIDIA Corporation) Hidden OpenOffice 4.0.0 (HKLM-x32\...\{B28DBCBA-60F8-40ED-B35B-F510C327946C}) (Version: 4.00.9702 - Apache Software Foundation) Origin (HKLM-x32\...\Origin) (Version: 9.3.1.4482 - Electronic Arts, Inc.) PhoneClean 3.2.0 (HKLM-x32\...\{2FAFFE02-4D6B-4C0A-906B-1B33DAF0DD14}}_is1) (Version: 3.2.0 - iMobie Inc.) PS_AIO_05_C4600_Software_Min (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP) SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 1.0.0.0 - Electronic Arts) SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden SolutionCenter (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.) Status (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) WebReg (x32 Version: 140.0.212.017 - Hewlett-Packard) Hidden Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) Zylom Games Player Plugin (HKLM-x32\...\Zylom Games Player Plugin) (Version: - Zylom Games) ==================== Restore Points ========================= 29-03-2014 14:57:46 Windows Update 29-03-2014 22:29:15 Removed Skype™ 6.14 30-03-2014 17:00:03 Windows-Sicherung 31-03-2014 12:06:53 Removed Skype™ 6.14 01-04-2014 17:48:29 zoek.exe restore point ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-01-04 10:45 - 01249516 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 08sr.combineads.info # hosts anti-adware / pups 127.0.0.1 08srvr.combineads.info # hosts anti-adware / pups 127.0.0.1 12srvr.combineads.info # hosts anti-adware / pups 127.0.0.1 2010-fr.com # hosts anti-adware / pups 127.0.0.1 2012-new.biz # hosts anti-adware / pups 127.0.0.1 212link.com # hosts anti-adware / pups 127.0.0.1 2319825.ourtoolbar.com # hosts anti-adware / pups 127.0.0.1 24h00business.com # hosts anti-adware / pups 127.0.0.1 a.adorika.net # hosts anti-adware / pups 127.0.0.1 a.ad-sys.com # hosts anti-adware / pups 127.0.0.1 a.daasafterdusk.com # hosts anti-adware / pups 127.0.0.1 ad.adn360.com # hosts anti-adware / pups 127.0.0.1 adeartss.eu # hosts anti-adware / pups 127.0.0.1 adesoeasy.eu # hosts anti-adware / pups 127.0.0.1 adf.girldatesforfree.net # hosts anti-adware / pups 127.0.0.1 adm.soft365.com # hosts anti-adware / pups 127.0.0.1 adomicileavail.googlepages.com # hosts anti-adware / pups 127.0.0.1 ads7.complexadveising.com # hosts anti-adware / pups 127.0.0.1 ads.adplxmd.com # hosts anti-adware / pups 127.0.0.1 ads.aff.co # hosts anti-adware / pups 127.0.0.1 ads.alpha00001.com # hosts anti-adware / pups 127.0.0.1 ads.cloud4ads.com # hosts anti-adware / pups 127.0.0.1 ads.eorezo.com # hosts anti-adware / pups 127.0.0.1 ads.hooqy.com # hosts anti-adware / pups 127.0.0.1 ads.pornerbros.com # hosts anti-adware / pups 127.0.0.1 ads.realken.com # hosts anti-adware / pups 127.0.0.1 ads.regiedepub.com # hosts anti-adware / pups 127.0.0.1 ads.sucomspot.com # hosts anti-adware / pups 127.0.0.1 ads.tersecta.com # hosts anti-adware / pups There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {15EC70B7-D8F6-4744-BEF7-96AA806B3738} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {253CD88B-67A5-4F20-B52F-CC8721C901B0} - System32\Tasks\Microsoft\Windows\RVLKL\RVLKL => C:\ProgramData\rvlkl\rvlkl.exe Task: {449AAA97-D9D6-46B3-B1D3-7645D14526C5} - System32\Tasks\GU4SkipUAC => C:\Program Files (x86)\Glary Utilities 4\Integrator.exe [2014-02-27] (Glarysoft Ltd) Task: {4867FFD1-DD08-483A-B86F-EAE7112C073C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {4CB4396D-7F8A-4CE4-936A-E21D73FE97EA} - \Dealply No Task File Task: {6AB6C7CC-8571-4D44-B44E-D0E900C92854} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {71604B2A-CD61-4B11-B820-16399C128A97} - \Software Updater No Task File Task: {7EEA86A3-A189-4E8A-9956-C882B0AD24EC} - \Software Updater Ui No Task File Task: {802E7B14-B3B2-4CBD-B642-0950701DB164} - System32\Tasks\GlaryInitialize 4 => C:\Program Files (x86)\Glary Utilities 4\Initialize.exe [2014-02-28] (Glarysoft Ltd) Task: {87431A4D-2D4B-4B97-81CE-05BBF098034A} - \BrowserDefendert No Task File Task: {906F3068-BD1B-44A4-8146-CF9B08A5EA3D} - \ProtectedSearch\Protected Search No Task File Task: {91038283-2D9E-4AA5-8A34-6EB41BA9907A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-11] (Adobe Systems Incorporated) Task: {91F9B71C-B6C3-41DC-9CD8-7B9F6585600D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd) Task: {922F5157-9D5E-4E7B-A56E-827560297E4B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {A4E4B7B1-D70E-4565-AE2F-C51F974C8B55} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {C0B984DF-02F8-4A3F-BF7F-E7F920201BC3} - \Browser Updater\Browser Updater No Task File Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GlaryInitialize 4.job => C:\Program Files (x86)\Glary Utilities 4\Initialize.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-07 10:52 - 2013-06-21 12:23 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-08-07 10:14 - 2010-06-14 14:56 - 04573664 _____ () C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe 2013-06-12 18:11 - 2013-08-07 12:22 - 01294336 _____ () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe 2013-08-07 12:24 - 2014-03-29 11:18 - 05329400 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.205\deploy\LoLLauncher.exe 2013-08-07 12:39 - 2013-08-07 12:39 - 00074752 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.78\deploy\LolClient.exe 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-12-26 21:07 - 2012-08-23 11:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-12-26 21:07 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-12-26 21:07 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-12-26 21:07 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-12-26 21:07 - 2012-04-03 18:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2014-02-26 07:39 - 2014-02-26 07:39 - 00080160 _____ () C:\Program Files (x86)\Glary Utilities 4\zlib1.dll 2013-08-07 10:14 - 2009-08-28 16:50 - 00282624 _____ () C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvcLib.dll 2014-03-29 18:09 - 2014-03-29 18:09 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-03-11 20:19 - 2014-03-11 20:19 - 16276872 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll 2013-09-04 16:20 - 2014-03-29 11:18 - 00264696 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.205\deploy\RiotLauncher.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:373E1720 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: jswpsapi => 3 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: ServiceLayer => 3 MSCONFIG\Services: SystemStoreService => 2 MSCONFIG\Services: WSWNA1100 => 2 MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: NTRedirect => C:\Windows\SysWOW64\rundll32.exe "C:\Users\angel\AppData\Roaming\BabSolution\Shared\enhancedNT.dll",Run MSCONFIG\startupreg: svchospt => C:\Windows\SysWOW64\svchospt.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/01/2014 08:01:20 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/01/2014 07:41:49 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (04/01/2014 08:04:14 PM) (Source: atapi) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden. Error: (04/01/2014 08:00:49 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\athExt.dll Fehlercode: 126 Error: (04/01/2014 08:00:34 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT) Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten. Error: (04/01/2014 07:56:49 PM) (Source: atapi) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden. Error: (04/01/2014 07:56:43 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (04/01/2014 07:56:43 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (04/01/2014 07:56:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (04/01/2014 07:56:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (04/01/2014 07:56:41 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (04/01/2014 07:41:18 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\athExt.dll Fehlercode: 126 Microsoft Office Sessions: ========================= Error: (04/01/2014 08:01:20 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/01/2014 07:41:49 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2013-09-19 18:23:39.819 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-19 18:23:39.817 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-19 18:23:39.815 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-19 18:23:39.803 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-19 18:23:39.801 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-19 18:23:39.799 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-17 18:49:25.420 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-17 18:49:25.418 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-17 18:49:25.416 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-17 18:49:25.396 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 55% Total physical RAM: 3263.3 MB Available physical RAM: 1461.59 MB Total Pagefile: 6524.79 MB Available Pagefile: 4025.68 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:399.45 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 1E217965) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff Log created at 20:30 on 01/04/2014 by angel Administrator - Elevation successful ========== regfind ========== Searching for "Systweak" No data found. Searching for "Browser Updater" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0B984DF-02F8-4A3F-BF7F-E7F920201BC3}] "Path"="\Browser Updater\Browser Updater" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater\Browser Updater] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{6482B61E-8E89-48B2-8D00-CC7FC95F4FDA}"="v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\HomeTab\TBUpdater.dll|Name=Browser Updater|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{9D90778A-A4B4-402D-9C9E-E6359B8A5D83}"="v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\HomeTab\TBUpdater.dll|Name=Browser Updater|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{6482B61E-8E89-48B2-8D00-CC7FC95F4FDA}"="v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\HomeTab\TBUpdater.dll|Name=Browser Updater|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{9D90778A-A4B4-402D-9C9E-E6359B8A5D83}"="v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\HomeTab\TBUpdater.dll|Name=Browser Updater|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{6482B61E-8E89-48B2-8D00-CC7FC95F4FDA}"="v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\HomeTab\TBUpdater.dll|Name=Browser Updater|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{9D90778A-A4B4-402D-9C9E-E6359B8A5D83}"="v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\HomeTab\TBUpdater.dll|Name=Browser Updater|" Searching for "ProtectedSearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{906F3068-BD1B-44A4-8146-CF9B08A5EA3D}] "Path"="\ProtectedSearch\Protected Search" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProtectedSearch] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{036B03BB-2E5B-444E-B4AE-C84B3B2B1AB4}"="v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\HomeTab\ProtectedSearch.exe|Name=Protected Search|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0CAE3CC-FE5C-45CC-82BB-3B4D5FAE13E3}"="v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\HomeTab\ProtectedSearch.exe|Name=Protected Search|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{036B03BB-2E5B-444E-B4AE-C84B3B2B1AB4}"="v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\HomeTab\ProtectedSearch.exe|Name=Protected Search|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0CAE3CC-FE5C-45CC-82BB-3B4D5FAE13E3}"="v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\HomeTab\ProtectedSearch.exe|Name=Protected Search|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{036B03BB-2E5B-444E-B4AE-C84B3B2B1AB4}"="v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\HomeTab\ProtectedSearch.exe|Name=Protected Search|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0CAE3CC-FE5C-45CC-82BB-3B4D5FAE13E3}"="v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\HomeTab\ProtectedSearch.exe|Name=Protected Search|" -= EOF =- ud wegen malware mhh kA merk ich dann nicht so habe mich daran gewönnt. das es nicht anderst sein dann. das problem was besteht das mein internetprower machnmal ziemlich lange lädt. das war nicht so wo ich den pc neuistalliert habe lief allle blitz schnell. abe rimmer nach neustart obwohl ihn online bin. danach läuft de rnormal der pc läuft noch normal wie vorher nicht schneller. vll zu viel autostart programme. ist abe rnur eine vermutung Geändert von Mahlec (01.04.2014 um 19:54 Uhr) |
02.04.2014, 15:20 | #8 |
/// TB-Ausbilder | Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? Servus, Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 2 h) dauern. Im Anschluss daran räumen wir auf und ich gebe dir noch ein paar Tipps mit auf den Weg. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start Task: {4CB4396D-7F8A-4CE4-936A-E21D73FE97EA} - \Dealply No Task File Task: {71604B2A-CD61-4B11-B820-16399C128A97} - \Software Updater No Task File Task: {7EEA86A3-A189-4E8A-9956-C882B0AD24EC} - \Software Updater Ui No Task File Task: {87431A4D-2D4B-4B97-81CE-05BBF098034A} - \BrowserDefendert No Task File Task: {906F3068-BD1B-44A4-8146-CF9B08A5EA3D} - \ProtectedSearch\Protected Search No Task File Task: {C0B984DF-02F8-4A3F-BF7F-E7F920201BC3} - \Browser Updater\Browser Updater No Task File AlternateDataStreams: C:\ProgramData\TEMP:373E1720 end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte SecurityCheck und:
Bitte poste mit deiner nächsten Antwort
|
03.04.2014, 10:57 | #9 |
| Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? die Logdatei von FRST, Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by angel at 2014-04-03 08:53:02 Run:1 Running from C:\Users\angel\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** start Task: {4CB4396D-7F8A-4CE4-936A-E21D73FE97EA} - \Dealply No Task File Task: {71604B2A-CD61-4B11-B820-16399C128A97} - \Software Updater No Task File Task: {7EEA86A3-A189-4E8A-9956-C882B0AD24EC} - \Software Updater Ui No Task File Task: {87431A4D-2D4B-4B97-81CE-05BBF098034A} - \BrowserDefendert No Task File Task: {906F3068-BD1B-44A4-8146-CF9B08A5EA3D} - \ProtectedSearch\Protected Search No Task File Task: {C0B984DF-02F8-4A3F-BF7F-E7F920201BC3} - \Browser Updater\Browser Updater No Task File AlternateDataStreams: C:\ProgramData\TEMP:373E1720 end ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4CB4396D-7F8A-4CE4-936A-E21D73FE97EA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CB4396D-7F8A-4CE4-936A-E21D73FE97EA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{71604B2A-CD61-4B11-B820-16399C128A97} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71604B2A-CD61-4B11-B820-16399C128A97} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Software Updater => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7EEA86A3-A189-4E8A-9956-C882B0AD24EC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7EEA86A3-A189-4E8A-9956-C882B0AD24EC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Software Updater Ui => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{87431A4D-2D4B-4B97-81CE-05BBF098034A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87431A4D-2D4B-4B97-81CE-05BBF098034A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{906F3068-BD1B-44A4-8146-CF9B08A5EA3D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{906F3068-BD1B-44A4-8146-CF9B08A5EA3D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProtectedSearch\Protected Search => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C0B984DF-02F8-4A3F-BF7F-E7F920201BC3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0B984DF-02F8-4A3F-BF7F-E7F920201BC3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater\Browser Updater => Key deleted successfully. C:\ProgramData\TEMP => ":373E1720" ADS removed successfully. ==== End of Fixlog ==== Code:
ATTFilter
Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=d615c1c2bb63dd4eba1ac6471004cc26 # engine=17733 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-03 08:31:16 # local_time=2014-04-03 10:31:16 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 20645716 148143726 0 0 # scanned=152849 # found=0 # cleaned=0 # scan_time=4881 Code:
ATTFilter Results of screen317's Security Check version 0.99.80 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials (On Access scanning disabled!) Error obtaining update status for antivirus! `````````Anti-malware/Other Utilities Check:````````` MVPS Hosts File Spybot - Search & Destroy Adobe Flash Player 12.0.0.77 Adobe Reader XI Mozilla Firefox (28.0) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Spybot Teatimer.exe is disabled! Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
03.04.2014, 16:00 | #10 |
/// TB-Ausbilder | Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? Servus, Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1 Die Reihenfolge ist hier entscheidend.
Schritt 2 Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Performance
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
03.04.2014, 20:22 | #11 |
| Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? Vielen vielen dank dafür da sdu mir geholfen hast. jetzt habe ich zu guter letzt noch eine frage ich habe ja spybot, ccleaner, glary utiltis 4, und emisoft emergency kit. und microsoft securtiy essentail drauf. ich glaube das ich eins oder zwei programme überflüssig sind aber welche ??? kannst du mir da noch ein rat geben welche ich löschen kann ?? deine 3 empfohlenen progamme habe ich gleich auf dem destop gemacht. die auch nutzen werde. sind die anderen progammme wie junk, frst usw. automatisch weg ?? nach der reinigung weil gefunden habe ich sie nicht. |
03.04.2014, 20:27 | #12 | ||
/// TB-Ausbilder | Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? Servus, Zitat:
Microsoft Security Essentials, Malwarebytes' Anti-Malware und AdwCleaner genügen. Zitat:
Ich bin froh, dass wir helfen konnten In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest: Lob, Kritik und Wünsche Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank! Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |
Themen zu Wie gehe ich richtig vor mit der Grundreinigung meines pc´s ? |
ander, fehler, gefunde, keylogger.logixoft, miteinander, programme, pup.optional.bundleinstaller.a, pup.optional.conduit.a, pup.optional.helperbar.a, pup.optional.qone8, pup.optional.regcleanerpro, pup.optional.searchprotect.a, pup.optional.simplytech, richtig, schaden, thema, trojan.agent, weiße |