|
Log-Analyse und Auswertung: Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
13.04.2014, 19:40 | #1 | ||
| Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Hallo, ich habe hier 2 PCs (Windows 7) und einen Laptop (8) mit dem gleichen Problem. Beim Öffnen von Links kommt Werbung/ Meldungen und nicht das gewünschte Ziel. Mal öffnet sich nur ein Fenster, mal ganz viele. Es sind ca. 6 verschiedene Meldungen die sich wiederholen: - Windows PC Reparatur - Bitte aktualisieren sie Java/ Mediaplay/ Videoplayer/ Firefox - Ihr Windows hat einen Fehler Avira hat 4 Wahrnungen gefunden und die in die Quarantäne gesteckt, aber das Problem war damit nicht behoben. Hier die Avira Ergebnisse: Leider bin ich zu blöd die exportierrten Ergebisse einzufügen und habe auch nirgendwo eine Hilfe dazu gefunden. Hier die defogger_disable Ergebnisse: Zitat:
FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 01 Ran by Lorelay (ATTENTION: The logged in user is not administrator) on Lorelay-PC on 13-04-2014 17:45:30 Running from C:\Users\Lorelay\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (Dropbox, Inc.) C:\Users\Lorelay\AppData\Roaming\Dropbox\bin\Dropbox.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\EvernoteClipper.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Iminent) C:\Program Files (x86)\Iminent\Iminent.exe (Iminent) C:\Program Files (x86)\Iminent\Iminent.Messengers.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\Evernote.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\EvernoteTray.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated) HKLM\...\Run: [Samsung Link] - C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [600928 2014-03-13] (Copyright 2013 SAMSUNG) HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1573584 2012-10-10] (Ask) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Iminent] - C:\Program Files (x86)\Iminent\Iminent.exe [1074376 2012-12-12] (Iminent) HKLM-x32\...\Run: [IminentMessenger] - C:\Program Files (x86)\Iminent\Iminent.Messengers.exe [884936 2012-12-12] (Iminent) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [LexwareInfoService] - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Runonce: [VOPackage] - C:\Users\Lorelay\AppData\Roaming\VOPackage\VOPackage.exe /runonce [X] HKU\S-1-5-21-3979088316-405595985-3978638949-1001\...\Run: [icq] - C:\Users\Lorelay\AppData\Roaming\ICQM\icq.exe [27453288 2013-03-07] (ICQ) HKU\S-1-5-21-3979088316-405595985-3978638949-1001\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3979088316-405595985-3978638949-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-3979088316-405595985-3978638949-1001\...\MountPoints2: {47e8a16e-0ef0-11e2-bdbf-001e8c804aa9} - G:\pushinst.exe HKU\S-1-5-21-3979088316-405595985-3978638949-1001\...\MountPoints2: {f474a15f-0edf-11e2-aa4b-806e6f6e6963} - J:\Start.exe Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lorelay\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-3979088316-405595985-3978638949-1001\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:13828 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.iminent.com/?appId=932475FC-7416-4A83-9341-C862AD5B7DA2 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xDD14BC0505F1CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?type=hp&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?type=hp&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms} SearchScopes: HKLM-x32 - {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://search.iminent.com/?appId=[AppInstanceUid]&ref=toolbox&q={searchTerms} SearchScopes: HKCU - DefaultScope {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://search.iminent.com/?appId=[AppInstanceUid]&ref=toolbox&q={searchTerms} SearchScopes: HKCU - bProtectorDefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} SearchScopes: HKCU - {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://search.iminent.com/?appId=[AppInstanceUid]&ref=toolbox&q={searchTerms} SearchScopes: HKCU - {FFEBBF0A-C22C-4172-89FF-45215A135AC8} URL = hxxp://search.icq.com/search/results.php?q=%s&ch_id=hm&search_mode=web BHO: MediaPlayerplus - {11111111-1111-1111-1111-110511421146} - C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho64.dll (Freeven) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: MediaPlayerplus - {11111111-1111-1111-1111-110511421146} - C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho.dll (Freeven) BHO-x32: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.3.8\bh\BabylonToolbar.dll (Babylon BHO) BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited) BHO-x32: FoxTab - {4DF4AC8C-FFA8-40FF-91F0-EB8389314B78} - C:\Users\Lorelay\AppData\LocalLow\FoxTab\IE\FoxTab.dll No File BHO-x32: TBSB01620 Class - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll () BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files (x86)\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM-x32 - Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.3.8\BabylonToolbarTlbr.dll (Babylon Ltd.) Toolbar: HKLM-x32 - IMinent Toolbar - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll () Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKCU - No Name - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\r7mxushs.default FF NewTab: user_pref("browser.newtab.url", ""); FF SearchEngineOrder.1: Search the web (Babylon) FF SelectedSearchEngine: SearchTheWeb FF Homepage: about:home FF Keyword.URL: hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-4&o=APN10261&locale=de_DE&apn_uid=d4a97d28-fddb-49b8-aef5-b9f6e29800ee&apn_ptnrs=%5EAGS&apn_sauid=723C7D07-093F-41FC-8299-10356595D3FA&apn_dtid=%5EYYYYYY%5EYY%5EDE&&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\webssearches.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: MediaPlayerplus - C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\r7mxushs.default\Extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com [2014-04-11] FF Extension: FoxTab - C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\r7mxushs.default\Extensions\addon@foxtab.com [2012-11-15] FF HKLM-x32\...\Firefox\Extensions: [webbooster@iminent.com] - C:\Program Files (x86)\Iminent\webbooster@iminent.com FF Extension: Iminent Minibar - C:\Program Files (x86)\Iminent\webbooster@iminent.com [2013-01-05] FF HKLM-x32\...\Firefox\Extensions: [quick_start@gmail.com] - C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default\extensions\quick_start@gmail.com FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://istart.webssearches.com/?type=sc&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968 ==================== Services (Whitelisted) ================= R2 AdobeActiveFileMonitor9.0; D:\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [169408 2010-09-30] (Adobe Systems Incorporated) R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-24] (Avira Operations GmbH & Co. KG) R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36392 2014-03-14] (Just Develop It) R2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [688240 2014-03-31] (Cherished Technololgy LIMITED) R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.) R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 Re-markit; C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe [141824 2014-04-11] () R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [609632 2014-03-13] (Copyright 2013 SAMSUNG) R2 SProtection; C:\Program Files (x86)\Common Files\Umbrella\Umbrella.exe [2620016 2013-01-24] (Iminent) R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [566272 2014-04-11] (Cherished Technololgy LIMITED) R2 vosr; C:\Users\Lorelay\AppData\Roaming\VOPackage\VOsrv.exe [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] () R3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1627520 2009-06-10] (NXP Semiconductors) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-13 17:45 - 2014-04-13 17:45 - 00019866 _____ () C:\Users\Lorelay\Downloads\FRST.txt 2014-04-13 17:45 - 2014-04-13 17:45 - 00000000 ____D () C:\FRST 2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe 2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log 2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe 2014-04-11 21:19 - 2014-04-11 21:24 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job 2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\ProgramData\WPM 2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\ProgramData\IePluginService 2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-04-11 21:18 - 2014-04-12 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job 2014-04-11 21:18 - 2014-04-11 21:39 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job 2014-04-11 21:17 - 2014-04-13 17:27 - 00001520 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-5.job 2014-04-11 21:17 - 2014-04-13 17:27 - 00001442 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-1.job 2014-04-11 21:17 - 2014-04-13 17:27 - 00001430 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-2.job 2014-04-11 21:16 - 2014-04-13 17:27 - 00003138 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-3.job 2014-04-11 21:16 - 2014-04-13 17:27 - 00002210 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-4.job 2014-04-11 21:16 - 2014-04-11 21:18 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup 2014-04-11 21:16 - 2014-04-11 21:17 - 00000000 ____D () C:\Program Files (x86)\MediaPlayerplus 2014-04-11 21:16 - 2014-04-11 21:16 - 00000000 ____D () C:\Program Files (x86)\Uniblue 2014-04-11 21:15 - 2014-04-13 17:27 - 00000422 _____ () C:\Windows\Tasks\Re-markit Update.job 2014-04-11 21:15 - 2014-04-13 17:27 - 00000412 _____ () C:\Windows\Tasks\Re-markit_wd.job 2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol 2014-04-11 21:15 - 2014-04-11 21:15 - 00000000 ____D () C:\Program Files (x86)\Re-markit-soft 2014-04-11 21:11 - 2014-04-11 21:11 - 00634288 _____ () C:\Users\Lorelay\Downloads\Player_Setup.exe 2014-04-11 21:11 - 2014-04-11 21:11 - 00634288 _____ () C:\Users\Lorelay\Downloads\Player_Setup(1).exe 2014-04-10 20:30 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 20:30 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 20:30 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 20:30 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 20:30 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 20:30 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 20:30 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 20:30 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 20:30 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 20:30 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 20:30 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 20:30 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 20:30 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 20:30 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-10 20:29 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 20:29 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-06 11:34 - 2014-04-06 11:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG 2014-03-18 19:17 - 2014-03-18 19:18 - 00000000 ____D () C:\Program Files\Samsung 2014-03-18 18:59 - 2014-03-18 19:06 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe 2014-03-18 17:44 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-18 17:44 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-18 17:44 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-18 17:43 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-18 17:43 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-18 17:43 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-18 17:43 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-18 17:43 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-18 17:43 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-18 17:43 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-18 17:43 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-18 17:43 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-18 17:43 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-18 17:43 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-18 17:43 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-18 17:43 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-18 17:43 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-18 17:43 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-18 17:43 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-18 17:43 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-18 17:43 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-18 17:43 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-18 17:43 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-18 17:43 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-18 17:43 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-18 17:43 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-18 17:43 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-18 17:43 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-18 17:43 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-18 17:43 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-18 17:43 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-18 17:43 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-18 17:43 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-18 17:43 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-18 17:43 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-18 17:43 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-18 17:43 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-18 17:43 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-18 17:43 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-18 17:43 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-18 17:43 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-18 17:43 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-18 17:43 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-18 17:43 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-13 17:45 - 2014-04-13 17:45 - 00019866 _____ () C:\Users\Lorelay\Downloads\FRST.txt 2014-04-13 17:45 - 2014-04-13 17:45 - 00000000 ____D () C:\FRST 2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe 2014-04-13 17:41 - 2012-11-15 18:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log 2014-04-13 17:40 - 2012-10-05 13:36 - 00000000 ____D () C:\Users\Lorelay2 2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe 2014-04-13 17:37 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-13 17:37 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-13 17:33 - 2012-10-05 13:32 - 01845728 _____ () C:\Windows\WindowsUpdate.log 2014-04-13 17:29 - 2014-01-04 14:37 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Dropbox 2014-04-13 17:27 - 2014-04-11 21:17 - 00001520 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-5.job 2014-04-13 17:27 - 2014-04-11 21:17 - 00001442 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-1.job 2014-04-13 17:27 - 2014-04-11 21:17 - 00001430 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-2.job 2014-04-13 17:27 - 2014-04-11 21:16 - 00003138 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-3.job 2014-04-13 17:27 - 2014-04-11 21:16 - 00002210 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-4.job 2014-04-13 17:27 - 2014-04-11 21:15 - 00000422 _____ () C:\Windows\Tasks\Re-markit Update.job 2014-04-13 17:27 - 2014-04-11 21:15 - 00000412 _____ () C:\Windows\Tasks\Re-markit_wd.job 2014-04-13 17:23 - 2013-01-05 17:18 - 00000266 _____ () C:\Windows\Tasks\AutoKMS.job 2014-04-13 17:23 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-13 17:23 - 2009-07-14 06:51 - 00044308 _____ () C:\Windows\setupact.log 2014-04-12 21:19 - 2014-04-11 21:18 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job 2014-04-11 23:54 - 2012-10-13 16:59 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-11 23:54 - 2012-10-13 16:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-11 21:39 - 2014-04-11 21:18 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job 2014-04-11 21:24 - 2014-04-11 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job 2014-04-11 21:23 - 2012-10-08 17:18 - 00171972 _____ () C:\Windows\PFRO.log 2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\ProgramData\WPM 2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\ProgramData\IePluginService 2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-04-11 21:18 - 2014-04-11 21:16 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup 2014-04-11 21:17 - 2014-04-11 21:16 - 00000000 ____D () C:\Program Files (x86)\MediaPlayerplus 2014-04-11 21:16 - 2014-04-11 21:16 - 00000000 ____D () C:\Program Files (x86)\Uniblue 2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol 2014-04-11 21:15 - 2014-04-11 21:15 - 00000000 ____D () C:\Program Files (x86)\Re-markit-soft 2014-04-11 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-11 21:11 - 2014-04-11 21:11 - 00634288 _____ () C:\Users\Lorelay\Downloads\Player_Setup.exe 2014-04-11 21:11 - 2014-04-11 21:11 - 00634288 _____ () C:\Users\Lorelay\Downloads\Player_Setup(1).exe 2014-04-10 23:33 - 2013-01-05 16:56 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-10 23:32 - 2013-07-24 22:51 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 23:30 - 2013-01-27 19:31 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 18:47 - 2012-10-13 17:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-08 21:58 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-04-08 21:58 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-04-08 21:58 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-06 11:34 - 2014-04-06 11:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-31 03:16 - 2014-04-10 20:30 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 20:30 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-20 21:07 - 2012-10-05 15:27 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Adobe 2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe 2014-03-20 16:14 - 2009-07-14 06:45 - 00442712 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload 2014-03-18 19:19 - 2012-10-05 14:59 - 00000000 ____D () C:\Users\Lorelay 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG 2014-03-18 19:18 - 2014-03-18 19:17 - 00000000 ____D () C:\Program Files\Samsung 2014-03-18 19:06 - 2014-03-18 18:59 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe 2014-03-18 18:47 - 2013-03-12 13:54 - 00002669 _____ () C:\Users\Public\Desktop\TAXMAN 2013 spezial.lnk Some content of TEMP: ==================== C:\Users\Lorelay\AppData\Local\Temp\avgnt.exe C:\Users\Lorelay\AppData\Local\Temp\i4jdel0.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================ --- --- --- Hier die Addition Ergebnisse: Zitat:
Ich habe die Log-Files jetzt erstmal nur an einem PC gemacht, bei bedarf kann ich das auch bei den anderene machen. Vielen dank im Vorraus Emmaline PS. Es ist etwas blöd, das man manche Worte nicht im Titel verweden kann, weil so kann man das Problem nicht genau darstellen. Die Meldung heißt meist "Bitte aktualisieren sie ihr Programm". da das Wort "Bitte" im Titel nicht benutzbar ist, konnte ich das nicht so schreiben. Geändert von Emmaline (13.04.2014 um 20:04 Uhr) |
13.04.2014, 20:55 | #2 |
/// the machine /// TB-Ausbilder | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) hi,
__________________unsere Tools brauchen immer Adminrechte. Revo Uninstaller - Download - Filepony Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION Mit Revo auch Moderat die Reste entfernen lassen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
13.04.2014, 23:39 | #3 | |
| Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Also,
__________________ich habe mit "Revo Uninstaller" alles deinstalliert was zu finden war. Ein Programm hat er allerdings nicht angezeigt, aber jetzt nach allen Anwendungen ist es verschwunden (MyPC Backup). Ich habe noch ein weiteres Program gelöscht (Bing Bar). Beim löschen über "Revo Uninstaller" meldeten sich immeer wieder die "Uninstall" Programme der Programme selbst. Die habe ich einfach übergangen. War das in Ordnung so? Malwarebytes Anti-Malware hat sehr viele Funde gehabt. Die Maske des "Suchlauf Protokoll" bleibt nach einem Klick auf Ansicht allerdings leer und wenn man es speichern will kommt eine Fehlermeldung. Kannd aas an der Größe liegen? AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 14/04/2014 um 00:04:01 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzername : Lorelay - Lorelay PC # Gestartet von : C:\Users\Lorelay\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : BackupStack ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\Iminent Ordner Gelöscht : C:\ProgramData\Tarma Installer Ordner Gelöscht : C:\Program Files (x86)\BabylonToolbar Ordner Gelöscht : C:\Program Files (x86)\Iminent Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup Ordner Gelöscht : C:\Program Files (x86)\uniblue Ordner Gelöscht : C:\Program Files (x86)\Common Files\Umbrella Ordner Gelöscht : C:\Users\\Lorelay~1\AppData\Local\Temp\AskSearch Ordner Gelöscht : C:\Users\\Lorelay\AppData\LocalLow\BabylonToolbar Ordner Gelöscht : C:\Users\Lorelay\AppData\LocalLow\FoxTab Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\BabylonToolbar Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\Iminent Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\SupTab Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\VOPackage Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage Ordner Gelöscht : C:\Users\Lorelay\AppData\Local\AskToolbar Ordner Gelöscht : C:\Users\Lorelay\AppData\LocalLow\BabylonToolbar Ordner Gelöscht : C:\Users\Lorelay\AppData\LocalLow\Toolbar4 Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\Iminent Datei Gelöscht : C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk Datei Gelöscht : C:\Users\Lorelay\Desktop\MyPC Backup.lnk Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\user.js ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk Verknüpfung Desinfiziert : C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Verknüpfung Desinfiziert : C:\Users\Lorelay\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Verknüpfung Desinfiziert : C:\Users\Lorelay\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [webbooster@iminent.com] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup Schlüssel Gelöscht : HKCU\Software\f6db8ae269eb43 Schlüssel Gelöscht : HKLM\SOFTWARE\f6db8ae269eb43 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02C9C7B0-C7C8-4AAC-A9E4-55295BF60F8F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0398B101-6DA7-473F-A290-17D2FBC88CC0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0CC36196-8589-4B80-A771-D659411D7F90} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{143D96F9-EB64-48B3-B192-91C2C41A1F43} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{14F7D91F-F669-45C9-9F42-BACBFDB86EAD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{187A6488-6E71-4A2A-B118-7BEFBFE58257} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2D065204-A024-4C39-8A38-EE7078EC7ACF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30F5476C-677B-4DB0-B397-51F5BFD86840} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3223F2FB-D9B9-45FC-9D66-CD717FFA4EE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{351798B1-C1D2-45AB-92B4-4D6C2D6AB5AF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3AEA1BEF-6195-46F4-ACA2-0ED14F7EFA1B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3D7F9AC3-BAC3-4E51-81D7-D121D79E550A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4498C5E9-93C6-4142-B6BE-F0C6DC48B77A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{479BF2D6-E362-4A99-B1AB-BC764D7B97AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{492A108F-51D0-4BD8-899D-AD4AB2893064} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4B6D6E60-FBD2-4E79-BF4B-886BC98F1797} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{60893E02-2E5B-43F9-A93A-BAD60C2DF6EF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6D39931F-451E-4BDD-BAF4-37FB96DBBA5D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{76C684D2-C35D-4284-976A-D862F53ADB81} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{796D822A-C3F9-4A97-BAAB-42FE7628EA63} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{79EF3691-EC1A-4705-A01A-D2E36EC11758} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82F41418-8E64-47EB-A7F1-4702A974D289} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{85D920CE-63A7-46DC-8992-41D1D2E07FAD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{895ED5E8-ABB4-40C3-A0CA-2571964268E2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8AAC123A-1959-4A45-BFC5-E2D50783098A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A07956CD-81F8-4A03-B524-5D87E690DC83} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B5E3B26B-6E5C-4865-A63D-58D04B10E245} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B84D2DC5-42B2-4E5E-BF61-7B48152FF8EF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B89D5309-0367-4494-A92F-3D4C94F88307} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C014EBF8-8854-448B-B5A4-557C4090EDCE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C31191DB-2F64-464C-B97C-6AC81ACB7AAC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C342C7A7-F622-4EF3-8B7F-ABB9FBE73F14} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C4765B07-BC2F-477B-925C-B2BF24887823} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C875C0A1-09E3-48D5-9F8E-BD337796FD14} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD126DA6-FF5B-4181-AC13-54A62240D2FA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DD438708-AAB4-422D-A322-B619589F5680} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E812AE43-7799-4E67-8CF8-4104297A2D16} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F0BAAEC7-9AE0-49FF-9C4B-86E774FF397F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F92193FD-2243-4401-9ACC-49FF30885898} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD21B8A2-910B-45AC-9C10-45E6A8B84984} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ACA608DB-A210-4253-B799-3FD24E9A7BF5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gelöscht : HKCU\Software\Iminent Schlüssel Gelöscht : HKCU\Software\Microsoft\Babylon Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\IePlugin Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions Schlüssel Gelöscht : HKLM\Software\supTab Schlüssel Gelöscht : HKLM\Software\supWPM Schlüssel Gelöscht : HKLM\Software\Umbrella Schlüssel Gelöscht : HKLM\Software\Uniblue Schlüssel Gelöscht : HKLM\Software\Wpm Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Tarma Installer Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\482AA67AD25E6E74E9F48BD5FBE8533C Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\482AA67AD25E6E74E9F48BD5FBE8533C ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default\prefs.js ] Zeile gelöscht : user_pref("avg.install.userHPSettings", "hxxp://search.babylon.com/?affID=109958&tt=4612_5&babsrc=HP_ss&mntrId=d05cfe72000000000000001c4af5625a"); Zeile gelöscht : user_pref("avg.install.userSPSettings", "Search the web (Babylon)"); Zeile gelöscht : user_pref("browser.search.order.1", "Search the web (Babylon)"); Zeile gelöscht : user_pref("browser.search.selectedEngine", "SearchTheWeb"); Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://search.iminent.com/?appId=932475FC-7416-4A83-9341-C862AD5B7DA2"); Zeile gelöscht : user_pref("extensions.crossrider.bic", "1455cc604f931a1f054fabb0c87cf0d6"); [ Datei : C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\r7mxushs.default\prefs.js ] Zeile gelöscht : user_pref("browser.search.order.1", "Search the web (Babylon)"); Zeile gelöscht : user_pref("browser.search.selectedEngine", "SearchTheWeb"); Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", ""); Zeile gelöscht : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-4&o=APN10261&locale=de_DE&apn_uid=d4a97d28-fddb-49b8-aef5-b9f6e29800ee&apn_ptnrs=%5EAGS&apn_sauid=723C7D07-093F-41FC[...] -\\ Google Chrome v [ Datei : C:\Users\Lorelay\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : homepage Gelöscht : urls_to_restore_on_startup ************************* AdwCleaner[R0].txt - [19470 octets] - [14/04/2014 00:03:09] AdwCleaner[S0].txt - [17844 octets] - [14/04/2014 00:04:01] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [17905 octets] ########## JRT: Zitat:
FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 01 Ran by Lorelay (administrator) on Lorelay-PC on 14-04-2014 00:23:20 Running from C:\Users\Lorelay\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Adobe Systems Incorporated) D:\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated) HKLM\...\Run: [Samsung Link] - C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [600928 2014-03-13] (Copyright 2013 SAMSUNG) HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [LexwareInfoService] - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Run: [EA Core] - "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lorelay\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\EvernoteClipper.exe (No File) Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-3979088316-405595985-3978638949-1001\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - iexplore.exe BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: FoxTab - {4DF4AC8C-FFA8-40FF-91F0-EB8389314B78} - C:\Users\Lorelay\AppData\LocalLow\FoxTab\IE\FoxTab.dll No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: Google FF Keyword.URL: user_pref("keyword.URL", ""); FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: GMX MailCheck - C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default\Extensions\toolbar@gmx.net.xpi [2014-04-13] FF HKCU\...\Firefox\Extensions: [{372479DD-B552-F0A8-F0E5-EEEEA6602285}] - C:\Program Files (x86)\Re-markit-soft\158.xpi FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (No Name) - C:\Users\Lorelay\AppData\Local\Google\Chrome\User Data\Default\Extensions\2.0.0.0_0 [2013-01-05] CHR Extension: (Re-markit) - C:\Users\Lorelay\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc [2014-04-11] CHR HKLM-x32\...\Chrome\Extension: [pailhpppfllmijejfccffanaigjphjnb] - C:\Users\Lorelay\AppData\LocalLow\FoxTab\CHROME\FoxTab.crx [2014-04-11] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AdobeActiveFileMonitor9.0; D:\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [169408 2010-09-30] (Adobe Systems Incorporated) R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-24] (Avira Operations GmbH & Co. KG) R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.) R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [609632 2014-03-13] (Copyright 2013 SAMSUNG) S2 vosr; C:\Users\Lorelay\AppData\Roaming\VOPackage\VOsrv.exe [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] () R3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1627520 2009-06-10] (NXP Semiconductors) R3 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-14 00:18 - 2014-04-14 00:18 - 00000957 _____ () C:\Users\Lorelay\Desktop\JRT.txt 2014-04-14 00:11 - 2014-04-14 00:11 - 00000000 ____D () C:\Windows\ERUNT 2014-04-14 00:10 - 2014-04-14 00:10 - 01016261 _____ (Thisisu) C:\Users\Lorelay\Downloads\JRT.exe 2014-04-14 00:06 - 2014-04-14 00:08 - 00018126 _____ () C:\Users\Lorelay\Desktop\AdwCleaner[S0].txt 2014-04-14 00:02 - 2014-04-14 00:04 - 00000000 ____D () C:\AdwCleaner 2014-04-14 00:00 - 2014-04-14 00:01 - 01426178 _____ () C:\Users\Lorelay\Downloads\adwcleaner.exe 2014-04-13 23:54 - 2014-04-13 23:54 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys 2014-04-13 23:28 - 2014-04-13 23:59 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-13 23:28 - 2014-04-13 23:28 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-13 23:28 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-13 23:28 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-13 23:28 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-13 23:27 - 2014-04-13 23:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Lorelay\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-13 22:38 - 2014-04-13 22:38 - 00001271 _____ () C:\Users\Lorelay\Desktop\Revo Uninstaller.lnk 2014-04-13 22:38 - 2014-04-13 22:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-13 22:36 - 2014-04-13 22:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lorelay\Downloads\revosetup95.exe 2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG 2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\.swt 2014-04-13 18:05 - 2014-04-13 18:05 - 00000490 _____ () C:\Users\Lorelay\Desktop\defogger_disable.log 2014-04-13 17:50 - 2014-04-13 17:50 - 00380416 _____ () C:\Users\Lorelay\Downloads\Gmer-19357.exe 2014-04-13 17:49 - 2014-04-13 20:32 - 00039065 _____ () C:\Users\Lorelay\Desktop\Addition.txt 2014-04-13 17:49 - 2014-04-13 20:29 - 00037713 _____ () C:\Users\Lorelay\Desktop\FRST.txt 2014-04-13 17:46 - 2014-04-13 17:46 - 00039075 _____ () C:\Users\Lorelay\Downloads\Addition.txt 2014-04-13 17:45 - 2014-04-14 00:23 - 00012184 _____ () C:\Users\Lorelay\Downloads\FRST.txt 2014-04-13 17:45 - 2014-04-14 00:23 - 00000000 ____D () C:\FRST 2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe 2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log 2014-04-13 17:40 - 2014-04-13 17:40 - 00000000 _____ () C:\Users\Lorelay\defogger_reenable 2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe 2014-04-11 21:19 - 2014-04-11 21:24 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job 2014-04-11 21:19 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP3 2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\com 2014-04-11 21:18 - 2014-04-12 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job 2014-04-11 21:18 - 2014-04-11 21:39 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job 2014-04-11 21:18 - 2014-04-11 21:19 - 00002846 _____ () C:\Windows\System32\Tasks\APSnotifierPP1 2014-04-11 21:18 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP2 2014-04-11 21:18 - 2014-04-11 21:18 - 00001976 _____ () C:\Users\Lorelay\Desktop\Sync Folder.lnk 2014-04-11 21:17 - 2014-04-11 21:19 - 00000322 _____ () C:\Users\Lorelay\AppData\Roaming\aps.uninstall.scan.results 2014-04-11 21:16 - 2014-04-11 21:16 - 01100856 _____ (AnyProtect.com) C:\Users\Lorelay\AppData\Local\nsz6B72.tmp 2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol 2014-04-10 20:30 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 20:30 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 20:30 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 20:30 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 20:30 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 20:30 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 20:30 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 20:30 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 20:30 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 20:30 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 20:30 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 20:30 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 20:30 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 20:30 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-10 20:29 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 20:29 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-06 11:34 - 2014-04-14 00:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG 2014-03-18 19:17 - 2014-03-18 19:18 - 00000000 ____D () C:\Program Files\Samsung 2014-03-18 18:59 - 2014-03-18 19:06 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe 2014-03-18 17:44 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-18 17:44 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-18 17:44 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-18 17:43 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-18 17:43 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-18 17:43 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-18 17:43 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-18 17:43 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-18 17:43 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-18 17:43 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-18 17:43 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-18 17:43 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-18 17:43 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-18 17:43 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-18 17:43 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-18 17:43 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-18 17:43 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-18 17:43 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-18 17:43 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-18 17:43 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-18 17:43 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-18 17:43 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-18 17:43 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-18 17:43 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-18 17:43 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-18 17:43 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-18 17:43 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-18 17:43 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-18 17:43 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-18 17:43 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-18 17:43 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-18 17:43 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-18 17:43 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-18 17:43 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-18 17:43 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-18 17:43 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-18 17:43 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-18 17:43 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-18 17:43 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-18 17:43 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-18 17:43 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-18 17:43 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-18 17:43 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-18 17:43 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-14 00:24 - 2014-04-13 17:45 - 00012184 _____ () C:\Users\Lorelay\Downloads\FRST.txt 2014-04-14 00:23 - 2014-04-13 17:45 - 00000000 ____D () C:\FRST 2014-04-14 00:18 - 2014-04-14 00:18 - 00000957 _____ () C:\Users\Lorelay\Desktop\JRT.txt 2014-04-14 00:15 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-14 00:15 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-14 00:11 - 2014-04-14 00:11 - 00000000 ____D () C:\Windows\ERUNT 2014-04-14 00:10 - 2014-04-14 00:10 - 01016261 _____ (Thisisu) C:\Users\Lorelay\Downloads\JRT.exe 2014-04-14 00:08 - 2014-04-14 00:06 - 00018126 _____ () C:\Users\Lorelay\Desktop\AdwCleaner[S0].txt 2014-04-14 00:05 - 2013-01-05 17:18 - 00000266 _____ () C:\Windows\Tasks\AutoKMS.job 2014-04-14 00:05 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-14 00:05 - 2009-07-14 06:51 - 00044588 _____ () C:\Windows\setupact.log 2014-04-14 00:04 - 2014-04-14 00:02 - 00000000 ____D () C:\AdwCleaner 2014-04-14 00:04 - 2014-04-06 11:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-14 00:04 - 2012-10-05 13:37 - 00001018 _____ () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-14 00:04 - 2012-10-05 13:36 - 00000000 ___RD () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-14 00:04 - 2012-10-05 13:32 - 01908279 _____ () C:\Windows\WindowsUpdate.log 2014-04-14 00:01 - 2014-04-14 00:00 - 01426178 _____ () C:\Users\Lorelay\Downloads\adwcleaner.exe 2014-04-13 23:59 - 2014-04-13 23:28 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-13 23:54 - 2014-04-13 23:54 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys 2014-04-13 23:51 - 2012-10-08 17:18 - 00316094 _____ () C:\Windows\PFRO.log 2014-04-13 23:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas 2014-04-13 23:50 - 2014-01-04 14:37 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Dropbox 2014-04-13 23:41 - 2012-11-15 18:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-13 23:28 - 2014-04-13 23:28 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-13 23:27 - 2014-04-13 23:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Lorelay\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-13 22:38 - 2014-04-13 22:38 - 00001271 _____ () C:\Users\Lorelay\Desktop\Revo Uninstaller.lnk 2014-04-13 22:38 - 2014-04-13 22:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-13 22:36 - 2014-04-13 22:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lorelay\Downloads\revosetup95.exe 2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG 2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\.swt 2014-04-13 22:25 - 2012-10-05 13:36 - 00000000 ____D () C:\Users\Lorelay 2014-04-13 20:32 - 2014-04-13 17:49 - 00039065 _____ () C:\Users\Lorelay\Desktop\Addition.txt 2014-04-13 20:29 - 2014-04-13 17:49 - 00037713 _____ () C:\Users\Lorelay\Desktop\FRST.txt 2014-04-13 18:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-13 18:05 - 2014-04-13 18:05 - 00000490 _____ () C:\Users\Lorelay\Desktop\defogger_disable.log 2014-04-13 17:50 - 2014-04-13 17:50 - 00380416 _____ () C:\Users\Lorelay\Downloads\Gmer-19357.exe 2014-04-13 17:46 - 2014-04-13 17:46 - 00039075 _____ () C:\Users\Lorelay\Downloads\Addition.txt 2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe 2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log 2014-04-13 17:40 - 2014-04-13 17:40 - 00000000 _____ () C:\Users\Lorelay\defogger_reenable 2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe 2014-04-12 21:19 - 2014-04-11 21:18 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job 2014-04-11 23:54 - 2013-01-05 13:21 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Adobe 2014-04-11 23:54 - 2012-11-15 18:42 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-11 23:54 - 2012-10-13 16:59 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-11 23:54 - 2012-10-13 16:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-11 21:39 - 2014-04-11 21:18 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job 2014-04-11 21:24 - 2014-04-11 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job 2014-04-11 21:19 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP3 2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\com 2014-04-11 21:19 - 2014-04-11 21:18 - 00002846 _____ () C:\Windows\System32\Tasks\APSnotifierPP1 2014-04-11 21:19 - 2014-04-11 21:18 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP2 2014-04-11 21:19 - 2014-04-11 21:17 - 00000322 _____ () C:\Users\Lorelay\AppData\Roaming\aps.uninstall.scan.results 2014-04-11 21:18 - 2014-04-11 21:18 - 00001976 _____ () C:\Users\Lorelay\Desktop\Sync Folder.lnk 2014-04-11 21:16 - 2014-04-11 21:16 - 01100856 _____ (AnyProtect.com) C:\Users\Lorelay\AppData\Local\nsz6B72.tmp 2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol 2014-04-11 21:15 - 2013-01-05 13:24 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Mozilla 2014-04-11 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-10 23:33 - 2013-01-05 16:56 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-10 23:32 - 2013-07-24 22:51 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 23:30 - 2013-01-27 19:31 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 18:47 - 2012-10-13 17:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-08 21:58 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-04-08 21:58 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-04-08 21:58 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-03 09:51 - 2014-04-13 23:28 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-13 23:28 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-13 23:28 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 03:16 - 2014-04-10 20:30 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 20:30 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-20 21:07 - 2012-10-05 15:27 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Adobe 2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe 2014-03-20 16:14 - 2009-07-14 06:45 - 00442712 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload 2014-03-18 19:19 - 2012-10-05 14:59 - 00000000 ____D () C:\Users\Lorelay 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG 2014-03-18 19:18 - 2014-03-18 19:17 - 00000000 ____D () C:\Program Files\Samsung 2014-03-18 19:06 - 2014-03-18 18:59 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe 2014-03-18 18:47 - 2013-03-12 13:54 - 00002669 _____ () C:\Users\Public\Desktop\TAXMAN 2013 spezial.lnk Some content of TEMP: ==================== C:\Users\Lorelay\AppData\Local\Temp\avgnt.exe C:\Users\Lorelay\AppData\Local\Temp\BackupSetup.exe C:\Users\Lorelay\AppData\Local\Temp\EAD20D8.exe C:\Users\Lorelay\AppData\Local\Temp\EAD3C25.exe C:\Users\Lorelay\AppData\Local\Temp\EAD4A77.exe C:\Users\Lorelay\AppData\Local\Temp\install_flashplayer11x32_mssd_aih.exe C:\Users\Lorelay\AppData\Local\Temp\Quarantine.exe C:\Users\Lorelay\AppData\Local\Temp\sqlite3.exe C:\Users\Lorelay\AppData\Local\Temp\uninst1.exe C:\Users\Lorelay\AppData\Local\Temp\UninstallEADM.dll C:\Users\Lorelay\AppData\Local\Temp\vcredist_x64.exe C:\Users\Lorelay\AppData\Local\Temp\avgnt.exe C:\Users\Lorelay\AppData\Local\Temp\i4jdel0.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 19:17 ==================== End Of Log ============================ --- --- ---[/CODE] Was mache ich mit den installierten Programmen? Und den anderen PCs? Noch mal Vielen Dank Emmaline |
15.04.2014, 10:22 | #4 |
/// the machine /// TB-Ausbilder | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Revo startet immer den programmeigenen Uninstaller, nachdem der durch ist wird nach Resten gesucht. ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.04.2014, 21:49 | #5 | ||
| Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Sooo, hier die ganzen Ergebnisse: Eset: Zitat:
Zitat:
FRST3: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-04-2014 02 Ran by Lorelay (administrator) on Lorelay-PC on 16-04-2014 22:29:10 Running from C:\Users\Lorelay\Desktop\Säuberungsprogramme Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Adobe Systems Incorporated) D:\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\LxWebAccess\LxWebAccess.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated) HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [600928 2014-03-13] (Copyright 2013 SAMSUNG) HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [LexwareInfoService] => C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lorelay\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\EvernoteClipper.exe (No File) Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-3979088316-405595985-3978638949-1001\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - iexplore.exe BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: FoxTab - {4DF4AC8C-FFA8-40FF-91F0-EB8389314B78} - C:\Users\Lorelay\AppData\LocalLow\FoxTab\IE\FoxTab.dll No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: Google FF Keyword.URL: user_pref("keyword.URL", ""); FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: GMX MailCheck - C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default\Extensions\toolbar@gmx.net.xpi [2014-04-13] FF HKCU\...\Firefox\Extensions: [{372479DD-B552-F0A8-F0E5-EEEEA6602285}] - C:\Program Files (x86)\Re-markit-soft\158.xpi FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (No Name) - C:\Users\Lorelay\AppData\Local\Google\Chrome\User Data\Default\Extensions\2.0.0.0_0 [2013-01-05] CHR Extension: (Re-markit) - C:\Users\Lorelay\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc [2014-04-11] CHR HKLM-x32\...\Chrome\Extension: [pailhpppfllmijejfccffanaigjphjnb] - C:\Users\Lorelay\AppData\LocalLow\FoxTab\CHROME\FoxTab.crx [2014-04-11] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AdobeActiveFileMonitor9.0; D:\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [169408 2010-09-30] (Adobe Systems Incorporated) R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-24] (Avira Operations GmbH & Co. KG) R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.) R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [609632 2014-03-13] (Copyright 2013 SAMSUNG) S2 vosr; C:\Users\Lorelay\AppData\Roaming\VOPackage\VOsrv.exe [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-14] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] () R3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1627520 2009-06-10] (NXP Semiconductors) R3 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-16 22:17 - 2014-04-16 22:17 - 00000813 _____ () C:\Users\Lorelay\Desktop\checkup.txt 2014-04-16 20:30 - 2014-04-16 20:30 - 02347384 _____ (ESET) C:\Users\Lorelay\Downloads\esetsmartinstaller_enu.exe 2014-04-14 00:40 - 2014-04-16 22:29 - 00000000 ____D () C:\Users\Lorelay\Desktop\Säuberungsprogramme 2014-04-14 00:25 - 2014-04-14 00:25 - 00000932 _____ () C:\Users\Lorelay\Desktop\Evernote.lnk 2014-04-14 00:25 - 2014-04-14 00:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Evernote 2014-04-14 00:25 - 2014-04-14 00:25 - 00000000 ____D () C:\Program Files (x86)\Evernote 2014-04-14 00:11 - 2014-04-14 00:11 - 00000000 ____D () C:\Windows\ERUNT 2014-04-14 00:10 - 2014-04-14 00:10 - 01016261 _____ (Thisisu) C:\Users\Lorelay\Downloads\JRT.exe 2014-04-14 00:02 - 2014-04-14 00:04 - 00000000 ____D () C:\AdwCleaner 2014-04-14 00:00 - 2014-04-14 00:01 - 01426178 _____ () C:\Users\Lorelay\Downloads\adwcleaner.exe 2014-04-13 23:54 - 2014-04-13 23:54 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys 2014-04-13 23:28 - 2014-04-14 00:30 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-13 23:28 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-13 23:28 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-13 23:28 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-13 23:27 - 2014-04-13 23:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Lorelay\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-13 22:38 - 2014-04-13 22:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-13 22:36 - 2014-04-13 22:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lorelay\Downloads\revosetup95.exe 2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG 2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\.swt 2014-04-13 18:05 - 2014-04-13 18:05 - 00000490 _____ () C:\Users\Lorelay\Desktop\defogger_disable.log 2014-04-13 17:50 - 2014-04-13 17:50 - 00380416 _____ () C:\Users\Lorelay\Downloads\Gmer-19357.exe 2014-04-13 17:49 - 2014-04-13 20:32 - 00039065 _____ () C:\Users\Lorelay\Desktop\Addition.txt 2014-04-13 17:49 - 2014-04-13 20:29 - 00037713 _____ () C:\Users\Lorelay\Desktop\FRST.txt 2014-04-13 17:46 - 2014-04-13 17:46 - 00039075 _____ () C:\Users\Lorelay\Downloads\Addition.txt 2014-04-13 17:45 - 2014-04-16 22:29 - 00000000 ____D () C:\FRST 2014-04-13 17:45 - 2014-04-14 00:25 - 00035216 _____ () C:\Users\Lorelay\Downloads\FRST.txt 2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe 2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log 2014-04-13 17:40 - 2014-04-13 17:40 - 00000000 _____ () C:\Users\Lorelay\defogger_reenable 2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe 2014-04-11 21:19 - 2014-04-11 21:24 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job 2014-04-11 21:19 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP3 2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\com 2014-04-11 21:18 - 2014-04-12 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job 2014-04-11 21:18 - 2014-04-11 21:39 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job 2014-04-11 21:18 - 2014-04-11 21:19 - 00002846 _____ () C:\Windows\System32\Tasks\APSnotifierPP1 2014-04-11 21:18 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP2 2014-04-11 21:18 - 2014-04-11 21:18 - 00001976 _____ () C:\Users\Lorelay\Desktop\Sync Folder.lnk 2014-04-11 21:17 - 2014-04-11 21:19 - 00000322 _____ () C:\Users\Lorelay\AppData\Roaming\aps.uninstall.scan.results 2014-04-11 21:16 - 2014-04-11 21:16 - 01100856 _____ (AnyProtect.com) C:\Users\Lorelay\AppData\Local\nsz6B72.tmp 2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol 2014-04-10 20:30 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 20:30 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 20:30 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 20:30 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 20:30 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 20:30 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 20:30 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 20:30 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 20:30 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 20:30 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 20:30 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 20:30 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 20:30 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 20:30 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 20:30 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-10 20:29 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 20:29 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-06 11:34 - 2014-04-14 00:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG 2014-03-18 19:17 - 2014-03-18 19:18 - 00000000 ____D () C:\Program Files\Samsung 2014-03-18 18:59 - 2014-03-18 19:06 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe 2014-03-18 17:44 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-18 17:44 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-18 17:44 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-18 17:43 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-18 17:43 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-18 17:43 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-18 17:43 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-18 17:43 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-18 17:43 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-18 17:43 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-18 17:43 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-18 17:43 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-18 17:43 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-18 17:43 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-18 17:43 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-18 17:43 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-18 17:43 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-18 17:43 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-18 17:43 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-18 17:43 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-18 17:43 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-18 17:43 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-18 17:43 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-18 17:43 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-18 17:43 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-18 17:43 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-18 17:43 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-18 17:43 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-18 17:43 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-18 17:43 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-18 17:43 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-18 17:43 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-18 17:43 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-18 17:43 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-18 17:43 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-18 17:43 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-18 17:43 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-18 17:43 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-18 17:43 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-18 17:43 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-18 17:43 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-18 17:43 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-18 17:43 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-18 17:43 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-16 22:29 - 2014-04-14 00:40 - 00000000 ____D () C:\Users\Lorelay\Desktop\Säuberungsprogramme 2014-04-16 22:29 - 2014-04-13 17:45 - 00000000 ____D () C:\FRST 2014-04-16 22:26 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-16 22:26 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-16 22:17 - 2014-04-16 22:17 - 00000813 _____ () C:\Users\Lorelay\Desktop\checkup.txt 2014-04-16 21:41 - 2012-11-15 18:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-16 20:30 - 2014-04-16 20:30 - 02347384 _____ (ESET) C:\Users\Lorelay\Downloads\esetsmartinstaller_enu.exe 2014-04-16 20:18 - 2012-10-05 13:32 - 01931852 _____ () C:\Windows\WindowsUpdate.log 2014-04-16 20:13 - 2013-01-05 17:18 - 00000266 _____ () C:\Windows\Tasks\AutoKMS.job 2014-04-16 20:13 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-16 20:13 - 2009-07-14 06:51 - 00044644 _____ () C:\Windows\setupact.log 2014-04-14 00:30 - 2014-04-13 23:28 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-14 00:25 - 2014-04-14 00:25 - 00000932 _____ () C:\Users\Lorelay\Desktop\Evernote.lnk 2014-04-14 00:25 - 2014-04-14 00:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Evernote 2014-04-14 00:25 - 2014-04-14 00:25 - 00000000 ____D () C:\Program Files (x86)\Evernote 2014-04-14 00:25 - 2014-04-13 17:45 - 00035216 _____ () C:\Users\Lorelay\Downloads\FRST.txt 2014-04-14 00:11 - 2014-04-14 00:11 - 00000000 ____D () C:\Windows\ERUNT 2014-04-14 00:10 - 2014-04-14 00:10 - 01016261 _____ (Thisisu) C:\Users\Lorelay\Downloads\JRT.exe 2014-04-14 00:04 - 2014-04-14 00:02 - 00000000 ____D () C:\AdwCleaner 2014-04-14 00:04 - 2014-04-06 11:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-14 00:04 - 2012-10-05 13:37 - 00001018 _____ () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-14 00:04 - 2012-10-05 13:36 - 00000000 ___RD () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-14 00:01 - 2014-04-14 00:00 - 01426178 _____ () C:\Users\Lorelay\Downloads\adwcleaner.exe 2014-04-13 23:54 - 2014-04-13 23:54 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys 2014-04-13 23:51 - 2012-10-08 17:18 - 00316094 _____ () C:\Windows\PFRO.log 2014-04-13 23:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas 2014-04-13 23:50 - 2014-01-04 14:37 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Dropbox 2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-13 23:27 - 2014-04-13 23:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Lorelay\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-13 22:38 - 2014-04-13 22:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-13 22:36 - 2014-04-13 22:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lorelay\Downloads\revosetup95.exe 2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG 2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\.swt 2014-04-13 22:25 - 2012-10-05 13:36 - 00000000 ____D () C:\Users\Lorelay 2014-04-13 20:32 - 2014-04-13 17:49 - 00039065 _____ () C:\Users\Lorelay\Desktop\Addition.txt 2014-04-13 20:29 - 2014-04-13 17:49 - 00037713 _____ () C:\Users\Lorelay\Desktop\FRST.txt 2014-04-13 18:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-13 18:05 - 2014-04-13 18:05 - 00000490 _____ () C:\Users\Lorelay\Desktop\defogger_disable.log 2014-04-13 17:50 - 2014-04-13 17:50 - 00380416 _____ () C:\Users\Lorelay\Downloads\Gmer-19357.exe 2014-04-13 17:46 - 2014-04-13 17:46 - 00039075 _____ () C:\Users\Lorelay\Downloads\Addition.txt 2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe 2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log 2014-04-13 17:40 - 2014-04-13 17:40 - 00000000 _____ () C:\Users\Lorelay\defogger_reenable 2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe 2014-04-12 21:19 - 2014-04-11 21:18 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job 2014-04-11 23:54 - 2013-01-05 13:21 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Adobe 2014-04-11 23:54 - 2012-11-15 18:42 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-11 23:54 - 2012-10-13 16:59 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-11 23:54 - 2012-10-13 16:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-11 21:39 - 2014-04-11 21:18 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job 2014-04-11 21:24 - 2014-04-11 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job 2014-04-11 21:19 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP3 2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\com 2014-04-11 21:19 - 2014-04-11 21:18 - 00002846 _____ () C:\Windows\System32\Tasks\APSnotifierPP1 2014-04-11 21:19 - 2014-04-11 21:18 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP2 2014-04-11 21:19 - 2014-04-11 21:17 - 00000322 _____ () C:\Users\Lorelay\AppData\Roaming\aps.uninstall.scan.results 2014-04-11 21:18 - 2014-04-11 21:18 - 00001976 _____ () C:\Users\Lorelay\Desktop\Sync Folder.lnk 2014-04-11 21:16 - 2014-04-11 21:16 - 01100856 _____ (AnyProtect.com) C:\Users\Lorelay\AppData\Local\nsz6B72.tmp 2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol 2014-04-11 21:15 - 2013-01-05 13:24 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Mozilla 2014-04-11 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-10 23:33 - 2013-01-05 16:56 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-10 23:32 - 2013-07-24 22:51 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 23:30 - 2013-01-27 19:31 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 18:47 - 2012-10-13 17:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-08 21:58 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-04-08 21:58 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-04-08 21:58 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-03 09:51 - 2014-04-13 23:28 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-13 23:28 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-13 23:28 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 03:16 - 2014-04-10 20:30 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 20:30 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-20 21:07 - 2012-10-05 15:27 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Adobe 2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe 2014-03-20 16:14 - 2009-07-14 06:45 - 00442712 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung 2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload 2014-03-18 19:19 - 2012-10-05 14:59 - 00000000 ____D () C:\Users\Lorelay 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt 2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG 2014-03-18 19:18 - 2014-03-18 19:17 - 00000000 ____D () C:\Program Files\Samsung 2014-03-18 19:06 - 2014-03-18 18:59 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe 2014-03-18 18:47 - 2013-03-12 13:54 - 00002669 _____ () C:\Users\Public\Desktop\TAXMAN 2013 spezial.lnk Some content of TEMP: ==================== C:\Users\Lorelay\AppData\Local\Temp\avgnt.exe C:\Users\Lorelay\AppData\Local\Temp\BackupSetup.exe C:\Users\Lorelay\AppData\Local\Temp\EAD20D8.exe C:\Users\Lorelay\AppData\Local\Temp\EAD3C25.exe C:\Users\Lorelay\AppData\Local\Temp\EAD4A77.exe C:\Users\Lorelay\AppData\Local\Temp\install_flashplayer11x32_mssd_aih.exe C:\Users\Lorelay\AppData\Local\Temp\Quarantine.exe C:\Users\Lorelay\AppData\Local\Temp\sqlite3.exe C:\Users\Lorelay\AppData\Local\Temp\uninst1.exe C:\Users\Lorelay\AppData\Local\Temp\UninstallEADM.dll C:\Users\Lorelay\AppData\Local\Temp\vcredist_x64.exe C:\Users\Lorelay\AppData\Local\Temp\avgnt.exe C:\Users\Lorelay\AppData\Local\Temp\i4jdel0.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 19:17 ==================== End Of Log ============================ Kann ich irgendwo finden nach was die einzelen Scanner eigentlich suchen und was die einzelnen Programme eigentlich machen? Und mach ich das alles jetzt auch mit meinen anderen befallenen PCs? Mein Werbungsproblem ist übriges nicht mehr aufgetaucht. Eine Idee wie ich verhindern kann das es wieder passiert? Übringens, schöne Feierrtage Emmaline |
17.04.2014, 13:58 | #6 | |
/// the machine /// TB-Ausbilder | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Java updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\$Recycle.Bin GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Von den anderen Rechnern bitte FRST Logs, nix auf eigene Faust machen. Zitat:
Für hier: Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) |
18.04.2014, 09:28 | #7 | |
| Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Guten Morgen und einen schönen Feiertag Die Fixlog.txt vom Rechner Lorelay ist beim kopieren gelöscht worden (kann sie auf jeden Fall nicht finden). Macht es Sinn sie nochmal zu machen? Und hier wäre die FRST vom zweiten Rechner: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01 Ran by Acidfree (administrator) on ACIDFREE-PC on 18-04-2014 10:06:38 Running from C:\Users\Acidfree\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (Adobe Systems Incorporated) E:\Photoshop\PhotoshopElementsFileAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe () C:\Windows\system32\dmwu.exe () C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe ( ) C:\Windows\system32\lxczcoms.exe () C:\Program Files (x86)\Re-Markable-soft\Re-MarkableyfYnIw.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (ICQ, LLC.) D:\ICQ7.5\ICQ.exe (Spotify Ltd) C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\Acidfree\AppData\Roaming\Spotify\spotify.exe () C:\Program Files (x86)\FastMediaConverter\FastMediaConverterApp.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (Nullsoft, Inc.) D:\Winamp\winampa.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () C:\Windows\SysWOW64\jmdp\stij.exe () C:\Windows\System32\ljkb\stij.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Program Files (x86)\Re-Markable-soft\Re-MarkableyfY158.exe () C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [DATAMNGR] => C:\PROGRA~2\WIF0E7~1\Datamngr\DATAMN~1.EXE HKLM-x32\...\Run: [WinampAgent] => D:\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.) HKLM-x32\...\Run: [Sweetpacks Communicator] => C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1801168 2014-03-26] (APN) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563608 2014-01-15] (SUPERAntiSpyware) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [ICQ] => D:\ICQ7.5\ICQ.exe [124480 2011-08-01] (ICQ, LLC.) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [RegistryBooster] => "C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe" delay 20000 HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Hoolapp Android] => /Minimized HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify Web Helper] => C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-11] (Spotify Ltd) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify] => C:\Users\Acidfree\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-11] (Spotify Ltd) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [BackgroundContainer] => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Acidfree\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun <===== ATTENTION HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {237ce8bd-cee5-11e0-b0cf-00242178af47} - J:\Startme.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {2518b13b-372c-11e2-87e8-00242178af47} - G:\pushinst.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {5738becf-f4ff-11e1-8895-806e6f6e6963} - explorer index_GB.html HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {afbc22a3-b183-11e1-b4a9-00242178af47} - G:\Setup.exe AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found AppInit_DLLs: C:\PROGRA~2\WIF0E7~1\Datamngr\x64\datamngr.dll => C:\PROGRA~2\WIF0E7~1\Datamngr\x64\datamngr.dll File Not Found AppInit_DLLs: C:\PROGRA~2\WIF0E7~1\Datamngr\x64\IEBHO.dll => C:\PROGRA~2\WIF0E7~1\Datamngr\x64\IEBHO.dll File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => "C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll" File Not Found AppInit_DLLs-x32: C:\PROGRA~2\WIF0E7~1\Datamngr\datamngr.dll => "C:\PROGRA~2\WIF0E7~1\Datamngr\datamngr.dll" File Not Found AppInit_DLLs-x32: C:\PROGRA~2\WIF0E7~1\Datamngr\IEBHO.dll => "C:\PROGRA~2\WIF0E7~1\Datamngr\IEBHO.dll" File Not Found Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:13828 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP34726308-2245-48C4-BB2E-DE4CA8A513E2&SSPV= HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x449DEC206E54CC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKLM-x32 - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ) URLSearchHook: HKLM-x32 - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) URLSearchHook: HKCU - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ) URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=102&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=102&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=102&q={searchTerms} SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10025&barid={693EDBF0-504A-11E2-98FC-00242178AF47} SearchScopes: HKCU - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=102&q={searchTerms} SearchScopes: HKCU - {A4A37A65-E638-486B-831A-5511E241A09C} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=e25bf9d6-fd67-46ac-bdc0-90268edc5315&apn_sauid=8373C6D9-B47B-4A5A-890A-29C5D75D99F7 SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://mysearch.sweetpacks.com?src=6&q={searchTerms}&barid=&&st=23 BHO: UrlHelper Class - {41C4AA37-1DDD-4345-B8DC-734E4B38414D} - C:\PROGRA~2\WIF0E7~1\Datamngr\x64\IEBHO.dll No File BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: jZip Toolbar - {1e48c56f-08cd-43aa-a6ef-c1ec891551ab} - C:\PROGRA~2\WIF0E7~1\Datamngr\ToolBar\jzipdtx.dll No File BHO-x32: UrlHelper Class - {41C4AA37-1DDD-4345-B8DC-734E4B38414D} - C:\PROGRA~2\WIF0E7~1\Datamngr\IEBHO.dll No File BHO-x32: ICQ Sparberater - {5A0D6E4B-B0DF-4148-8B1E-F7A430FF5E24} - C:\Program Files (x86)\icq\Internet Explorer\icq.dll (solute gmbh) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) BHO-x32: DealPly - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly Technologies Ltd) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ) Toolbar: HKLM-x32 - jZip Toolbar - {1e48c56f-08cd-43aa-a6ef-c1ec891551ab} - C:\PROGRA~2\WIF0E7~1\Datamngr\ToolBar\jzipdtx.dll No File Toolbar: HKLM-x32 - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default FF user.js: detected! => C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\user.js FF NewTab: hxxp://www.sweetpacks-search.com/?barid=&src=97&&st=23 FF DefaultSearchEngine: ICQ Search FF SearchEngineOrder.1: Google FF SelectedSearchEngine: ICQ Search FF Homepage: hxxp://www.sweetpacks-search.com/?barid=&src=10&&st=23 FF Keyword.URL: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&CUI=UN95533741736100730&UM=&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.10.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\ask-search.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\askcomsearch.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\conduit.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-1.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-10.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-11.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-12.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-13.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-14.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-15.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-16.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-17.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-18.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-19.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-2.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-20.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-21.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-22.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-23.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-24.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-25.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-26.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-27.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-28.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-29.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-3.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-30.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-4.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-5.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-6.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-7.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-8.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-9.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin.gif FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin.src FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\MyStart Search.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\MyStart.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\SearchResults.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\Sweetpacks Search.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DVDVideoSoftTB - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2013-11-20] FF Extension: Evernote Web Clipper - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} [2013-12-19] FF Extension: DivX Web Player - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\DivXWebPlayer@divx.com.xpi [2012-03-01] FF Extension: GMX MailCheck - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar@gmx.net.xpi [2012-05-04] FF Extension: Ask Toolbar - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-02-25] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-19] FF HKCU\...\Firefox\Extensions: [{9A963233-37BD-837B-48FF-3AD40489A05D}] - C:\Program Files (x86)\Re-Markable-soft\158.xpi FF Extension: Re-Markable - C:\Program Files (x86)\Re-Markable-soft\158.xpi [2014-04-13] Chrome: ======= CHR HomePage: hxxp://search.jzip.com/ CHR RestoreOnStartup: "hxxp://search.jzip.com/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll No File CHR Plugin: (Skype Toolbars) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll (Skype Technologies S.A.) CHR Plugin: (registryAccess) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj\7.15.1.0_0\background/registryAccess.dll (APN) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Unity Player) - C:\Users\Acidfree\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Extension: (Avira Toolbar) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj [2012-09-02] CHR Extension: (Re-Markable) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc [2014-04-13] CHR Extension: (Skype Click to Call) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2011-08-19] CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-03-11] CHR HKCU\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [2012-10-21] CHR HKLM-x32\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [2012-10-21] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-10-10] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-09-12] (SUPERAntiSpyware.com) R2 AdobeActiveFileMonitor7.0; E:\Photoshop\PhotoshopElementsFileAgent.exe [169312 2008-09-16] (Adobe Systems Incorporated) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-03-26] (APN LLC.) R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1859376 2014-02-04] () R2 ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [247608 2010-11-21] () R2 lxcz_device; C:\Windows\system32\lxczcoms.exe [566192 2007-04-19] ( ) R2 lxcz_device; C:\Windows\SysWOW64\lxczcoms.exe [537520 2007-04-19] ( ) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.) R2 Re-Markable; C:\Program Files (x86)\Re-Markable-soft\Re-MarkableyfY158.exe [143360 2014-04-13] () S2 CltMngSvc; C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe [X] S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2013-03-07] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [9584 2013-03-07] () R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-18 10:02 - 2014-04-18 10:02 - 00027723 _____ () C:\Users\Acidfree\Desktop\Addition.txt 2014-04-18 10:00 - 2014-04-18 10:07 - 00029185 _____ () C:\Users\Acidfree\Desktop\FRST.txt 2014-04-18 10:00 - 2014-04-18 10:06 - 00000000 ____D () C:\FRST 2014-04-18 10:00 - 2014-04-18 09:59 - 02158592 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe 2014-04-15 05:13 - 2014-04-18 07:12 - 00003388 _____ () C:\Windows\System32\Tasks\BackgroundContainer Startup Task 2014-04-13 17:56 - 2012-11-04 14:42 - 00001866 _____ () C:\Users\Acidfree\Desktop\SUPERAntiSpyware Free Edition.lnk 2014-04-13 16:52 - 2014-04-18 07:15 - 00000424 _____ () C:\Windows\Tasks\Re-Markable Update.job 2014-04-13 16:52 - 2014-04-13 16:52 - 00003078 _____ () C:\Windows\System32\Tasks\Re-Markable Update 2014-04-13 16:51 - 2014-04-18 09:59 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter 2014-04-13 16:51 - 2014-04-18 07:12 - 00000414 _____ () C:\Windows\Tasks\Re-Markable_wd.job 2014-04-13 16:51 - 2014-04-13 16:52 - 00000000 ____D () C:\Program Files (x86)\Re-Markable-soft 2014-04-13 16:51 - 2014-04-13 16:51 - 00003008 _____ () C:\Windows\System32\Tasks\Re-Markable_wd 2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk 2014-04-13 16:51 - 2014-04-13 16:51 - 00000512 __RSH () C:\ProgramData\ntuser.pol 2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter 2014-04-09 07:24 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 07:24 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 07:24 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 07:24 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 07:24 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 07:24 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 07:24 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 07:24 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 07:24 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 07:24 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 07:24 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 07:24 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 07:24 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 07:24 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 07:24 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 07:24 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\APN 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork 2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-03-19 14:03 - 2014-03-19 14:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-04-18 10:07 - 2014-04-18 10:00 - 00029185 _____ () C:\Users\Acidfree\Desktop\FRST.txt 2014-04-18 10:06 - 2014-04-18 10:00 - 00000000 ____D () C:\FRST 2014-04-18 10:06 - 2012-11-02 09:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-18 10:04 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-18 10:04 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-18 10:02 - 2014-04-18 10:02 - 00027723 _____ () C:\Users\Acidfree\Desktop\Addition.txt 2014-04-18 09:59 - 2014-04-18 10:00 - 02158592 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe 2014-04-18 09:59 - 2014-04-13 16:51 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter 2014-04-18 09:27 - 2011-08-19 21:27 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-18 09:26 - 2014-02-15 19:26 - 00000304 _____ () C:\Windows\Tasks\Hoolapp For Android.job 2014-04-18 08:57 - 2011-08-06 20:48 - 01158927 _____ () C:\Windows\WindowsUpdate.log 2014-04-18 07:42 - 2013-02-01 22:32 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Spotify 2014-04-18 07:15 - 2014-04-13 16:52 - 00000424 _____ () C:\Windows\Tasks\Re-Markable Update.job 2014-04-18 07:12 - 2014-04-15 05:13 - 00003388 _____ () C:\Windows\System32\Tasks\BackgroundContainer Startup Task 2014-04-18 07:12 - 2014-04-13 16:51 - 00000414 _____ () C:\Windows\Tasks\Re-Markable_wd.job 2014-04-18 07:12 - 2014-02-15 19:26 - 00000292 _____ () C:\Windows\Tasks\Hoolapp Init.job 2014-04-18 07:12 - 2011-09-16 05:04 - 00135339 _____ () C:\Windows\setupact.log 2014-04-18 07:12 - 2011-08-19 21:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-18 07:12 - 2011-08-07 10:03 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\ICQ 2014-04-18 07:12 - 2011-08-06 21:24 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-18 07:12 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-17 18:25 - 2012-12-27 19:25 - 00000000 ____D () C:\Program Files (x86)\DealPly 2014-04-14 17:29 - 2013-02-01 22:33 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Spotify 2014-04-14 04:21 - 2012-11-02 09:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-14 04:21 - 2012-10-03 13:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-14 04:21 - 2011-08-22 10:13 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Adobe 2014-04-14 04:21 - 2011-08-07 08:14 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-13 16:52 - 2014-04-13 16:52 - 00003078 _____ () C:\Windows\System32\Tasks\Re-Markable Update 2014-04-13 16:52 - 2014-04-13 16:51 - 00000000 ____D () C:\Program Files (x86)\Re-Markable-soft 2014-04-13 16:51 - 2014-04-13 16:51 - 00003008 _____ () C:\Windows\System32\Tasks\Re-Markable_wd 2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk 2014-04-13 16:51 - 2014-04-13 16:51 - 00000512 __RSH () C:\ProgramData\ntuser.pol 2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter 2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-10 03:57 - 2013-05-23 19:02 - 00000000 ____D () C:\Windows\rescache 2014-04-10 03:02 - 2013-07-24 21:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 03:01 - 2011-12-12 08:37 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\APN 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork 2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-04-06 17:17 - 2012-09-13 16:16 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-04-06 17:17 - 2011-12-01 08:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-04-06 17:17 - 2011-12-01 08:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-04-06 17:17 - 2011-08-17 16:40 - 00000000 ____D () C:\Program Files (x86)\Java 2014-04-04 16:00 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-04-04 16:00 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-04-04 16:00 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-31 18:50 - 2013-12-18 19:25 - 00000202 _____ () C:\Users\Acidfree\AppData\Roaming\WB.CFG 2014-03-31 03:16 - 2014-04-09 07:24 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 07:24 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-22 09:48 - 2011-10-20 17:38 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Winamp 2014-03-20 17:09 - 2012-05-03 20:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-19 14:03 - 2014-03-19 14:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox Files to move or delete: ==================== C:\ProgramData\nud0repor.pad Some content of TEMP: ==================== C:\Users\Acidfree\AppData\Local\Temp\APNSetup.exe C:\Users\Acidfree\AppData\Local\Temp\avgnt.exe C:\Users\Acidfree\AppData\Local\Temp\DWPUpgradeInstaller.exe C:\Users\Acidfree\AppData\Local\Temp\InstallFlashPlayer.exe C:\Users\Acidfree\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Acidfree\AppData\Local\Temp\nsd5F7B.exe C:\Users\Acidfree\AppData\Local\Temp\nsd623A.exe C:\Users\Acidfree\AppData\Local\Temp\nsn9DE5.exe C:\Users\Acidfree\AppData\Local\Temp\nsnA056.exe C:\Users\Acidfree\AppData\Local\Temp\setup.exe C:\Users\Acidfree\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 06:09 ==================== End Of Log ============================ --- --- --- --- --- --- Und die Addition: Zitat:
Danke für die Hilfe, gibt ja leider keine Ostereier als Smilies :-) Liebe Grüße Emmaline Schreib ich auf die Liste der Dinge die ich machen will, wenn meine Kinder größer sind. So uninteressant finde ich das gar nicht :-) |
18.04.2014, 17:07 | #8 |
/// the machine /// TB-Ausbilder | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Gerne, ich bin dann warscheinlich immer noch hier Revo Uninstaller - Download - Filepony Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION Mit Revo auch Moderat die Reste entfernen lassen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.04.2014, 22:29 | #9 |
| Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Hallo, ich hab da leider ein Problem. Ich konnte nur die "Installed Progamms" mit "ATTENTION"-Vermerk löschen. Es gibt aber noch einige "Tasks" mit dem Vermerk und die konnte ich nicht löschen. Das andere Problem ist, dass die Malware immer an der gleichen Stelle hängen bleibt und daraufhin der PC abstürzt. Das ist jetzt 3x passiert. Die 2x, die ich den Vorgang beobachtet habe, blieb das Programm an der gleichen Stelle hängen. Eine Audiodatei auf dem Desktop. Was soll ich jetzt machen. Frohe Ostern Emmaline |
20.04.2014, 18:10 | #10 |
/// the machine /// TB-Ausbilder | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Tasks und MBAM weglassen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.04.2014, 10:24 | #11 | ||
| Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Sooo, hab die Audiodatei gelöscht und dann ging alles. Hier die ganzen Files Zitat:
Zitat:
FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2014 Ran by Acidfree (administrator) on ACIDFREE-PC on 20-04-2014 14:07:43 Running from C:\Users\Acidfree\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Adobe Systems Incorporated) E:\Photoshop\PhotoshopElementsFileAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe ( ) C:\Windows\system32\lxczcoms.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Spotify Ltd) C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Program Files (x86)\FastMediaConverter\FastMediaConverterApp.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Nullsoft, Inc.) D:\Winamp\winampa.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [WinampAgent] => D:\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [ICQ] => D:\ICQ7.5\ICQ.exe [124480 2011-08-01] (ICQ, LLC.) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Hoolapp Android] => /Minimized HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify Web Helper] => C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-11] (Spotify Ltd) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify] => C:\Users\Acidfree\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-11] (Spotify Ltd) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [PrivacyDr] => C:\Program Files (x86)\Privacy Dr\PrivacyDr.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {237ce8bd-cee5-11e0-b0cf-00242178af47} - J:\Startme.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {2518b13b-372c-11e2-87e8-00242178af47} - G:\pushinst.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {5738becf-f4ff-11e1-8895-806e6f6e6963} - explorer index_GB.html HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {afbc22a3-b183-11e1-b4a9-00242178af47} - G:\Setup.exe Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x449DEC206E54CC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} StartMenuInternet: IEXPLORE.EXE - iexplore.exe BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: ICQ Sparberater - {5A0D6E4B-B0DF-4148-8B1E-F7A430FF5E24} - C:\Program Files (x86)\icq\Internet Explorer\icq.dll (solute gmbh) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default FF NewTab: chrome://quick_start/content/index.html FF SearchEngineOrder.1: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.10.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-26.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-27.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-28.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-29.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-30.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Evernote Web Clipper - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} [2013-12-19] FF Extension: DivX Web Player - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\DivXWebPlayer@divx.com.xpi [2012-03-01] FF Extension: GMX MailCheck - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar@gmx.net.xpi [2012-05-04] FF Extension: Ask Toolbar - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-02-25] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-19] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll No File CHR Plugin: (Skype Toolbars) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll (Skype Technologies S.A.) CHR Plugin: (registryAccess) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj\7.15.1.0_0\background/registryAccess.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Unity Player) - C:\Users\Acidfree\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Extension: (No Name) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj [2012-09-02] CHR Extension: (Skype Click to Call) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2011-08-19] CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-03-11] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-10-10] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AdobeActiveFileMonitor7.0; E:\Photoshop\PhotoshopElementsFileAgent.exe [169312 2008-09-16] (Adobe Systems Incorporated) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-03-26] (APN LLC.) R2 lxcz_device; C:\Windows\system32\lxczcoms.exe [566192 2007-04-19] ( ) R2 lxcz_device; C:\Windows\SysWOW64\lxczcoms.exe [537520 2007-04-19] ( ) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.) S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S2 vosr; C:\Users\Acidfree\AppData\Roaming\VOPackage\VOsrv.exe [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [119512 2014-04-20] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2013-03-07] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [9584 2013-03-07] () S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-20 14:07 - 2014-04-20 14:07 - 00000000 ____D () C:\Users\Acidfree\Desktop\FRST-OlderVersion 2014-04-20 13:57 - 2014-04-20 14:04 - 00002052 _____ () C:\Users\Acidfree\Desktop\JRT.txt 2014-04-20 13:49 - 2014-04-20 13:49 - 01016261 _____ (Thisisu) C:\Users\Acidfree\Desktop\JRT.exe 2014-04-20 13:49 - 2014-04-20 13:49 - 00000000 ____D () C:\Windows\ERUNT 2014-04-20 13:48 - 2014-04-20 13:48 - 00123323 _____ () C:\Users\Acidfree\Desktop\AdwCleaner[S0].txt 2014-04-20 13:17 - 2014-04-20 13:24 - 00000000 ____D () C:\AdwCleaner 2014-04-20 13:17 - 2014-04-20 13:16 - 01308369 _____ () C:\Users\Acidfree\Desktop\adwcleaner.exe 2014-04-20 13:00 - 2014-04-20 13:00 - 00003654 _____ () C:\Users\Acidfree\Desktop\mbam.txt 2014-04-19 21:55 - 2014-04-19 21:55 - 423694260 _____ () C:\Windows\MEMORY.DMP 2014-04-19 21:55 - 2014-04-19 21:55 - 00298800 _____ () C:\Windows\Minidump\041914-17659-01.dmp 2014-04-19 21:13 - 2014-04-20 13:37 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 21:13 - 2014-04-19 21:13 - 00001116 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 21:13 - 2014-04-19 21:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 21:13 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-19 21:13 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-19 21:13 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-19 20:51 - 2014-04-19 20:51 - 00001278 _____ () C:\Users\Acidfree\Desktop\Revo Uninstaller.lnk 2014-04-19 20:51 - 2014-04-19 20:51 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-18 12:01 - 2014-04-18 14:47 - 00003368 _____ () C:\Windows\System32\Tasks\PrivacyDr_Splash 2014-04-18 12:01 - 2014-04-18 12:03 - 00000000 ____D () C:\Users\Acidfree\Documents\PrivacyDr 2014-04-18 12:01 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\HistoryCleaner 2014-04-18 11:58 - 2014-04-18 11:58 - 01097384 _____ (AnyProtect.com) C:\Users\Acidfree\AppData\Local\nsvD72C.tmp 2014-04-18 10:11 - 2014-04-18 10:11 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Evernote 2014-04-18 10:10 - 2014-04-18 10:10 - 00000932 _____ () C:\Users\Acidfree\Desktop\Evernote.lnk 2014-04-18 10:10 - 2014-04-18 10:10 - 00000000 ____D () C:\Program Files (x86)\Evernote 2014-04-18 10:02 - 2014-04-18 10:08 - 00027724 _____ () C:\Users\Acidfree\Desktop\Addition.txt 2014-04-18 10:00 - 2014-04-20 14:07 - 02055680 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe 2014-04-18 10:00 - 2014-04-20 14:07 - 00017482 _____ () C:\Users\Acidfree\Desktop\FRST.txt 2014-04-18 10:00 - 2014-04-20 14:07 - 00000000 ____D () C:\FRST 2014-04-13 16:51 - 2014-04-20 13:48 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter 2014-04-13 16:51 - 2014-04-19 21:06 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk 2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter 2014-04-09 07:24 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 07:24 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 07:24 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 07:24 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 07:24 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 07:24 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 07:24 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 07:24 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 07:24 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 07:24 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 07:24 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 07:24 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 07:24 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 07:24 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 07:24 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 07:24 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork 2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll ==================== One Month Modified Files and Folders ======= 2014-04-20 14:08 - 2014-04-18 10:00 - 00017482 _____ () C:\Users\Acidfree\Desktop\FRST.txt 2014-04-20 14:07 - 2014-04-20 14:07 - 00000000 ____D () C:\Users\Acidfree\Desktop\FRST-OlderVersion 2014-04-20 14:07 - 2014-04-18 10:00 - 02055680 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe 2014-04-20 14:07 - 2014-04-18 10:00 - 00000000 ____D () C:\FRST 2014-04-20 14:06 - 2012-11-02 09:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-20 14:04 - 2014-04-20 13:57 - 00002052 _____ () C:\Users\Acidfree\Desktop\JRT.txt 2014-04-20 13:49 - 2014-04-20 13:49 - 01016261 _____ (Thisisu) C:\Users\Acidfree\Desktop\JRT.exe 2014-04-20 13:49 - 2014-04-20 13:49 - 00000000 ____D () C:\Windows\ERUNT 2014-04-20 13:48 - 2014-04-20 13:48 - 00123323 _____ () C:\Users\Acidfree\Desktop\AdwCleaner[S0].txt 2014-04-20 13:48 - 2014-04-13 16:51 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter 2014-04-20 13:48 - 2013-02-01 22:32 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Spotify 2014-04-20 13:47 - 2011-08-07 10:03 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\ICQ 2014-04-20 13:42 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-20 13:42 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-20 13:37 - 2014-04-19 21:13 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-20 13:36 - 2011-08-19 21:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-20 13:34 - 2011-09-16 05:04 - 00135787 _____ () C:\Windows\setupact.log 2014-04-20 13:34 - 2011-08-06 21:24 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-20 13:34 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-20 13:33 - 2011-08-06 20:48 - 01294945 _____ () C:\Windows\WindowsUpdate.log 2014-04-20 13:27 - 2011-08-19 21:27 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-20 13:24 - 2014-04-20 13:17 - 00000000 ____D () C:\AdwCleaner 2014-04-20 13:16 - 2014-04-20 13:17 - 01308369 _____ () C:\Users\Acidfree\Desktop\adwcleaner.exe 2014-04-20 13:03 - 2011-10-21 08:26 - 00319134 _____ () C:\Windows\PFRO.log 2014-04-20 13:00 - 2014-04-20 13:00 - 00003654 _____ () C:\Users\Acidfree\Desktop\mbam.txt 2014-04-19 22:47 - 2011-08-07 08:15 - 00000000 ____D () C:\Windows\System32\Tasks\Games 2014-04-19 22:40 - 2011-08-06 21:29 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware 2014-04-19 21:55 - 2014-04-19 21:55 - 423694260 _____ () C:\Windows\MEMORY.DMP 2014-04-19 21:55 - 2014-04-19 21:55 - 00298800 _____ () C:\Windows\Minidump\041914-17659-01.dmp 2014-04-19 21:55 - 2011-08-08 06:57 - 00000000 ____D () C:\Windows\Minidump 2014-04-19 21:13 - 2014-04-19 21:13 - 00001116 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 21:13 - 2014-04-19 21:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 21:13 - 2012-09-03 16:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 21:11 - 2011-08-06 21:34 - 00001152 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-19 21:11 - 2011-08-06 21:03 - 00001435 _____ () C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-19 21:06 - 2014-04-13 16:51 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-04-19 20:51 - 2014-04-19 20:51 - 00001278 _____ () C:\Users\Acidfree\Desktop\Revo Uninstaller.lnk 2014-04-19 20:51 - 2014-04-19 20:51 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-18 14:47 - 2014-04-18 12:01 - 00003368 _____ () C:\Windows\System32\Tasks\PrivacyDr_Splash 2014-04-18 12:03 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\Documents\PrivacyDr 2014-04-18 12:01 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\HistoryCleaner 2014-04-18 11:58 - 2014-04-18 11:58 - 01097384 _____ (AnyProtect.com) C:\Users\Acidfree\AppData\Local\nsvD72C.tmp 2014-04-18 10:12 - 2011-08-06 21:03 - 00000000 ___RD () C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-18 10:11 - 2014-04-18 10:11 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Evernote 2014-04-18 10:10 - 2014-04-18 10:10 - 00000932 _____ () C:\Users\Acidfree\Desktop\Evernote.lnk 2014-04-18 10:10 - 2014-04-18 10:10 - 00000000 ____D () C:\Program Files (x86)\Evernote 2014-04-18 10:08 - 2014-04-18 10:02 - 00027724 _____ () C:\Users\Acidfree\Desktop\Addition.txt 2014-04-14 17:29 - 2013-02-01 22:33 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Spotify 2014-04-14 04:21 - 2012-11-02 09:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-14 04:21 - 2012-10-03 13:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-14 04:21 - 2011-08-22 10:13 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Adobe 2014-04-14 04:21 - 2011-08-07 08:14 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk 2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter 2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-10 03:57 - 2013-05-23 19:02 - 00000000 ____D () C:\Windows\rescache 2014-04-10 03:02 - 2013-07-24 21:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 03:01 - 2011-12-12 08:37 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork 2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-04-06 17:17 - 2012-09-13 16:16 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-04-06 17:17 - 2011-12-01 08:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-04-06 17:17 - 2011-12-01 08:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-04-06 17:17 - 2011-08-17 16:40 - 00000000 ____D () C:\Program Files (x86)\Java 2014-04-04 16:00 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-04-04 16:00 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-04-04 16:00 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-03 09:51 - 2014-04-19 21:13 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-19 21:13 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-19 21:13 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 18:50 - 2013-12-18 19:25 - 00000202 _____ () C:\Users\Acidfree\AppData\Roaming\WB.CFG 2014-03-31 03:16 - 2014-04-09 07:24 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 07:24 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-22 09:48 - 2011-10-20 17:38 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Winamp Files to move or delete: ==================== C:\ProgramData\nud0repor.pad Some content of TEMP: ==================== C:\Users\Acidfree\AppData\Local\Temp\APNSetup.exe C:\Users\Acidfree\AppData\Local\Temp\avgnt.exe C:\Users\Acidfree\AppData\Local\Temp\DWPUpgradeInstaller.exe C:\Users\Acidfree\AppData\Local\Temp\installer.exe C:\Users\Acidfree\AppData\Local\Temp\InstallFlashPlayer.exe C:\Users\Acidfree\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Acidfree\AppData\Local\Temp\PrivacyDrSetup_S.exe C:\Users\Acidfree\AppData\Local\Temp\Quarantine.exe C:\Users\Acidfree\AppData\Local\Temp\setup.exe C:\Users\Acidfree\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 06:09 ==================== End Of Log ============================ Ich mach dann mal die Anfangs Logs am Laptop. Den hab ich nicht so oft. Liebe Grüße Emmaline |
21.04.2014, 20:55 | #12 |
/// the machine /// TB-Ausbilder | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...)ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.04.2014, 12:40 | #13 | ||
| Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Sieht alles ganz gut aus :-) ESET Zitat:
Zitat:
FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014 Ran by Acidfree (administrator) on ACIDFREE-PC on 22-04-2014 13:34:44 Running from C:\Users\Acidfree\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Adobe Systems Incorporated) E:\Photoshop\PhotoshopElementsFileAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe ( ) C:\Windows\system32\lxczcoms.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Spotify Ltd) C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Program Files (x86)\FastMediaConverter\FastMediaConverterApp.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Nullsoft, Inc.) D:\Winamp\winampa.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [WinampAgent] => D:\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [ICQ] => D:\ICQ7.5\ICQ.exe [124480 2011-08-01] (ICQ, LLC.) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Hoolapp Android] => /Minimized HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify Web Helper] => C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-11] (Spotify Ltd) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify] => C:\Users\Acidfree\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-11] (Spotify Ltd) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [PrivacyDr] => C:\Program Files (x86)\Privacy Dr\PrivacyDr.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {237ce8bd-cee5-11e0-b0cf-00242178af47} - J:\Startme.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {2518b13b-372c-11e2-87e8-00242178af47} - G:\pushinst.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {5738becf-f4ff-11e1-8895-806e6f6e6963} - explorer index_GB.html HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {afbc22a3-b183-11e1-b4a9-00242178af47} - G:\Setup.exe Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x449DEC206E54CC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} StartMenuInternet: IEXPLORE.EXE - iexplore.exe BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: ICQ Sparberater - {5A0D6E4B-B0DF-4148-8B1E-F7A430FF5E24} - C:\Program Files (x86)\icq\Internet Explorer\icq.dll (solute gmbh) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: ICQ Search FF SearchEngineOrder.1: Google FF SelectedSearchEngine: ICQ Search FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.10.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-26.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-27.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-28.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-29.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-30.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Evernote Web Clipper - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} [2013-12-19] FF Extension: DivX Web Player - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\DivXWebPlayer@divx.com.xpi [2012-03-01] FF Extension: GMX MailCheck - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar@gmx.net.xpi [2012-05-04] FF Extension: Ask Toolbar - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-02-25] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-19] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll No File CHR Plugin: (Skype Toolbars) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll (Skype Technologies S.A.) CHR Plugin: (registryAccess) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj\7.15.1.0_0\background/registryAccess.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Unity Player) - C:\Users\Acidfree\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Extension: (No Name) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj [2012-09-02] CHR Extension: (Skype Click to Call) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2011-08-19] CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-03-11] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-10-10] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AdobeActiveFileMonitor7.0; E:\Photoshop\PhotoshopElementsFileAgent.exe [169312 2008-09-16] (Adobe Systems Incorporated) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-03-26] (APN LLC.) R2 lxcz_device; C:\Windows\system32\lxczcoms.exe [566192 2007-04-19] ( ) R2 lxcz_device; C:\Windows\SysWOW64\lxczcoms.exe [537520 2007-04-19] ( ) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.) S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S2 vosr; C:\Users\Acidfree\AppData\Roaming\VOPackage\VOsrv.exe [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-22] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2013-03-07] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [9584 2013-03-07] () S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-22 13:24 - 2014-04-22 13:24 - 00001177 _____ () C:\Users\Acidfree\Desktop\checkup.txt 2014-04-22 13:03 - 2014-04-22 13:02 - 00855379 _____ () C:\Users\Acidfree\Desktop\SecurityCheck.exe 2014-04-22 13:02 - 2014-04-22 13:02 - 00000917 _____ () C:\Users\Acidfree\Desktop\ESET.txt 2014-04-22 12:50 - 2014-04-22 12:50 - 02347384 _____ (ESET) C:\Users\Acidfree\Desktop\esetsmartinstaller_enu.exe 2014-04-20 14:12 - 2014-04-20 14:12 - 00033047 _____ () C:\Users\Acidfree\Desktop\FRST2.txt 2014-04-20 14:07 - 2014-04-22 13:34 - 00000000 ____D () C:\Users\Acidfree\Desktop\FRST-OlderVersion 2014-04-20 13:57 - 2014-04-20 14:04 - 00002052 _____ () C:\Users\Acidfree\Desktop\JRT.txt 2014-04-20 13:49 - 2014-04-20 13:49 - 01016261 _____ (Thisisu) C:\Users\Acidfree\Desktop\JRT.exe 2014-04-20 13:49 - 2014-04-20 13:49 - 00000000 ____D () C:\Windows\ERUNT 2014-04-20 13:48 - 2014-04-20 13:48 - 00123323 _____ () C:\Users\Acidfree\Desktop\AdwCleaner[S0].txt 2014-04-20 13:17 - 2014-04-20 13:24 - 00000000 ____D () C:\AdwCleaner 2014-04-20 13:17 - 2014-04-20 13:16 - 01308369 _____ () C:\Users\Acidfree\Desktop\adwcleaner.exe 2014-04-20 13:00 - 2014-04-20 13:00 - 00003654 _____ () C:\Users\Acidfree\Desktop\mbam.txt 2014-04-19 21:55 - 2014-04-19 21:55 - 423694260 _____ () C:\Windows\MEMORY.DMP 2014-04-19 21:55 - 2014-04-19 21:55 - 00298800 _____ () C:\Windows\Minidump\041914-17659-01.dmp 2014-04-19 21:13 - 2014-04-22 13:28 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 21:13 - 2014-04-19 21:13 - 00001116 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 21:13 - 2014-04-19 21:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 21:13 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-19 21:13 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-19 21:13 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-19 20:51 - 2014-04-19 20:51 - 00001278 _____ () C:\Users\Acidfree\Desktop\Revo Uninstaller.lnk 2014-04-19 20:51 - 2014-04-19 20:51 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-18 12:01 - 2014-04-18 14:47 - 00003368 _____ () C:\Windows\System32\Tasks\PrivacyDr_Splash 2014-04-18 12:01 - 2014-04-18 12:03 - 00000000 ____D () C:\Users\Acidfree\Documents\PrivacyDr 2014-04-18 12:01 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\HistoryCleaner 2014-04-18 11:58 - 2014-04-18 11:58 - 01097384 _____ (AnyProtect.com) C:\Users\Acidfree\AppData\Local\nsvD72C.tmp 2014-04-18 10:11 - 2014-04-18 10:11 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Evernote 2014-04-18 10:10 - 2014-04-18 10:10 - 00000932 _____ () C:\Users\Acidfree\Desktop\Evernote.lnk 2014-04-18 10:10 - 2014-04-18 10:10 - 00000000 ____D () C:\Program Files (x86)\Evernote 2014-04-18 10:02 - 2014-04-18 10:08 - 00027724 _____ () C:\Users\Acidfree\Desktop\Addition.txt 2014-04-18 10:00 - 2014-04-22 13:34 - 02061312 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe 2014-04-18 10:00 - 2014-04-22 13:34 - 00017476 _____ () C:\Users\Acidfree\Desktop\FRST.txt 2014-04-18 10:00 - 2014-04-22 13:34 - 00000000 ____D () C:\FRST 2014-04-13 16:51 - 2014-04-22 13:33 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter 2014-04-13 16:51 - 2014-04-19 21:06 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk 2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter 2014-04-09 07:24 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 07:24 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 07:24 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 07:24 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 07:24 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 07:24 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 07:24 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 07:24 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 07:24 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 07:24 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 07:24 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 07:24 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 07:24 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 07:24 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 07:24 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 07:24 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork 2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll ==================== One Month Modified Files and Folders ======= 2014-04-22 13:34 - 2014-04-20 14:07 - 00000000 ____D () C:\Users\Acidfree\Desktop\FRST-OlderVersion 2014-04-22 13:34 - 2014-04-18 10:00 - 02061312 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe 2014-04-22 13:34 - 2014-04-18 10:00 - 00017476 _____ () C:\Users\Acidfree\Desktop\FRST.txt 2014-04-22 13:34 - 2014-04-18 10:00 - 00000000 ____D () C:\FRST 2014-04-22 13:33 - 2014-04-13 16:51 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter 2014-04-22 13:28 - 2014-04-19 21:13 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-22 13:27 - 2011-08-19 21:27 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-22 13:24 - 2014-04-22 13:24 - 00001177 _____ () C:\Users\Acidfree\Desktop\checkup.txt 2014-04-22 13:06 - 2012-11-02 09:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-22 13:02 - 2014-04-22 13:03 - 00855379 _____ () C:\Users\Acidfree\Desktop\SecurityCheck.exe 2014-04-22 13:02 - 2014-04-22 13:02 - 00000917 _____ () C:\Users\Acidfree\Desktop\ESET.txt 2014-04-22 12:52 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-04-22 12:52 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-04-22 12:52 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-22 12:51 - 2013-02-01 22:32 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Spotify 2014-04-22 12:50 - 2014-04-22 12:50 - 02347384 _____ (ESET) C:\Users\Acidfree\Desktop\esetsmartinstaller_enu.exe 2014-04-22 12:48 - 2011-08-07 10:03 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\ICQ 2014-04-22 12:47 - 2011-08-19 21:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-22 12:46 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-22 12:46 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-22 12:42 - 2011-08-06 20:48 - 01369921 _____ () C:\Windows\WindowsUpdate.log 2014-04-22 12:38 - 2011-09-16 05:04 - 00135955 _____ () C:\Windows\setupact.log 2014-04-22 12:38 - 2011-08-06 21:24 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-22 12:38 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-20 14:12 - 2014-04-20 14:12 - 00033047 _____ () C:\Users\Acidfree\Desktop\FRST2.txt 2014-04-20 14:04 - 2014-04-20 13:57 - 00002052 _____ () C:\Users\Acidfree\Desktop\JRT.txt 2014-04-20 13:49 - 2014-04-20 13:49 - 01016261 _____ (Thisisu) C:\Users\Acidfree\Desktop\JRT.exe 2014-04-20 13:49 - 2014-04-20 13:49 - 00000000 ____D () C:\Windows\ERUNT 2014-04-20 13:48 - 2014-04-20 13:48 - 00123323 _____ () C:\Users\Acidfree\Desktop\AdwCleaner[S0].txt 2014-04-20 13:24 - 2014-04-20 13:17 - 00000000 ____D () C:\AdwCleaner 2014-04-20 13:23 - 2011-08-07 10:03 - 00000000 ____D () C:\ProgramData\ICQ 2014-04-20 13:16 - 2014-04-20 13:17 - 01308369 _____ () C:\Users\Acidfree\Desktop\adwcleaner.exe 2014-04-20 13:03 - 2011-10-21 08:26 - 00319134 _____ () C:\Windows\PFRO.log 2014-04-20 13:00 - 2014-04-20 13:00 - 00003654 _____ () C:\Users\Acidfree\Desktop\mbam.txt 2014-04-19 22:47 - 2011-08-07 08:15 - 00000000 ____D () C:\Windows\System32\Tasks\Games 2014-04-19 22:40 - 2011-08-06 21:29 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware 2014-04-19 21:55 - 2014-04-19 21:55 - 423694260 _____ () C:\Windows\MEMORY.DMP 2014-04-19 21:55 - 2014-04-19 21:55 - 00298800 _____ () C:\Windows\Minidump\041914-17659-01.dmp 2014-04-19 21:55 - 2011-08-08 06:57 - 00000000 ____D () C:\Windows\Minidump 2014-04-19 21:13 - 2014-04-19 21:13 - 00001116 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 21:13 - 2014-04-19 21:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 21:13 - 2012-09-03 16:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 21:11 - 2011-08-06 21:34 - 00001152 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-19 21:11 - 2011-08-06 21:03 - 00001435 _____ () C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-19 21:06 - 2014-04-13 16:51 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-04-19 20:51 - 2014-04-19 20:51 - 00001278 _____ () C:\Users\Acidfree\Desktop\Revo Uninstaller.lnk 2014-04-19 20:51 - 2014-04-19 20:51 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-18 14:47 - 2014-04-18 12:01 - 00003368 _____ () C:\Windows\System32\Tasks\PrivacyDr_Splash 2014-04-18 12:03 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\Documents\PrivacyDr 2014-04-18 12:01 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\HistoryCleaner 2014-04-18 11:58 - 2014-04-18 11:58 - 01097384 _____ (AnyProtect.com) C:\Users\Acidfree\AppData\Local\nsvD72C.tmp 2014-04-18 10:12 - 2011-08-06 21:03 - 00000000 ___RD () C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-18 10:11 - 2014-04-18 10:11 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Evernote 2014-04-18 10:10 - 2014-04-18 10:10 - 00000932 _____ () C:\Users\Acidfree\Desktop\Evernote.lnk 2014-04-18 10:10 - 2014-04-18 10:10 - 00000000 ____D () C:\Program Files (x86)\Evernote 2014-04-18 10:08 - 2014-04-18 10:02 - 00027724 _____ () C:\Users\Acidfree\Desktop\Addition.txt 2014-04-14 17:29 - 2013-02-01 22:33 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Spotify 2014-04-14 04:21 - 2012-11-02 09:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-14 04:21 - 2012-10-03 13:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-14 04:21 - 2011-08-22 10:13 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Adobe 2014-04-14 04:21 - 2011-08-07 08:14 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk 2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter 2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-10 03:57 - 2013-05-23 19:02 - 00000000 ____D () C:\Windows\rescache 2014-04-10 03:02 - 2013-07-24 21:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 03:01 - 2011-12-12 08:37 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork 2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-04-06 17:17 - 2012-09-13 16:16 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-04-06 17:17 - 2011-12-01 08:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-04-06 17:17 - 2011-12-01 08:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-04-06 17:17 - 2011-08-17 16:40 - 00000000 ____D () C:\Program Files (x86)\Java 2014-04-03 09:51 - 2014-04-19 21:13 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-19 21:13 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-19 21:13 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 18:50 - 2013-12-18 19:25 - 00000202 _____ () C:\Users\Acidfree\AppData\Roaming\WB.CFG 2014-03-31 03:16 - 2014-04-09 07:24 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 07:24 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll Files to move or delete: ==================== C:\ProgramData\nud0repor.pad Some content of TEMP: ==================== C:\Users\Acidfree\AppData\Local\Temp\APNSetup.exe C:\Users\Acidfree\AppData\Local\Temp\avgnt.exe C:\Users\Acidfree\AppData\Local\Temp\DWPUpgradeInstaller.exe C:\Users\Acidfree\AppData\Local\Temp\installer.exe C:\Users\Acidfree\AppData\Local\Temp\InstallFlashPlayer.exe C:\Users\Acidfree\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Acidfree\AppData\Local\Temp\PrivacyDrSetup_S.exe C:\Users\Acidfree\AppData\Local\Temp\Quarantine.exe C:\Users\Acidfree\AppData\Local\Temp\setup.exe C:\Users\Acidfree\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-20 14:48 ==================== End Of Log ============================ Danke :-) |
22.04.2014, 19:06 | #14 |
/// the machine /// TB-Ausbilder | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Java und Thunderbird updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Hoolapp Android] => /Minimized GroupPolicy: Group Policy on Chrome detected <======= ATTENTION C:\ProgramData\nud0repor.pad Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade dir bitte Farbar Service Scanner
Poste bitte den Inhalt hier.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.04.2014, 21:39 | #15 | ||
| Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Java habe ich aktuallisiert. Thunderbird wird überhaupt nicht mehr genutzt. Soll ich es trotzdem aktuallisieren? Hier die gewünschten Infos: Fixlog Zitat:
Zitat:
Emmaline |
Themen zu Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) |
antivir, antivirus, avg, bingbar, browser, defender, desktop, excel, fehlercode 1, flash player, helper, homepage, iexplore.exe, installation, mozilla, msiinstaller, newtab, object, programm, quick_start, registry, scan, security, services.exe, software, stick, svchost.exe, updates, werbung, windows |