|
Plagegeister aller Art und deren Bekämpfung: Probleme mit istart.webssearches.comWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
15.04.2014, 18:03 | #1 |
| Probleme mit istart.webssearches.com Hallo, nachdem ich schon mal Probleme mit heruntergeladenen Programmen hatte, brauche ich mal wieder Hilfe, weil ich versucht habe, ein Freeware-Programm herunterzuladen. z.B. Java Update wurde angefangen, brach dann aber ab. Wenn ich Firefox öffne, sollte eigentlich Google als Startseite erscheinen, aber es taucht immer:hxxp://istart.webssearches.com/?type=sc&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69 auf. Aussserdem erscheit im Browserfenster immer ein Popup mitWerbung. Scan mit Malware habe ich gemacht, Bedrohungen gelöscht, bringt aber nichts. Wäre nett, wenn mir jemand helfen kann. Viele Grüsse Driver23 Geändert von Driver23 (15.04.2014 um 18:14 Uhr) |
15.04.2014, 18:04 | #2 |
/// the machine /// TB-Ausbilder | Probleme mit istart.webssearches.com hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
15.04.2014, 19:08 | #3 |
| Probleme mit istart.webssearches.com Herzlichen Dank für die superschnelle Antwort.
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-04-2014 Ran by Pod (administrator) on POD-PC on 15-04-2014 20:01:01 Running from C:\Users\Pod\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe (Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe () C:\Windows\SysWOW64\PSIService.exe () c:\Program Files\RrFilter\RrFilterService64.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Dropbox, Inc.) C:\Users\Pod\AppData\Roaming\Dropbox\bin\Dropbox.exe (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Bartels Media GmbH) C:\PhraseExpress\phraseexpress.exe () C:\Program Files (x86)\IDMSQ\idmsq.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\splwow64.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKU\S-1-5-19\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation) HKU\S-1-5-20\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation) HKU\S-1-5-21-3960197758-2477925476-223839332-1001\...\Run: [] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-14] (Samsung) HKU\S-1-5-21-3960197758-2477925476-223839332-1001\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\sidebar.exe [1475584 2010-11-21] (Microsoft Corporation) HKU\S-1-5-21-3960197758-2477925476-223839332-1001\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-14] (Samsung) HKU\S-1-5-21-3960197758-2477925476-223839332-1001\...\Run: [Messenger (Yahoo!)] => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.) HKU\S-1-5-21-3960197758-2477925476-223839332-1001\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-3960197758-2477925476-223839332-1001\...\Run: [IDMSQ] => C:\Program Files (x86)\IDMSQ\idmsq.exe [2561088 2013-10-30] () AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => "C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll" File Not Found Startup: C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Pod\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC3322628F9C1CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM-x32 - DefaultScope {BC73C780-0926-4885-8602-33442E1C6EF9} URL = SearchScopes: HKCU - DefaultScope {BC73C780-0926-4885-8602-33442E1C6EF9} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKCU - {9BD27B24-13BE-4DDD-9586-61254659E6CD} URL = hxxp://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = SearchScopes: HKCU - {BC73C780-0926-4885-8602-33442E1C6EF9} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO-x32: Browser Guard - {02a0d829-4393-46fc-a37e-126263035883} - C:\Program Files (x86)\Browser Guard\browserguard.dll (Browser Guard) BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: Idmsq Extension - {3AA4FC9D-FB51-44a2-B09F-0457857CA7C2} - C:\Users\Pod\AppData\Roaming\IDMSQ\idmsqext.dll (Or Interactive Ltd) BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) Toolbar: HKLM - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent64.dll (soft Xpansion) Toolbar: HKLM-x32 - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent32.dll (soft Xpansion) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Hosts: 127.0.0.1 d3oxij66pru1i3.cloudfront.net Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: webssearches FF SelectedSearchEngine: webssearches FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @soft-xpansion/npsxpdf - C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\searchplugins\yahoo_ff.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Internet Download Manager Squared - C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\Extensions\idmsq@idmsq.com [2014-04-15] FF Extension: Adblock Plus - C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-15] FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi FF Extension: Browser Guard - C:\Program Files (x86)\Browser Guard\browserguard.xpi [2013-08-27] FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb [2013-10-08] FF HKLM-x32\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb [2013-10-08] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR DefaultSearchProvider: Search the web (Softonic) CHR DefaultSearchURL: hxxp://www.google.com CHR Extension: (No Name) - C:\Users\Pod\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab [2014-01-01] CHR HKLM-x32\...\Chrome\Extension: [hbcennhacfaagdopikcegfcobcadeocj] - C:\Program Files (x86)\Common Files\Spigot\GC\saebay_1.1.crx [2014-01-01] CHR HKLM-x32\...\Chrome\Extension: [icdlfehblmklkikfigmjhbmmpmkmpooj] - C:\Program Files (x86)\Common Files\Spigot\GC\errorassistant_1.1.crx [2014-01-01] CHR HKLM-x32\...\Chrome\Extension: [kfepagcelbegkpkcjgfeecmlnmkedjin] - C:\Program Files (x86)\Browser Guard\browserguard.crx [2013-08-27] CHR HKLM-x32\...\Chrome\Extension: [mhkaekfpcppmmioggniknbnbdbcigpkk] - C:\Users\Pod\AppData\Local\Slick Savings\coupons.crx [2013-08-27] CHR HKLM-x32\...\Chrome\Extension: [ohenffmfbnoidogjgebadealdkecjdal] - C:\Users\Pod\AppData\Roaming\IDMSQ\IDMSQ.crx [2013-09-24] CHR HKLM-x32\...\Chrome\Extension: [pfndaklgolladniicklehhancnlgocpp] - C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx [2013-09-24] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-22] (Advanced Micro Devices, Inc.) R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [506288 2011-02-08] (REINER SCT) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-02-18] (Nero AG) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [529704 2008-02-28] (Nero AG) R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) R2 ProtexisLicensing; C:\Windows\SysWOW64\PSIService.exe [177704 2007-06-05] () R2 RrFilterService64; c:\Program Files\RrFilter\RrFilterService64.exe [171008 2014-03-06] () R2 StarMoney Business 6.0 OnlineUpdate; C:\Program Files (x86)\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-10-08] (soft Xpansion) S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe" [X] ==================== Drivers (Whitelisted) ==================== S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2010-11-27] (REINER SCT) S3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-19] (Siliten) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-15] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [61736 2014-02-28] (NetFilterSDK.com) R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) S1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [90960 2013-03-15] (Windows (R) 2000 DDK provider) S1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633680 2013-03-15] (Paragon) S1 Uim_VIM; C:\Windows\System32\Drivers\uim_vimx64.sys [390352 2013-03-15] (Paragon) S3 MSICDSetup; \??\F:\CDriver64.sys [X] S3 NTIDrvr; System32\Drivers\NTIDrvr.sys [X] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-15 20:01 - 2014-04-15 20:01 - 00016475 _____ () C:\Users\Pod\Downloads\FRST.txt 2014-04-15 20:00 - 2014-04-15 20:01 - 00000000 ____D () C:\FRST 2014-04-15 19:59 - 2014-04-15 20:00 - 02054144 _____ (Farbar) C:\Users\Pod\Downloads\FRST64 (2).exe 2014-04-15 19:58 - 2014-04-15 19:58 - 02054144 _____ (Farbar) C:\Users\Pod\Downloads\FRST64 (1).exe 2014-04-15 19:54 - 2014-04-15 19:55 - 02054144 _____ (Farbar) C:\Users\Pod\Downloads\FRST64.exe 2014-04-15 18:52 - 2014-04-15 18:52 - 00000000 _____ () C:\Users\Pod\defogger_reenable 2014-04-15 18:51 - 2014-04-15 18:51 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\IDM2 2014-04-15 18:48 - 2014-04-15 20:00 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\IDMSQ 2014-04-15 18:48 - 2014-04-15 18:48 - 00050477 _____ () C:\Users\Pod\Downloads\Defogger.exe 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IDMSQ 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D () C:\Program Files (x86)\IDMSQ 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D () C:\MININT 2014-04-15 16:18 - 2014-04-15 16:26 - 00000000 ____D () C:\Users\Pod\AppData\Local\Mobogenie 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D () C:\Users\Pod\Documents\Mobogenie 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D () C:\Users\Pod\AppData\Local\cache 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 _____ () C:\Users\Pod\daemonprocess.txt 2014-04-15 16:17 - 2014-04-15 16:26 - 00000000 ____D () C:\Program Files (x86)\Mobogenie 2014-04-15 16:16 - 2014-04-15 16:17 - 00000000 ____D () C:\Users\Pod\AppData\Local\SearchProtect 2014-04-15 16:15 - 2014-04-15 18:42 - 00000000 ____D () C:\Program Files\RrFilter 2014-04-15 16:14 - 2014-04-15 16:14 - 00000000 ____D () C:\Program Files (x86)\RrSavings 2014-04-15 16:13 - 2014-04-15 16:13 - 00000000 ____D () C:\Program Files\rrsavings 2014-04-15 16:12 - 2014-04-15 16:44 - 00000000 ____D () C:\Program Files\002 2014-04-15 16:12 - 2014-04-15 16:26 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\SupTab 2014-04-15 16:12 - 2014-04-15 16:12 - 00001950 _____ () C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lollipop.lnk 2014-04-15 16:11 - 2014-04-15 16:12 - 00000000 ____D () C:\ProgramData\WPM 2014-04-15 16:10 - 2014-04-15 16:26 - 00000000 ____D () C:\Users\Pod\AppData\Local\41 2014-04-14 17:50 - 2014-04-14 19:20 - 00000000 ____D () C:\ProgramData\boost_interprocess 2014-04-12 15:14 - 2014-04-15 19:46 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-12 15:14 - 2014-04-12 15:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-12 15:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-12 15:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-10 19:06 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 19:06 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 19:06 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 19:06 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 19:05 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 19:05 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 19:05 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 19:05 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 19:05 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 19:05 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 19:05 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 19:05 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 19:05 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 19:05 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 19:05 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 19:05 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-03-29 14:15 - 2014-03-29 14:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-21 11:05 - 2014-03-21 15:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird ==================== One Month Modified Files and Folders ======= 2014-04-15 20:01 - 2014-04-15 20:01 - 00016475 _____ () C:\Users\Pod\Downloads\FRST.txt 2014-04-15 20:01 - 2014-04-15 20:00 - 00000000 ____D () C:\FRST 2014-04-15 20:00 - 2014-04-15 19:59 - 02054144 _____ (Farbar) C:\Users\Pod\Downloads\FRST64 (2).exe 2014-04-15 20:00 - 2014-04-15 18:48 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\IDMSQ 2014-04-15 20:00 - 2009-07-14 06:45 - 00022240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-15 20:00 - 2009-07-14 06:45 - 00022240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-15 19:58 - 2014-04-15 19:58 - 02054144 _____ (Farbar) C:\Users\Pod\Downloads\FRST64 (1).exe 2014-04-15 19:55 - 2014-04-15 19:54 - 02054144 _____ (Farbar) C:\Users\Pod\Downloads\FRST64.exe 2014-04-15 19:55 - 2013-10-05 20:31 - 00081480 _____ () C:\Users\Pod\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-15 19:46 - 2014-04-12 15:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-15 19:41 - 2013-10-08 14:21 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-15 19:29 - 2013-10-09 09:35 - 01629081 _____ () C:\Windows\WindowsUpdate.log 2014-04-15 19:18 - 2013-10-26 10:56 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-15 18:52 - 2014-04-15 18:52 - 00000000 _____ () C:\Users\Pod\defogger_reenable 2014-04-15 18:52 - 2013-10-05 20:24 - 00000000 ____D () C:\Users\Pod 2014-04-15 18:51 - 2014-04-15 18:51 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\IDM2 2014-04-15 18:48 - 2014-04-15 18:48 - 00050477 _____ () C:\Users\Pod\Downloads\Defogger.exe 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IDMSQ 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D () C:\Program Files (x86)\IDMSQ 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D () C:\MININT 2014-04-15 18:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources 2014-04-15 18:42 - 2014-04-15 16:15 - 00000000 ____D () C:\Program Files\RrFilter 2014-04-15 17:31 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-04-15 17:31 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-04-15 17:31 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-15 17:27 - 2013-12-07 12:28 - 00000000 ___RD () C:\Users\Pod\Dropbox 2014-04-15 17:27 - 2013-12-07 12:23 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\Dropbox 2014-04-15 17:26 - 2013-10-26 10:56 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-15 17:26 - 2013-10-10 13:23 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-04-15 17:26 - 2013-10-09 09:33 - 00038350 _____ () C:\Windows\setupact.log 2014-04-15 17:26 - 2010-11-21 05:47 - 00439756 _____ () C:\Windows\PFRO.log 2014-04-15 17:26 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-15 17:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2014-04-15 17:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-04-15 16:48 - 2013-11-12 23:18 - 00000000 ____D () C:\Program Files (x86)\Free Video Converter 2014-04-15 16:44 - 2014-04-15 16:12 - 00000000 ____D () C:\Program Files\002 2014-04-15 16:44 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\DigitalLocker 2014-04-15 16:41 - 2013-10-05 21:44 - 00000000 ____D () C:\Users\Pod\Documents\PhraseExpress 2014-04-15 16:26 - 2014-04-15 16:18 - 00000000 ____D () C:\Users\Pod\AppData\Local\Mobogenie 2014-04-15 16:26 - 2014-04-15 16:17 - 00000000 ____D () C:\Program Files (x86)\Mobogenie 2014-04-15 16:26 - 2014-04-15 16:12 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\SupTab 2014-04-15 16:26 - 2014-04-15 16:10 - 00000000 ____D () C:\Users\Pod\AppData\Local\41 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D () C:\Users\Pod\Documents\Mobogenie 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D () C:\Users\Pod\AppData\Local\cache 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 _____ () C:\Users\Pod\daemonprocess.txt 2014-04-15 16:17 - 2014-04-15 16:16 - 00000000 ____D () C:\Users\Pod\AppData\Local\SearchProtect 2014-04-15 16:14 - 2014-04-15 16:14 - 00000000 ____D () C:\Program Files (x86)\RrSavings 2014-04-15 16:13 - 2014-04-15 16:13 - 00000000 ____D () C:\Program Files\rrsavings 2014-04-15 16:12 - 2014-04-15 16:12 - 00001950 _____ () C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lollipop.lnk 2014-04-15 16:12 - 2014-04-15 16:11 - 00000000 ____D () C:\ProgramData\WPM 2014-04-15 16:11 - 2013-10-06 17:15 - 00001372 _____ () C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-04-15 16:11 - 2013-10-05 21:20 - 00001359 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-15 16:11 - 2013-10-05 20:24 - 00001645 _____ () C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-14 19:20 - 2014-04-14 17:50 - 00000000 ____D () C:\ProgramData\boost_interprocess 2014-04-12 15:14 - 2014-04-12 15:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-12 15:14 - 2013-11-12 19:52 - 00001136 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\Malwarebytes 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-04-11 17:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-11 15:59 - 2013-10-22 12:15 - 00000000 ____D () C:\Users\Pod\Desktop\Tour neu 2014-04-11 03:04 - 2013-10-08 13:50 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-11 03:03 - 2013-10-28 18:00 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 03:02 - 2013-10-28 18:00 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-10 21:13 - 2013-10-06 20:54 - 00000000 ____D () C:\Program Files (x86)\StarMoney Business 6.0 2014-04-07 08:40 - 2013-10-22 13:30 - 00000964 _____ () C:\Windows\Tasks\Paragon Archive name arc_221013112910391.job 2014-04-07 08:40 - 2013-10-17 13:04 - 00000964 _____ () C:\Windows\Tasks\Paragon Archive name arc_171013110200181.job 2014-04-03 14:13 - 2013-10-26 10:56 - 00004100 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-03 14:13 - 2013-10-26 10:56 - 00003848 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-03 09:51 - 2014-04-12 15:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-12 15:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2013-11-12 19:52 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 03:16 - 2014-04-10 19:06 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 19:06 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-30 16:12 - 2013-10-05 21:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 14:15 - 2014-03-29 14:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-27 11:02 - 2013-10-07 13:30 - 00002828 ___SH () C:\Windows\SysWOW64\KGyGaAvL.sys 2014-03-27 11:02 - 2013-10-07 13:30 - 00000000 ____D () C:\Users\Pod\AppData\Local\Corel 2014-03-21 15:18 - 2014-03-21 11:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-16 20:07 - 2013-12-22 13:50 - 00000000 ____D () C:\Users\Pod\Documents\My Digital Editions Some content of TEMP: ==================== C:\Users\Pod\AppData\Local\Temp\avgnt.exe C:\Users\Pod\AppData\Local\Temp\instract.exe C:\Users\Pod\AppData\Local\Temp\nsc883D.exe C:\Users\Pod\AppData\Local\Temp\nsx7D73.exe C:\Users\Pod\AppData\Local\Temp\nsxFF43.exe C:\Users\Pod\AppData\Local\Temp\repair4.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 15:13 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-04-2014 Ran by Pod at 2014-04-15 20:01:28 Running from C:\Users\Pod\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Abacus Documenten Center 1.3 (HKLM-x32\...\Abacus Documenten Center_is1) (Version: - Abacus Computer Services, Inc.) Adobe Acrobat 5.0 (HKLM-x32\...\Adobe Acrobat 5.0) (Version: 5.0 - Adobe Systems, Inc.) Adobe Digital Editions 2.0 (HKLM-x32\...\Adobe Digital Editions 2.0) (Version: 2.0.1 - Adobe Systems Incorporated) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 12.10.100.30322 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{DD86C046-D5AB-954F-EBB7-592EB36BD196}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.) AMD Fuel (Version: 2013.0322.413.5642 - Ihr Firmenname) Hidden AMD Steady Video Plug-In (Version: 2.06.0000 - AMD) Hidden AMD VISION Engine Control Center (x32 Version: 2013.0322.413.5642 - Ihr Firmenname) Hidden Browser Guard (HKLM-x32\...\Browser Guard) (Version: - ) Catalyst Control Center InstallProxy (x32 Version: 2013.0322.413.5642 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0322.413.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0322.0412.5642 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0322.413.5642 - Advanced Micro Devices, Inc.) Hidden Corel MediaOne (HKLM-x32\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.00.0000 - Corel Corporation) CorelDRAW Essential Edition 3 (HKLM-x32\...\_{ADDBE07D-95B8-4789-9C76-187FFF9624B4}) (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (x32 Version: 3.0 - Corel Corporation) Hidden cyberJack Base Components (HKLM-x32\...\{FC338210-F594-11D3-BA24-00001C3AB4DF}) (Version: 6.9.10 - REINER SCT) DDBAC (HKLM-x32\...\{97917E37-B1D5-4D96-AECA-23013B099FFD}) (Version: 5.3.19 - DataDesign) DE (x32 Version: 3.0 - Corel Corporation) Hidden DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.) Druckerdeinstallation für EPSON SX235 Series (HKLM\...\EPSON SX235 Series) (Version: - SEIKO EPSON Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Free Pdf Perfect Prereq (HKLM-x32\...\{84f6a795-0521-46e1-a4d5-c7ad67bf0c55}) (Version: 1.0.0.0 - Covus Freemium GmbH) Free Pdf Perfect Prereq (x32 Version: 1.0.0.0 - Covus Freemium GmbH) Hidden Freemium Free PDF Perfect (HKLM-x32\...\{88265079-D6F4-4292-86BE-D2053E80BFE4}) (Version: 1.0 - Freemium) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Internet Download Manager² 1.0 (HKLM-x32\...\IDMSQ) (Version: 1.0 - OR Interactive Ltd) Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works 6-9 Converter (HKLM-x32\...\{95140000-0137-0407-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 8 Essentials (HKLM-x32\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG) neroxml (x32 Version: 1.0.0 - Nero AG) Hidden OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) PDF/X-3 Inspector (Freeware) (HKLM-x32\...\PDF/X-3 Inspector (Freeware)) (Version: - ) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.67.1226.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6849 - Realtek Semiconductor Corp.) ResultsAlpha (HKLM\...\ResultsAlpha) (Version: 2013.11.20.232030 - ResultsAlpha) RrFilter (Version: 1.0.0.0 - RrFilter) Hidden rrsavings (HKLM\...\rrsavings) (Version: 2.0.1 - rrsavings) RrSavings (x32 Version: 1.0.0.0 - RrSavings) Hidden Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.34.0 - SAMSUNG Electronics Co., Ltd.) Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.12.20.154 - Conduit) <==== ATTENTION Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) StarMoney (x32 Version: 1.0 - StarFinanz) Hidden StarMoney (x32 Version: 4.0.1.51 - StarFinanz) Hidden StarMoney Business 6.0 (HKLM-x32\...\{BF909116-CB0B-4023-B04E-3E3E87E61E28}) (Version: 6.0 - Star Finanz GmbH) TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.26038 - TeamViewer) T-Online 6.0 (HKLM-x32\...\{B1275E23-717A-4D52-997A-1AD1E24BC7F3}) (Version: - ) TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.89 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Update Manager (x32 Version: 4.60 - Corel Corporation) Hidden Usenet.nl (HKLM-x32\...\Usenet.nl_is1) (Version: - ) VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden VIS (HKLM-x32\...\VIS) (Version: - ) <==== ATTENTION WinPatrol (HKLM\...\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 29.0.2013 - BillP Studios) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WPM18.8.0.212 (HKLM-x32\...\WPM) (Version: 18.8.0.212 - Cherished Technololgy LIMITED) <==== ATTENTION Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.) Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version: - ) Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - ) ==================== Restore Points ========================= 31-03-2014 14:15:18 Windows Update 07-04-2014 06:40:43 Windows-Sicherung 11-04-2014 01:00:46 Windows Update 13-04-2014 17:00:39 Windows-Sicherung 14-04-2014 15:48:57 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 15-04-2014 14:41:27 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-04-15 18:48 - 00000867 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 d3oxij66pru1i3.cloudfront.net ==================== Scheduled Tasks (whitelisted) ============= Task: {2C38994A-B8A9-4FCF-A6E1-8D516CCDA81E} - System32\Tasks\Paragon Archive name arc_171013110200181 => C:\Program Files (x86)\Paragon Software\Backup and Recovery 2013 Free\program\scripts.exe Task: {44B67670-1974-420D-8E16-BBE9BAAB5120} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {5B467C9B-5023-4772-950F-BAD85FCB5BB6} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {9B9ACC06-5F70-4280-9159-DC2B98EAD11E} - System32\Tasks\{48B6A75E-6EDD-4206-B3DF-C60B9E43E02C} => C:\Program Files (x86)\StarMoney Business 6.0\app\StartStarMoney.exe [2014-04-07] (Star Finanz-Software Entwicklung und Vertriebs GmbH) Task: {9EB0BB0C-E561-4501-B100-92EB861ED9DD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-26] (Google Inc.) Task: {CE321798-5F91-4554-AB4D-50A061DA0716} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-26] (Google Inc.) Task: {E5A727AE-0D9A-4318-B4AB-805702A57C4F} - \BackgroundContainer Startup Task ATTENTION ====> No Task File Task: {F7E83655-35EF-411E-9960-B6D81A8176B0} - System32\Tasks\Paragon Archive name arc_221013112910391 => C:\Program Files (x86)\Paragon Software\Backup and Recovery 2013 Free\program\scripts.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Paragon Archive name arc_171013110200181.job => C:\Program Files (x86)\Paragon Software\Backup and Recovery 2013 Free\program\scripts.exe Task: C:\Windows\Tasks\Paragon Archive name arc_221013112910391.job => C:\Program Files (x86)\Paragon Software\Backup and Recovery 2013 Free\program\scripts.exe ==================== Loaded Modules (whitelisted) ============= 2007-06-05 13:20 - 2007-06-05 13:20 - 00177704 _____ () C:\Windows\SysWOW64\PSIService.exe 2014-03-06 15:52 - 2014-03-06 15:52 - 00171008 _____ () c:\Program Files\RrFilter\RrFilterService64.exe 2014-03-04 13:25 - 2014-03-04 13:25 - 00110080 _____ () c:\Program Files\RrFilter\nfapi.dll 2014-03-04 13:25 - 2014-03-04 13:25 - 00317952 _____ () c:\Program Files\RrFilter\ProtocolFilters.dll 2013-10-30 08:21 - 2013-10-30 08:21 - 02561088 _____ () C:\Program Files (x86)\IDMSQ\idmsq.exe 2013-10-06 11:55 - 2007-05-31 07:38 - 00167936 ____N () C:\Windows\SysWOW64\SerialXP.dll 2013-10-15 14:47 - 2012-05-25 04:25 - 00921600 _____ () C:\Program Files (x86)\Yahoo!\Messenger\yui.dll 2013-10-15 14:46 - 2012-05-25 04:25 - 00078336 _____ () C:\Program Files (x86)\Yahoo!\Messenger\pcre.dll 2014-02-02 18:21 - 2011-01-13 12:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney Business 6.0\ouservice\PATCHW32.dll 2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\Pod\AppData\Roaming\Dropbox\bin\libcef.dll 2013-10-07 11:01 - 2013-04-22 17:25 - 00445648 _____ () C:\PhraseExpress\pexlang.dll 2014-03-29 14:15 - 2014-03-29 14:15 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^Users^Pod^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupfolder: C:^Users^Pod^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Mediencenter.lnk => C:\Windows\pss\Mediencenter.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: avgnt => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min MSCONFIG\startupreg: Corel Photo Downloader => "C:\Program Files (x86)\Corel\Corel MediaOne\Corel PhotoDownloader.exe" -startup MSCONFIG\startupreg: EaseUs Tray => "C:\Program Files (x86)\EaseUS\Todo Backup\bin\TrayNotify.exe" MSCONFIG\startupreg: EaseUs Watch => "C:\Program Files (x86)\EaseUS\Todo Backup\bin\EuWatch.exe" MSCONFIG\startupreg: EPLTarget => MSCONFIG\startupreg: IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => "C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 MSCONFIG\startupreg: ISUSPM => "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler MSCONFIG\startupreg: KiesAirMessage => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup MSCONFIG\startupreg: KiesPreload => C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: NBKeyScan => "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: SMB60StarMoneyRunEntry => "C:\Program Files (x86)\StarMoney Business 6.0\app\oflagent.exe" MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: WinPatrol => C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/15/2014 05:27:59 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2014 04:46:36 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2014 04:41:33 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddWin32ServiceFiles: Unable to back up image of service Search Protect by Conduit Service since QueryServiceConfig API failed System Error: Das System kann die angegebene Datei nicht finden. . Error: (04/15/2014 04:41:33 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddWin32ServiceFiles: Unable to back up image of service fpvoixdaog64 since QueryServiceConfig API failed System Error: Das System kann die angegebene Datei nicht finden. . Error: (04/15/2014 04:41:33 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddWin32ServiceFiles: Unable to back up image of service IePlugin Service since QueryServiceConfig API failed System Error: Das System kann die angegebene Datei nicht finden. . Error: (04/15/2014 04:41:33 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddWin32ServiceFiles: Unable to back up image of service Wpm Service since QueryServiceConfig API failed System Error: Das System kann die angegebene Datei nicht finden. . Error: (04/15/2014 04:19:12 PM) (Source: Application Hang) (User: ) Description: Programm Mobogenie.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2ac Startzeit: 01cf58b5889da980 Endzeit: 36 Anwendungspfad: C:\Program Files (x86)\Mobogenie\Mobogenie.exe Berichts-ID: df6135c6-c4a8-11e3-8f2e-d43d7ee1bfba Error: (04/15/2014 04:14:17 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: MsiExec.exe, Version: 5.0.7601.17514, Zeitstempel: 0x4ce792c4 Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1d731 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00086828 ID des fehlerhaften Prozesses: 0x175c Startzeit der fehlerhaften Anwendung: 0xMsiExec.exe0 Pfad der fehlerhaften Anwendung: MsiExec.exe1 Pfad des fehlerhaften Moduls: MsiExec.exe2 Berichtskennung: MsiExec.exe3 Error: (04/15/2014 02:49:14 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/15/2014 10:48:14 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (04/15/2014 05:26:37 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UimBus Uim_IM Uim_VIM Error: (04/15/2014 04:45:21 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UimBus Uim_IM Uim_VIM Error: (04/15/2014 04:41:45 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f020b fehlgeschlagen: SAMSUNG Electronics Co., Ltd. - Other hardware - SAMSUNG Mobile MTP Device Error: (04/15/2014 04:18:09 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "MgAssist Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (04/15/2014 04:17:45 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Installer" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (04/15/2014 04:15:45 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/15/2014 10:47:32 AM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UimBus Uim_IM Uim_VIM Error: (04/14/2014 07:20:11 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (04/14/2014 07:20:07 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (04/14/2014 07:19:48 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Microsoft Office Sessions: ========================= Error: (01/01/2014 04:31:54 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 50 seconds with 0 seconds of active time. This session ended with a crash. Error: (01/01/2014 04:30:52 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 122 seconds with 120 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-02-11 19:41:37.904 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-11 19:41:37.811 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-11 19:41:37.702 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-11 19:27:45.334 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6002.18005_none_f0780c78ec8773db\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-11 19:27:45.256 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6002.18005_none_f0780c78ec8773db\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-11 19:27:45.162 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6002.18005_none_f0780c78ec8773db\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-11 19:27:45.037 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-11 19:27:44.944 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-11 19:27:44.866 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-11 19:21:14.411 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\winsxs\Backup\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6002.18005_none_f0780c78ec8773db_bcrypt.dll_e2f091ac" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 57% Total physical RAM: 3279.16 MB Available physical RAM: 1399.39 MB Total Pagefile: 6556.49 MB Available Pagefile: 4340.95 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:393.12 GB) NTFS Drive d: (BOOT) (Fixed) (Total:911.51 GB) (Free:477.97 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (RECOVER) (Fixed) (Total:19.99 GB) (Free:9.8 GB) FAT32 Drive k: () (Fixed) (Total:628.02 GB) (Free:627.91 GB) NTFS Drive l: (Volume) (Fixed) (Total:488.28 GB) (Free:388.44 GB) NTFS Drive m: (Volume) (Fixed) (Total:398.17 GB) (Free:358.78 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 79504372) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: F98D6E74) Partition: GPT Partition Type. ======================================================== Disk: 3 (MBR Code: Windows 7 or Vista) (Size: 1863 GB) (Disk ID: 7BCD28C2) Partition 1: (Not Active) - (Size=628 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=488 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=398 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=349 GB) - (Type=BC) ==================== End Of Log ============================ Gruß Driver23 |
16.04.2014, 18:57 | #4 |
/// the machine /// TB-Ausbilder | Probleme mit istart.webssearches.com Revo Uninstaller - Download - Filepony Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION Mit Revo auch Moderat die Reste entfernen lassen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.04.2014, 19:46 | #5 |
| Probleme mit istart.webssearches.com Hallo Schrauber, ich habe Revo installiert. In Addition finde ich z.B. die Zeile: Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.12.20.154 - Conduit) <==== ATTENTION Meinst Du das? Wenn ja, wie entferne ich das mit Revo? Malwarebites Anti-Malware benutze ich regelmäßig. Gruß Driver23 PS Bitte nicht lachen, ich bin halt etwas blöd. |
17.04.2014, 13:39 | #6 |
/// the machine /// TB-Ausbilder | Probleme mit istart.webssearches.com Revo öffnen, in der Liste der installierten Programme Search Protect anklicken und auf Uninstall klicken
__________________ --> Probleme mit istart.webssearches.com |
18.04.2014, 18:44 | #7 |
| Probleme mit istart.webssearches.com Hallo Schrauber, der erste Erfolg ist bereits eingetreten, Firefox hat wieder Google als Startseite. Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 18.04.2014 Suchlauf-Zeit: 18:54:01 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.18.07 Rootkit Datenbank: v2014.03.27.01 Lizenz: Premium Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Pod Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 256481 Verstrichene Zeit: 9 Min, 45 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Shuriken: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 4 PUP.Optional.RRSavings.A, HKLM\SOFTWARE\rrsavings, In Quarantäne, [22addb504b3041f5548ba7c3c53de11f], PUP.Optional.RRSavings.A, HKU\S-1-5-21-3960197758-2477925476-223839332-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\RrSavings, In Quarantäne, [9936de4dcab1c5710ad7d892847e36ca], PUP.Optional.RRSavings.A, HKU\S-1-5-21-3960197758-2477925476-223839332-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Rr Savings, In Quarantäne, [5679fa311e5de84e3ea792d8ad55e11f], PUP.Optional.RRSavings.A, HKU\S-1-5-21-3960197758-2477925476-223839332-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\rrsavings, In Quarantäne, [ae2146e57efdba7c13d10e5c54aef20e], Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 2 PUP.Optional.WebsSearches.A, HKU\S-1-5-21-3960197758-2477925476-223839332-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69&q={searchTerms}),Ersetzt,[e2ed9398cab167cfd9522fef4fb502fe] PUP.Optional.WebsSearches.A, HKU\S-1-5-21-3960197758-2477925476-223839332-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69),Ersetzt,[567970bbe9922511161365b9f50fe11f] Ordner: 3 PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files\RrFilter, In Quarantäne, [6a65b57672099d99d5a29dcd29d9c040], PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\SSL, In Quarantäne, [6a65b57672099d99d5a29dcd29d9c040], Dateien: 15 PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\background.js, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\CustomActionInstall, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\CustomActionUninstall, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon128.png, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon16.png, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon32.png, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon48.png, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon64.png, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon8.png, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\iwalyk.js, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\manifest.json, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\marcopolo.js, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\Microsoft.Deployment.WindowsInstaller.dll, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\Microsoft.Deployment.WindowsInstaller.xml, In Quarantäne, [d5faf239afccc472e195d8927191837d], PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\SendJson.dll, In Quarantäne, [d5faf239afccc472e195d8927191837d], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 18/04/2014 um 19:34:59 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Pod - POD-PC # Gestartet von : C:\Users\Pod\Desktop\Downloads\Sicherheits-Tools\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Pod\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [26173 octets] - [11/11/2013 18:44:59] AdwCleaner[R1].txt - [16766 octets] - [11/11/2013 18:52:19] AdwCleaner[R2].txt - [19899 octets] - [12/11/2013 20:12:58] AdwCleaner[S0].txt - [27430 octets] - [12/11/2013 20:15:33] AdwCleaner[S1].txt - [1041 octets] - [18/04/2014 19:34:59] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1101 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Professional x64 Ran by Pod on 18.04.2014 at 19:13:18,72 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BC73C780-0926-4885-8602-33442E1C6EF9} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Program Files (x86)\free video converter" ~~~ FireFox Emptied folder: C:\Users\Pod\AppData\Roaming\mozilla\firefox\profiles\n7yu7958.default\minidumps [7 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 18.04.2014 at 19:22:21,49 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2013 01 (ATTENTION: ====> FRST version is 159 days old and could be outdated) Ran by Pod (administrator) on POD-PC on 18-04-2014 19:39:57 Running from C:\Users\Pod\Downloads\Sicherheit Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe (Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe () C:\Windows\SysWOW64\PSIService.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Dropbox, Inc.) C:\Users\Pod\AppData\Roaming\Dropbox\bin\Dropbox.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-14] (Samsung) HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-14] (Samsung) HKCU\...\Run: [Messenger (Yahoo!)] - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.) HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ReminderApp_EEAC3053-7055-4143-B8A0-306758055099] - C:\Program Files (x86)\Nova Development\Print Artist Gold 25\ReminderApp.exe [146080 2013-08-06] () AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [97280 2009-07-14] () Startup: C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Pod\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC3322628F9C1CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKCU - {9BD27B24-13BE-4DDD-9586-61254659E6CD} URL = hxxp://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO-x32: Browser Guard - {02a0d829-4393-46fc-a37e-126263035883} - C:\Program Files (x86)\Browser Guard\browserguard.dll (Browser Guard) BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) Toolbar: HKLM - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent64.dll (soft Xpansion) Toolbar: HKLM-x32 - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent32.dll (soft Xpansion) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Hosts: 127.0.0.1 d3oxij66pru1i3.cloudfront.net Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: webssearches FF SelectedSearchEngine: webssearches FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @soft-xpansion/npsxpdf - C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\searchplugins\yahoo_ff.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\Extensions\WTB_GLOBAL.sqlite FF Extension: Adblock Plus - C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi FF Extension: No Name - C:\Program Files (x86)\Browser Guard\browserguard.xpi FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF HKLM-x32\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [kfepagcelbegkpkcjgfeecmlnmkedjin] - C:\Program Files (x86)\Browser Guard\browserguard.crx ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-22] (Advanced Micro Devices, Inc.) R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [506288 2011-02-08] (REINER SCT) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-02-18] (Nero AG) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [529704 2008-02-28] (Nero AG) R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) R2 ProtexisLicensing; C:\Windows\SysWOW64\PSIService.exe [177704 2007-06-05] () R2 StarMoney Business 6.0 OnlineUpdate; C:\Program Files (x86)\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-10-08] (soft Xpansion) S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2010-11-27] (REINER SCT) S3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-19] (Siliten) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-18] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) S1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [90960 2013-03-15] (Windows (R) 2000 DDK provider) S1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633680 2013-03-15] (Paragon) S1 Uim_VIM; C:\Windows\System32\Drivers\uim_vimx64.sys [390352 2013-03-15] (Paragon) S3 MSICDSetup; \??\F:\CDriver64.sys [x] S3 NTIDrvr; System32\Drivers\NTIDrvr.sys [x] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-18 19:22 - 2014-04-18 19:22 - 00001108 _____ C:\Users\Pod\Desktop\JRT.txt 2014-04-18 19:00 - 2014-04-18 19:00 - 00004997 _____ C:\mbam.txt 2014-04-17 15:27 - 2014-04-17 15:27 - 00000000 ____D C:\Users\Pod\AppData\Local\PAShell 2014-04-17 15:24 - 2014-04-17 15:24 - 00000000 ____D C:\Users\Pod\AppData\Local\Nova Development 2014-04-17 15:23 - 2014-04-17 15:23 - 00002937 _____ C:\Users\Public\Desktop\Print Artist Gold 25.lnk 2014-04-17 15:22 - 2014-04-17 15:22 - 00000000 ____D C:\Program Files (x86)\Nova Development 2014-04-16 20:29 - 2014-04-16 20:29 - 00001298 _____ C:\Users\Pod\Desktop\Revo Uninstaller.lnk 2014-04-16 20:29 - 2014-04-16 20:29 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2014-04-16 07:23 - 2014-04-16 07:23 - 00015102 _____ C:\Users\Pod\Downloads\Defogger (1).exe 2014-04-15 20:00 - 2014-04-15 20:01 - 00000000 ____D C:\FRST 2014-04-15 18:52 - 2014-04-15 18:52 - 00000000 _____ C:\Users\Pod\defogger_reenable 2014-04-15 18:51 - 2014-04-15 18:51 - 00000000 ____D C:\Users\Pod\AppData\Roaming\IDM2 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D C:\MININT 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D C:\Users\Pod\AppData\Local\cache 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 _____ C:\Users\Pod\daemonprocess.txt 2014-04-15 16:12 - 2014-04-15 16:44 - 00000000 ____D C:\Program Files\002 2014-04-15 16:10 - 2014-04-15 16:26 - 00000000 ____D C:\Users\Pod\AppData\Local\41 2014-04-12 15:14 - 2014-04-18 19:36 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-12 15:14 - 2014-04-12 15:14 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-12 15:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-12 15:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-10 19:06 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 19:06 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 19:06 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 19:06 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 19:05 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 19:05 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 19:05 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 19:05 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 19:05 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 19:05 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 19:05 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 19:05 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 19:05 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 19:05 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 19:05 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 19:05 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-03-29 14:15 - 2014-03-29 14:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-03-21 11:05 - 2014-03-21 15:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird ==================== One Month Modified Files and Folders ======= 2014-04-18 19:39 - 2013-11-12 21:44 - 00000000 ____D C:\Users\Pod\Downloads\Sicherheit 2014-04-18 19:36 - 2014-04-12 15:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-18 19:36 - 2013-12-07 12:28 - 00000000 ___RD C:\Users\Pod\Dropbox 2014-04-18 19:36 - 2013-12-07 12:23 - 00000000 ____D C:\Users\Pod\AppData\Roaming\Dropbox 2014-04-18 19:36 - 2013-10-26 10:56 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-18 19:36 - 2013-10-10 13:23 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2014-04-18 19:36 - 2013-10-09 09:33 - 00039134 _____ C:\Windows\setupact.log 2014-04-18 19:36 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-04-18 19:35 - 2013-11-11 18:44 - 00000000 ____D C:\AdwCleaner 2014-04-18 19:35 - 2013-10-09 09:35 - 01864143 _____ C:\Windows\WindowsUpdate.log 2014-04-18 19:22 - 2014-04-18 19:22 - 00001108 _____ C:\Users\Pod\Desktop\JRT.txt 2014-04-18 19:18 - 2013-10-26 10:56 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-18 19:15 - 2009-07-14 06:45 - 00022240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-18 19:15 - 2009-07-14 06:45 - 00022240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-18 19:12 - 2011-04-12 09:43 - 00699416 _____ C:\Windows\system32\perfh007.dat 2014-04-18 19:12 - 2011-04-12 09:43 - 00149556 _____ C:\Windows\system32\perfc007.dat 2014-04-18 19:12 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI 2014-04-18 19:06 - 2013-10-06 17:15 - 00001113 _____ C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-04-18 19:06 - 2013-10-05 21:20 - 00001083 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-18 19:06 - 2013-10-05 20:24 - 00001025 _____ C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-18 19:00 - 2014-04-18 19:00 - 00004997 _____ C:\mbam.txt 2014-04-18 18:55 - 2010-11-21 05:47 - 00444622 _____ C:\Windows\PFRO.log 2014-04-18 11:41 - 2013-10-08 14:21 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-17 18:38 - 2013-10-05 20:31 - 00117408 _____ C:\Users\Pod\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-17 18:36 - 2013-10-06 20:54 - 00000000 ____D C:\Program Files (x86)\StarMoney Business 6.0 2014-04-17 18:30 - 2009-07-14 06:45 - 00419856 _____ C:\Windows\system32\FNTCACHE.DAT 2014-04-17 15:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\tracing 2014-04-17 15:27 - 2014-04-17 15:27 - 00000000 ____D C:\Users\Pod\AppData\Local\PAShell 2014-04-17 15:24 - 2014-04-17 15:24 - 00000000 ____D C:\Users\Pod\AppData\Local\Nova Development 2014-04-17 15:23 - 2014-04-17 15:23 - 00002937 _____ C:\Users\Public\Desktop\Print Artist Gold 25.lnk 2014-04-17 15:22 - 2014-04-17 15:22 - 00000000 ____D C:\Program Files (x86)\Nova Development 2014-04-17 13:03 - 2013-10-22 12:15 - 00000000 ____D C:\Users\Pod\Desktop\Tour neu 2014-04-17 12:14 - 2014-03-01 22:04 - 00007168 ___SH C:\Users\Pod\Desktop\Thumbs.db 2014-04-16 20:29 - 2014-04-16 20:29 - 00001298 _____ C:\Users\Pod\Desktop\Revo Uninstaller.lnk 2014-04-16 20:29 - 2014-04-16 20:29 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2014-04-16 17:26 - 2013-10-05 21:44 - 00000000 ____D C:\Users\Pod\Documents\PhraseExpress 2014-04-16 07:23 - 2014-04-16 07:23 - 00015102 _____ C:\Users\Pod\Downloads\Defogger (1).exe 2014-04-15 20:01 - 2014-04-15 20:00 - 00000000 ____D C:\FRST 2014-04-15 18:52 - 2014-04-15 18:52 - 00000000 _____ C:\Users\Pod\defogger_reenable 2014-04-15 18:52 - 2013-10-05 20:24 - 00000000 ____D C:\Users\Pod 2014-04-15 18:51 - 2014-04-15 18:51 - 00000000 ____D C:\Users\Pod\AppData\Roaming\IDM2 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D C:\MININT 2014-04-15 18:48 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Resources 2014-04-15 17:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\LiveKernelReports 2014-04-15 16:44 - 2014-04-15 16:12 - 00000000 ____D C:\Program Files\002 2014-04-15 16:44 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\DigitalLocker 2014-04-15 16:26 - 2014-04-15 16:10 - 00000000 ____D C:\Users\Pod\AppData\Local\41 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D C:\Users\Pod\AppData\Local\cache 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 _____ C:\Users\Pod\daemonprocess.txt 2014-04-12 15:14 - 2014-04-12 15:14 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-12 15:14 - 2013-11-12 19:52 - 00001136 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D C:\Users\Pod\AppData\Roaming\Malwarebytes 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-04-11 17:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2014-04-11 03:04 - 2013-10-08 13:50 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-04-11 03:03 - 2013-10-28 18:00 - 00000000 ____D C:\Windows\system32\MRT 2014-04-11 03:02 - 2013-10-28 18:00 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-07 08:40 - 2013-10-22 13:30 - 00000964 _____ C:\Windows\Tasks\Paragon Archive name arc_221013112910391.job 2014-04-07 08:40 - 2013-10-17 13:04 - 00000964 _____ C:\Windows\Tasks\Paragon Archive name arc_171013110200181.job 2014-04-03 14:13 - 2013-10-26 10:56 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-03 14:13 - 2013-10-26 10:56 - 00003848 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-03 09:51 - 2014-04-12 15:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-12 15:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2013-11-12 19:52 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-31 03:16 - 2014-04-10 19:06 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 19:06 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-30 16:12 - 2013-10-05 21:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 14:15 - 2014-03-29 14:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-03-27 11:02 - 2013-10-07 13:30 - 00002828 ___SH C:\Windows\SysWOW64\KGyGaAvL.sys 2014-03-27 11:02 - 2013-10-07 13:30 - 00000000 ____D C:\Users\Pod\AppData\Local\Corel 2014-03-21 15:18 - 2014-03-21 11:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird Some content of TEMP: ==================== C:\Users\Pod\AppData\Local\Temp\avgnt.exe C:\Users\Pod\AppData\Local\Temp\instract.exe C:\Users\Pod\AppData\Local\Temp\nsc883D.exe C:\Users\Pod\AppData\Local\Temp\nsx7D73.exe C:\Users\Pod\AppData\Local\Temp\nsxFF43.exe C:\Users\Pod\AppData\Local\Temp\Quarantine.exe C:\Users\Pod\AppData\Local\Temp\repair4.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 15:13 ==================== End Of Log ============================ So, alles erledigt, dabei ist mir aufgefallen, dass Du mir im November schon mal geholfen hast. Hat gut gewirkt, bis ich wieder beim Herunterladen Mist gemacht habe. Bin mal gespannt, ob es jetzt OK ist. Ist AVG Antivirus gut? Habe ich im Moment. Viele Grüsse, Driver23 |
19.04.2014, 12:11 | #8 |
/// the machine /// TB-Ausbilder | Probleme mit istart.webssearches.com Nutze ich nicht, aber geht ok ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.04.2014, 13:41 | #9 |
| Probleme mit istart.webssearches.com Hallo Schrauber, FROHE OSTERN! Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=5e44eb07e48e9748b32d2cabb4f25704 # engine=17955 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-19 11:33:31 # local_time=2014-04-20 01:33:31 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 147982 149580261 0 0 # scanned=600629 # found=2 # cleaned=0 # scan_time=20072 sh=F13364BC15A6685A04D6F297C65B0814265AF5FB ft=0 fh=0000000000000000 vn="a variant of Win32/Injector.Autoit.FX trojan" ac=I fn="D:\POD-PC\Backup Set 2013-10-06 190001\Backup Files 2013-10-13 190001\Backup files 55.zip" sh=15FC4DFDE91F07FC8E1AFA3E0E6A06A0D3D67CC8 ft=0 fh=0000000000000000 vn="a variant of Win32/Injector.Autoit.FX trojan" ac=I fn="D:\Users\Jakob\Desktop\Downloads\Documents\Usenet.nl\alt.binaries.warez\Microsoft.Outlook.2007-rG.rar" Code:
ATTFilter Results of screen317's Security Check version 0.99.76 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` TuneUp Utilities 2014 (de-DE) Adobe Flash Player 12.0.0.77 Flash Player out of Date! Adobe Reader XI Mozilla Firefox (28.0) Mozilla Thunderbird (24.4.0) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe StarMoney Business 6.0 ouservice StarMoneyOnlineUpdate.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2013 01 (ATTENTION: ====> FRST version is 159 days old and could be outdated) Ran by Pod (administrator) on POD-PC on 18-04-2014 19:39:57 Running from C:\Users\Pod\Downloads\Sicherheit Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe (Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe () C:\Windows\SysWOW64\PSIService.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Dropbox, Inc.) C:\Users\Pod\AppData\Roaming\Dropbox\bin\Dropbox.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-14] (Samsung) HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-14] (Samsung) HKCU\...\Run: [Messenger (Yahoo!)] - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.) HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ReminderApp_EEAC3053-7055-4143-B8A0-306758055099] - C:\Program Files (x86)\Nova Development\Print Artist Gold 25\ReminderApp.exe [146080 2013-08-06] () AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [97280 2009-07-14] () Startup: C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Pod\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC3322628F9C1CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKCU - {9BD27B24-13BE-4DDD-9586-61254659E6CD} URL = hxxp://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO-x32: Browser Guard - {02a0d829-4393-46fc-a37e-126263035883} - C:\Program Files (x86)\Browser Guard\browserguard.dll (Browser Guard) BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) Toolbar: HKLM - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent64.dll (soft Xpansion) Toolbar: HKLM-x32 - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent32.dll (soft Xpansion) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Hosts: 127.0.0.1 d3oxij66pru1i3.cloudfront.net Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: webssearches FF SelectedSearchEngine: webssearches FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @soft-xpansion/npsxpdf - C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\searchplugins\yahoo_ff.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\Extensions\WTB_GLOBAL.sqlite FF Extension: Adblock Plus - C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi FF Extension: No Name - C:\Program Files (x86)\Browser Guard\browserguard.xpi FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF HKLM-x32\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [kfepagcelbegkpkcjgfeecmlnmkedjin] - C:\Program Files (x86)\Browser Guard\browserguard.crx ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-22] (Advanced Micro Devices, Inc.) R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [506288 2011-02-08] (REINER SCT) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-02-18] (Nero AG) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [529704 2008-02-28] (Nero AG) R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) R2 ProtexisLicensing; C:\Windows\SysWOW64\PSIService.exe [177704 2007-06-05] () R2 StarMoney Business 6.0 OnlineUpdate; C:\Program Files (x86)\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-10-08] (soft Xpansion) S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2010-11-27] (REINER SCT) S3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-19] (Siliten) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-18] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) S1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [90960 2013-03-15] (Windows (R) 2000 DDK provider) S1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633680 2013-03-15] (Paragon) S1 Uim_VIM; C:\Windows\System32\Drivers\uim_vimx64.sys [390352 2013-03-15] (Paragon) S3 MSICDSetup; \??\F:\CDriver64.sys [x] S3 NTIDrvr; System32\Drivers\NTIDrvr.sys [x] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-18 19:22 - 2014-04-18 19:22 - 00001108 _____ C:\Users\Pod\Desktop\JRT.txt 2014-04-18 19:00 - 2014-04-18 19:00 - 00004997 _____ C:\mbam.txt 2014-04-17 15:27 - 2014-04-17 15:27 - 00000000 ____D C:\Users\Pod\AppData\Local\PAShell 2014-04-17 15:24 - 2014-04-17 15:24 - 00000000 ____D C:\Users\Pod\AppData\Local\Nova Development 2014-04-17 15:23 - 2014-04-17 15:23 - 00002937 _____ C:\Users\Public\Desktop\Print Artist Gold 25.lnk 2014-04-17 15:22 - 2014-04-17 15:22 - 00000000 ____D C:\Program Files (x86)\Nova Development 2014-04-16 20:29 - 2014-04-16 20:29 - 00001298 _____ C:\Users\Pod\Desktop\Revo Uninstaller.lnk 2014-04-16 20:29 - 2014-04-16 20:29 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2014-04-16 07:23 - 2014-04-16 07:23 - 00015102 _____ C:\Users\Pod\Downloads\Defogger (1).exe 2014-04-15 20:00 - 2014-04-15 20:01 - 00000000 ____D C:\FRST 2014-04-15 18:52 - 2014-04-15 18:52 - 00000000 _____ C:\Users\Pod\defogger_reenable 2014-04-15 18:51 - 2014-04-15 18:51 - 00000000 ____D C:\Users\Pod\AppData\Roaming\IDM2 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D C:\MININT 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D C:\Users\Pod\AppData\Local\cache 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 _____ C:\Users\Pod\daemonprocess.txt 2014-04-15 16:12 - 2014-04-15 16:44 - 00000000 ____D C:\Program Files\002 2014-04-15 16:10 - 2014-04-15 16:26 - 00000000 ____D C:\Users\Pod\AppData\Local\41 2014-04-12 15:14 - 2014-04-18 19:36 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-12 15:14 - 2014-04-12 15:14 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-12 15:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-12 15:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-10 19:06 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 19:06 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 19:06 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 19:06 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 19:05 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 19:05 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 19:05 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 19:05 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 19:05 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 19:05 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 19:05 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 19:05 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 19:05 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 19:05 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 19:05 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 19:05 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-03-29 14:15 - 2014-03-29 14:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-03-21 11:05 - 2014-03-21 15:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird ==================== One Month Modified Files and Folders ======= 2014-04-18 19:39 - 2013-11-12 21:44 - 00000000 ____D C:\Users\Pod\Downloads\Sicherheit 2014-04-18 19:36 - 2014-04-12 15:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-18 19:36 - 2013-12-07 12:28 - 00000000 ___RD C:\Users\Pod\Dropbox 2014-04-18 19:36 - 2013-12-07 12:23 - 00000000 ____D C:\Users\Pod\AppData\Roaming\Dropbox 2014-04-18 19:36 - 2013-10-26 10:56 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-18 19:36 - 2013-10-10 13:23 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2014-04-18 19:36 - 2013-10-09 09:33 - 00039134 _____ C:\Windows\setupact.log 2014-04-18 19:36 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-04-18 19:35 - 2013-11-11 18:44 - 00000000 ____D C:\AdwCleaner 2014-04-18 19:35 - 2013-10-09 09:35 - 01864143 _____ C:\Windows\WindowsUpdate.log 2014-04-18 19:22 - 2014-04-18 19:22 - 00001108 _____ C:\Users\Pod\Desktop\JRT.txt 2014-04-18 19:18 - 2013-10-26 10:56 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-18 19:15 - 2009-07-14 06:45 - 00022240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-18 19:15 - 2009-07-14 06:45 - 00022240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-18 19:12 - 2011-04-12 09:43 - 00699416 _____ C:\Windows\system32\perfh007.dat 2014-04-18 19:12 - 2011-04-12 09:43 - 00149556 _____ C:\Windows\system32\perfc007.dat 2014-04-18 19:12 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI 2014-04-18 19:06 - 2013-10-06 17:15 - 00001113 _____ C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-04-18 19:06 - 2013-10-05 21:20 - 00001083 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-18 19:06 - 2013-10-05 20:24 - 00001025 _____ C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-18 19:00 - 2014-04-18 19:00 - 00004997 _____ C:\mbam.txt 2014-04-18 18:55 - 2010-11-21 05:47 - 00444622 _____ C:\Windows\PFRO.log 2014-04-18 11:41 - 2013-10-08 14:21 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-17 18:38 - 2013-10-05 20:31 - 00117408 _____ C:\Users\Pod\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-17 18:36 - 2013-10-06 20:54 - 00000000 ____D C:\Program Files (x86)\StarMoney Business 6.0 2014-04-17 18:30 - 2009-07-14 06:45 - 00419856 _____ C:\Windows\system32\FNTCACHE.DAT 2014-04-17 15:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\tracing 2014-04-17 15:27 - 2014-04-17 15:27 - 00000000 ____D C:\Users\Pod\AppData\Local\PAShell 2014-04-17 15:24 - 2014-04-17 15:24 - 00000000 ____D C:\Users\Pod\AppData\Local\Nova Development 2014-04-17 15:23 - 2014-04-17 15:23 - 00002937 _____ C:\Users\Public\Desktop\Print Artist Gold 25.lnk 2014-04-17 15:22 - 2014-04-17 15:22 - 00000000 ____D C:\Program Files (x86)\Nova Development 2014-04-17 13:03 - 2013-10-22 12:15 - 00000000 ____D C:\Users\Pod\Desktop\Tour neu 2014-04-17 12:14 - 2014-03-01 22:04 - 00007168 ___SH C:\Users\Pod\Desktop\Thumbs.db 2014-04-16 20:29 - 2014-04-16 20:29 - 00001298 _____ C:\Users\Pod\Desktop\Revo Uninstaller.lnk 2014-04-16 20:29 - 2014-04-16 20:29 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2014-04-16 17:26 - 2013-10-05 21:44 - 00000000 ____D C:\Users\Pod\Documents\PhraseExpress 2014-04-16 07:23 - 2014-04-16 07:23 - 00015102 _____ C:\Users\Pod\Downloads\Defogger (1).exe 2014-04-15 20:01 - 2014-04-15 20:00 - 00000000 ____D C:\FRST 2014-04-15 18:52 - 2014-04-15 18:52 - 00000000 _____ C:\Users\Pod\defogger_reenable 2014-04-15 18:52 - 2013-10-05 20:24 - 00000000 ____D C:\Users\Pod 2014-04-15 18:51 - 2014-04-15 18:51 - 00000000 ____D C:\Users\Pod\AppData\Roaming\IDM2 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D C:\MININT 2014-04-15 18:48 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Resources 2014-04-15 17:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\LiveKernelReports 2014-04-15 16:44 - 2014-04-15 16:12 - 00000000 ____D C:\Program Files\002 2014-04-15 16:44 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\DigitalLocker 2014-04-15 16:26 - 2014-04-15 16:10 - 00000000 ____D C:\Users\Pod\AppData\Local\41 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D C:\Users\Pod\AppData\Local\cache 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 _____ C:\Users\Pod\daemonprocess.txt 2014-04-12 15:14 - 2014-04-12 15:14 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-12 15:14 - 2013-11-12 19:52 - 00001136 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D C:\Users\Pod\AppData\Roaming\Malwarebytes 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-04-11 17:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2014-04-11 03:04 - 2013-10-08 13:50 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-04-11 03:03 - 2013-10-28 18:00 - 00000000 ____D C:\Windows\system32\MRT 2014-04-11 03:02 - 2013-10-28 18:00 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-07 08:40 - 2013-10-22 13:30 - 00000964 _____ C:\Windows\Tasks\Paragon Archive name arc_221013112910391.job 2014-04-07 08:40 - 2013-10-17 13:04 - 00000964 _____ C:\Windows\Tasks\Paragon Archive name arc_171013110200181.job 2014-04-03 14:13 - 2013-10-26 10:56 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-03 14:13 - 2013-10-26 10:56 - 00003848 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-03 09:51 - 2014-04-12 15:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-12 15:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2013-11-12 19:52 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-31 03:16 - 2014-04-10 19:06 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 19:06 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-30 16:12 - 2013-10-05 21:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 14:15 - 2014-03-29 14:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-03-27 11:02 - 2013-10-07 13:30 - 00002828 ___SH C:\Windows\SysWOW64\KGyGaAvL.sys 2014-03-27 11:02 - 2013-10-07 13:30 - 00000000 ____D C:\Users\Pod\AppData\Local\Corel 2014-03-21 15:18 - 2014-03-21 11:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird Some content of TEMP: ==================== C:\Users\Pod\AppData\Local\Temp\avgnt.exe C:\Users\Pod\AppData\Local\Temp\instract.exe C:\Users\Pod\AppData\Local\Temp\nsc883D.exe C:\Users\Pod\AppData\Local\Temp\nsx7D73.exe C:\Users\Pod\AppData\Local\Temp\nsxFF43.exe C:\Users\Pod\AppData\Local\Temp\Quarantine.exe C:\Users\Pod\AppData\Local\Temp\repair4.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 15:13 ==================== End Of Log ============================ ..und gerade erstellt: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2014 Ran by Pod (administrator) on POD-PC on 20-04-2014 14:44:29 Running from C:\Users\Pod\Desktop\Downloads\Sicherheits-Tools Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe (Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe () C:\Windows\SysWOW64\PSIService.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Dropbox, Inc.) C:\Users\Pod\AppData\Roaming\Dropbox\bin\Dropbox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ReminderApp_EEAC3053-7055-4143-B8A0-306758055099] => C:\Program Files (x86)\Nova Development\Print Artist Gold 25\ReminderApp.exe [146080 2013-08-06] () HKU\S-1-5-21-3960197758-2477925476-223839332-1001\...\Run: [] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-14] (Samsung) HKU\S-1-5-21-3960197758-2477925476-223839332-1001\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-14] (Samsung) HKU\S-1-5-21-3960197758-2477925476-223839332-1001\...\Run: [Messenger (Yahoo!)] => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.) HKU\S-1-5-21-3960197758-2477925476-223839332-1001\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation) AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found Startup: C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Pod\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC3322628F9C1CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKCU - {9BD27B24-13BE-4DDD-9586-61254659E6CD} URL = hxxp://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO-x32: Browser Guard - {02a0d829-4393-46fc-a37e-126263035883} - C:\Program Files (x86)\Browser Guard\browserguard.dll (Browser Guard) BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) Toolbar: HKLM - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent64.dll (soft Xpansion) Toolbar: HKLM-x32 - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent32.dll (soft Xpansion) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Hosts: 127.0.0.1 d3oxij66pru1i3.cloudfront.net Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: webssearches FF SelectedSearchEngine: webssearches FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @soft-xpansion/npsxpdf - C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\searchplugins\yahoo_ff.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-15] FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi FF Extension: Browser Guard - C:\Program Files (x86)\Browser Guard\browserguard.xpi [2013-08-27] FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb [2013-10-08] FF HKLM-x32\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb [2013-10-08] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR DefaultSearchProvider: Search the web (Softonic) CHR DefaultSearchURL: hxxp://www.google.com CHR HKLM-x32\...\Chrome\Extension: [kfepagcelbegkpkcjgfeecmlnmkedjin] - C:\Program Files (x86)\Browser Guard\browserguard.crx [2013-08-27] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-22] (Advanced Micro Devices, Inc.) R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [506288 2011-02-08] (REINER SCT) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-02-18] (Nero AG) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [529704 2008-02-28] (Nero AG) R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) R2 ProtexisLicensing; C:\Windows\SysWOW64\PSIService.exe [177704 2007-06-05] () R2 StarMoney Business 6.0 OnlineUpdate; C:\Program Files (x86)\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-10-08] (soft Xpansion) S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe" [X] ==================== Drivers (Whitelisted) ==================== S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2010-11-27] (REINER SCT) S3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-19] (Siliten) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-20] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) S1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [90960 2013-03-15] (Windows (R) 2000 DDK provider) S1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633680 2013-03-15] (Paragon) S1 Uim_VIM; C:\Windows\System32\Drivers\uim_vimx64.sys [390352 2013-03-15] (Paragon) S3 MSICDSetup; \??\F:\CDriver64.sys [X] S3 NTIDrvr; System32\Drivers\NTIDrvr.sys [X] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-18 19:48 - 2014-04-18 19:48 - 00000000 ____D () C:\Users\Pod\AppData\Local\NovaRegister 2014-04-18 19:00 - 2014-04-18 19:00 - 00004997 _____ () C:\mbam.txt 2014-04-17 15:27 - 2014-04-17 15:27 - 00000000 ____D () C:\Users\Pod\AppData\Local\PAShell 2014-04-17 15:24 - 2014-04-17 15:24 - 00000000 ____D () C:\Users\Pod\AppData\Local\Nova Development 2014-04-17 15:23 - 2014-04-17 15:23 - 00002937 _____ () C:\Users\Public\Desktop\Print Artist Gold 25.lnk 2014-04-17 15:22 - 2014-04-17 15:22 - 00000000 ____D () C:\Program Files (x86)\Nova Development 2014-04-16 20:29 - 2014-04-16 20:29 - 00001298 _____ () C:\Users\Pod\Desktop\Revo Uninstaller.lnk 2014-04-16 20:29 - 2014-04-16 20:29 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-16 07:23 - 2014-04-16 07:23 - 00015102 _____ () C:\Users\Pod\Downloads\Defogger (1).exe 2014-04-15 20:00 - 2014-04-20 14:44 - 00000000 ____D () C:\FRST 2014-04-15 18:52 - 2014-04-15 18:52 - 00000000 _____ () C:\Users\Pod\defogger_reenable 2014-04-15 18:51 - 2014-04-15 18:51 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\IDM2 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D () C:\MININT 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D () C:\Users\Pod\AppData\Local\cache 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 _____ () C:\Users\Pod\daemonprocess.txt 2014-04-15 16:12 - 2014-04-15 16:44 - 00000000 ____D () C:\Program Files\002 2014-04-15 16:10 - 2014-04-15 16:26 - 00000000 ____D () C:\Users\Pod\AppData\Local\41 2014-04-12 15:14 - 2014-04-20 14:36 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-12 15:14 - 2014-04-12 15:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-12 15:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-12 15:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-10 19:06 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 19:06 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 19:06 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 19:06 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 19:05 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 19:05 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 19:05 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 19:05 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 19:05 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 19:05 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 19:05 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 19:05 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 19:05 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 19:05 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 19:05 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 19:05 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 19:05 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-03-29 14:15 - 2014-03-29 14:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-21 11:05 - 2014-03-21 15:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird ==================== One Month Modified Files and Folders ======= 2014-04-20 14:44 - 2014-04-15 20:00 - 00000000 ____D () C:\FRST 2014-04-20 14:41 - 2013-10-08 14:21 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-20 14:36 - 2014-04-12 15:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-20 14:18 - 2013-10-26 10:56 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-20 14:18 - 2013-10-26 10:56 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-20 14:09 - 2009-07-14 06:45 - 00022240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-20 14:09 - 2009-07-14 06:45 - 00022240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-20 14:06 - 2013-10-09 09:35 - 01919089 _____ () C:\Windows\WindowsUpdate.log 2014-04-20 14:06 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-04-20 14:06 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-04-20 14:06 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-20 14:03 - 2013-12-07 12:28 - 00000000 ___RD () C:\Users\Pod\Dropbox 2014-04-20 14:03 - 2013-12-07 12:23 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\Dropbox 2014-04-20 14:02 - 2013-10-10 13:23 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-04-20 14:02 - 2013-10-09 09:33 - 00039302 _____ () C:\Windows\setupact.log 2014-04-20 14:02 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-19 08:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2014-04-18 19:48 - 2014-04-18 19:48 - 00000000 ____D () C:\Users\Pod\AppData\Local\NovaRegister 2014-04-18 19:40 - 2013-11-12 21:44 - 00000000 ____D () C:\Users\Pod\Downloads\Sicherheit 2014-04-18 19:35 - 2013-11-11 18:44 - 00000000 ____D () C:\AdwCleaner 2014-04-18 19:06 - 2013-10-06 17:15 - 00001113 _____ () C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-04-18 19:06 - 2013-10-05 21:20 - 00001083 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-18 19:06 - 2013-10-05 20:24 - 00001025 _____ () C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-18 19:00 - 2014-04-18 19:00 - 00004997 _____ () C:\mbam.txt 2014-04-18 18:55 - 2010-11-21 05:47 - 00444622 _____ () C:\Windows\PFRO.log 2014-04-17 18:38 - 2013-10-05 20:31 - 00117408 _____ () C:\Users\Pod\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-17 18:36 - 2013-10-06 20:54 - 00000000 ____D () C:\Program Files (x86)\StarMoney Business 6.0 2014-04-17 18:30 - 2009-07-14 06:45 - 00419856 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-17 15:27 - 2014-04-17 15:27 - 00000000 ____D () C:\Users\Pod\AppData\Local\PAShell 2014-04-17 15:24 - 2014-04-17 15:24 - 00000000 ____D () C:\Users\Pod\AppData\Local\Nova Development 2014-04-17 15:23 - 2014-04-17 15:23 - 00002937 _____ () C:\Users\Public\Desktop\Print Artist Gold 25.lnk 2014-04-17 15:22 - 2014-04-17 15:22 - 00000000 ____D () C:\Program Files (x86)\Nova Development 2014-04-17 13:03 - 2013-10-22 12:15 - 00000000 ____D () C:\Users\Pod\Desktop\Tour neu 2014-04-17 12:14 - 2014-03-01 22:04 - 00007168 ___SH () C:\Users\Pod\Desktop\Thumbs.db 2014-04-16 20:29 - 2014-04-16 20:29 - 00001298 _____ () C:\Users\Pod\Desktop\Revo Uninstaller.lnk 2014-04-16 20:29 - 2014-04-16 20:29 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-16 17:26 - 2013-10-05 21:44 - 00000000 ____D () C:\Users\Pod\Documents\PhraseExpress 2014-04-16 07:23 - 2014-04-16 07:23 - 00015102 _____ () C:\Users\Pod\Downloads\Defogger (1).exe 2014-04-15 18:52 - 2014-04-15 18:52 - 00000000 _____ () C:\Users\Pod\defogger_reenable 2014-04-15 18:52 - 2013-10-05 20:24 - 00000000 ____D () C:\Users\Pod 2014-04-15 18:51 - 2014-04-15 18:51 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\IDM2 2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D () C:\MININT 2014-04-15 18:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources 2014-04-15 17:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-04-15 16:44 - 2014-04-15 16:12 - 00000000 ____D () C:\Program Files\002 2014-04-15 16:44 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\DigitalLocker 2014-04-15 16:26 - 2014-04-15 16:10 - 00000000 ____D () C:\Users\Pod\AppData\Local\41 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D () C:\Users\Pod\AppData\Local\cache 2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 _____ () C:\Users\Pod\daemonprocess.txt 2014-04-12 15:14 - 2014-04-12 15:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-12 15:14 - 2013-11-12 19:52 - 00001136 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D () C:\Users\Pod\AppData\Roaming\Malwarebytes 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-04-11 17:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-11 03:04 - 2013-10-08 13:50 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-11 03:03 - 2013-10-28 18:00 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 03:02 - 2013-10-28 18:00 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-07 08:40 - 2013-10-22 13:30 - 00000964 _____ () C:\Windows\Tasks\Paragon Archive name arc_221013112910391.job 2014-04-07 08:40 - 2013-10-17 13:04 - 00000964 _____ () C:\Windows\Tasks\Paragon Archive name arc_171013110200181.job 2014-04-03 14:13 - 2013-10-26 10:56 - 00004100 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-03 14:13 - 2013-10-26 10:56 - 00003848 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-03 09:51 - 2014-04-12 15:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-12 15:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2013-11-12 19:52 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-31 03:16 - 2014-04-10 19:06 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 19:06 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-30 16:12 - 2013-10-05 21:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 14:15 - 2014-03-29 14:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-27 11:02 - 2013-10-07 13:30 - 00002828 ___SH () C:\Windows\SysWOW64\KGyGaAvL.sys 2014-03-27 11:02 - 2013-10-07 13:30 - 00000000 ____D () C:\Users\Pod\AppData\Local\Corel 2014-03-21 15:18 - 2014-03-21 11:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird Some content of TEMP: ==================== C:\Users\Pod\AppData\Local\Temp\avgnt.exe C:\Users\Pod\AppData\Local\Temp\instract.exe C:\Users\Pod\AppData\Local\Temp\nsc883D.exe C:\Users\Pod\AppData\Local\Temp\nsx7D73.exe C:\Users\Pod\AppData\Local\Temp\nsxFF43.exe C:\Users\Pod\AppData\Local\Temp\Quarantine.exe C:\Users\Pod\AppData\Local\Temp\repair4.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-19 08:42 ==================== End Of Log ============================ --- --- --- Das Problem mit istart.websearches ist gelöst, was sonst noch bleibt, wirst Du wissen. Bis jetzt erstmal herzlichen Dasnk. Viele Grüsse Driver23 Geändert von Driver23 (20.04.2014 um 13:48 Uhr) |
20.04.2014, 18:38 | #10 |
/// the machine /// TB-Ausbilder | Probleme mit istart.webssearches.com Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [97280 2009-07-14] () Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Lösch das was ESET anmeckert, vor alem den gecrackten Usenet Office Scheiss. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.04.2014, 09:43 | #11 |
| Probleme mit istart.webssearches.com Hallo Schrauber, Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-04-2014 02 Ran by Pod at 2014-04-21 10:41:04 Run:1 Running from C:\Users\Pod\Desktop\Downloads\Sicherheits-Tools Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [97280 2009-07-14] () ***************** "AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [97280 2009-07-14] ()" => Value Data not found. ==== End of Fixlog ==== Viele Grüsse Driver23 |
21.04.2014, 20:54 | #12 |
/// the machine /// TB-Ausbilder | Probleme mit istart.webssearches.com ok
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.04.2014, 14:09 | #13 |
| Probleme mit istart.webssearches.com Hallo Schrauber, ich habe die Punkte abgearbeitet und alles läuft wieder super. Danke für die tolle Hilfe. Wenn beim Scan mit Malwarebytes etwas gefunden wird und ich es in Quarantäne schiebe, ist das dann ausreichend, oder was muss ich machen? Viele Grüsse, Driver23 |
30.04.2014, 23:08 | #14 |
/// the machine /// TB-Ausbilder | Probleme mit istart.webssearches.com das reicht
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Probleme mit istart.webssearches.com |
als startseite, browserfenster, erscheine, firefox, gelöscht, heulen, hilfe, istart.webssearches.com, mobogenie, mobogenie entfernen, popup, probleme, programmen, pup.optional.rrsavings.a, pup.optional.webssearches.a, seite, taucht, versuch |