|
Plagegeister aller Art und deren Bekämpfung: Weit über 100 PUPs etc. bei MalwarebytesWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
23.04.2014, 21:22 | #1 |
| Weit über 100 PUPs etc. bei Malwarebytes Hallo liebes Team von Trojaner-Board, ein Freund empfahl mir einen Durchlauf von Malwarebytes. Ich fiel fast vom Stuhl als ich die weit über 100 Funde entdeckte. Ich fürchte mein Rechner ist total verseucht... Ich wäre Euch sehr dankbar wenn ihr mir helft meinen Laptop zu reinigen! Vielen Dank und Gruß Fuat Hier alle logs: Malware Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 23.04.2014 Suchlauf-Zeit: 21:33:21 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.23.07 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: *** Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 296746 Verstrichene Zeit: 40 Min, 49 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 45 PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, , [5ea202febb45c53bc957be908a7847b9], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, , [5ea202febb45c53bc957be908a7847b9], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, , [e818fb05de22ca3602c861b6da28f30d], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.dskBnd.1, , [e818fb05de22ca3602c861b6da28f30d], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.dskBnd, , [e818fb05de22ca3602c861b6da28f30d], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.dskBnd, , [e818fb05de22ca3602c861b6da28f30d], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.dskBnd.1, , [e818fb05de22ca3602c861b6da28f30d], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane.1, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane.1, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.SoftonicHlpr.1, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.SoftonicHlpr, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.SoftonicHlpr, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.SoftonicHlpr.1, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Delta.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, , [7a86946c2cd49d63e9370a435fa309f7], PUP.Optional.Delta.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, , [7a86946c2cd49d63e9370a435fa309f7], PUP.Optional.Delta.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, , [47b9f40c6997cf312bf453fafe04fa06], PUP.Optional.Delta.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, , [47b9f40c6997cf312bf453fafe04fa06], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc, , [3ec24ab614ec619f20c6cea5936f1ce4], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc.1, , [d828c7391ce4a858e6004e25e81a916f], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc, , [1ee27c8448b8629e33b3f38054ae46ba], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc.1, , [8977b14fcc343fc1974ffd768c76fe02], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\elchiiiejkobdbblfejjkbphbddgmljf, , [4ab6eb1567994bb5edfca8cba062e020], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\SOFTONIC\Softonic, , [2ed2fa06d42ccf31da100d667191936d], PUP.Optional.DataMngr.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, , [bf416d937e825ca4a5d836623ac97789], PUP.Optional.DataMngr.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, , [01ff8779f50b1ce45a224058dc27e31d], PUP.Optional.Babylon.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Redir, , [ab5522de7789f30de99ceaafac5752ae], PUP.Optional.Babylon.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, , [ca363bc558a835cbd3b38b0ee0237987], PUP.Optional.Softonic.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Softonic, , [956b0af62bd524dc1ec92b4822e048b8], PUP.Optional.Softonic.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [c33d25db58a8fd03b0ee0d63857d916f], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore.1, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore.1, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\S, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\S, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Softonic, , [aa56827e7789ad538267cb9d18ea3ac6], Registrierungswerte: 2 PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, Softonic Toolbar, , [e818fb05de22ca3602c861b6da28f30d] PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, , [a35ddb2501ff23dd567445d2758dc739], Registrierungsdaten: 0 (No malicious items detected) Ordner: 14 PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\225724A56DC14C7E9F829212E2AD9957, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\358ADAE8E67541ECB69F8A04F0102DE7, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\8DE5407FF51A4831A9321DD709F20985, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AAF0B8FFDA8048F7B06085E02F90D512, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\bh, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Temp\mt_ffx\Softonic, , [43bd9e627a86ee12f2f8e97fa75b44bc], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Temp\mt_ffx\Softonic\Softonic, , [43bd9e627a86ee12f2f8e97fa75b44bc], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Temp\mt_ffx\Softonic\Softonic\1.8.21.14, , [43bd9e627a86ee12f2f8e97fa75b44bc], Dateien: 95 PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicTlbr.dll, , [e818fb05de22ca3602c861b6da28f30d], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\bh\Softonic.dll, , [35cbce32867ade2233982becec1660a0], PUP.Optional.Babylon.A, C:\Users\***\AppData\Roaming\OpenCandy\358ADAE8E67541ECB69F8A04F0102DE7\DeltaTB.exe, , [8b759d63ac540cf4f65d30d1a55c6799], PUP.Optional.Babylon.A, C:\Users\***\AppData\Roaming\OpenCandy\8DE5407FF51A4831A9321DD709F20985\DeltaTB.exe, , [5ca4c23e3dc32ed20d46ea1749b8ca36], PUP.Optional.OpenCandy.A, C:\Users\***\AppData\Roaming\OpenCandy\AAF0B8FFDA8048F7B06085E02F90D512\Setupsft_chr_p1v7.exe, , [08f8b24efc04ec14ad5953cdc63ea35d], PUP.Optional.Babylon.A, C:\Program Files (x86)\Mozilla Firefox\ccp.bao, , [af51926e9868b54b3ae6ff1f6e9246ba], PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\BExternal.dll, , [04fc11efa858ef1126b8cd5513ed60a0], PUP.Optional.BabSolution.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\BUSolution.dll, , [32ce40c0a15fb44c27a14fb859a823dd], PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\CrxInstaller.dll, , [817f34cc08f84fb19eded1437889de22], PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\MntrDLLInstall.dll, , [639d33cd02fef30d2a53ec2838c954ac], PUP.Optional.Delta.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\MyDeltaTB.exe, , [7c8442be35cbb44c0b11dd8e13eefe02], PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\Setup.exe, , [659b788810f09d6334edf6287c8413ed], PUP.Optional.BabSolution.A, C:\Users\***\AppData\Local\Temp\bus8390\BUSolution.dll, , [fa06fe026a966c9425a30bfc09f804fc], PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\9818B6B5-BAB0-7891-AD0F-046BAF01DD80\Latest\BExternal.dll, , [f01013ed54acfe0226b85bc710f052ae], PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\9818B6B5-BAB0-7891-AD0F-046BAF01DD80\Latest\CrxInstaller.dll, , [808057a9fc046d93fb818b89699854ac], PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\9818B6B5-BAB0-7891-AD0F-046BAF01DD80\Latest\MntrDLLInstall.dll, , [27d9bc4441bf46ba3845858f699816ea], PUP.Optional.Delta.A, C:\Users\***\AppData\Local\Temp\9818B6B5-BAB0-7891-AD0F-046BAF01DD80\Latest\MyDeltaTB.exe, , [47b9b24e39c702fefc20175425dcc43c], PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\9818B6B5-BAB0-7891-AD0F-046BAF01DD80\Latest\Setup.exe, , [cd3334cc45bb02feb66bf628ca36be42], PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\searchplugins\softonic.xml, , [8779718fd92730d074705a19867c6a96], PUP.Optional.Babylon.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\searchplugins\babylon.xml, , [55abee12f010847c1dfa2c4b3ac8c937], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\225724A56DC14C7E9F829212E2AD9957\HSS-2.83-install-plain-452-silent.exe, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB\2877.ico, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB\avg.exe, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB\AVG923_p1v3.exe, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB\EBB77268-338F-4C6A-8590-AD88FED26F4A, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB\OCBrowserHelper_1.0.3.85.dll, , [8c74dc24ff0108f8e12ed38e15ed867a], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\appCntrl.js, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\bg.html, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\bg.js, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\chMntz.dll, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\CrmAdpt.dll, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\ct.js, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\CTB.dll, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\dpk.js, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\hprtkMsg.htm, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\hprtkMsg.js, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\json2.min.js, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\logo.png, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\manifest.json, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\pref.json, , [7789be4270908f712bbde97f70925ea2], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\softonic.crx, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicApp.dll, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicEng.dll, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\Softonicsrv.exe, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\uninstall.exe, , [aa56827e7789ad538267cb9d18ea3ac6], PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Temp\mt_ffx\Softonic\Softonic\1.8.21.14\softonic.xpi, , [43bd9e627a86ee12f2f8e97fa75b44bc], PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.admin", false);), ,[5ca4728eb14fb0504620c692d72dd729] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.aflt", "OC");), ,[b749de2254acea167beb154345bf22de] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");), ,[34ccdf21fe0210f0c0a685d36c980af6] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.autoRvrt", "false");), ,[f20e1ae6f907ec14a9bde0780ff59e62] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dfltLng", "de");), ,[f80806fad0309a663a2ca9af36ce40c0] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dfltSrch", true);), ,[728e817f14ec966a2541c8903cc8d32d] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dnsErr", true);), ,[e818b050fc048c742c3aacace61e47b9] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.excTlbr", false);), ,[52ae8a76cf31ba462f37134521e304fc] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.ffxUnstlRst", false);), ,[1de358a8788888785115a4b4af5548b8] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpg", true);), ,[c937837d1ce44cb471f52830768e6898] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=20ca48d400000000000074de2beaeff9");), ,[2bd557a917e94ab6046281d72dd738c8] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.id", "20ca48d400000000000074de2beaeff9");), ,[b14f1fe18c741fe15d0993c5fb09916f] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.instlDay", "16026");), ,[12eec23e29d741bffd696aee55af10f0] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.instlRef", "MOY00621");), ,[7090867abd43af51b4b2ed6bb25243bd] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.newTab", true);), ,[9e6228d8926e738d69fd85d390744bb5] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=20ca48d400000000000074de2beaeff9");), ,[7987f20eb8486d93ed79fb5ddb299769] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.prdct", "Softonic");), ,[c43c36ca14ec7e8213536eeaad570000] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.prtnrId", "softonic");), ,[0af630d0f70968982d39a1b76c988878] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.rvrt", "false");), ,[2fd110f0659bec14a7bf4414996bfb05] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.smplGrp", "none");), ,[659bee12c53b70906df9bb9d34d0a45c] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");), ,[c33dd03029d76b9567ffa3b5b64ea858] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.tlbrId", "opencandy2013");), ,[a858b64a03fd6b95b4b26cece3213cc4] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=20ca48d400000000000074de2beaeff9&q=");), ,[6898a85815eb6997fb6baaae53b1ea16] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsn", "1.8.21.14");), ,[5da30000f60afb055e0818407a8a19e7] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsnTs", "1.8.21.1414:03:01");), ,[8b75c73937c97789ec7ac197c242669a] PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsni", "1.8.21.14");), ,[ba465ca41ee20df33e2869efcc388977] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.admin", false);), ,[629ef50ba060a65a2844b1a762a2f40c] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.aflt", "babsst");), ,[aa56619f9769ef11d59721377292ea16] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");), ,[649c02fe8d7347b995d735239d671be5] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.autoRvrt", "false");), ,[42bea759f50bab55680450084fb5df21] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.dfltLng", "de");), ,[31cf37c91ee29b65bab262f618ecd729] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.excTlbr", false);), ,[8c7422de9d6334cc36363b1d3bc9aa56] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.ffxUnstlRst", true);), ,[d32d8a7602fe5ea23c304414b252738d] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.id", "20ca48d400000000000000ffbb10c4d0");), ,[5da31ce4de22cf31343882d6f3115fa1] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlDay", "15941");), ,[4eb2946cb44cbd431c50292f3dc7b44c] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlRef", "sst");), ,[1fe1c63a9f617c847def64f4a95b3bc5] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.newTab", false);), ,[ab55cc343ac62cd409630553a460669a] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prdct", "delta");), ,[758b3cc40cf451afb7b5f95fe222cc34] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prtnrId", "delta");), ,[b947c43cab55956b1557193f37cd42be] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.rvrt", "false");), ,[2ad62cd4b9474cb4b7b5d286659f40c0] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.smplGrp", "none");), ,[a95722deb749e91764089bbd3dc7718f] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrId", "base");), ,[8a76bc44639d45bbbab282d6788c37c9] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrSrchUrl", "");), ,[fb05e31df709b7497bf180d837cd46ba] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsn", "1.8.24.6");), ,[6e92f90790709e62016b8dcbcc3810f0] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsnTs", "1.8.24.69:59:04");), ,[bc445fa10af6639d8ae22e2a7a8a7888] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsni", "1.8.24.6");), ,[8c74db25bd4360a058146deb16eed030] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.babExt", "");), ,[cc34b64af40cfc04c4a863f5758f43bd] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.babTrack", "affID=121564&tsp=4984");), ,[718f9f61f01023ddf37970e88b79c23e] PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.srcExt", "ss");), ,[4ab6eb1541bf1ae668041246b74d847c] Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 21:33 on 23/04/2014 (Fuat) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-04-2014 Ran by *** (administrator) on ***-PC on 23-04-2014 21:34:41 Running from C:\Users\***\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\windows\system32\atiesrxx.exe (AMD) C:\windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Marvell Semiconductor, Inc.) C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe () C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\ipmGui.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated) HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-11-24] (Lenovo) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2011-11-24] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-11-24] (Lenovo(beijing) Limited) HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation) HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1238528 2007-08-29] (Marvell Semiconductor, Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.) HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.) HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2011-11-24] (Lenovo) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-807794254-139005778-1418515836-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-807794254-139005778-1418515836-1000\...\Run: [Amazon Cloud Player] => C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3140608 2014-01-14] () HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Amazon Cloud Player] => C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3140608 2014-01-14] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=10&cc=&mi=20ca48d400000000000074de2beaeff9 HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ SearchScopes: HKCU - DefaultScope {1D6289B1-98DF-40A3-A61C-E9F912C40B47} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=20ca48d400000000000074de2beaeff9&r=412 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=20CA00FFBB10C4D0&affID=121564&tsp=4984 SearchScopes: HKCU - {1D6289B1-98DF-40A3-A61C-E9F912C40B47} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=20ca48d400000000000074de2beaeff9&r=412 SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://isearch.avg.com/search?cid={7B80D188-C6D3-4804-831B-94DAA4A1BCDC}&mid=36fa2a3dc6fa47d0a5400d47e788938e-2407c80f4ea851e8267460b2327656fcd5111031&lang=de&ds=od011&pr=sa&d=2012-07-18 16:51:35&v=12.1.0.20&sap=dsp&q={searchTerms} BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll No File BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\bh\Softonic.dll (Softonic.com) Toolbar: HKLM-x32 - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicTlbr.dll (Softonic.com) Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default FF user.js: detected! => C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101753.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\searchplugins\softonic.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Add to Amazon Wish List Button - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\Extensions\amznUWL2@amazon.com.xpi [2012-12-31] FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-21] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Softonic Chrome Toolbar) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf [2013-11-17] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\***\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-11-01] CHR HKLM-x32\...\Chrome\Extension: [elchiiiejkobdbblfejjkbphbddgmljf] - C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\Softonic.crx [2013-06-11] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-02] (Avira Operations GmbH & Co. KG) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-23] (Malwarebytes Corporation) R3 SPUVCbv; C:\Windows\System32\Drivers\usbvideo.sys [185344 2013-07-12] (Microsoft Corporation) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-01-10] (Anchorfree Inc.) U3 BcmSqlStartupSvc; U2 CLKMSVC10_3A60B698; U2 CLKMSVC10_C3B3B687; U2 DriverService; U2 iATAgentService; U2 idealife Update Service; U3 IGRS; U2 IviRegMgr; U2 nvUpdatusService; U2 Oasis2Service; U2 PCCarerService; U2 ReadyComm.DirectRouter; U2 RichVideo; U2 RtLedService; U2 SeaPort; U2 SoftwareService; U3 SQLWriter; U2 Stereo Service; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-23 21:34 - 2014-04-23 21:34 - 00014988 _____ () C:\Users\***\Desktop\FRST.txt 2014-04-23 21:34 - 2014-04-23 21:34 - 00000000 ____D () C:\FRST 2014-04-23 21:33 - 2014-04-23 21:33 - 00027969 _____ () C:\Users\***\Desktop\mbam.txt 2014-04-23 21:33 - 2014-04-23 21:33 - 00000470 _____ () C:\Users\***\Desktop\defogger_disable.log 2014-04-23 21:33 - 2014-04-23 21:33 - 00000000 _____ () C:\Users\***\defogger_reenable 2014-04-23 21:13 - 2014-04-23 21:13 - 00380416 _____ () C:\Users\***\Desktop\Gmer-19357.exe 2014-04-23 21:12 - 2014-04-23 21:13 - 02061312 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe 2014-04-23 21:12 - 2014-04-23 21:12 - 00050477 _____ () C:\Users\***\Desktop\Defogger.exe 2014-04-23 20:51 - 2014-04-23 20:52 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-23 20:51 - 2014-04-23 20:51 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-23 20:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-04-23 20:50 - 2014-04-23 20:51 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\***\Desktop\mbam-setup-2.0.1.1004.exe 2014-04-17 19:53 - 2014-04-17 19:53 - 00000000 ____D () C:\Users\***\AppData\Local\{C55381F5-CA4A-4FD6-8D4B-17A6191F056B} 2014-04-10 06:13 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-04-10 06:13 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-04-10 06:13 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-04-10 06:13 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll 2014-04-10 06:12 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll 2014-04-10 06:12 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll 2014-04-10 06:12 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe 2014-04-10 06:12 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll 2014-04-10 06:12 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe 2014-04-10 06:12 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe 2014-04-10 06:12 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys 2014-04-10 06:12 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys 2014-04-10 06:12 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys 2014-04-10 06:12 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll 2014-04-10 06:12 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll 2014-04-10 06:12 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys 2014-04-09 19:01 - 2014-04-09 19:01 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_deu(1).exe 2014-04-01 18:09 - 2014-04-01 18:10 - 00006011 _____ () C:\Users\***\Desktop\Themenvorschläge zur Fortbildungsprüfung.odt 2014-03-29 13:19 - 2014-03-29 13:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-04-23 21:34 - 2014-04-23 21:34 - 00014988 _____ () C:\Users\***\Desktop\FRST.txt 2014-04-23 21:34 - 2014-04-23 21:34 - 00000000 ____D () C:\FRST 2014-04-23 21:33 - 2014-04-23 21:33 - 00027969 _____ () C:\Users\***\Desktop\mbam.txt 2014-04-23 21:33 - 2014-04-23 21:33 - 00000470 _____ () C:\Users\***\Desktop\defogger_disable.log 2014-04-23 21:33 - 2014-04-23 21:33 - 00000000 _____ () C:\Users\***\defogger_reenable 2014-04-23 21:33 - 2012-02-17 18:35 - 00000000 ____D () C:\Users\*** 2014-04-23 21:30 - 2012-04-09 09:23 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-23 21:17 - 2009-07-14 06:45 - 00021072 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-23 21:17 - 2009-07-14 06:45 - 00021072 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-23 21:13 - 2014-04-23 21:13 - 00380416 _____ () C:\Users\***\Desktop\Gmer-19357.exe 2014-04-23 21:13 - 2014-04-23 21:12 - 02061312 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe 2014-04-23 21:12 - 2014-04-23 21:12 - 00050477 _____ () C:\Users\***\Desktop\Defogger.exe 2014-04-23 20:56 - 2011-11-24 15:23 - 01424365 _____ () C:\windows\WindowsUpdate.log 2014-04-23 20:52 - 2014-04-23 20:51 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-23 20:51 - 2014-04-23 20:51 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-23 20:50 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\***\Desktop\mbam-setup-2.0.1.1004.exe 2014-04-23 20:51 - 2012-10-08 09:25 - 00000000 ____D () C:\Users\***\AppData\Roaming\Malwarebytes 2014-04-23 20:51 - 2012-10-08 09:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-23 20:51 - 2012-10-08 09:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-04-23 20:51 - 2011-11-24 07:09 - 00700134 _____ () C:\windows\system32\perfh007.dat 2014-04-23 20:51 - 2011-11-24 07:09 - 00149984 _____ () C:\windows\system32\perfc007.dat 2014-04-23 20:51 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI 2014-04-23 20:47 - 2011-11-24 16:11 - 00138091 _____ () C:\windows\system32\fastboot.set 2014-04-23 20:47 - 2011-11-24 16:04 - 03384033 _____ () C:\FaceProv.log 2014-04-23 20:47 - 2011-11-24 16:04 - 00000000 ____D () C:\ProgramData\VeriFace 2014-04-23 20:47 - 2011-11-24 15:56 - 00001120 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-23 20:47 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-04-23 20:47 - 2009-07-14 06:51 - 00115591 _____ () C:\windows\setupact.log 2014-04-21 19:53 - 2013-12-27 12:33 - 00000000 ____D () C:\Users\***\Desktop\Handy 2014-04-21 19:43 - 2011-11-24 15:57 - 00001124 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-18 13:14 - 2009-07-14 07:08 - 00032632 _____ () C:\windows\Tasks\SCHEDLGU.TXT 2014-04-17 19:53 - 2014-04-17 19:53 - 00000000 ____D () C:\Users\***\AppData\Local\{C55381F5-CA4A-4FD6-8D4B-17A6191F056B} 2014-04-10 06:16 - 2013-08-13 19:37 - 00000000 ____D () C:\windows\system32\MRT 2014-04-10 06:14 - 2012-08-06 16:30 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-04-09 19:09 - 2012-05-22 21:46 - 00000000 ____D () C:\Users\***\AppData\Local\Adobe 2014-04-09 19:04 - 2012-04-09 09:23 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-04-09 19:04 - 2012-04-09 09:23 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-04-09 19:04 - 2012-02-17 18:52 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-09 19:01 - 2014-04-09 19:01 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_deu(1).exe 2014-04-03 19:58 - 2013-08-07 17:54 - 00000000 ____D () C:\Users\***\Desktop\Bilder130807 2014-04-03 09:51 - 2014-04-23 20:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-23 20:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2012-10-08 09:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-04-01 18:13 - 2012-07-18 11:33 - 00000000 ____D () C:\Users\***\AppData\Roaming\SoftGrid Client 2014-04-01 18:10 - 2014-04-01 18:09 - 00006011 _____ () C:\Users\***\Desktop\Themenvorschläge zur Fortbildungsprüfung.odt 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe 2014-03-31 03:16 - 2014-04-10 06:13 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 06:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 06:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 06:13 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-03-30 10:01 - 2012-10-08 09:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 13:19 - 2014-03-29 13:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-29 12:38 - 2011-11-24 15:57 - 00004120 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-29 12:38 - 2011-11-24 15:57 - 00003868 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-27 16:55 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\NDF Some content of TEMP: ==================== C:\Users\***\AppData\Local\Temp\AskSLib.dll C:\Users\***\AppData\Local\Temp\avgnt.exe C:\Users\***\AppData\Local\Temp\avguidx.dll C:\Users\***\AppData\Local\Temp\CommonInstaller.exe C:\Users\***\AppData\Local\Temp\contentDATs.exe C:\Users\***\AppData\Local\Temp\MachineIdCreator.exe C:\Users\***\AppData\Local\Temp\oi_{292C31A9-1BA2-4016-8710-0657D1C588A7}.exe C:\Users\***\AppData\Local\Temp\pdf24-creator-update.exe C:\Users\***\AppData\Local\Temp\SecurityScan_Release.exe C:\Users\***\AppData\Local\Temp\ToolbarInstaller.exe C:\Users\***\AppData\Local\Temp\uninst1.exe C:\Users\***\AppData\Local\Temp\UNINSTALL.exe C:\Users\Gastkonto\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-24 16:22 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-04-2014 Ran by *** at 2014-04-23 21:35:17 Running from C:\Users\***\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.182 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.9 - Adobe Systems Incorporated) Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.3.0.422 - Amazon Services LLC) Amazon MP3-Downloader 1.0.17 (HKLM-x32\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC) Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Client Installation Program (HKLM-x32\...\{D3694B69-6F8C-42D3-8A0A-EB2AB528C02C}) (Version: 7.0 - Atheros) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.36 - Atheros Communications Inc.) ATI Catalyst Install Manager (HKLM\...\{C3E6E2B5-DEB5-235A-4999-4D424C11788B}) (Version: 3.0.808.0 - ATI Technologies, Inc.) ATI Uninstaller (HKLM\...\ATI Uninstaller) (Version: 8.813.3.2-110324a-116588C-Lenovo - ATI Technologies, Inc.) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) Benutzerhandbuch (x32 Version: 1.0.0.6 - Lenovo) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0324.2228.38483 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2011.0324.2228.38483 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2011.0324.2228.38483 - ATI) Hidden Catalyst Control Center Profiles Mobile (x32 Version: 2011.0324.2228.38483 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Czech (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Danish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Dutch (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help English (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Finnish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help French (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help German (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Greek (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Hungarian (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Italian (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Japanese (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Korean (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Norwegian (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Polish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Portuguese (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Russian (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Spanish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Swedish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Thai (x32 Version: 2011.0324.2227.38483 - ATI) Hidden CCC Help Turkish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden ccc-core-static (x32 Version: 2011.0324.2228.38483 - Ihr Firmenname) Hidden ccc-utility64 (Version: 2011.0324.2228.38483 - ATI) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.15 - Piriform) ClipGrab 3.2.0.10 (HKLM-x32\...\{8A1033B0-EF33-4FB5-97A1-C47A7DCDD7E6}_is1) (Version: - Philipp Schmieder Medien) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.1.0 - Conexant) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden ElsterFormular (HKLM-x32\...\ElsterFormular 13.0.0.8086p) (Version: 13.0.0.8086p - Landesfinanzdirektion Thüringen) Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.0 - Lenovo) Energy Management (x32 Version: 6.0.2.0 - Lenovo) Hidden ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Free YouTube to MP3 Converter version 3.12.20.1230 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.20.1230 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 7.0.517.43 - Google Inc.) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3074 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.10.1209.1 - Lenovo EasyCamera) Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.6 - Lenovo) Lenovo Games Console (HKLM-x32\...\Lenovo Games Console) (Version: 1.2.6.436 - Oberon Media Inc.) Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 7.0.1628 - CyberLink Corp.) Hidden Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3728 - CyberLink Corp.) Lenovo YouCam (x32 Version: 3.1.3728 - CyberLink Corp.) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft IntelliPoint 8.2 (HKLM\...\Microsoft IntelliPoint 8.2) (Version: 8.20.468.0 - Microsoft Corporation) Microsoft IntelliPoint 8.2 (Version: 8.20.468.0 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden Nur Entfernen der CopyTrans Suite möglich (HKCU\...\CopyTrans Suite) (Version: 2.34 - WindSolutions) OpenOffice.org 3.4 (HKLM-x32\...\{4C552FD3-2CCD-4E00-AC64-0681DBB3F8B5}) (Version: 3.4.9590 - OpenOffice.org) PDF24 Creator 5.2.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.4.2 - Frank Heindörfer, Philip Chinery) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.7303 - CyberLink Corp.) PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10003 - Realtek Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden SopCast 3.4.8 (HKLM-x32\...\SopCast) (Version: 3.4.8 - www.sopcast.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.0.0 - Synaptics Incorporated) UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.6 - Lenovo) VeriFace (HKLM-x32\...\VeriFace) (Version: 4.0.0.1224 - Lenovo) VLC media player 2.0.1 (HKLM-x32\...\VLC media player) (Version: 2.0.1 - VideoLAN) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows-Treiberpaket - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo) WMV9/VC-1 Video Playback (Version: 1.00.0000 - ATI Technologies Inc.) Hidden ==================== Restore Points ========================= 22-03-2014 09:32:39 Windows Update 22-03-2014 10:47:27 Windows Update 28-03-2014 15:00:17 Windows Update 01-04-2014 07:12:29 Windows Update 10-04-2014 04:08:02 Windows Update 10-04-2014 04:13:51 Windows Update 15-04-2014 16:59:09 Windows Update 19-04-2014 07:32:50 Windows Update 23-04-2014 18:54:27 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {27CD145D-A9C2-4754-B9BF-29F8A6DACD79} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-29] (CyberLink) Task: {30A5F4A5-D235-4BC0-B96F-D36708FD05F8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-24] (Google Inc.) Task: {3D8A5982-1B07-4CD9-B3BA-C9B0054D4A68} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-08-01] (Microsoft Corporation) Task: {6D124FF4-D929-4CDB-8719-57BD45F62B50} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {FB8C0B16-D800-4FAB-9818-E3CEB9F4A6D4} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-09] (Adobe Systems Incorporated) Task: {FFF66D4A-54F8-4060-B237-6FD9E9D92358} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-24] (Google Inc.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-11-24 16:04 - 2011-11-24 16:03 - 01508192 _____ () C:\windows\system32\IcnOvrly.dll 2011-11-24 16:04 - 2011-11-24 16:03 - 00628064 _____ () C:\windows\system32\SimpleExt.dll 2011-11-24 15:35 - 2011-03-25 11:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2008-12-20 05:20 - 2011-11-24 16:14 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll 2008-12-20 05:20 - 2011-11-24 16:14 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll 2014-02-13 22:46 - 2014-01-14 21:46 - 03140608 _____ () C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe 2013-05-04 20:09 - 2013-05-04 20:05 - 00397704 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2011-11-24 16:03 - 2011-11-24 16:03 - 00013664 _____ () C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll 2014-02-19 19:59 - 2014-02-19 19:59 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\aeb07412ad41bff851002a4cd8ed97d1\IsdiInterop.ni.dll 2011-11-24 15:34 - 2011-02-18 10:16 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2014-03-29 13:19 - 2014-03-29 13:19 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/23/2014 09:35:45 PM) (Source: Application Hang) (User: ) Description: Programm mbam.exe, Version 1.0.0.500 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 13c8 Startzeit: 01cf5f251826bba0 Endzeit: 15 Anwendungspfad: C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe Berichts-ID: 6fe2b746-cb1e-11e3-98e9-dc0ea16c7a7d Error: (04/23/2014 09:04:12 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 09:04:12 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 09:04:11 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 08:48:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord) (User: ) Description: ATI EEU failed to post message to CCC Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord) (User: ) Description: ATI EEU failed to post message to CCC Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord) (User: ) Description: ATI EEU failed to post message to CCC Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord) (User: ) Description: ATI EEU failed to post message to CCC Error: (04/21/2014 07:10:04 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (04/23/2014 08:47:15 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/21/2014 07:08:29 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/21/2014 02:05:22 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/21/2014 11:51:18 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/21/2014 09:01:50 AM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Error: (04/21/2014 08:59:00 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/20/2014 06:24:09 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/20/2014 08:13:05 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/19/2014 01:31:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/19/2014 11:24:37 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Client Virtualization Handler" ist vom Dienst "Application Virtualization Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1053 Microsoft Office Sessions: ========================= Error: (04/23/2014 09:35:45 PM) (Source: Application Hang)(User: ) Description: mbam.exe1.0.0.50013c801cf5f251826bba015C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe6fe2b746-cb1e-11e3-98e9-dc0ea16c7a7d Error: (04/23/2014 09:04:12 PM) (Source: SideBySide)(User: ) Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\***\Downloads\esetsmartinstaller_deu(1).exe Error: (04/23/2014 09:04:12 PM) (Source: SideBySide)(User: ) Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\***\Downloads\esetsmartinstaller_deu(1).exe Error: (04/23/2014 09:04:11 PM) (Source: SideBySide)(User: ) Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\***\Downloads\esetsmartinstaller_deu.exe Error: (04/23/2014 08:48:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord)(User: ) Description: Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord)(User: ) Description: Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord)(User: ) Description: Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord)(User: ) Description: Error: (04/21/2014 07:10:04 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 41% Total physical RAM: 4039.86 MB Available physical RAM: 2375.67 MB Total Pagefile: 8077.9 MB Available Pagefile: 6161.13 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:421.81 GB) (Free:332.37 GB) NTFS Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:26.59 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 1ADBAB2B) Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=422 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=15 GB) - (Type=12) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-04-23 22:07:57 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0011 465,76GB Running: Gmer-19357.exe; Driver: C:\Users\***\AppData\Local\Temp\kxldypow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2616] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77] .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2616] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77] .text ... * 2 .text C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe[2980] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77] .text C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe[2980] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77] .text ... * 2 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[3252] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77] .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[3252] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77] .text ... * 2 ---- Processes - GMER 2.1 ---- Process C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe (*** suspicious ***) @ C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [2980](2014-02-13 20:46:39) 0000000000f10000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076fc1a13 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076fc1a13 (not active ControlSet) ---- EOF - GMER 2.1 ---- |
24.04.2014, 06:23 | #2 |
/// the machine /// TB-Ausbilder | Weit über 100 PUPs etc. bei Malwarebytes hi,
__________________MBAM updaten, Quick Scan, Funde löschen lassen. Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
24.04.2014, 19:43 | #3 |
| Weit über 100 PUPs etc. bei Malwarebytes Hallo Schrauber,
__________________danke für Deine Hilfe! Hier also die gewünschten Logs: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 24.04.2014 Suchlauf-Zeit: 20:13:33 Logdatei: MBAM.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.24.07 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: *** Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 297298 Verstrichene Zeit: 41 Min, 56 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.202 - Bericht erstellt am 24/04/2014 um 20:18:05 # Aktualisiert 23/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : *** - ***-PC # Gestartet von : C:\Users\***\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\Partner Ordner Gelöscht : C:\Program Files (x86)\Softonic Ordner Gelöscht : C:\Users\***\AppData\Local\Temp\mt_ffx Ordner Gelöscht : C:\Users\***\AppData\Roaming\BabSolution Ordner Gelöscht : C:\Users\***\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\***\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\***\AppData\Roaming\pdfforge Datei Gelöscht : C:\Users\***\AppData\Local\Temp\Uninstall.exe Datei Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\invalidprefs.js Datei Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\5968d88b034b845 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E69D4A59-73DE-4E38-9FB3-740EC4D9060D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gelöscht : HKCU\Software\BabSolution Schlüssel Gelöscht : HKCU\Software\Delta Schlüssel Gelöscht : HKCU\Software\IGearSettings Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\Delta Schlüssel Gelöscht : HKLM\Software\Softonic ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs] -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js ] Zeile gelöscht : user_pref("extensions.Softonic.admin", false); Zeile gelöscht : user_pref("extensions.Softonic.aflt", "OC"); Zeile gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}"); Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "de"); Zeile gelöscht : user_pref("extensions.Softonic.dfltSrch", true); Zeile gelöscht : user_pref("extensions.Softonic.dnsErr", true); Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false); Zeile gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false); Zeile gelöscht : user_pref("extensions.Softonic.hmpg", true); Zeile gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=20ca48d400000000000074de2beaeff9"); Zeile gelöscht : user_pref("extensions.Softonic.id", "20ca48d400000000000074de2beaeff9"); Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "16026"); Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00621"); Zeile gelöscht : user_pref("extensions.Softonic.newTab", true); Zeile gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=20ca48d400000000000074de2beaeff9"); Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic"); Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic"); Zeile gelöscht : user_pref("extensions.Softonic.rvrt", "false"); Zeile gelöscht : user_pref("extensions.Softonic.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "opencandy2013"); Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=20ca48d400000000000074de2beaeff9&q="); Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.21.14"); Zeile gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.21.1414:03:01"); Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.21.14"); Zeile gelöscht : user_pref("extensions.delta.admin", false); Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst"); Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de"); Zeile gelöscht : user_pref("extensions.delta.excTlbr", false); Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true); Zeile gelöscht : user_pref("extensions.delta.id", "20ca48d400000000000000ffbb10c4d0"); Zeile gelöscht : user_pref("extensions.delta.instlDay", "15941"); Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst"); Zeile gelöscht : user_pref("extensions.delta.newTab", false); Zeile gelöscht : user_pref("extensions.delta.prdct", "delta"); Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta"); Zeile gelöscht : user_pref("extensions.delta.rvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", ""); Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6"); Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.69:59:04"); Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6"); Zeile gelöscht : user_pref("extensions.delta_i.babExt", ""); Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=121564&tsp=4984"); Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss"); [ Datei : C:\Users\Gastkonto\AppData\Roaming\Mozilla\Firefox\Profiles\s0v1dyf9.default\prefs.js ] ************************* AdwCleaner[R0].txt - [12353 octets] - [24/04/2014 20:15:02] AdwCleaner[S0].txt - [11581 octets] - [24/04/2014 20:18:05] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11642 octets] ########## [/CODE] Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by *** on 24.04.2014 at 20:22:36,11 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-807794254-139005778-1418515836-1000\Software\sweetim Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{1D6289B1-98DF-40A3-A61C-E9F912C40B47} ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{0983F971-5555-4092-BF5D-72803AA93D9A} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{21FEE3A6-39C9-4123-A7AC-D7B4AD4DCD99} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{32A590BA-F5C1-4325-806F-F9602BDC1D19} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{4EEE6F7A-F50A-4C2D-A1E8-E3C9C3F5316A} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{611565AF-E641-4405-86F7-908CF27104A4} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{6BD5F1AE-9F1C-4BA5-B988-25112AE432C7} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{A1BC52E0-5DA7-4975-A271-4AECACA01793} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{C55381F5-CA4A-4FD6-8D4B-17A6191F056B} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{D28DA445-B445-4FB3-83B4-BFBC6FABA55D} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{EC818EFF-700F-4ABC-B00D-4E01F6ED5A32} ~~~ FireFox Emptied folder: C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zn8jndgw.default\minidumps [396 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 24.04.2014 at 20:29:00,67 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Danke und Grüße Fuat Ach, das frische FRST FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-04-2014 Ran by *** (administrator) on ***-PC on 24-04-2014 20:40:12 Running from C:\Users\***\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\windows\system32\atiesrxx.exe (AMD) C:\windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Marvell Semiconductor, Inc.) C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe () C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated) HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-11-24] (Lenovo) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2011-11-24] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-11-24] (Lenovo(beijing) Limited) HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation) HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1238528 2007-08-29] (Marvell Semiconductor, Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.) HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.) HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2011-11-24] (Lenovo) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-807794254-139005778-1418515836-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-807794254-139005778-1418515836-1000\...\Run: [Amazon Cloud Player] => C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3140608 2014-01-14] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101753.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Add to Amazon Wish List Button - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\Extensions\amznUWL2@amazon.com.xpi [2012-12-31] FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-21] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\***\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-11-01] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-02] (Avira Operations GmbH & Co. KG) R3 SPUVCbv; C:\Windows\System32\Drivers\usbvideo.sys [185344 2013-07-12] (Microsoft Corporation) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-01-10] (Anchorfree Inc.) U3 BcmSqlStartupSvc; U2 CLKMSVC10_3A60B698; U2 CLKMSVC10_C3B3B687; U2 DriverService; U2 iATAgentService; U2 idealife Update Service; U3 IGRS; U2 IviRegMgr; U2 nvUpdatusService; U2 Oasis2Service; U2 PCCarerService; U2 ReadyComm.DirectRouter; U2 RichVideo; U2 RtLedService; U2 SeaPort; U2 SoftwareService; U3 SQLWriter; U2 Stereo Service; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-24 20:40 - 2014-04-24 20:40 - 00011915 _____ () C:\Users\***\Desktop\FRST.txt 2014-04-24 20:40 - 2014-04-24 20:40 - 00000000 ____D () C:\Users\***\Desktop\FRST-OlderVersion 2014-04-24 20:29 - 2014-04-24 20:35 - 00002129 _____ () C:\Users\***\Desktop\JRT.txt 2014-04-24 20:22 - 2014-04-24 20:22 - 00000000 ____D () C:\windows\ERUNT 2014-04-24 20:20 - 2014-04-24 20:20 - 00011783 _____ () C:\Users\***\Desktop\AdwCleaner[S0].txt 2014-04-24 20:14 - 2014-04-24 20:18 - 00000000 ____D () C:\AdwCleaner 2014-04-24 20:13 - 2014-04-24 20:37 - 00001144 _____ () C:\Users\***\Desktop\MBAM.txt 2014-04-24 19:34 - 2014-04-24 19:34 - 01016261 _____ (Thisisu) C:\Users\***\Desktop\JRT.exe 2014-04-24 19:32 - 2014-04-24 19:33 - 00000000 ____D () C:\Users\***\Desktop\Virenbekämpfung 2014-04-24 19:32 - 2014-04-24 19:32 - 01365865 _____ () C:\Users\***\Desktop\adwcleaner.exe 2014-04-23 21:56 - 2014-04-23 21:56 - 553133490 _____ () C:\windows\MEMORY.DMP 2014-04-23 21:56 - 2014-04-23 21:56 - 00262144 _____ () C:\windows\Minidump\042314-29640-01.dmp 2014-04-23 21:56 - 2014-04-23 21:56 - 00000000 ____D () C:\windows\Minidump 2014-04-23 21:34 - 2014-04-24 20:40 - 00000000 ____D () C:\FRST 2014-04-23 21:33 - 2014-04-23 21:33 - 00000000 _____ () C:\Users\***\defogger_reenable 2014-04-23 21:13 - 2014-04-23 21:13 - 00380416 _____ () C:\Users\***\Desktop\Gmer-19357.exe 2014-04-23 21:12 - 2014-04-24 20:40 - 02061824 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe 2014-04-23 21:12 - 2014-04-23 21:12 - 00050477 _____ () C:\Users\***\Desktop\Defogger.exe 2014-04-23 20:51 - 2014-04-24 19:30 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-23 20:51 - 2014-04-23 20:51 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-23 20:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-04-23 20:50 - 2014-04-23 20:51 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\***\Desktop\mbam-setup-2.0.1.1004.exe 2014-04-10 06:13 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-04-10 06:13 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-04-10 06:13 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-04-10 06:13 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll 2014-04-10 06:12 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll 2014-04-10 06:12 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll 2014-04-10 06:12 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe 2014-04-10 06:12 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll 2014-04-10 06:12 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe 2014-04-10 06:12 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe 2014-04-10 06:12 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys 2014-04-10 06:12 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys 2014-04-10 06:12 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys 2014-04-10 06:12 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll 2014-04-10 06:12 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll 2014-04-10 06:12 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys 2014-04-09 19:01 - 2014-04-09 19:01 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_deu(1).exe 2014-04-01 18:09 - 2014-04-01 18:10 - 00006011 _____ () C:\Users\***\Desktop\Themenvorschläge zur Fortbildungsprüfung.odt 2014-03-29 13:19 - 2014-04-23 21:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-04-24 20:40 - 2014-04-24 20:40 - 00011915 _____ () C:\Users\***\Desktop\FRST.txt 2014-04-24 20:40 - 2014-04-24 20:40 - 00000000 ____D () C:\Users\***\Desktop\FRST-OlderVersion 2014-04-24 20:40 - 2014-04-23 21:34 - 00000000 ____D () C:\FRST 2014-04-24 20:40 - 2014-04-23 21:12 - 02061824 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe 2014-04-24 20:37 - 2014-04-24 20:13 - 00001144 _____ () C:\Users\***\Desktop\MBAM.txt 2014-04-24 20:35 - 2014-04-24 20:29 - 00002129 _____ () C:\Users\***\Desktop\JRT.txt 2014-04-24 20:30 - 2012-04-09 09:23 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-24 20:28 - 2009-07-14 06:45 - 00021072 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-24 20:28 - 2009-07-14 06:45 - 00021072 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-24 20:26 - 2011-11-24 07:09 - 00700134 _____ () C:\windows\system32\perfh007.dat 2014-04-24 20:26 - 2011-11-24 07:09 - 00149984 _____ () C:\windows\system32\perfc007.dat 2014-04-24 20:26 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI 2014-04-24 20:22 - 2014-04-24 20:22 - 00000000 ____D () C:\windows\ERUNT 2014-04-24 20:20 - 2014-04-24 20:20 - 00011783 _____ () C:\Users\***\Desktop\AdwCleaner[S0].txt 2014-04-24 20:19 - 2011-11-24 16:11 - 00492463 _____ () C:\windows\system32\fastboot.set 2014-04-24 20:19 - 2011-11-24 16:04 - 03397254 _____ () C:\FaceProv.log 2014-04-24 20:19 - 2011-11-24 16:04 - 00000000 ____D () C:\ProgramData\VeriFace 2014-04-24 20:19 - 2011-11-24 15:56 - 00001120 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-24 20:19 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-04-24 20:19 - 2009-07-14 06:51 - 00115815 _____ () C:\windows\setupact.log 2014-04-24 20:18 - 2014-04-24 20:14 - 00000000 ____D () C:\AdwCleaner 2014-04-24 20:18 - 2011-11-24 15:23 - 01470027 _____ () C:\windows\WindowsUpdate.log 2014-04-24 19:43 - 2011-11-24 15:57 - 00001124 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-24 19:34 - 2014-04-24 19:34 - 01016261 _____ (Thisisu) C:\Users\***\Desktop\JRT.exe 2014-04-24 19:33 - 2014-04-24 19:32 - 00000000 ____D () C:\Users\***\Desktop\Virenbekämpfung 2014-04-24 19:32 - 2014-04-24 19:32 - 01365865 _____ () C:\Users\***\Desktop\adwcleaner.exe 2014-04-24 19:30 - 2014-04-23 20:51 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-23 21:56 - 2014-04-23 21:56 - 553133490 _____ () C:\windows\MEMORY.DMP 2014-04-23 21:56 - 2014-04-23 21:56 - 00262144 _____ () C:\windows\Minidump\042314-29640-01.dmp 2014-04-23 21:56 - 2014-04-23 21:56 - 00000000 ____D () C:\windows\Minidump 2014-04-23 21:56 - 2010-11-21 05:47 - 00224666 _____ () C:\windows\PFRO.log 2014-04-23 21:55 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\security 2014-04-23 21:35 - 2014-03-29 13:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-23 21:33 - 2014-04-23 21:33 - 00000000 _____ () C:\Users\***\defogger_reenable 2014-04-23 21:33 - 2012-02-17 18:35 - 00000000 ____D () C:\Users\*** 2014-04-23 21:13 - 2014-04-23 21:13 - 00380416 _____ () C:\Users\***\Desktop\Gmer-19357.exe 2014-04-23 21:12 - 2014-04-23 21:12 - 00050477 _____ () C:\Users\***\Desktop\Defogger.exe 2014-04-23 20:51 - 2014-04-23 20:51 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-23 20:50 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\***\Desktop\mbam-setup-2.0.1.1004.exe 2014-04-23 20:51 - 2012-10-08 09:25 - 00000000 ____D () C:\Users\***\AppData\Roaming\Malwarebytes 2014-04-23 20:51 - 2012-10-08 09:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-21 19:53 - 2013-12-27 12:33 - 00000000 ____D () C:\Users\***\Desktop\Handy 2014-04-18 13:14 - 2009-07-14 07:08 - 00032632 _____ () C:\windows\Tasks\SCHEDLGU.TXT 2014-04-10 06:16 - 2013-08-13 19:37 - 00000000 ____D () C:\windows\system32\MRT 2014-04-10 06:14 - 2012-08-06 16:30 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-04-09 19:09 - 2012-05-22 21:46 - 00000000 ____D () C:\Users\***\AppData\Local\Adobe 2014-04-09 19:04 - 2012-04-09 09:23 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-04-09 19:04 - 2012-04-09 09:23 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-04-09 19:04 - 2012-02-17 18:52 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-09 19:01 - 2014-04-09 19:01 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_deu(1).exe 2014-04-03 19:58 - 2013-08-07 17:54 - 00000000 ____D () C:\Users\***\Desktop\Bilder130807 2014-04-03 09:51 - 2014-04-23 20:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-23 20:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2012-10-08 09:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-04-01 18:13 - 2012-07-18 11:33 - 00000000 ____D () C:\Users\***\AppData\Roaming\SoftGrid Client 2014-04-01 18:10 - 2014-04-01 18:09 - 00006011 _____ () C:\Users\***\Desktop\Themenvorschläge zur Fortbildungsprüfung.odt 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe 2014-03-31 03:16 - 2014-04-10 06:13 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 06:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 06:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 06:13 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-03-30 10:01 - 2012-10-08 09:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 12:38 - 2011-11-24 15:57 - 00004120 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-29 12:38 - 2011-11-24 15:57 - 00003868 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-27 16:55 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\NDF Some content of TEMP: ==================== C:\Users\***\AppData\Local\Temp\AskSLib.dll C:\Users\***\AppData\Local\Temp\avgnt.exe C:\Users\***\AppData\Local\Temp\avguidx.dll C:\Users\***\AppData\Local\Temp\CommonInstaller.exe C:\Users\***\AppData\Local\Temp\contentDATs.exe C:\Users\***\AppData\Local\Temp\MachineIdCreator.exe C:\Users\***\AppData\Local\Temp\oi_{292C31A9-1BA2-4016-8710-0657D1C588A7}.exe C:\Users\***\AppData\Local\Temp\pdf24-creator-update.exe C:\Users\***\AppData\Local\Temp\Quarantine.exe C:\Users\***\AppData\Local\Temp\SecurityScan_Release.exe C:\Users\***\AppData\Local\Temp\ToolbarInstaller.exe C:\Users\***\AppData\Local\Temp\uninst1.exe C:\Users\Gastkonto\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-24 16:22 ==================== End Of Log ============================ --- --- --- --- --- --- |
25.04.2014, 18:46 | #4 |
/// the machine /// TB-Ausbilder | Weit über 100 PUPs etc. bei MalwarebytesESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.04.2014, 19:05 | #5 |
| Weit über 100 PUPs etc. bei Malwarebytes Hallo Schrauber, ich glaube/hoffe, dass es ganz gut aussieht.... Was meinst Du??? Gruß und Dank! Fuat Hier sind die Logs Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=a91af36fd4c6f7428a764f5ed98464cf # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-10-08 11:02:52 # local_time=2012-10-08 01:02:52 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1792 16777215 100 0 20190713 20190713 0 0 # compatibility_mode=5893 16776573 100 94 266545 101314195 0 0 # compatibility_mode=8192 67108863 100 0 132 132 0 0 # scanned=128365 # found=1 # cleaned=0 # scan_time=9827 C:\Users\***\Downloads\SoftonicDownloader_fuer_indiana-jones-and-the-last-crusade.exe Variante von Win32/SoftonicDownloader.D Anwendung (Säubern nicht möglich) 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=a91af36fd4c6f7428a764f5ed98464cf # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-10-08 01:53:23 # local_time=2012-10-08 03:53:23 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1792 16777215 100 0 20200822 20200822 0 0 # compatibility_mode=5893 16776573 100 94 276654 101324304 0 0 # compatibility_mode=8192 67108863 100 0 10241 10241 0 0 # scanned=130052 # found=1 # cleaned=1 # scan_time=9949 C:\Users\***\Downloads\SoftonicDownloader_fuer_indiana-jones-and-the-last-crusade.exe Variante von Win32/SoftonicDownloader.D Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert) 00000000000000000000000000000000 C ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a91af36fd4c6f7428a764f5ed98464cf # engine=17817 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-10 04:12:56 # local_time=2014-04-10 06:12:56 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 96 40392 142866196 109248 0 # compatibility_mode=5893 16776574 100 94 766777 148733026 0 0 # scanned=191576 # found=0 # cleaned=0 # scan_time=40125 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a91af36fd4c6f7428a764f5ed98464cf # engine=18042 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-26 05:15:07 # local_time=2014-04-26 07:15:07 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 96 35489 144295527 28252 0 # compatibility_mode=5893 16776573 100 94 87422 150162357 0 0 # scanned=191788 # found=0 # cleaned=0 # scan_time=15279 Code:
ATTFilter Results of screen317's Security Check version 0.99.82 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 13.0.0.182 Adobe Reader 10.1.9 Adobe Reader out of Date! Mozilla Firefox (28.0) Google Chrome 7.0.517.43 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-04-2014 Ran by *** (administrator) on ***-PC on 26-04-2014 19:49:10 Running from C:\Users\***\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\windows\system32\atiesrxx.exe (AMD) C:\windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Marvell Semiconductor, Inc.) C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe () C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated) HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-11-24] (Lenovo) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2011-11-24] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-11-24] (Lenovo(beijing) Limited) HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation) HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1238528 2007-08-29] (Marvell Semiconductor, Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.) HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.) HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2011-11-24] (Lenovo) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-807794254-139005778-1418515836-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-807794254-139005778-1418515836-1000\...\Run: [Amazon Cloud Player] => C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3140608 2014-01-14] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101753.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Add to Amazon Wish List Button - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\Extensions\amznUWL2@amazon.com.xpi [2012-12-31] FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-21] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\***\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-11-01] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG) S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-02] (Avira Operations GmbH & Co. KG) R3 SPUVCbv; C:\Windows\System32\Drivers\usbvideo.sys [185344 2013-07-12] (Microsoft Corporation) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-01-10] (Anchorfree Inc.) U3 BcmSqlStartupSvc; U2 CLKMSVC10_3A60B698; U2 CLKMSVC10_C3B3B687; U2 DriverService; U2 iATAgentService; U2 idealife Update Service; U3 IGRS; U2 IviRegMgr; U2 nvUpdatusService; U2 Oasis2Service; U2 PCCarerService; U2 ReadyComm.DirectRouter; U2 RichVideo; U2 RtLedService; U2 SeaPort; U2 SoftwareService; U3 SQLWriter; U2 Stereo Service; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-26 19:42 - 2014-04-26 19:42 - 00000822 _____ () C:\Users\***\Desktop\checkup.txt 2014-04-26 14:59 - 2014-04-26 14:59 - 00855379 _____ () C:\Users\***\Desktop\SecurityCheck.exe 2014-04-26 14:58 - 2014-04-26 14:58 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_enu.exe 2014-04-24 20:40 - 2014-04-26 19:49 - 00012002 _____ () C:\Users\***\Desktop\FRST.txt 2014-04-24 20:40 - 2014-04-24 20:40 - 00000000 ____D () C:\Users\***\Desktop\FRST-OlderVersion 2014-04-24 20:29 - 2014-04-24 20:35 - 00002129 _____ () C:\Users\***\Desktop\JRT.txt 2014-04-24 20:22 - 2014-04-24 20:22 - 00000000 ____D () C:\windows\ERUNT 2014-04-24 20:20 - 2014-04-24 20:20 - 00011783 _____ () C:\Users\***\Desktop\AdwCleaner[S0].txt 2014-04-24 20:14 - 2014-04-24 20:18 - 00000000 ____D () C:\AdwCleaner 2014-04-24 20:13 - 2014-04-24 20:37 - 00001144 _____ () C:\Users\***\Desktop\MBAM.txt 2014-04-24 19:34 - 2014-04-24 19:34 - 01016261 _____ (Thisisu) C:\Users\***\Desktop\JRT.exe 2014-04-24 19:32 - 2014-04-24 19:33 - 00000000 ____D () C:\Users\***\Desktop\Virenbekämpfung 2014-04-24 19:32 - 2014-04-24 19:32 - 01365865 _____ () C:\Users\***\Desktop\adwcleaner.exe 2014-04-23 21:56 - 2014-04-23 21:56 - 553133490 _____ () C:\windows\MEMORY.DMP 2014-04-23 21:56 - 2014-04-23 21:56 - 00262144 _____ () C:\windows\Minidump\042314-29640-01.dmp 2014-04-23 21:56 - 2014-04-23 21:56 - 00000000 ____D () C:\windows\Minidump 2014-04-23 21:34 - 2014-04-26 19:49 - 00000000 ____D () C:\FRST 2014-04-23 21:33 - 2014-04-23 21:33 - 00000000 _____ () C:\Users\***\defogger_reenable 2014-04-23 21:13 - 2014-04-23 21:13 - 00380416 _____ () C:\Users\***\Desktop\Gmer-19357.exe 2014-04-23 21:12 - 2014-04-24 20:40 - 02061824 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe 2014-04-23 21:12 - 2014-04-23 21:12 - 00050477 _____ () C:\Users\***\Desktop\Defogger.exe 2014-04-23 20:51 - 2014-04-24 19:30 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-23 20:51 - 2014-04-23 20:51 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-23 20:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-04-23 20:50 - 2014-04-23 20:51 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\***\Desktop\mbam-setup-2.0.1.1004.exe 2014-04-10 06:13 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-04-10 06:13 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-04-10 06:13 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-04-10 06:13 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll 2014-04-10 06:12 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll 2014-04-10 06:12 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll 2014-04-10 06:12 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll 2014-04-10 06:12 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe 2014-04-10 06:12 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll 2014-04-10 06:12 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe 2014-04-10 06:12 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe 2014-04-10 06:12 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys 2014-04-10 06:12 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys 2014-04-10 06:12 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys 2014-04-10 06:12 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll 2014-04-10 06:12 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll 2014-04-10 06:12 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys 2014-04-09 19:01 - 2014-04-09 19:01 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_deu(1).exe 2014-04-01 18:09 - 2014-04-01 18:10 - 00006011 _____ () C:\Users\***\Desktop\Themenvorschläge zur Fortbildungsprüfung.odt 2014-03-29 13:19 - 2014-04-23 21:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-04-26 19:49 - 2014-04-24 20:40 - 00012002 _____ () C:\Users\***\Desktop\FRST.txt 2014-04-26 19:49 - 2014-04-23 21:34 - 00000000 ____D () C:\FRST 2014-04-26 19:43 - 2011-11-24 15:57 - 00001124 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-26 19:42 - 2014-04-26 19:42 - 00000822 _____ () C:\Users\***\Desktop\checkup.txt 2014-04-26 19:30 - 2012-04-09 09:23 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-26 19:21 - 2011-11-24 15:23 - 01559488 _____ () C:\windows\WindowsUpdate.log 2014-04-26 14:59 - 2014-04-26 14:59 - 00855379 _____ () C:\Users\***\Desktop\SecurityCheck.exe 2014-04-26 14:58 - 2014-04-26 14:58 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_enu.exe 2014-04-26 14:52 - 2009-07-14 06:45 - 00021072 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-26 14:52 - 2009-07-14 06:45 - 00021072 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-26 14:49 - 2011-11-24 07:09 - 00700134 _____ () C:\windows\system32\perfh007.dat 2014-04-26 14:49 - 2011-11-24 07:09 - 00149984 _____ () C:\windows\system32\perfc007.dat 2014-04-26 14:49 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI 2014-04-26 14:45 - 2011-11-24 16:11 - 00479795 _____ () C:\windows\system32\fastboot.set 2014-04-26 14:45 - 2011-11-24 16:04 - 03411487 _____ () C:\FaceProv.log 2014-04-26 14:45 - 2011-11-24 16:04 - 00000000 ____D () C:\ProgramData\VeriFace 2014-04-26 14:45 - 2011-11-24 15:56 - 00001120 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-26 14:44 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-04-26 14:44 - 2009-07-14 06:51 - 00116039 _____ () C:\windows\setupact.log 2014-04-24 20:40 - 2014-04-24 20:40 - 00000000 ____D () C:\Users\***\Desktop\FRST-OlderVersion 2014-04-24 20:40 - 2014-04-23 21:12 - 02061824 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe 2014-04-24 20:37 - 2014-04-24 20:13 - 00001144 _____ () C:\Users\***\Desktop\MBAM.txt 2014-04-24 20:35 - 2014-04-24 20:29 - 00002129 _____ () C:\Users\***\Desktop\JRT.txt 2014-04-24 20:22 - 2014-04-24 20:22 - 00000000 ____D () C:\windows\ERUNT 2014-04-24 20:20 - 2014-04-24 20:20 - 00011783 _____ () C:\Users\***\Desktop\AdwCleaner[S0].txt 2014-04-24 20:18 - 2014-04-24 20:14 - 00000000 ____D () C:\AdwCleaner 2014-04-24 19:34 - 2014-04-24 19:34 - 01016261 _____ (Thisisu) C:\Users\***\Desktop\JRT.exe 2014-04-24 19:33 - 2014-04-24 19:32 - 00000000 ____D () C:\Users\***\Desktop\Virenbekämpfung 2014-04-24 19:32 - 2014-04-24 19:32 - 01365865 _____ () C:\Users\***\Desktop\adwcleaner.exe 2014-04-24 19:30 - 2014-04-23 20:51 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-23 21:56 - 2014-04-23 21:56 - 553133490 _____ () C:\windows\MEMORY.DMP 2014-04-23 21:56 - 2014-04-23 21:56 - 00262144 _____ () C:\windows\Minidump\042314-29640-01.dmp 2014-04-23 21:56 - 2014-04-23 21:56 - 00000000 ____D () C:\windows\Minidump 2014-04-23 21:56 - 2010-11-21 05:47 - 00224666 _____ () C:\windows\PFRO.log 2014-04-23 21:55 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\security 2014-04-23 21:35 - 2014-03-29 13:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-23 21:33 - 2014-04-23 21:33 - 00000000 _____ () C:\Users\***\defogger_reenable 2014-04-23 21:33 - 2012-02-17 18:35 - 00000000 ____D () C:\Users\*** 2014-04-23 21:13 - 2014-04-23 21:13 - 00380416 _____ () C:\Users\***\Desktop\Gmer-19357.exe 2014-04-23 21:12 - 2014-04-23 21:12 - 00050477 _____ () C:\Users\***\Desktop\Defogger.exe 2014-04-23 20:51 - 2014-04-23 20:51 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-23 20:51 - 2014-04-23 20:50 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\***\Desktop\mbam-setup-2.0.1.1004.exe 2014-04-23 20:51 - 2012-10-08 09:25 - 00000000 ____D () C:\Users\***\AppData\Roaming\Malwarebytes 2014-04-23 20:51 - 2012-10-08 09:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-21 19:53 - 2013-12-27 12:33 - 00000000 ____D () C:\Users\***\Desktop\Handy 2014-04-18 13:14 - 2009-07-14 07:08 - 00032632 _____ () C:\windows\Tasks\SCHEDLGU.TXT 2014-04-10 06:16 - 2013-08-13 19:37 - 00000000 ____D () C:\windows\system32\MRT 2014-04-10 06:14 - 2012-08-06 16:30 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-04-09 19:09 - 2012-05-22 21:46 - 00000000 ____D () C:\Users\***\AppData\Local\Adobe 2014-04-09 19:04 - 2012-04-09 09:23 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-04-09 19:04 - 2012-04-09 09:23 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-04-09 19:04 - 2012-02-17 18:52 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-09 19:01 - 2014-04-09 19:01 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_deu(1).exe 2014-04-03 19:58 - 2013-08-07 17:54 - 00000000 ____D () C:\Users\***\Desktop\Bilder130807 2014-04-03 09:51 - 2014-04-23 20:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-23 20:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2012-10-08 09:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-04-01 18:13 - 2012-07-18 11:33 - 00000000 ____D () C:\Users\***\AppData\Roaming\SoftGrid Client 2014-04-01 18:10 - 2014-04-01 18:09 - 00006011 _____ () C:\Users\***\Desktop\Themenvorschläge zur Fortbildungsprüfung.odt 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe 2014-03-31 03:16 - 2014-04-10 06:13 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 06:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 06:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 06:13 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-03-30 10:01 - 2012-10-08 09:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 12:38 - 2011-11-24 15:57 - 00004120 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-29 12:38 - 2011-11-24 15:57 - 00003868 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-27 16:55 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\NDF Some content of TEMP: ==================== C:\Users\***\AppData\Local\Temp\AskSLib.dll C:\Users\***\AppData\Local\Temp\avgnt.exe C:\Users\***\AppData\Local\Temp\avguidx.dll C:\Users\***\AppData\Local\Temp\CommonInstaller.exe C:\Users\***\AppData\Local\Temp\contentDATs.exe C:\Users\***\AppData\Local\Temp\MachineIdCreator.exe C:\Users\***\AppData\Local\Temp\oi_{292C31A9-1BA2-4016-8710-0657D1C588A7}.exe C:\Users\***\AppData\Local\Temp\pdf24-creator-update.exe C:\Users\***\AppData\Local\Temp\Quarantine.exe C:\Users\***\AppData\Local\Temp\SecurityScan_Release.exe C:\Users\***\AppData\Local\Temp\ToolbarInstaller.exe C:\Users\***\AppData\Local\Temp\uninst1.exe C:\Users\Gastkonto\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-24 16:22 ==================== End Of Log ============================ --- --- --- --- --- --- |
27.04.2014, 18:13 | #6 |
/// the machine /// TB-Ausbilder | Weit über 100 PUPs etc. bei Malwarebytes Adobe updaten. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Weit über 100 PUPs etc. bei Malwarebytes |
29.04.2014, 19:00 | #7 |
| Weit über 100 PUPs etc. bei Malwarebytes Vielen tausend Dank für Deine Hilfe!! Hab ja echt gedacht, dass das viel Arbeit wird, aber es ging je echt fix... War wohl nix schlimmes drauf.... Viele Grüße und danke auch für die Tipps! Fuat |
30.04.2014, 23:37 | #8 |
/// the machine /// TB-Ausbilder | Weit über 100 PUPs etc. bei Malwarebytes Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Weit über 100 PUPs etc. bei Malwarebytes |
device driver, downloader, dvdvideosoft ltd., entfernen, flash player, helper, hotspot, install.exe, installation, internet explorer, launch, pup.optional.babsolution.a, pup.optional.babylon.a, pup.optional.datamngr.a, pup.optional.delta.a, pup.optional.opencandy, pup.optional.opencandy.a, pup.optional.softonic.a, siteadvisor, software, svchost.exe, usbvideo.sys, win32/softonicdownloader.d, windows |