![]() |
|
Plagegeister aller Art und deren Bekämpfung: nach firefox update / portaldosites in jedem neuen tapWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() nach firefox update / portaldosites in jedem neuen tapESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #2 |
| ![]() nach firefox update / portaldosites in jedem neuen tap![]() ![]() ![]() ![]() ![]() ![]() und hier die gewünschten Logfiles. Eset: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=92e2e47536e5a44ab26633612dce0cd2 # engine=18453 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-05-29 08:54:59 # local_time=2014-05-29 10:54:59 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 17752278 152983549 0 0 # scanned=289056 # found=1 # cleaned=0 # scan_time=4701 sh=BD7191934AD2B1159ABFD20C26A0EF8E870015EC ft=1 fh=3d9a72fb821c127c vn="Variante von Win32/Toolbar.Conduit.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Spiele (Programme)\Farm_Up\Farm_Up.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.83 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` AVG AntiVirus Free Edition 2014 Antivirus out of date! `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 12.0.0.43 Flash Player out of Date! Adobe Reader XI Mozilla Firefox (29.0.1) Mozilla Thunderbird (24.5.0) ````````Process Check: objlist.exe by Laurent```````` AVG avgwdsvc.exe Online Games Manager ogmservice.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02 Ran by Martina (administrator) on MARTINA-PC on 29-05-2014 11:16:33 Running from C:\Users\Martina\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (RealNetworks, Inc.) C:\Program Files (x86)\Online Games Manager\ogmservice.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe (Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.) HKU\S-1-5-21-690356491-1174369309-2236414189-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {FC739C94-F44E-4EBA-9B70-87AB45DFD999} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS SearchScopes: HKLM-x32 - {FC739C94-F44E-4EBA-9B70-87AB45DFD999} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Tcpip\..\Interfaces\{0F245E3B-7DC2-4299-BED7-9089C5A77AA1}: [NameServer]62.109.121.2 62.109.121.1 Tcpip\..\Interfaces\{441E04CD-6116-4027-919E-D2D34375EACE}: [NameServer]8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 FireFox: ======== FF ProfilePath: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default FF Homepage: about:blank FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} [2013-12-25] FF Extension: Noia 4 Theme Manager - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\Noia4Options@ArisT2.xpi [2013-11-03] FF Extension: Noia Fox options - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\NoiaFoxoption@davidvincent.tld.xpi [2013-11-03] FF Extension: Personas Plus - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\personas@christopher.beard.xpi [2013-11-03] FF Extension: No Name - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\savedpasswordeditor@daniel.dawson.xpi [2013-11-03] FF Extension: AniWeather - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi [2013-11-03] FF Extension: KOLOBOK Smiles - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{5CEFD22F-9A9E-4544-9BFC-C4F2FBCA87D6}.xpi [2013-11-03] FF Extension: eCleaner - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi [2013-11-03] FF Extension: Ecosia - The search engine that plants trees - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2013-11-03] FF Extension: Adblock Plus - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-03] FF Extension: BetterPrivacy - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-12-09] FF Extension: Extended Statusbar - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d}.xpi [2013-11-03] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION ==================== Services (Whitelisted) ================= S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.) R2 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [581568 2014-03-27] (RealNetworks, Inc.) ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-11-16] () R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-11-16] () S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 DIRECTIO; \??\UNC\srv1c027.wds8.intern\reminst\Test\BitPro64\DirectIo.sys [X] S2 sbapifs; system32\DRIVERS\sbapifs.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-29 11:16 - 2014-05-29 11:16 - 00009341 _____ () C:\Users\Martina\Desktop\FRST.txt 2014-05-29 11:15 - 2014-05-29 11:15 - 00000835 _____ () C:\Users\Martina\Desktop\checkup.txt 2014-05-29 11:04 - 2014-05-29 11:04 - 00854367 _____ () C:\Users\Martina\Desktop\SecurityCheck.exe 2014-05-26 12:12 - 2014-05-26 12:12 - 00000000 ____D () C:\BigFishCache 2014-05-26 10:46 - 2014-05-26 10:46 - 00000000 ____D () C:\Users\Martina\Desktop\FRST-OlderVersion 2014-05-26 10:32 - 2014-05-26 10:32 - 00001936 _____ () C:\Users\Martina\Malw. Suchlauf Protokoll.txt 2014-05-26 10:24 - 2014-05-26 10:28 - 00000000 ____D () C:\AdwCleaner 2014-05-26 10:06 - 2014-05-26 10:29 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-26 10:06 - 2014-05-26 10:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-26 10:06 - 2014-05-26 10:06 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-26 10:06 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-26 10:06 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-26 10:06 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-22 22:23 - 2014-05-22 22:23 - 00001800 _____ () C:\Users\Public\Desktop\ANNO 1503.lnk 2014-05-22 22:20 - 2014-05-22 22:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ANNO 1503 GOLD 2014-05-21 23:43 - 2014-05-21 23:43 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\cerasus.media 2014-05-21 23:43 - 2014-05-21 23:43 - 00000000 ____D () C:\ProgramData\cerasus.media 2014-05-21 23:42 - 2014-05-21 23:42 - 00000961 _____ () C:\Users\Public\Desktop\MahJongg - Ancient Mayas.lnk 2014-05-21 23:42 - 2014-05-21 23:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\freundin-Games 2014-05-21 09:32 - 2014-05-21 09:43 - 00000000 ____D () C:\Qoobox 2014-05-21 09:32 - 2014-05-21 09:42 - 00000000 ____D () C:\Windows\erdnt 2014-05-21 09:32 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-05-21 09:32 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-05-21 09:32 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-05-21 09:32 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-05-21 09:32 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-05-21 09:32 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-05-21 09:32 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-05-21 09:32 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-05-20 10:23 - 2014-05-29 11:16 - 00000000 ____D () C:\Users\Martina\Desktop\Neuer Ordner 2014-05-20 09:52 - 2014-05-29 11:16 - 00000000 ____D () C:\FRST 2014-05-20 09:51 - 2014-05-26 10:46 - 02066944 _____ (Farbar) C:\Users\Martina\Desktop\FRST64.exe 2014-05-20 07:38 - 2014-05-20 07:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-17 15:52 - 2014-05-17 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tradewinds Caravans 2014-05-16 20:03 - 2014-05-16 20:03 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Farm Up 2014-05-16 20:03 - 2014-05-16 20:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Farm Up 2014-05-16 19:48 - 2014-05-16 19:48 - 00001743 _____ () C:\Users\Public\Desktop\The Snow Fable.lnk 2014-05-16 19:48 - 2014-05-16 19:48 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Snow Fable 2014-05-16 19:48 - 2014-05-16 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Snow Fable 2014-05-15 18:42 - 2014-05-15 18:42 - 00001888 _____ () C:\Users\Martina\Desktop\Mystika 2 - The Sanctuary.lnk 2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\unikgame 2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mystika 2 - The Sanctuary 2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mystika 2 - The Sanctuary 2014-05-14 23:24 - 2014-05-15 00:39 - 00000000 ____D () C:\Users\Martina\Documents\Big Bang West 2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys 2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys 2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys 2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys 2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys 2014-05-13 00:36 - 2014-05-13 00:36 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\GameInvest 2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Zellians - Kingdom Builder 2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Zellians - Kingdom Builder 2014-05-11 09:46 - 2014-05-11 09:46 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Forgotten Books - The Enchanted Crown Collectors Edition 2014-05-11 09:46 - 2014-05-11 09:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Forgotten Books - The Enchanted Crown Collectors Edition 2014-05-07 13:01 - 2014-05-07 13:01 - 00017047 _____ () C:\Users\Martina\Documents\Mietvertrag Wohnungsbörse.odt 2014-05-04 16:54 - 2014-05-04 16:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-05-03 08:27 - 2014-05-03 08:30 - 00000000 ____D () C:\ProgramData\Emberwind 2014-05-03 08:25 - 2014-05-03 08:25 - 00419840 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-05-03 08:25 - 2014-05-03 08:25 - 00413696 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2014-05-03 08:25 - 2014-05-03 08:25 - 00133632 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-05-03 08:25 - 2014-05-03 08:25 - 00110592 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2014-05-03 08:25 - 2014-05-03 08:25 - 00000000 ____D () C:\Program Files (x86)\OpenAL 2014-05-02 12:23 - 2014-05-02 12:23 - 00000000 ____D () C:\ProgramData\Magic-Heroes 2014-05-02 12:06 - 2014-05-02 12:06 - 00001923 _____ () C:\Users\Public\Desktop\Magic Heroes - Save Our Park.lnk 2014-05-02 12:06 - 2014-05-02 12:06 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Magic Heroes - Save Our Park 2014-05-02 12:06 - 2014-05-02 12:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Heroes - Save Our Park 2014-05-01 13:19 - 2014-05-03 08:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zylom 2014-05-01 13:19 - 2014-05-03 08:34 - 00000000 ____D () C:\Program Files (x86)\RealArcade 2014-04-30 18:55 - 2014-04-30 18:55 - 00000000 ____D () C:\ProgramData\PlayFirst 2014-04-30 18:55 - 2014-04-30 18:55 - 00000000 ____D () C:\Program Files (x86)\Online Games Manager 2014-04-30 18:52 - 2014-04-30 18:52 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\WinRAR ==================== One Month Modified Files and Folders ======= 2014-05-29 11:16 - 2014-05-29 11:16 - 00009341 _____ () C:\Users\Martina\Desktop\FRST.txt 2014-05-29 11:16 - 2014-05-20 10:23 - 00000000 ____D () C:\Users\Martina\Desktop\Neuer Ordner 2014-05-29 11:16 - 2014-05-20 09:52 - 00000000 ____D () C:\FRST 2014-05-29 11:15 - 2014-05-29 11:15 - 00000835 _____ () C:\Users\Martina\Desktop\checkup.txt 2014-05-29 11:04 - 2014-05-29 11:04 - 00854367 _____ () C:\Users\Martina\Desktop\SecurityCheck.exe 2014-05-29 09:20 - 2013-11-03 22:26 - 00000000 ____D () C:\ProgramData\MFAData 2014-05-29 08:46 - 2013-11-03 20:32 - 01561723 _____ () C:\Windows\WindowsUpdate.log 2014-05-29 07:46 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-29 07:46 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-29 07:43 - 2011-04-12 09:43 - 00698688 _____ () C:\Windows\system32\perfh007.dat 2014-05-29 07:43 - 2011-04-12 09:43 - 00148828 _____ () C:\Windows\system32\perfc007.dat 2014-05-29 07:43 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-29 07:39 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-29 07:39 - 2009-07-14 06:51 - 00074431 _____ () C:\Windows\setupact.log 2014-05-26 12:12 - 2014-05-26 12:12 - 00000000 ____D () C:\BigFishCache 2014-05-26 10:46 - 2014-05-26 10:46 - 00000000 ____D () C:\Users\Martina\Desktop\FRST-OlderVersion 2014-05-26 10:46 - 2014-05-20 09:51 - 02066944 _____ (Farbar) C:\Users\Martina\Desktop\FRST64.exe 2014-05-26 10:32 - 2014-05-26 10:32 - 00001936 _____ () C:\Users\Martina\Malw. Suchlauf Protokoll.txt 2014-05-26 10:32 - 2013-11-03 20:34 - 00000000 ____D () C:\Users\Martina 2014-05-26 10:29 - 2014-05-26 10:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-26 10:28 - 2014-05-26 10:24 - 00000000 ____D () C:\AdwCleaner 2014-05-26 10:28 - 2010-11-21 05:47 - 00459318 _____ () C:\Windows\PFRO.log 2014-05-26 10:06 - 2014-05-26 10:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-26 10:06 - 2014-05-26 10:06 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-26 10:06 - 2013-12-09 23:29 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-23 18:05 - 2013-11-17 18:20 - 00000000 ____D () C:\Users\Martina\AppData\Local\CrashDumps 2014-05-22 22:37 - 2013-11-04 07:43 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-05-22 22:23 - 2014-05-22 22:23 - 00001800 _____ () C:\Users\Public\Desktop\ANNO 1503.lnk 2014-05-22 22:23 - 2014-05-22 22:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ANNO 1503 GOLD 2014-05-22 22:20 - 2013-11-16 19:35 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-05-22 22:19 - 2013-12-11 01:00 - 00000000 ____D () C:\Spiele (Programme) 2014-05-21 23:43 - 2014-05-21 23:43 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\cerasus.media 2014-05-21 23:43 - 2014-05-21 23:43 - 00000000 ____D () C:\ProgramData\cerasus.media 2014-05-21 23:42 - 2014-05-21 23:42 - 00000961 _____ () C:\Users\Public\Desktop\MahJongg - Ancient Mayas.lnk 2014-05-21 23:42 - 2014-05-21 23:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\freundin-Games 2014-05-21 22:33 - 2013-11-17 22:37 - 00000000 ___RD () C:\Users\Martina\Desktop\Games 2014-05-21 09:43 - 2014-05-21 09:32 - 00000000 ____D () C:\Qoobox 2014-05-21 09:42 - 2014-05-21 09:32 - 00000000 ____D () C:\Windows\erdnt 2014-05-21 09:41 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-05-20 08:28 - 2013-11-17 15:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-20 08:26 - 2014-04-04 18:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2014-05-20 07:38 - 2014-05-20 07:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-18 20:32 - 2013-11-13 15:35 - 00000000 ___RD () C:\Users\Martina\Desktop\Mieter & Verträge 2014-05-18 06:28 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-05-17 15:52 - 2014-05-17 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tradewinds Caravans 2014-05-17 15:52 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-05-16 20:04 - 2014-02-13 01:47 - 00001722 _____ () C:\Users\Public\Desktop\Farm Up.lnk 2014-05-16 20:03 - 2014-05-16 20:03 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Farm Up 2014-05-16 20:03 - 2014-05-16 20:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Farm Up 2014-05-16 19:59 - 2013-11-18 16:15 - 00000000 ___RD () C:\MaBluEden 2014-05-16 19:59 - 2013-11-04 23:18 - 00000000 ___RD () C:\Users\Martina\AppData\Roaming\Realore 2014-05-16 19:48 - 2014-05-16 19:48 - 00001743 _____ () C:\Users\Public\Desktop\The Snow Fable.lnk 2014-05-16 19:48 - 2014-05-16 19:48 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Snow Fable 2014-05-16 19:48 - 2014-05-16 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Snow Fable 2014-05-15 18:42 - 2014-05-15 18:42 - 00001888 _____ () C:\Users\Martina\Desktop\Mystika 2 - The Sanctuary.lnk 2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\unikgame 2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mystika 2 - The Sanctuary 2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mystika 2 - The Sanctuary 2014-05-15 00:39 - 2014-05-14 23:24 - 00000000 ____D () C:\Users\Martina\Documents\Big Bang West 2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys 2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys 2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys 2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys 2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys 2014-05-13 00:36 - 2014-05-13 00:36 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\GameInvest 2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Zellians - Kingdom Builder 2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Zellians - Kingdom Builder 2014-05-12 07:26 - 2014-05-26 10:06 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-05-26 10:06 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-05-26 10:06 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-11 21:27 - 2013-11-06 08:46 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\AlawarEntertainment 2014-05-11 17:12 - 2013-12-24 23:15 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\ERS Game Studios 2014-05-11 17:00 - 2014-04-26 21:11 - 00000000 ____D () C:\Users\Martina\Documents\LDW 2014-05-11 09:46 - 2014-05-11 09:46 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Forgotten Books - The Enchanted Crown Collectors Edition 2014-05-11 09:46 - 2014-05-11 09:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Forgotten Books - The Enchanted Crown Collectors Edition 2014-05-08 08:39 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-05-07 13:01 - 2014-05-07 13:01 - 00017047 _____ () C:\Users\Martina\Documents\Mietvertrag Wohnungsbörse.odt 2014-05-04 16:55 - 2014-05-04 16:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-05-03 08:34 - 2014-05-01 13:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zylom 2014-05-03 08:34 - 2014-05-01 13:19 - 00000000 ____D () C:\Program Files (x86)\RealArcade 2014-05-03 08:30 - 2014-05-03 08:27 - 00000000 ____D () C:\ProgramData\Emberwind 2014-05-03 08:25 - 2014-05-03 08:25 - 00419840 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-05-03 08:25 - 2014-05-03 08:25 - 00413696 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2014-05-03 08:25 - 2014-05-03 08:25 - 00133632 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-05-03 08:25 - 2014-05-03 08:25 - 00110592 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2014-05-03 08:25 - 2014-05-03 08:25 - 00000000 ____D () C:\Program Files (x86)\OpenAL 2014-05-02 12:23 - 2014-05-02 12:23 - 00000000 ____D () C:\ProgramData\Magic-Heroes 2014-05-02 12:06 - 2014-05-02 12:06 - 00001923 _____ () C:\Users\Public\Desktop\Magic Heroes - Save Our Park.lnk 2014-05-02 12:06 - 2014-05-02 12:06 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Magic Heroes - Save Our Park 2014-05-02 12:06 - 2014-05-02 12:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Heroes - Save Our Park 2014-05-01 13:46 - 2013-11-17 16:18 - 00000000 ____D () C:\Users\Martina\AppData\Local\VirtualStore 2014-04-30 18:55 - 2014-04-30 18:55 - 00000000 ____D () C:\ProgramData\PlayFirst 2014-04-30 18:55 - 2014-04-30 18:55 - 00000000 ____D () C:\Program Files (x86)\Online Games Manager 2014-04-30 18:55 - 2013-11-13 17:01 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\PlayFirst 2014-04-30 18:52 - 2014-04-30 18:52 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\WinRAR Some content of TEMP: ==================== C:\Users\Martina\AppData\Local\Temp\NOSEventMessages.dll C:\Users\Martina\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-29 00:47 ==================== End Of Log ============================ --- --- --- Ich sage noch ein mal herzlichen Dank und wünsche Dir einen schönen Tag LG Martina |
![]() |
Themen zu nach firefox update / portaldosites in jedem neuen tap |
erschein, erscheint, firefox, frage, heute, morgen, nationzoom, nationzoom entfernen, neue, neuen, portaldosites, pup.optional.feven.a, pup.optional.nationzoom.a, pup.optional.qone8, schnell, spyware, suche, update, win32/toolbar.conduit.ae |