Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Nach websearches Befall, was in AdwCleaner löschen?

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 25.05.2014, 15:00   #1
ThorsZeh
 
Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



Hallo zusammen,

ich hab mir den Blue Stacks App Player installiert und mir so den websearches-Virus auf mein Win7 Notebook eingefangen.

Ich hab diese Anleitung befolgt, um ihn wieder loszuwerden:

hxxp://praxistipps.chip.de/websearch-webisawesome-virus-entfernen-so-klappts_27893

Ich hab mir den AdwCleaner runtergeladen und jetzt ist der letzte Schritt die Spuren des viruses mit dem Programm zu löschen. Bei dem programm steht: "[...] wählen Sie alle Elemente ab, die Sie nicht entfernen wollen." Jetzt hab ich total Angst etwas zu entfernen was systemrelvant ist oder sonst irgendwie Schwierigkeiten bereitet, wenn ich es entferne. Ich poste hier mal Die Screenshots, was der AdwCleaner alles gefunden hat. Was kann ich guten Gewissens entfernen und was sollte ich abwählen? (Die Reiter "Verknüpfungen" und "Chrome" sind leer)







Alt 25.05.2014, 18:02   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



hi,

alles löschen, dann:

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 25.05.2014, 20:35   #3
ThorsZeh
 
Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



Danke, hab ich gemacht

FRST.txt:


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by Computer (administrator) on COMPUTER-TOSH on 25-05-2014 21:31:43
Running from C:\Users\Computer\Downloads
Platform: Windows 7 Home Premium (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Users\Computer\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
() C:\Program Files (x86)\Youtube Downloader HD\YouTubeDownloaderHD.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566184 2010-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [SmartFaceVWatcher] => C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1489760 2010-03-17] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [705368 2010-02-23] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1050072 2010-05-11] (Toshiba Europe GmbH)
HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [915320 2010-05-10] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [35672 2010-03-03] (TOSHIBA Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation)
HKLM-x32\...\Run: [NBAgent] => c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1234216 2010-09-02] (Nero AG)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-15] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-05-05] (AVAST Software)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1294136 2009-10-06] (TOSHIBA Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [832272 2014-05-01] (BlueStack Systems, Inc.)
HKU\.DEFAULT\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\S-1-5-21-2560161592-3816387559-2359114276-1000\...\Run: [Amazon Cloud Player] => C:\Users\Computer\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3168576 2014-03-07] ()
HKU\S-1-5-21-2560161592-3816387559-2359114276-1000\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://toshiba.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {06E96EFE-8043-459D-925B-B4D5B82A2743} URL = hxxp://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}
SearchScopes: HKCU - {4DCB657A-6192-491C-B068-4554A7124208} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2
BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll (CANON INC.)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\6hvqdrtx.default-1401045432870
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ []
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-10]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-05] (AVAST Software)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-05-01] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-05-01] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [774928 2014-05-01] (BlueStack Systems, Inc.)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [124368 2010-05-11] (Toshiba Europe GmbH)

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-05] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-05] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-05] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-15] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-05] ()
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [123152 2014-05-01] (BlueStack Systems)
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-25 21:31 - 2014-05-25 21:31 - 00015797 _____ () C:\Users\Computer\Downloads\FRST.txt
2014-05-25 21:31 - 2014-05-25 21:31 - 00000000 ____D () C:\FRST
2014-05-25 21:30 - 2014-05-25 21:30 - 02066944 _____ (Farbar) C:\Users\Computer\Downloads\FRST64.exe
2014-05-25 21:18 - 2014-05-25 21:26 - 129141360 _____ () C:\Users\Computer\Documents\Lügen in der Politik - Ich gebe Ihnen mein Ehrenwort _ ARD-Dokumentation_(360p).mp4
2014-05-25 20:52 - 2014-05-25 21:17 - 433812888 _____ () C:\Users\Computer\Documents\hart aber fair Handy an, Hirn aus - wie doof machen uns Apple und Co.__(480p).mp4
2014-05-25 20:42 - 2014-05-25 20:52 - 124447560 _____ () C:\Users\Computer\Documents\Die KiK Story 2 - Neue Recherchen zum Textildiscounter_(360p).mp4
2014-05-25 19:49 - 2014-05-25 20:42 - 768610915 _____ () C:\Users\Computer\Documents\Der Kampf der Kleinen_(480p).mp4
2014-05-25 19:48 - 2014-05-25 19:48 - 03474636 _____ () C:\Users\Computer\Documents\Der Kampf der Kleinen_(360p).mp4
2014-05-25 19:43 - 2014-05-25 19:48 - 56076948 _____ () C:\Users\Computer\Documents\KiK-Ausbeute [ARD exclusiv] Teil 2_2_(360p).mp4
2014-05-25 19:40 - 2014-05-25 19:43 - 46510199 _____ () C:\Users\Computer\Documents\KiK-Ausbeute [ARD exclusiv] Teil 1_2_(360p).mp4
2014-05-25 17:54 - 2014-05-25 17:54 - 00000000 ____D () C:\Windows\system32\SPReview
2014-05-25 14:35 - 2014-05-25 21:21 - 00000000 ____D () C:\AdwCleaner
2014-05-25 14:35 - 2014-05-25 14:35 - 01326389 _____ () C:\Users\Computer\Downloads\adwcleaner_3.210.exe
2014-05-24 16:34 - 2014-05-25 19:26 - 00004982 _____ () C:\Users\Computer\Documents\24.05.2014.m3u8
2014-05-24 15:50 - 2014-05-25 21:17 - 00000000 ____D () C:\Users\Computer\Desktop\Alte Firefox-Daten
2014-05-24 12:27 - 2014-05-24 12:27 - 00003194 _____ () C:\Windows\System32\Tasks\{EEC10F91-11D8-4131-908C-FC47C488B291}
2014-05-23 19:47 - 2014-05-23 19:47 - 00000000 ____D () C:\Users\Computer\AppData\Local\com
2014-05-23 19:31 - 2014-05-24 15:47 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-05-23 19:27 - 2014-05-23 19:27 - 00290760 _____ () C:\Users\Computer\Downloads\Player_Setup.exe
2014-05-23 19:25 - 2014-05-23 19:25 - 00001814 _____ () C:\Users\Public\Desktop\Start BlueStacks.lnk
2014-05-23 19:25 - 2014-05-23 19:25 - 00001787 _____ () C:\Users\Public\Desktop\Apps.lnk
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-05-23 19:24 - 2014-05-23 19:39 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-05-23 19:24 - 2014-05-23 19:24 - 00000000 ____D () C:\Users\Computer\AppData\Local\Bluestacks
2014-05-23 18:59 - 2014-05-23 18:59 - 00000000 ____D () C:\Users\Computer\Downloads\gramblr
2014-05-23 18:53 - 2014-05-23 18:55 - 28516777 _____ () C:\Users\Computer\Downloads\gramblr.zip
2014-05-22 19:41 - 2014-05-22 19:46 - 00012881 _____ () C:\Users\Computer\Documents\Zusage der Kostenübernahme von Eltern.odt
2014-05-22 16:15 - 2014-05-22 16:15 - 10485760 _____ () C:\Users\Computer\Desktop\für Syavash.part2.rar
2014-05-22 16:15 - 2014-05-22 16:15 - 10485760 _____ () C:\Users\Computer\Desktop\für Syavash.part1.rar
2014-05-22 16:15 - 2014-05-22 16:15 - 07918941 _____ () C:\Users\Computer\Desktop\für Syavash.part3.rar
2014-05-22 15:50 - 2014-05-22 16:00 - 00000000 ____D () C:\Users\Computer\Desktop\für Syavash
2014-05-17 17:44 - 2014-05-17 17:46 - 34419752 _____ (DVDVideoSoft Ltd. ) C:\Users\Computer\Downloads\FreeYouTubeToMP3Converter.exe
2014-05-10 00:54 - 2014-05-10 00:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-06 23:36 - 2014-05-14 19:40 - 00000000 ____D () C:\Users\Computer\Desktop\zu drucken 2
2014-05-06 23:26 - 2014-05-06 23:26 - 02752854 _____ () C:\Users\Computer\Desktop\uni lageplan.bmp
2014-05-06 23:23 - 2014-05-06 23:24 - 03072054 _____ () C:\Users\Computer\Desktop\Neue Bitmap.bmp
2014-05-06 23:23 - 2014-05-06 23:23 - 03072054 _____ () C:\Users\Computer\Desktop\Neue Bitmap (3).bmp
2014-05-05 10:19 - 2014-05-05 10:19 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-05 10:19 - 2014-05-05 10:19 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-04 22:42 - 2014-05-04 23:16 - 106479872 _____ () C:\Users\Computer\Downloads\Kavi.part1.rar
2014-05-04 22:29 - 2014-05-04 22:31 - 31419822 _____ () C:\Users\Computer\Downloads\JDownloader.zip
2014-05-03 22:36 - 2014-05-03 22:49 - 00013614 _____ () C:\Users\Computer\Desktop\Metallica-Load.txt
2014-05-03 00:47 - 2014-05-03 00:49 - 31507478 _____ () C:\Users\Computer\Documents\Wie der Mc Donalds Konzern seine Mitarbeiter Behandelt_(360p).mp4
2014-05-03 00:00 - 2014-05-03 00:12 - 00014861 _____ () C:\Users\Computer\Desktop\Metallica-Metallica.txt
2014-05-02 17:35 - 2014-05-14 19:05 - 00006874 _____ () C:\Users\Computer\Documents\02.05.2014.m3u8
2014-04-30 10:54 - 2014-04-30 17:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-04-28 21:44 - 2014-04-28 21:51 - 00008661 _____ () C:\Users\Computer\Desktop\Metallica Kill ’Em All.txt
2014-04-27 15:38 - 2014-04-27 15:38 - 09664032 _____ (YoutubeDownloaderHD.com ) C:\Users\Computer\Downloads\youtube_downloader_hd_setup.exe

==================== One Month Modified Files and Folders =======

2014-05-25 21:31 - 2014-05-25 21:31 - 00015797 _____ () C:\Users\Computer\Downloads\FRST.txt
2014-05-25 21:31 - 2014-05-25 21:31 - 00000000 ____D () C:\FRST
2014-05-25 21:30 - 2014-05-25 21:30 - 02066944 _____ (Farbar) C:\Users\Computer\Downloads\FRST64.exe
2014-05-25 21:29 - 2014-01-10 19:06 - 01205135 _____ () C:\Windows\WindowsUpdate.log
2014-05-25 21:26 - 2014-05-25 21:18 - 129141360 _____ () C:\Users\Computer\Documents\Lügen in der Politik - Ich gebe Ihnen mein Ehrenwort _ ARD-Dokumentation_(360p).mp4
2014-05-25 21:24 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-25 21:24 - 2009-07-14 06:51 - 00072022 _____ () C:\Windows\setupact.log
2014-05-25 21:22 - 2014-01-11 12:14 - 00130182 _____ () C:\Windows\PFRO.log
2014-05-25 21:22 - 2009-07-14 06:45 - 00016080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-25 21:22 - 2009-07-14 06:45 - 00016080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-25 21:21 - 2014-05-25 14:35 - 00000000 ____D () C:\AdwCleaner
2014-05-25 21:17 - 2014-05-25 20:52 - 433812888 _____ () C:\Users\Computer\Documents\hart aber fair Handy an, Hirn aus - wie doof machen uns Apple und Co.__(480p).mp4
2014-05-25 21:17 - 2014-05-24 15:50 - 00000000 ____D () C:\Users\Computer\Desktop\Alte Firefox-Daten
2014-05-25 21:17 - 2014-02-05 12:45 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\Youtube Downloader HD
2014-05-25 20:52 - 2014-05-25 20:42 - 124447560 _____ () C:\Users\Computer\Documents\Die KiK Story 2 - Neue Recherchen zum Textildiscounter_(360p).mp4
2014-05-25 20:43 - 2014-01-21 20:24 - 00000000 ____D () C:\Users\Computer\AppData\Local\Last.fm
2014-05-25 20:42 - 2014-05-25 19:49 - 768610915 _____ () C:\Users\Computer\Documents\Der Kampf der Kleinen_(480p).mp4
2014-05-25 20:39 - 2014-01-10 20:00 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\Audacity
2014-05-25 20:36 - 2009-07-14 19:58 - 00654166 _____ () C:\Windows\system32\perfh007.dat
2014-05-25 20:36 - 2009-07-14 19:58 - 00130006 _____ () C:\Windows\system32\perfc007.dat
2014-05-25 20:36 - 2009-07-14 07:13 - 01498506 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-25 19:48 - 2014-05-25 19:48 - 03474636 _____ () C:\Users\Computer\Documents\Der Kampf der Kleinen_(360p).mp4
2014-05-25 19:48 - 2014-05-25 19:43 - 56076948 _____ () C:\Users\Computer\Documents\KiK-Ausbeute [ARD exclusiv] Teil 2_2_(360p).mp4
2014-05-25 19:43 - 2014-05-25 19:40 - 46510199 _____ () C:\Users\Computer\Documents\KiK-Ausbeute [ARD exclusiv] Teil 1_2_(360p).mp4
2014-05-25 19:26 - 2014-05-24 16:34 - 00004982 _____ () C:\Users\Computer\Documents\24.05.2014.m3u8
2014-05-25 17:54 - 2014-05-25 17:54 - 00000000 ____D () C:\Windows\system32\SPReview
2014-05-25 14:35 - 2014-05-25 14:35 - 01326389 _____ () C:\Users\Computer\Downloads\adwcleaner_3.210.exe
2014-05-25 14:28 - 2014-01-21 14:38 - 00000000 ____D () C:\Users\Computer\Documents\Planung
2014-05-24 15:47 - 2014-05-23 19:31 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-05-24 15:46 - 2014-01-18 14:16 - 00001416 _____ () C:\Users\Computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-05-24 15:46 - 2014-01-10 19:56 - 00001170 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-24 15:46 - 2014-01-10 19:56 - 00001158 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-05-24 15:46 - 2014-01-10 19:46 - 00001450 _____ () C:\Users\Computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-24 13:46 - 2014-02-04 20:33 - 00067737 _____ () C:\Users\Computer\Desktop\noch zu lesen2.odt
2014-05-24 13:23 - 2014-01-26 16:31 - 00000000 ____D () C:\Users\Computer\Desktop\wiki artikel für Kindle
2014-05-24 12:27 - 2014-05-24 12:27 - 00003194 _____ () C:\Windows\System32\Tasks\{EEC10F91-11D8-4131-908C-FC47C488B291}
2014-05-23 21:59 - 2014-02-21 14:14 - 00030304 _____ () C:\Users\Computer\Desktop\schon gelesen zu sortieren.odt
2014-05-23 21:41 - 2014-02-05 21:34 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\vlc
2014-05-23 19:47 - 2014-05-23 19:47 - 00000000 ____D () C:\Users\Computer\AppData\Local\com
2014-05-23 19:39 - 2014-05-23 19:24 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-05-23 19:27 - 2014-05-23 19:27 - 00290760 _____ () C:\Users\Computer\Downloads\Player_Setup.exe
2014-05-23 19:25 - 2014-05-23 19:25 - 00001814 _____ () C:\Users\Public\Desktop\Start BlueStacks.lnk
2014-05-23 19:25 - 2014-05-23 19:25 - 00001787 _____ () C:\Users\Public\Desktop\Apps.lnk
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-05-23 19:25 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-05-23 19:24 - 2014-05-23 19:24 - 00000000 ____D () C:\Users\Computer\AppData\Local\Bluestacks
2014-05-23 18:59 - 2014-05-23 18:59 - 00000000 ____D () C:\Users\Computer\Downloads\gramblr
2014-05-23 18:55 - 2014-05-23 18:53 - 28516777 _____ () C:\Users\Computer\Downloads\gramblr.zip
2014-05-22 19:46 - 2014-05-22 19:41 - 00012881 _____ () C:\Users\Computer\Documents\Zusage der Kostenübernahme von Eltern.odt
2014-05-22 16:15 - 2014-05-22 16:15 - 10485760 _____ () C:\Users\Computer\Desktop\für Syavash.part2.rar
2014-05-22 16:15 - 2014-05-22 16:15 - 10485760 _____ () C:\Users\Computer\Desktop\für Syavash.part1.rar
2014-05-22 16:15 - 2014-05-22 16:15 - 07918941 _____ () C:\Users\Computer\Desktop\für Syavash.part3.rar
2014-05-22 16:00 - 2014-05-22 15:50 - 00000000 ____D () C:\Users\Computer\Desktop\für Syavash
2014-05-22 15:42 - 2014-02-09 16:11 - 00000000 ____D () C:\Users\Computer\Desktop\M
2014-05-17 17:51 - 2014-01-21 17:49 - 00001543 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2014-05-17 17:51 - 2014-01-21 17:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-05-17 17:51 - 2014-01-21 17:48 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\DVDVideoSoft
2014-05-17 17:51 - 2014-01-21 17:48 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-05-17 17:46 - 2014-05-17 17:44 - 34419752 _____ (DVDVideoSoft Ltd. ) C:\Users\Computer\Downloads\FreeYouTubeToMP3Converter.exe
2014-05-15 20:12 - 2014-01-17 03:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 20:09 - 2014-01-17 03:06 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-15 18:10 - 2014-01-10 20:49 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-05-15 18:10 - 2014-01-10 20:49 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-05-15 18:10 - 2014-01-10 20:49 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-14 19:40 - 2014-05-06 23:36 - 00000000 ____D () C:\Users\Computer\Desktop\zu drucken 2
2014-05-14 19:05 - 2014-05-02 17:35 - 00006874 _____ () C:\Users\Computer\Documents\02.05.2014.m3u8
2014-05-13 19:16 - 2014-03-07 23:55 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\dvdcss
2014-05-13 10:19 - 2014-01-10 20:49 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-05-10 15:30 - 2014-01-10 19:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 00:54 - 2014-05-10 00:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-07 08:32 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-06 23:26 - 2014-05-06 23:26 - 02752854 _____ () C:\Users\Computer\Desktop\uni lageplan.bmp
2014-05-06 23:24 - 2014-05-06 23:23 - 03072054 _____ () C:\Users\Computer\Desktop\Neue Bitmap.bmp
2014-05-06 23:23 - 2014-05-06 23:23 - 03072054 _____ () C:\Users\Computer\Desktop\Neue Bitmap (3).bmp
2014-05-05 10:19 - 2014-05-05 10:19 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-05 10:19 - 2014-05-05 10:19 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-05 10:19 - 2014-01-10 20:50 - 00001973 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-05-05 10:19 - 2014-01-10 20:49 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1400170257058
2014-05-05 10:19 - 2014-01-10 20:49 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1400170257058
2014-05-05 10:19 - 2014-01-10 20:49 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-05-05 10:19 - 2014-01-10 20:49 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-05-05 10:19 - 2014-01-10 20:49 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-05-05 10:19 - 2014-01-10 20:49 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-05-05 10:19 - 2014-01-10 20:49 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-05-05 09:38 - 2014-01-16 21:37 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-05 09:38 - 2014-01-16 21:37 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-04 23:16 - 2014-05-04 22:42 - 106479872 _____ () C:\Users\Computer\Downloads\Kavi.part1.rar
2014-05-04 22:31 - 2014-05-04 22:29 - 31419822 _____ () C:\Users\Computer\Downloads\JDownloader.zip
2014-05-03 22:49 - 2014-05-03 22:36 - 00013614 _____ () C:\Users\Computer\Desktop\Metallica-Load.txt
2014-05-03 00:49 - 2014-05-03 00:47 - 31507478 _____ () C:\Users\Computer\Documents\Wie der Mc Donalds Konzern seine Mitarbeiter Behandelt_(360p).mp4
2014-05-03 00:12 - 2014-05-03 00:00 - 00014861 _____ () C:\Users\Computer\Desktop\Metallica-Metallica.txt
2014-04-30 20:14 - 2014-01-25 13:44 - 00006786 _____ () C:\Users\Computer\Documents\25.01.2014.m3u8
2014-04-30 17:59 - 2014-04-30 10:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-04-30 17:59 - 2014-03-19 19:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird.bak
2014-04-28 21:51 - 2014-04-28 21:44 - 00008661 _____ () C:\Users\Computer\Desktop\Metallica Kill ’Em All.txt
2014-04-27 15:42 - 2014-02-05 12:45 - 00001164 _____ () C:\Users\Computer\Desktop\Youtube Downloader HD.lnk
2014-04-27 15:42 - 2014-02-05 12:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Youtube Downloader HD
2014-04-27 15:42 - 2014-02-05 12:45 - 00000000 ____D () C:\Program Files (x86)\Youtube Downloader HD
2014-04-27 15:40 - 2014-03-18 13:57 - 00012535 _____ () C:\Users\Computer\Documents\18.03.2014.m3u8
2014-04-27 15:38 - 2014-04-27 15:38 - 09664032 _____ (YoutubeDownloaderHD.com ) C:\Users\Computer\Downloads\youtube_downloader_hd_setup.exe

Some content of TEMP:
====================
C:\Users\Computer\AppData\Local\Temp\BlueStacks089-SplitInstaller_native.exe
C:\Users\Computer\AppData\Local\Temp\KUIU.EXE
C:\Users\Computer\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Computer\AppData\Local\Temp\Quarantine.exe
C:\Users\Computer\AppData\Local\Temp\sdanircmdc.exe
C:\Users\Computer\AppData\Local\Temp\sdapskill.exe
C:\Users\Computer\AppData\Local\Temp\sdaspwn.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2010-12-08 12:36

==================== End Of Log ============================
         
--- --- ---
__________________

Alt 26.05.2014, 19:27   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



Addition.txt fehlt noch
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 26.05.2014, 20:40   #5
ThorsZeh
 
Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



Addition.txt:

Zitat:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-05-2014 02
Ran by Computer at 2014-05-25 21:32:38
Running from C:\Users\Computer\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.0.3.13070 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 2.0.3.13070 - Adobe Systems Inc.) Hidden
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.38 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.4.0.26 - Amazon Services LLC)
Amazon.de (HKLM-x32\...\{A74F16FA-1D5B-405B-8D8D-1BC6F9DAED8B}) (Version: - Amazon EU S.a.r.L.)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.26 - Atheros Communications Inc.)
ATI Catalyst Install Manager (HKLM\...\{5792CD64-61B4-C448-0D22-3C51DD73AB2A}) (Version: 3.0.765.0 - ATI Technologies, Inc.)
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2018 - Avast Software)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bing Bar (HKLM-x32\...\{08234a0d-cf39-4dca-99f0-0c5cb496da81}) (Version: 5.0.1401.0 - Microsoft Corporation)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.8.9.3088 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{4C02AFA8-074D-44FE-B0E1-A73D4AA65390}) (Version: 0.8.9.3088 - BlueStack Systems, Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.4.0.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.)
Canon MG5200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series) (Version: - )
Canon MG5500 series Benutzerregistrierung (HKLM-x32\...\Canon MG5500 series Benutzerregistrierung) (Version: - *Canon Inc.)
Canon MG5500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5500_series) (Version: 1.01 - Canon Inc.)
Canon MG5500 series On-screen Manual (HKLM-x32\...\Canon MG5500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 2.0.1 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 2.0.0 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.2.1 - Canon Inc.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2010.0315.1050.17562 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0315.1050.17562 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2010.0315.1050.17562 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2010.0315.1050.17562 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0315.1050.17562 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0315.1050.17562 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2010.0315.1050.17562 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2010.0315.1050.17562 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Czech (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Danish (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Dutch (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help English (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Finnish (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help French (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help German (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Greek (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Italian (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Japanese (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Korean (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Polish (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Russian (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Spanish (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Swedish (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Thai (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
CCC Help Turkish (x32 Version: 2010.0315.1049.17562 - ATI) Hidden
ccc-core-static (x32 Version: 2010.0315.1050.17562 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2010.0315.1050.17562 - ATI) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DVDFab 9.1.2.5 (22/01/2014) (HKLM-x32\...\DVDFab 9_is1) (Version: - Fengtao Software Inc.)
eBay (HKLM-x32\...\{FDE58148-57E7-43BF-879A-29CCE818C078}) (Version: 1.1.9 - eBay Inc.)
Farm Mania 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Fishdom (x32 Version: 2.2.0.95 - WildTangent) Hidden
Free YouTube to MP3 Converter version 3.12.35.514 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.35.514 - DVDVideoSoft Ltd.)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 17 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216017FF}) (Version: 6.0.170 - Sun Microsystems, Inc.)
Jewel Quest II (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
Last.fm Scrobbler 2.1.36 (HKLM-x32\...\LastFM_is1) (Version: - Last.fm)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Default Manager (x32 Version: 2.1.55.0 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Search Enhancement Pack (x32 Version: 2.0.271.0 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 10 Movie ThemePack Basic (x32 Version: 10.0.10600.6.0 - Nero AG) Hidden
Nero BackItUp 10 (HKLM-x32\...\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.4.24700.31.100 - Nero AG)
Nero BackItUp 10 Help (CHM) (x32 Version: 1.0.10900 - Nero AG) Hidden
Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.0.11300.14.100 - Nero AG)
Nero BurnRights 10 Help (CHM) (x32 Version: 1.0.10900 - Nero AG) Hidden
Nero Control Center 10 (x32 Version: 10.2.200.0.2 - Nero AG) Hidden
Nero ControlCenter 10 Help (CHM) (x32 Version: 1.0.10900 - Nero AG) Hidden
Nero Core Components 10 (x32 Version: 2.0.16800.7.15 - Nero AG) Hidden
Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.0.12100.22.100 - Nero AG)
Nero Express 10 Help (CHM) (x32 Version: 1.0.10900 - Nero AG) Hidden
Nero InfoTool 10 (HKLM-x32\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.0.11400.15.100 - Nero AG)
Nero InfoTool 10 Help (CHM) (x32 Version: 1.0.10900 - Nero AG) Hidden
Nero MediaHub 10 (HKLM-x32\...\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.0.14800.28.100 - Nero AG)
Nero MediaHub 10 Help (CHM) (x32 Version: 1.0.10900 - Nero AG) Hidden
Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{0FF68F26-416C-4954-ACA5-6AD5F9DE99C1}) (Version: 10.0.15000 - Nero AG)
Nero RescueAgent 10 (HKLM-x32\...\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.0.11800.26.100 - Nero AG)
Nero RescueAgent 10 Help (CHM) (x32 Version: 1.0.10900 - Nero AG) Hidden
Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.0.12300.27.100 - Nero AG)
Nero StartSmart 10 Help (CHM) (x32 Version: 1.0.10900 - Nero AG) Hidden
Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
PDF24 Creator 6.3.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Photo Service - powered by myphotobook (HKLM-x32\...\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1) (Version: 1.2.0-545 - myphotobook GmbH)
Photo Service - powered by myphotobook (x32 Version: 1.2.0 - myphotobook GmbH) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7083 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0016 - REALTEK Semiconductor Corp.)
SDFormatter (HKLM-x32\...\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association)
Skype Toolbars (HKLM-x32\...\{981029E0-7FC9-4CF3-AB39-6F133621921A}) (Version: 1.0.4051 - Skype Technologies S.A.)
Skype™ 4.2 (HKLM-x32\...\{D103C4BA-F905-437A-8049-DB24763BBE36}) (Version: 4.2.187 - Skype Technologies S.A.)
Slingo Supreme (x32 Version: 2.2.0.95 - WildTangent) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.8.1 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.26297 - TeamViewer)
Toshiba Assist (HKLM-x32\...\{1B87C40B-A60B-4EF3-9A68-706CF4B69978}) (Version: 3.00.10 - TOSHIBA)
TOSHIBA Bulletin Board (HKLM-x32\...\InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380}) (Version: 1.6.06.64 - TOSHIBA Corporation)
TOSHIBA Bulletin Board (Version: 1.6.06.64 - TOSHIBA Corporation) Hidden
TOSHIBA ConfigFree (HKLM-x32\...\{E0FAA369-B0E3-48B8-9447-4873103B0012}) (Version: 8.0.34 - TOSHIBA CORPORATION)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.2 for x64 - TOSHIBA Corporation)
TOSHIBA eco Utility (HKLM-x32\...\InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}) (Version: 1.2.10.64 - TOSHIBA Corporation)
TOSHIBA eco Utility (Version: 1.2.10.64 - TOSHIBA Corporation) Hidden
TOSHIBA eco Utility (x32 Version: 1.2.10.64 - TOSHIBA Corporation) Hidden
TOSHIBA Face Recognition (HKLM-x32\...\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.3.64 - TOSHIBA Corporation)
TOSHIBA Face Recognition (Version: 3.1.3.64 - TOSHIBA Corporation) Hidden
TOSHIBA Hardware Setup (HKLM-x32\...\{8E9CEA3B-EBD1-439C-A01D-830CB39613C6}) (Version: 2.00.06 - TOSHIBA Corporation)
TOSHIBA HDD/SSD Alert (HKLM-x32\...\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.6 - TOSHIBA Corporation)
TOSHIBA HDD/SSD Alert (Version: 3.1.64.6 - TOSHIBA Corporation) Hidden
TOSHIBA HDD/SSD Alert (x32 Version: 3.1.64.6 - TOSHIBA Corporation) Hidden
Toshiba Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.02 - TOSHIBA)
TOSHIBA Media Controller (HKLM-x32\...\{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}) (Version: 1.0.80.8.64 - TOSHIBA CORPORATION)
TOSHIBA Media Controller Plug-in (HKLM-x32\...\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}) (Version: 1.0.5.12 - TOSHIBA CORPORATION)
TOSHIBA Online Product Information (HKLM-x32\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 2.09.0001 - TOSHIBA)
TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.6.0.64 - TOSHIBA Corporation)
TOSHIBA Recovery Media Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.0.5 x64 - TOSHIBA Corporation)
TOSHIBA Recovery Media Creator Reminder (HKLM-x32\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0019 - TOSHIBA)
TOSHIBA Recovery Media Creator Reminder (x32 Version: 1.00.0019 - TOSHIBA) Hidden
TOSHIBA ReelTime (HKLM-x32\...\InstallShield_{A0E99122-25C1-4CA4-9063-499A2A814EB6}) (Version: 1.6.06.64 - TOSHIBA Corporation)
TOSHIBA ReelTime (Version: 1.6.06.64 - TOSHIBA Corporation) Hidden
TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.1.40 - TOSHIBA)
TOSHIBA Supervisor Password (HKLM-x32\...\{073B89C3-BA88-41B5-965F-B35A88EAE838}) (Version: 2.00.03 - TOSHIBA Corporation)
Toshiba TEMPRO (HKLM-x32\...\{DBB7021A-3437-446F-ACE5-7261644A972C}) (Version: 3.33 - Toshiba Europe GmbH)
TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.3.19.64 - TOSHIBA Corporation)
TOSHIBA Value Added Package (Version: 1.3.19.64 - TOSHIBA Corporation) Hidden
TOSHIBA Value Added Package (x32 Version: 1.3.19.64 - TOSHIBA Corporation) Hidden
TOSHIBA Web Camera Application (HKLM-x32\...\{5E6F6CF3-BACC-4144-868C-E14622C658F3}) (Version: 1.1.1.15 - TOSHIBA Corporation)
TRORMCLauncher (HKLM-x32\...\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version: - )
TRORMCLauncher (Version: 1.0.0.10 - TOSHIBA) Hidden
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2600217) (Version: 1 - Microsoft Corporation)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
WildTangent ORB Game Console (x32 Version: - WildTangent) Hidden
WildTangent-Spiele (HKLM-x32\...\WildTangent toshiba Master Uninstall) (Version: 1.0.1.5 - WildTangent)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Youtube Downloader HD v. 2.9.9.13 (HKLM-x32\...\Youtube Downloader HD_is1) (Version: - YoutubeDownloaderHD.com)
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden

==================== Restore Points =========================

25-05-2014 15:54:28 Windows 7 Service Pack 1

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {008D2F2E-C1CA-4EEA-BF2E-ABB100FD2C8B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-05-05] (AVAST Software)
Task: {0E72A026-E786-4132-8976-3FAADD35CF59} - System32\Tasks\ConfigFree Startup Programs => C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [2010-06-03] (TOSHIBA CORPORATION)
Task: {A5212BDE-F5CF-4796-B9E1-2EE433F1A2AD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)

==================== Loaded Modules (whitelisted) =============

2010-03-17 17:01 - 2010-03-17 17:01 - 00578936 _____ () C:\Program Files\TOSHIBA\TECO\TecoPower.dll
2014-01-24 12:38 - 2014-03-07 22:39 - 03168576 _____ () C:\Users\Computer\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
2009-10-13 11:00 - 2009-10-13 11:00 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2014-01-10 19:08 - 2014-01-10 19:08 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2014-02-05 12:45 - 2014-02-07 00:55 - 28075872 _____ () C:\Program Files (x86)\Youtube Downloader HD\YouTubeDownloaderHD.exe
2010-02-05 18:44 - 2010-02-05 18:44 - 00079192 _____ () C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll
2014-05-25 15:36 - 2014-05-25 15:36 - 02255872 _____ () C:\Program Files\AVAST Software\Avast\defs\14052500\algo.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-05-10 00:54 - 2014-05-10 00:54 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-01-10 20:49 - 2014-01-10 20:49 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-05-05 09:38 - 2014-05-05 09:38 - 16351920 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============

MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: GameConsoleService => 3
MSCONFIG\Services: iPod Service => 3
MSCONFIG\startupfolder: C:^Users^Computer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TRDCReminder.lnk => C:\Windows\pss\TRDCReminder.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: CanonQuickMenu => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: PDFPrint => C:\Program Files (x86)\PDF24\pdf24.exe
MSCONFIG\startupreg: Toshiba Registration => C:\Program Files\Toshiba\Registration\ToshibaReminder.exe
MSCONFIG\startupreg: TosNC => %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
MSCONFIG\startupreg: TWebCamera => "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/25/2014 09:25:03 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (05/25/2014 07:24:52 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (05/25/2014 05:54:28 PM) (Source: VSS) (EventID: 12305) (User: )
Description: Volumeschattenkopie-Dienstfehler: Volume bzw. Datenträger ist nicht richtig angeschlossen oder wurde nicht gefunden.
Fehlerkontext: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5 - 0000000000000128,0x00560038,00000000003E5000,0,00000000003E3FF0,4096,[0]).


Vorgang:
PostFinalCommitSnapshots wird verarbeitet

Kontext:
Ausführungskontext: System Provider

Error: (05/25/2014 04:51:54 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (05/25/2014 03:36:44 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (05/25/2014 00:58:05 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (05/24/2014 03:47:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 29.0.1.5239, Zeitstempel: 0x536995c2
Name des fehlerhaften Moduls: mozalloc.dll, Version: 29.0.1.5239, Zeitstempel: 0x536968fa
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000119c
ID des fehlerhaften Prozesses: 0x14d4
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3

Error: (05/23/2014 01:02:10 AM) (Source: VSS) (EventID: 12305) (User: )
Description: Volumeschattenkopie-Dienstfehler: Volume bzw. Datenträger ist nicht richtig angeschlossen oder wurde nicht gefunden.
Fehlerkontext: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2 - 00000000000000C0,0x00560038,0000000000393000,0,0000000000391FF0,4096,[0]).


Vorgang:
PostFinalCommitSnapshots wird verarbeitet

Kontext:
Ausführungskontext: System Provider

Error: (05/23/2014 00:23:38 AM) (Source: VSS) (EventID: 12305) (User: )
Description: Volumeschattenkopie-Dienstfehler: Volume bzw. Datenträger ist nicht richtig angeschlossen oder wurde nicht gefunden.
Fehlerkontext: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2,0xc0000000,0x00000003,...).


Vorgang:
PostFinalCommitSnapshots wird verarbeitet

Kontext:
Ausführungskontext: System Provider

Error: (05/22/2014 06:29:11 PM) (Source: VSS) (EventID: 12305) (User: )
Description: Volumeschattenkopie-Dienstfehler: Volume bzw. Datenträger ist nicht richtig angeschlossen oder wurde nicht gefunden.
Fehlerkontext: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3 - 0000000000000128,0x00560034,00000000002A32E0,0,00000000002A1FF0,4096,[0]).


Vorgang:
PostFinalCommitSnapshots wird verarbeitet

Kontext:
Ausführungskontext: System Provider


System errors:
=============
Error: (05/25/2014 09:25:03 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (05/25/2014 09:24:51 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (05/25/2014 09:24:51 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (05/25/2014 09:24:51 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (05/25/2014 09:24:51 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (05/25/2014 07:24:52 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (05/25/2014 07:24:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "BlueStacks Log Rotator Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (05/25/2014 07:24:26 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst BlueStacks Log Rotator Service erreicht.

Error: (05/25/2014 05:54:45 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800b0100 fehlgeschlagen: Windows 7 Service Pack 1 für x64-basierte Systeme (KB976932)

Error: (05/25/2014 04:51:54 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064


Microsoft Office Sessions:
=========================
Error: (05/25/2014 09:25:03 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (05/25/2014 07:24:52 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (05/25/2014 05:54:28 PM) (Source: VSS) (EventID: 12305) (User: )
Description: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5 - 0000000000000128,0x00560038,00000000003E5000,0,00000000003E3FF0,4096,[0])

Vorgang:
PostFinalCommitSnapshots wird verarbeitet

Kontext:
Ausführungskontext: System Provider

Error: (05/25/2014 04:51:54 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (05/25/2014 03:36:44 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (05/25/2014 00:58:05 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (05/24/2014 03:47:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe29.0.1.5239536995c2mozalloc.dll29.0.1.5239536968fa800000030000119c14d401cf775402a7511cC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllfec4dde6-e349-11e3-893e-00266c9f4681

Error: (05/23/2014 01:02:10 AM) (Source: VSS) (EventID: 12305) (User: )
Description: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2 - 00000000000000C0,0x00560038,0000000000393000,0,0000000000391FF0,4096,[0])

Vorgang:
PostFinalCommitSnapshots wird verarbeitet

Kontext:
Ausführungskontext: System Provider

Error: (05/23/2014 00:23:38 AM) (Source: VSS) (EventID: 12305) (User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2,0xc0000000,0x00000003,...)

Vorgang:
PostFinalCommitSnapshots wird verarbeitet

Kontext:
Ausführungskontext: System Provider

Error: (05/22/2014 06:29:11 PM) (Source: VSS) (EventID: 12305) (User: )
Description: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3 - 0000000000000128,0x00560034,00000000002A32E0,0,00000000002A1FF0,4096,[0])

Vorgang:
PostFinalCommitSnapshots wird verarbeitet

Kontext:
Ausführungskontext: System Provider


Alt 27.05.2014, 18:15   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.



Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
--> Nach websearches Befall, was in AdwCleaner löschen?

Alt 05.06.2014, 20:43   #7
ThorsZeh
 
Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



Tut mir leid, dass ich mich erst jetzt melde, ich hatte beruflich viel um die Ohren (inkl. Wochenend-& Feiertagsdienst)

erstmal, nach dem ich alles im AdwCleaner gelöscht hatte erhalte ich bei jedem Systemstart folgende Meldung auf den Desktop:



mbam.txt:

Zitat:
Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software

Suchlauf Datum: 05.06.2014
Suchlauf-Zeit: 20:02:57
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.06.05.11
Rootkit Datenbank: v2014.06.02.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7
CPU: x64
Dateisystem: NTFS
Benutzer: Computer

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 277166
Verstrichene Zeit: 19 Min, 15 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[4897cfa537447eb81e2fbbb018ec45bb]

Ordner: 0
(No malicious items detected)

Dateien: 6
Trojan.FakeMS.ED, C:\Users\Computer\AppData\Local\Temp\0390.dll, In Quarantäne, [7768324222593006d496354dd32ed12f],
PUP.Optional.DomaIQ, C:\Users\Computer\AppData\Local\Temp\dfsFA94.tmp, In Quarantäne, [c51a3b39f58678be94ed4de4cd35f50b],
PUP.Optional.ScramblePacker.A, C:\Users\Computer\AppData\Local\Temp\7dc2692b-7c13-4e7c-8719-b346fe6fe0c4\software\mplus.exe, In Quarantäne, [c11ef67ed8a337ff44313b45a75a8e72],
PUP.Optional.NewPlayer.A, C:\Users\Computer\AppData\Local\Temp\7dc2692b-7c13-4e7c-8719-b346fe6fe0c4\software\New_Player.exe, In Quarantäne, [974893e18eed7bbb68fd2c5459a8ab55],
PUP.Optional.OpenCandy, C:\Users\Computer\Downloads\DTLite4491-0356.exe, In Quarantäne, [449b720228533105f0683758d13308f8],
PUP.Optional.DomaIQ, C:\Users\Computer\Downloads\Player_Setup.exe, In Quarantäne, [c7186f05e09b92a479400a77d72a2bd5],

Physische Sektoren: 0
(No malicious items detected)


(end)
JRT.txt

Zitat:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Computer on 05.06.2014 at 21:19:04,82
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Emptied folder: C:\Users\Computer\AppData\Roaming\mozilla\firefox\profiles\6hvqdrtx.default-1401045432870\minidumps [17 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.06.2014 at 21:31:15,02
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by Computer (administrator) on COMPUTER-TOSH on 05-06-2014 21:32:34
Running from C:\Users\Computer\Downloads
Platform: Windows 7 Home Premium (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool 
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
() C:\Users\Computer\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Microsoft Corporation) C:\Windows\System32\mspaint.exe
() C:\Program Files (x86)\Youtube Downloader HD\YouTubeDownloaderHD.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Thisisu) C:\Users\Computer\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566184 2010-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [SmartFaceVWatcher] => C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1489760 2010-03-17] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [705368 2010-02-23] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1050072 2010-05-11] (Toshiba Europe GmbH)
HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [915320 2010-05-10] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [35672 2010-03-03] (TOSHIBA Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation)
HKLM-x32\...\Run: [NBAgent] => c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1234216 2010-09-02] (Nero AG)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-15] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3890208 2014-06-05] (AVAST Software)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1294136 2009-10-06] (TOSHIBA Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [832272 2014-05-01] (BlueStack Systems, Inc.)
HKU\.DEFAULT\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\S-1-5-21-2560161592-3816387559-2359114276-1000\...\Run: [Amazon Cloud Player] => C:\Users\Computer\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3168576 2014-03-07] ()
HKU\S-1-5-21-2560161592-3816387559-2359114276-1000\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\S-1-5-21-2560161592-3816387559-2359114276-1000\...\Run: [UsowoLqera] => regsvr32.exe "C:\ProgramData\UsowoLqera.dat"
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {06E96EFE-8043-459D-925B-B4D5B82A2743} URL = hxxp://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}
SearchScopes: HKCU - {4DCB657A-6192-491C-B068-4554A7124208} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2
BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll (CANON INC.)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\6hvqdrtx.default-1401045432870
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*'))%20%7B%20return%20'PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us07.personalitycores.com%3A8000%3B%20PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us04.personalitycores.com%3A8000%3B%20PROXY%20nq-us05.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000%3B%20PROXY%20nq-us10.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\6hvqdrtx.default-1401045432870\searchplugins\youtube-videosuche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\6hvqdrtx.default-1401045432870\Extensions\youtubeunblocker@unblocker.yt [2014-06-02]
FF Extension: ProxMate - Proxy on steroids! - C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\6hvqdrtx.default-1401045432870\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2014-05-26]
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ []
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-10]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-05] (AVAST Software)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-05-01] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-05-01] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [774928 2014-05-01] (BlueStack Systems, Inc.)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [124368 2010-05-11] (Toshiba Europe GmbH)

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-05] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-05] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-05] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-15] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-05] ()
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [123152 2014-05-01] (BlueStack Systems)
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-05 21:32 - 2014-06-05 21:32 - 00000000 ____D () C:\Users\Computer\Downloads\FRST-OlderVersion
2014-06-05 21:31 - 2014-06-05 21:31 - 00000777 _____ () C:\Users\Computer\Desktop\JRT.txt
2014-06-05 21:26 - 2014-06-05 21:26 - 02972033 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [8_8]_(360p).mp4
2014-06-05 21:22 - 2014-06-05 21:25 - 62399917 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [7_8]_(360p).mp4
2014-06-05 21:19 - 2014-06-05 21:19 - 00000000 ____D () C:\Windows\ERUNT
2014-06-05 21:18 - 2014-06-05 21:21 - 66858058 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [6_8]_(360p).mp4
2014-06-05 21:11 - 2014-06-05 21:18 - 65750430 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [5_8]_(360p).mp4
2014-06-05 20:59 - 2014-06-05 20:59 - 01016261 _____ (Thisisu) C:\Users\Computer\Downloads\JRT.exe
2014-06-05 20:55 - 2014-06-05 20:59 - 62012422 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [4_8]_(360p).mp4
2014-06-05 20:46 - 2014-06-05 20:54 - 71286219 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [3_8]_(360p).mp4
2014-06-05 20:41 - 2014-06-05 20:44 - 42394797 _____ () C:\Users\Computer\Documents\NWA - Deleted Scenes_(480p).mp4
2014-06-05 20:29 - 2014-06-05 20:40 - 115568286 _____ () C:\Users\Computer\Documents\Shindy - NWA DVD pt. 2_(480p).mp4
2014-06-05 20:24 - 2014-06-05 20:24 - 00002200 _____ () C:\Users\Computer\Desktop\mbam.txt
2014-06-05 20:15 - 2014-06-05 20:28 - 116095089 _____ () C:\Users\Computer\Documents\Shindy - NWA DVD pt. 1_(480p).mp4
2014-06-05 20:00 - 2014-06-05 20:07 - 61035378 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [1_8]_(360p).mp4
2014-06-05 19:58 - 2014-06-05 19:59 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-05 19:58 - 2014-06-05 19:58 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-05 19:58 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-05 19:58 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-05 19:58 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-05 19:55 - 2014-06-05 19:56 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Computer\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-05 18:19 - 2014-06-05 18:19 - 00000000 ____D () C:\Windows\system32\SPReview
2014-06-02 22:37 - 2014-06-02 22:54 - 18475736 _____ () C:\Users\Computer\Documents\Kollegah King DVD [5_5] - Anekdoten zu Regen 2, Openair Frauenfeld 2, Abschluss_(360p).mp4
2014-06-02 22:34 - 2014-06-02 22:37 - 43375205 _____ () C:\Users\Computer\Documents\Kollegah King DVD [4_5] - Budva, Vojvoda Vuk, Drogenkonsum, Anekdoten zu Regen_(360p).mp4
2014-06-02 22:19 - 2014-06-02 22:27 - 56244361 _____ () C:\Users\Computer\Documents\Kollegah King DVD [3_5] - Doubletime, Urlaub, Kollegha, Beine beanspruchen_(360p).mp4
2014-06-02 22:13 - 2014-06-02 22:18 - 53775617 _____ () C:\Users\Computer\Documents\Kollegah King DVD [2_5] - Openair Frauenfeld, Montenegro, Studio-Session, Foto-Shooting_(360p).mp4
2014-06-02 21:41 - 2014-06-02 22:12 - 363564030 _____ () C:\Users\Computer\Documents\Disco MMA DVD_(480p).mp4
2014-06-02 21:30 - 2014-06-02 21:38 - 56948003 _____ () C:\Users\Computer\Documents\Kollegah King DVD [1_5] - Fragen, Barcelona, Schloss, Studio, Farid Bang_(360p).mp4
2014-05-29 23:13 - 2014-05-29 23:21 - 173525581 _____ () C:\Users\Computer\Documents\Die Getriebenen - Politik bis zur Schmerzgrenze - ZDF Dokumentation - 20.09.2013_(480p).mp4
2014-05-29 22:56 - 2014-05-29 23:12 - 324496940 _____ () C:\Users\Computer\Documents\Pussy Riot - Ein russischer Skandal_(480p).mp4
2014-05-28 18:24 - 2014-05-29 22:55 - 228077703 _____ () C:\Users\Computer\Documents\Die Story im Ersten_ Sex - Made in Germany_ Prostitution und ihre Profiteure_(480p).mp4
2014-05-28 18:14 - 2014-05-28 18:23 - 00210540 _____ () C:\Users\Computer\Documents\Klartext spezial_ Streit um Asylbewerber_(360p).mp4
2014-05-28 18:01 - 2014-05-28 18:13 - 247472284 _____ () C:\Users\Computer\Documents\Schlachtfeld Politik - Die finstere Seite der Macht (Doku)_(480p).mp4
2014-05-28 17:51 - 2014-05-28 18:01 - 00950892 _____ () C:\Users\Computer\Documents\Wie billig kann Bio sein_ ARD Reportage Exklusiv im Ersten (2012)_(360p).mp4
2014-05-28 17:38 - 2014-05-28 17:50 - 225443263 _____ () C:\Users\Computer\Documents\Facebook - Milliardengeschäft Freundschaft _ Die Story im Ersten _ DAS ERSTE _ NDR _ ARD_(480p).mp4
2014-05-28 17:25 - 2014-05-28 17:38 - 179701788 _____ () C:\Users\Computer\Documents\Deutschlands neue Slums - Das Geschäft mit den Armutseinwanderern _ EXCLUSIV IM ERSTEN  _ ARD_(480p).mp4
2014-05-28 17:12 - 2014-05-28 17:23 - 114524040 _____ () C:\Users\Computer\Documents\Lobbyisten.in.der.Politik.ARD.Exclusiv.Die_Einfluesterer_12.09_(360p).mp4
2014-05-28 16:49 - 2014-05-28 17:11 - 156076220 _____ () C:\Users\Computer\Documents\Die story - Wir sind drin! - Die neuen Tricks der Lobbyisten_(360p).mp4
2014-05-28 16:35 - 2014-05-28 16:48 - 175141740 _____ () C:\Users\Computer\Documents\Über Merkel - Politik als Kompromiss_(360p).mp4
2014-05-28 16:27 - 2014-05-28 16:32 - 108406679 _____ () C:\Users\Computer\Documents\Die Einflüsterer - Wie Geld Politik macht (Doku)_(360p).mp4
2014-05-28 16:14 - 2014-05-28 16:27 - 129870401 _____ () C:\Users\Computer\Documents\Die Story im Ersten_ Du schaffst das!_(360p).mp4
2014-05-28 15:39 - 2014-05-28 16:12 - 243450891 _____ () C:\Users\Computer\Documents\Gysi und die Stasi - Ein Politiker im Zwielicht (Doku)_(480p).mp4
2014-05-26 22:13 - 2013-09-18 17:03 - 00377153 _____ () C:\Users\Computer\Downloads\proxmate_unblock_the_internet-2.3.3-fx.xpi
2014-05-26 22:12 - 2014-05-26 22:12 - 00359040 _____ () C:\Users\Computer\Downloads\proxmate_unblock_the_internet-2.3.3-fx.xpi.zip
2014-05-26 22:11 - 2014-05-26 22:21 - 149601442 _____ () C:\Users\Computer\Documents\Al-Gear WMA DVD [4_5]_(720p).mp4
2014-05-26 22:07 - 2014-05-26 22:11 - 63563803 _____ () C:\Users\Computer\Documents\Al-Gear WMA DVD [3_5]_(720p).mp4
2014-05-26 21:57 - 2014-05-26 22:06 - 101403368 _____ () C:\Users\Computer\Documents\Al-Gear WMA DVD [2_5]_(720p).mp4
2014-05-26 21:47 - 2014-05-26 21:56 - 109448303 _____ () C:\Users\Computer\Documents\Al-Gear WMA DVD [1_5]_(720p).mp4
2014-05-26 06:02 - 2014-05-26 06:09 - 120517619 _____ () C:\Users\Computer\Documents\-  Die Akte Gysi -_(360p).mp4
2014-05-26 05:49 - 2014-05-26 06:01 - 165155406 _____ () C:\Users\Computer\Documents\Wie weit links_ 150 Jahre SPD - Dokumentation_Doku über die SPD_(360p).mp4
2014-05-25 21:32 - 2014-05-25 21:33 - 00036526 _____ () C:\Users\Computer\Downloads\Addition.txt
2014-05-25 21:31 - 2014-06-05 21:32 - 00019660 _____ () C:\Users\Computer\Downloads\FRST.txt
2014-05-25 21:31 - 2014-06-05 21:32 - 00000000 ____D () C:\FRST
2014-05-25 21:30 - 2014-06-05 21:32 - 02068992 _____ (Farbar) C:\Users\Computer\Downloads\FRST64.exe
2014-05-25 14:35 - 2014-05-25 21:21 - 00000000 ____D () C:\AdwCleaner
2014-05-25 14:35 - 2014-05-25 14:35 - 01326389 _____ () C:\Users\Computer\Downloads\adwcleaner_3.210.exe
2014-05-24 16:34 - 2014-05-25 19:26 - 00004982 _____ () C:\Users\Computer\Documents\24.05.2014.m3u8
2014-05-24 15:50 - 2014-05-25 21:17 - 00000000 ____D () C:\Users\Computer\Desktop\Alte Firefox-Daten
2014-05-24 12:27 - 2014-05-24 12:27 - 00003194 _____ () C:\Windows\System32\Tasks\{EEC10F91-11D8-4131-908C-FC47C488B291}
2014-05-23 19:47 - 2014-05-23 19:47 - 00000000 ____D () C:\Users\Computer\AppData\Local\com
2014-05-23 19:31 - 2014-05-24 15:47 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-05-23 19:25 - 2014-05-23 19:25 - 00001814 _____ () C:\Users\Public\Desktop\Start BlueStacks.lnk
2014-05-23 19:25 - 2014-05-23 19:25 - 00001787 _____ () C:\Users\Public\Desktop\Apps.lnk
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-05-23 19:24 - 2014-05-23 19:39 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-05-23 19:24 - 2014-05-23 19:24 - 00000000 ____D () C:\Users\Computer\AppData\Local\Bluestacks
2014-05-23 18:59 - 2014-05-23 18:59 - 00000000 ____D () C:\Users\Computer\Downloads\gramblr
2014-05-23 18:53 - 2014-05-23 18:55 - 28516777 _____ () C:\Users\Computer\Downloads\gramblr.zip
2014-05-22 19:41 - 2014-05-22 19:46 - 00012881 _____ () C:\Users\Computer\Documents\Zusage der Kostenübernahme von Eltern.odt
2014-05-22 16:15 - 2014-05-22 16:15 - 10485760 _____ () C:\Users\Computer\Desktop\für Syavash.part2.rar
2014-05-22 16:15 - 2014-05-22 16:15 - 10485760 _____ () C:\Users\Computer\Desktop\für Syavash.part1.rar
2014-05-22 16:15 - 2014-05-22 16:15 - 07918941 _____ () C:\Users\Computer\Desktop\für Syavash.part3.rar
2014-05-22 15:50 - 2014-05-22 16:00 - 00000000 ____D () C:\Users\Computer\Desktop\für Syavash
2014-05-17 17:44 - 2014-05-17 17:46 - 34419752 _____ (DVDVideoSoft Ltd. ) C:\Users\Computer\Downloads\FreeYouTubeToMP3Converter.exe
2014-05-10 00:54 - 2014-05-10 00:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-06 23:36 - 2014-05-14 19:40 - 00000000 ____D () C:\Users\Computer\Desktop\zu drucken 2
2014-05-06 23:26 - 2014-05-06 23:26 - 02752854 _____ () C:\Users\Computer\Desktop\uni lageplan.bmp
2014-05-06 23:23 - 2014-05-06 23:24 - 03072054 _____ () C:\Users\Computer\Desktop\Neue Bitmap.bmp
2014-05-06 23:23 - 2014-05-06 23:23 - 03072054 _____ () C:\Users\Computer\Desktop\Neue Bitmap (3).bmp

==================== One Month Modified Files and Folders =======

2014-06-05 21:32 - 2014-06-05 21:32 - 00000000 ____D () C:\Users\Computer\Downloads\FRST-OlderVersion
2014-06-05 21:32 - 2014-05-25 21:31 - 00019660 _____ () C:\Users\Computer\Downloads\FRST.txt
2014-06-05 21:32 - 2014-05-25 21:31 - 00000000 ____D () C:\FRST
2014-06-05 21:32 - 2014-05-25 21:30 - 02068992 _____ (Farbar) C:\Users\Computer\Downloads\FRST64.exe
2014-06-05 21:32 - 2014-01-10 19:41 - 00000000 ____D () C:\Users\Computer\AppData\Local\Temp
2014-06-05 21:31 - 2014-06-05 21:31 - 00000777 _____ () C:\Users\Computer\Desktop\JRT.txt
2014-06-05 21:26 - 2014-06-05 21:26 - 02972033 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [8_8]_(360p).mp4
2014-06-05 21:25 - 2014-06-05 21:22 - 62399917 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [7_8]_(360p).mp4
2014-06-05 21:21 - 2014-06-05 21:18 - 66858058 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [6_8]_(360p).mp4
2014-06-05 21:19 - 2014-06-05 21:19 - 00000000 ____D () C:\Windows\ERUNT
2014-06-05 21:18 - 2014-06-05 21:11 - 65750430 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [5_8]_(360p).mp4
2014-06-05 21:18 - 2014-02-05 12:45 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\Youtube Downloader HD
2014-06-05 21:08 - 2009-07-14 06:45 - 00016080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-05 21:08 - 2009-07-14 06:45 - 00016080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-05 21:01 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-05 21:01 - 2009-07-14 06:51 - 00073982 _____ () C:\Windows\setupact.log
2014-06-05 21:00 - 2014-01-11 12:14 - 00131858 _____ () C:\Windows\PFRO.log
2014-06-05 21:00 - 2014-01-10 19:06 - 01770881 _____ () C:\Windows\WindowsUpdate.log
2014-06-05 21:00 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\ShellNew
2014-06-05 20:59 - 2014-06-05 20:59 - 01016261 _____ (Thisisu) C:\Users\Computer\Downloads\JRT.exe
2014-06-05 20:59 - 2014-06-05 20:55 - 62012422 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [4_8]_(360p).mp4
2014-06-05 20:54 - 2014-06-05 20:46 - 71286219 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [3_8]_(360p).mp4
2014-06-05 20:44 - 2014-06-05 20:41 - 42394797 _____ () C:\Users\Computer\Documents\NWA - Deleted Scenes_(480p).mp4
2014-06-05 20:40 - 2014-06-05 20:29 - 115568286 _____ () C:\Users\Computer\Documents\Shindy - NWA DVD pt. 2_(480p).mp4
2014-06-05 20:28 - 2014-06-05 20:15 - 116095089 _____ () C:\Users\Computer\Documents\Shindy - NWA DVD pt. 1_(480p).mp4
2014-06-05 20:24 - 2014-06-05 20:24 - 00002200 _____ () C:\Users\Computer\Desktop\mbam.txt
2014-06-05 20:07 - 2014-06-05 20:00 - 61035378 _____ () C:\Users\Computer\Documents\JBG2 Tour DVD [1_8]_(360p).mp4
2014-06-05 19:59 - 2014-06-05 19:58 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-05 19:58 - 2014-06-05 19:58 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-05 19:56 - 2014-06-05 19:55 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Computer\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-05 18:19 - 2014-06-05 18:19 - 00000000 ____D () C:\Windows\system32\SPReview
2014-06-05 17:24 - 2014-02-05 21:34 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\vlc
2014-06-04 20:38 - 2009-07-14 19:58 - 00654166 _____ () C:\Windows\system32\perfh007.dat
2014-06-04 20:38 - 2009-07-14 19:58 - 00130006 _____ () C:\Windows\system32\perfc007.dat
2014-06-04 20:38 - 2009-07-14 07:13 - 01498506 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-02 23:06 - 2014-01-21 20:24 - 00000000 ____D () C:\Users\Computer\AppData\Local\Last.fm
2014-06-02 22:54 - 2014-06-02 22:37 - 18475736 _____ () C:\Users\Computer\Documents\Kollegah King DVD [5_5] - Anekdoten zu Regen 2, Openair Frauenfeld 2, Abschluss_(360p).mp4
2014-06-02 22:37 - 2014-06-02 22:34 - 43375205 _____ () C:\Users\Computer\Documents\Kollegah King DVD [4_5] - Budva, Vojvoda Vuk, Drogenkonsum, Anekdoten zu Regen_(360p).mp4
2014-06-02 22:27 - 2014-06-02 22:19 - 56244361 _____ () C:\Users\Computer\Documents\Kollegah King DVD [3_5] - Doubletime, Urlaub, Kollegha, Beine beanspruchen_(360p).mp4
2014-06-02 22:18 - 2014-06-02 22:13 - 53775617 _____ () C:\Users\Computer\Documents\Kollegah King DVD [2_5] - Openair Frauenfeld, Montenegro, Studio-Session, Foto-Shooting_(360p).mp4
2014-06-02 22:12 - 2014-06-02 21:41 - 363564030 _____ () C:\Users\Computer\Documents\Disco MMA DVD_(480p).mp4
2014-06-02 21:38 - 2014-06-02 21:30 - 56948003 _____ () C:\Users\Computer\Documents\Kollegah King DVD [1_5] - Fragen, Barcelona, Schloss, Studio, Farid Bang_(360p).mp4
2014-06-02 20:47 - 2014-01-10 20:00 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\Audacity
2014-06-02 18:09 - 2014-02-09 16:11 - 00000000 ____D () C:\Users\Computer\Desktop\M
2014-05-29 23:28 - 2014-02-04 20:33 - 00068088 _____ () C:\Users\Computer\Desktop\noch zu lesen2.odt
2014-05-29 23:21 - 2014-05-29 23:13 - 173525581 _____ () C:\Users\Computer\Documents\Die Getriebenen - Politik bis zur Schmerzgrenze - ZDF Dokumentation - 20.09.2013_(480p).mp4
2014-05-29 23:12 - 2014-05-29 22:56 - 324496940 _____ () C:\Users\Computer\Documents\Pussy Riot - Ein russischer Skandal_(480p).mp4
2014-05-29 22:55 - 2014-05-28 18:24 - 228077703 _____ () C:\Users\Computer\Documents\Die Story im Ersten_ Sex - Made in Germany_ Prostitution und ihre Profiteure_(480p).mp4
2014-05-28 18:23 - 2014-05-28 18:14 - 00210540 _____ () C:\Users\Computer\Documents\Klartext spezial_ Streit um Asylbewerber_(360p).mp4
2014-05-28 18:13 - 2014-05-28 18:01 - 247472284 _____ () C:\Users\Computer\Documents\Schlachtfeld Politik - Die finstere Seite der Macht (Doku)_(480p).mp4
2014-05-28 18:01 - 2014-05-28 17:51 - 00950892 _____ () C:\Users\Computer\Documents\Wie billig kann Bio sein_ ARD Reportage Exklusiv im Ersten (2012)_(360p).mp4
2014-05-28 17:50 - 2014-05-28 17:38 - 225443263 _____ () C:\Users\Computer\Documents\Facebook - Milliardengeschäft Freundschaft _ Die Story im Ersten _ DAS ERSTE _ NDR _ ARD_(480p).mp4
2014-05-28 17:38 - 2014-05-28 17:25 - 179701788 _____ () C:\Users\Computer\Documents\Deutschlands neue Slums - Das Geschäft mit den Armutseinwanderern _ EXCLUSIV IM ERSTEN  _ ARD_(480p).mp4
2014-05-28 17:23 - 2014-05-28 17:12 - 114524040 _____ () C:\Users\Computer\Documents\Lobbyisten.in.der.Politik.ARD.Exclusiv.Die_Einfluesterer_12.09_(360p).mp4
2014-05-28 17:11 - 2014-05-28 16:49 - 156076220 _____ () C:\Users\Computer\Documents\Die story - Wir sind drin! - Die neuen Tricks der Lobbyisten_(360p).mp4
2014-05-28 17:00 - 2014-01-21 14:38 - 00000000 ____D () C:\Users\Computer\Documents\Planung
2014-05-28 16:48 - 2014-05-28 16:35 - 175141740 _____ () C:\Users\Computer\Documents\Über Merkel - Politik als Kompromiss_(360p).mp4
2014-05-28 16:32 - 2014-05-28 16:27 - 108406679 _____ () C:\Users\Computer\Documents\Die Einflüsterer - Wie Geld Politik macht (Doku)_(360p).mp4
2014-05-28 16:27 - 2014-05-28 16:14 - 129870401 _____ () C:\Users\Computer\Documents\Die Story im Ersten_ Du schaffst das!_(360p).mp4
2014-05-28 16:12 - 2014-05-28 15:39 - 243450891 _____ () C:\Users\Computer\Documents\Gysi und die Stasi - Ein Politiker im Zwielicht (Doku)_(480p).mp4
2014-05-27 06:10 - 2014-01-16 21:37 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-27 06:10 - 2014-01-16 21:37 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-26 22:21 - 2014-05-26 22:11 - 149601442 _____ () C:\Users\Computer\Documents\Al-Gear WMA DVD [4_5]_(720p).mp4
2014-05-26 22:12 - 2014-05-26 22:12 - 00359040 _____ () C:\Users\Computer\Downloads\proxmate_unblock_the_internet-2.3.3-fx.xpi.zip
2014-05-26 22:11 - 2014-05-26 22:07 - 63563803 _____ () C:\Users\Computer\Documents\Al-Gear WMA DVD [3_5]_(720p).mp4
2014-05-26 22:06 - 2014-05-26 21:57 - 101403368 _____ () C:\Users\Computer\Documents\Al-Gear WMA DVD [2_5]_(720p).mp4
2014-05-26 21:56 - 2014-05-26 21:47 - 109448303 _____ () C:\Users\Computer\Documents\Al-Gear WMA DVD [1_5]_(720p).mp4
2014-05-26 06:09 - 2014-05-26 06:02 - 120517619 _____ () C:\Users\Computer\Documents\-  Die Akte Gysi -_(360p).mp4
2014-05-26 06:01 - 2014-05-26 05:49 - 165155406 _____ () C:\Users\Computer\Documents\Wie weit links_ 150 Jahre SPD - Dokumentation_Doku über die SPD_(360p).mp4
2014-05-25 21:33 - 2014-05-25 21:32 - 00036526 _____ () C:\Users\Computer\Downloads\Addition.txt
2014-05-25 21:21 - 2014-05-25 14:35 - 00000000 ____D () C:\AdwCleaner
2014-05-25 21:17 - 2014-05-24 15:50 - 00000000 ____D () C:\Users\Computer\Desktop\Alte Firefox-Daten
2014-05-25 19:26 - 2014-05-24 16:34 - 00004982 _____ () C:\Users\Computer\Documents\24.05.2014.m3u8
2014-05-25 14:35 - 2014-05-25 14:35 - 01326389 _____ () C:\Users\Computer\Downloads\adwcleaner_3.210.exe
2014-05-24 15:47 - 2014-05-23 19:31 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-05-24 15:46 - 2014-01-18 14:16 - 00001416 _____ () C:\Users\Computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-05-24 15:46 - 2014-01-10 19:56 - 00001170 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-24 15:46 - 2014-01-10 19:56 - 00001158 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-05-24 15:46 - 2014-01-10 19:46 - 00001450 _____ () C:\Users\Computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-24 13:23 - 2014-01-26 16:31 - 00000000 ____D () C:\Users\Computer\Desktop\wiki artikel für Kindle
2014-05-24 12:27 - 2014-05-24 12:27 - 00003194 _____ () C:\Windows\System32\Tasks\{EEC10F91-11D8-4131-908C-FC47C488B291}
2014-05-23 21:59 - 2014-02-21 14:14 - 00030304 _____ () C:\Users\Computer\Desktop\schon gelesen zu sortieren.odt
2014-05-23 19:47 - 2014-05-23 19:47 - 00000000 ____D () C:\Users\Computer\AppData\Local\com
2014-05-23 19:39 - 2014-05-23 19:24 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-05-23 19:25 - 2014-05-23 19:25 - 00001814 _____ () C:\Users\Public\Desktop\Start BlueStacks.lnk
2014-05-23 19:25 - 2014-05-23 19:25 - 00001787 _____ () C:\Users\Public\Desktop\Apps.lnk
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-05-23 19:25 - 2014-05-23 19:25 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-05-23 19:25 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-05-23 19:24 - 2014-05-23 19:24 - 00000000 ____D () C:\Users\Computer\AppData\Local\Bluestacks
2014-05-23 18:59 - 2014-05-23 18:59 - 00000000 ____D () C:\Users\Computer\Downloads\gramblr
2014-05-23 18:55 - 2014-05-23 18:53 - 28516777 _____ () C:\Users\Computer\Downloads\gramblr.zip
2014-05-22 19:46 - 2014-05-22 19:41 - 00012881 _____ () C:\Users\Computer\Documents\Zusage der Kostenübernahme von Eltern.odt
2014-05-22 16:15 - 2014-05-22 16:15 - 10485760 _____ () C:\Users\Computer\Desktop\für Syavash.part2.rar
2014-05-22 16:15 - 2014-05-22 16:15 - 10485760 _____ () C:\Users\Computer\Desktop\für Syavash.part1.rar
2014-05-22 16:15 - 2014-05-22 16:15 - 07918941 _____ () C:\Users\Computer\Desktop\für Syavash.part3.rar
2014-05-22 16:00 - 2014-05-22 15:50 - 00000000 ____D () C:\Users\Computer\Desktop\für Syavash
2014-05-17 17:51 - 2014-01-21 17:49 - 00001543 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2014-05-17 17:51 - 2014-01-21 17:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-05-17 17:51 - 2014-01-21 17:48 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\DVDVideoSoft
2014-05-17 17:51 - 2014-01-21 17:48 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-05-17 17:46 - 2014-05-17 17:44 - 34419752 _____ (DVDVideoSoft Ltd. ) C:\Users\Computer\Downloads\FreeYouTubeToMP3Converter.exe
2014-05-15 20:12 - 2014-01-17 03:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 20:09 - 2014-01-17 03:06 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-15 18:10 - 2014-01-10 20:49 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-05-15 18:10 - 2014-01-10 20:49 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-05-15 18:10 - 2014-01-10 20:49 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-14 19:40 - 2014-05-06 23:36 - 00000000 ____D () C:\Users\Computer\Desktop\zu drucken 2
2014-05-14 19:05 - 2014-05-02 17:35 - 00006874 _____ () C:\Users\Computer\Documents\02.05.2014.m3u8
2014-05-13 19:16 - 2014-03-07 23:55 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\dvdcss
2014-05-13 10:19 - 2014-01-10 20:49 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-05-12 07:26 - 2014-06-05 19:58 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-06-05 19:58 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-06-05 19:58 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-10 15:30 - 2014-01-10 19:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 00:54 - 2014-05-10 00:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-07 08:32 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-06 23:26 - 2014-05-06 23:26 - 02752854 _____ () C:\Users\Computer\Desktop\uni lageplan.bmp
2014-05-06 23:24 - 2014-05-06 23:23 - 03072054 _____ () C:\Users\Computer\Desktop\Neue Bitmap.bmp
2014-05-06 23:23 - 2014-05-06 23:23 - 03072054 _____ () C:\Users\Computer\Desktop\Neue Bitmap (3).bmp

Some content of TEMP:
====================
C:\Users\Computer\AppData\Local\Temp\BlueStacks089-SplitInstaller_native.exe
C:\Users\Computer\AppData\Local\Temp\KUIU.EXE
C:\Users\Computer\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Computer\AppData\Local\Temp\Quarantine.exe
C:\Users\Computer\AppData\Local\Temp\sdanircmdc.exe
C:\Users\Computer\AppData\Local\Temp\sdapskill.exe
C:\Users\Computer\AppData\Local\Temp\sdaspwn.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2010-12-08 12:36

==================== End Of Log ============================
         
--- --- ---

Alt 06.06.2014, 18:57   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKU\S-1-5-21-2560161592-3816387559-2359114276-1000\...\Run: [UsowoLqera] => regsvr32.exe "C:\ProgramData\UsowoLqera.dat"
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.





ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 08.06.2014, 13:29   #9
ThorsZeh
 
Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



Ich erhalte beim ersten Schritt folgende Fehlermeldung:


Alt 09.06.2014, 06:41   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



mach mal den Rest.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 27.06.2014, 20:56   #11
ThorsZeh
 
Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



Tut mir Leid, dass wieder so viel Zeit zwischen dem letzten Post liegt, hab immer noch viel auf der Arbeit zu tun. Bin zwischen durch umgezogen und hab (noch) kein Internet dort. Schreibe hier gerade von meinem Elternhaus aus.

Eset Log:

Zitat:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=68ed7299bd24724fb4ed13dfdfc9fd68
# engine=18917
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-06-27 03:32:03
# local_time=2014-06-27 05:32:03 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7600 NT
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777213 100 97 1888267 14506956 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 149540 156288794 0 0
# scanned=325704
# found=9
# cleaned=0
# scan_time=9346
sh=C7C0F42A23562AA6DCCD60326FD8CC2AA41B5448 ft=1 fh=c053642cee9f3def vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir"
sh=125B1C393F2104CBA08183E495C0907BFF7EDA22 ft=1 fh=ea25908c8365106f vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface64.dll.vir"
sh=8E85792765D0E0BF52107CFF4A6620995DB19BB0 ft=1 fh=627da500ea2e265f vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterfacef32.dll.vir"
sh=6043D1ACD51FD373472020FBB748C405AAF22397 ft=1 fh=4c716dbbae6c21b9 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect32.dll.vir"
sh=FF431CD8693F4045BD7BD87DBCE54B820F000FC0 ft=1 fh=16c2e1bd3fd6b7e2 vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect64.dll.vir"
sh=5836A5DF3860241F6B69F2292ABCE592A13689B6 ft=1 fh=a3db04555f559ea8 vn="Variante von Win32/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SpAPPSv32.dll.vir"
sh=9DC13DB9C123270C2356ED410128E11D5ADF7C6E ft=1 fh=023ab782f0a9b07d vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir"
sh=56659F7FF1F1FA7906A77228E315F65F38BCEF73 ft=1 fh=0ff759dfc352fd03 vn="Variante von Win32/ELEX.AD evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir"
sh=31CE21FE36C11E107A6E315EFE1875743809B4CC ft=1 fh=48abcfa6ce4a4014 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Computer\AppData\Local\Temp\OCS\ocs_v71b.exe.vir"
checkup.txt
Zitat:
Results of screen317's Security Check version 0.99.83
Windows 7 x64 (UAC is enabled)
Out of date service pack!!
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
avast! Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java(TM) 6 Update 17
Java 7 Update 51
Java version out of Date!
Adobe Flash Player 14.0.0.125
Adobe Reader XI
Mozilla Firefox (30.0)
Mozilla Thunderbird (24.6.0)
````````Process Check: objlist.exe by Laurent````````
TOSHIBA TOSHIBA Online Product Information TOPI.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRST log:


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-06-2014
Ran by Computer (administrator) on COMPUTER-TOSH on 27-06-2014 21:33:22
Running from C:\Users\Computer\Downloads
Platform: Windows 7 Home Premium (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
() C:\Users\Computer\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winamp.exe
(Last.fm) C:\Program Files (x86)\Last.fm\Last.fm Scrobbler.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
() C:\Users\Computer\Downloads\SecurityCheck.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe
(The Audacity Team) C:\Program Files (x86)\Audacity\audacity.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566184 2010-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1489760 2010-03-17] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [705368 2010-02-23] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1050072 2010-05-11] (Toshiba Europe GmbH)
HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [915320 2010-05-10] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [35672 2010-03-03] (TOSHIBA Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation)
HKLM-x32\...\Run: [NBAgent] => c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1234216 2010-09-02] (Nero AG)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-15] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3890208 2014-06-05] (AVAST Software)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1294136 2009-10-06] (TOSHIBA Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [832272 2014-05-01] (BlueStack Systems, Inc.)
HKU\.DEFAULT\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\S-1-5-21-2560161592-3816387559-2359114276-1000\...\Run: [Amazon Cloud Player] => C:\Users\Computer\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3168576 2014-03-07] ()
HKU\S-1-5-21-2560161592-3816387559-2359114276-1000\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\S-1-5-21-2560161592-3816387559-2359114276-1000\...\Run: [UsowoLqera] => regsvr32.exe "C:\ProgramData\UsowoLqera.dat"
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://toshiba.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {06E96EFE-8043-459D-925B-B4D5B82A2743} URL = hxxp://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}
SearchScopes: HKCU - {4DCB657A-6192-491C-B068-4554A7124208} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2
BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll (CANON INC.)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\6hvqdrtx.default-1401045432870
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*'))%20%7B%20return%20'PROXY%20nq-us10.personalitycores.com%3A8000%3B%20PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us07.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000%3B%20PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us05.personalitycores.com%3A8000%3B%20PROXY%20nq-us04.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\6hvqdrtx.default-1401045432870\searchplugins\youtube-videosuche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\6hvqdrtx.default-1401045432870\Extensions\youtubeunblocker@unblocker.yt [2014-06-02]
FF Extension: ProxMate - Proxy on steroids! - C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\6hvqdrtx.default-1401045432870\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2014-05-26]
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2010-12-08]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-10]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-05] (AVAST Software)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-05-01] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-05-01] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [774928 2014-05-01] (BlueStack Systems, Inc.)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [124368 2010-05-11] (Toshiba Europe GmbH)

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-05] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-05] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-05] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-15] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-05] ()
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [123152 2014-05-01] (BlueStack Systems)
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-27 17:37 - 2014-06-27 17:37 - 00854367 _____ () C:\Users\Computer\Downloads\SecurityCheck.exe
2014-06-27 17:25 - 2014-06-27 17:53 - 299423150 _____ () C:\Users\Computer\Documents\Zane Lowe meets.... Rick Rubin_(720p).mp4
2014-06-27 14:46 - 2014-06-27 14:46 - 02347384 _____ (ESET) C:\Users\Computer\Downloads\esetsmartinstaller_deu.exe
2014-06-27 14:46 - 2014-06-27 14:46 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-06-25 15:54 - 2014-06-25 16:36 - 00013422 _____ () C:\Users\Computer\Documents\Zusage der Ausbildung SBK zum 01.10.2014.odt
2014-06-25 09:20 - 2014-06-25 09:20 - 00000000 ____D () C:\Windows\system32\SPReview
2014-06-24 19:29 - 2014-06-25 16:54 - 00011057 _____ () C:\Users\Computer\Documents\Briefkastenettiketten.odt
2014-06-19 14:41 - 2014-06-19 14:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-15 19:41 - 2014-06-15 19:41 - 00010022 _____ () C:\Users\Computer\Desktop\öfnnung reimer huxhold.odt
2014-06-11 21:29 - 2014-06-12 22:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-06-10 19:48 - 2014-06-10 20:00 - 00026105 _____ () C:\Users\Computer\Desktop\carola leyendecker.odt
2014-06-06 18:37 - 2014-06-06 18:39 - 00000000 ____D () C:\Users\Computer\Desktop\Lyrics
2014-06-05 21:33 - 2014-06-05 21:33 - 00045405 _____ () C:\Users\Computer\Desktop\FRST.txt
2014-06-05 21:32 - 2014-06-27 21:33 - 00000000 ____D () C:\Users\Computer\Downloads\FRST-OlderVersion
2014-06-05 21:31 - 2014-06-05 21:31 - 00000777 _____ () C:\Users\Computer\Desktop\JRT.txt
2014-06-05 21:19 - 2014-06-05 21:19 - 00000000 ____D () C:\Windows\ERUNT
2014-06-05 20:59 - 2014-06-05 20:59 - 01016261 _____ (Thisisu) C:\Users\Computer\Downloads\JRT.exe
2014-06-05 20:24 - 2014-06-05 20:24 - 00002200 _____ () C:\Users\Computer\Desktop\mbam.txt
2014-06-05 19:58 - 2014-06-05 19:59 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-05 19:58 - 2014-06-05 19:58 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-05 19:58 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-05 19:58 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-05 19:58 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-05 19:55 - 2014-06-05 19:56 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Computer\Downloads\mbam-setup-2.0.2.1012.exe

==================== One Month Modified Files and Folders =======

2014-06-27 21:33 - 2014-06-05 21:32 - 00000000 ____D () C:\Users\Computer\Downloads\FRST-OlderVersion
2014-06-27 21:33 - 2014-05-25 21:31 - 00020174 _____ () C:\Users\Computer\Downloads\FRST.txt
2014-06-27 21:33 - 2014-05-25 21:31 - 00000000 ____D () C:\FRST
2014-06-27 21:33 - 2014-05-25 21:30 - 02083328 _____ (Farbar) C:\Users\Computer\Downloads\FRST64.exe
2014-06-27 21:32 - 2009-07-14 06:51 - 00083156 _____ () C:\Windows\setupact.log
2014-06-27 21:26 - 2014-01-10 19:06 - 01824181 _____ () C:\Windows\WindowsUpdate.log
2014-06-27 21:20 - 2014-01-10 20:00 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\Audacity
2014-06-27 21:13 - 2014-01-21 20:24 - 00000000 ____D () C:\Users\Computer\AppData\Local\Last.fm
2014-06-27 21:09 - 2014-01-16 21:37 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-27 21:09 - 2014-01-16 21:37 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-27 21:03 - 2009-07-14 06:45 - 00016080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-27 21:03 - 2009-07-14 06:45 - 00016080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-27 20:55 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-27 17:53 - 2014-06-27 17:25 - 299423150 _____ () C:\Users\Computer\Documents\Zane Lowe meets.... Rick Rubin_(720p).mp4
2014-06-27 17:37 - 2014-06-27 17:37 - 00854367 _____ () C:\Users\Computer\Downloads\SecurityCheck.exe
2014-06-27 17:35 - 2014-02-04 20:33 - 00071217 _____ () C:\Users\Computer\Desktop\noch zu lesen2.odt
2014-06-27 14:47 - 2009-07-14 19:58 - 00654166 _____ () C:\Windows\system32\perfh007.dat
2014-06-27 14:47 - 2009-07-14 19:58 - 00130006 _____ () C:\Windows\system32\perfc007.dat
2014-06-27 14:47 - 2009-07-14 07:13 - 01498506 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-27 14:46 - 2014-06-27 14:46 - 02347384 _____ (ESET) C:\Users\Computer\Downloads\esetsmartinstaller_deu.exe
2014-06-27 14:46 - 2014-06-27 14:46 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-06-27 13:19 - 2014-01-10 20:49 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-27 10:41 - 2014-02-05 21:34 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\vlc
2014-06-26 12:14 - 2014-01-21 14:38 - 00000000 ____D () C:\Users\Computer\Documents\Planung
2014-06-25 23:25 - 2014-02-09 16:11 - 00000000 ____D () C:\Users\Computer\Desktop\M
2014-06-25 16:54 - 2014-06-24 19:29 - 00011057 _____ () C:\Users\Computer\Documents\Briefkastenettiketten.odt
2014-06-25 16:36 - 2014-06-25 15:54 - 00013422 _____ () C:\Users\Computer\Documents\Zusage der Ausbildung SBK zum 01.10.2014.odt
2014-06-25 09:20 - 2014-06-25 09:20 - 00000000 ____D () C:\Windows\system32\SPReview
2014-06-21 00:03 - 2014-01-10 19:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-20 16:58 - 2014-03-19 21:21 - 00001109 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-06-20 16:58 - 2014-03-19 21:21 - 00001097 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-06-19 16:27 - 2014-02-05 12:45 - 00000000 ____D () C:\Users\Computer\AppData\Roaming\Youtube Downloader HD
2014-06-19 14:42 - 2014-06-19 14:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-15 19:41 - 2014-06-15 19:41 - 00010022 _____ () C:\Users\Computer\Desktop\öfnnung reimer huxhold.odt
2014-06-13 00:22 - 2014-01-17 03:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-13 00:20 - 2014-01-17 03:06 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 22:31 - 2014-06-11 21:29 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-06-10 20:00 - 2014-06-10 19:48 - 00026105 _____ () C:\Users\Computer\Desktop\carola leyendecker.odt
2014-06-08 14:09 - 2014-02-21 14:14 - 00030735 _____ () C:\Users\Computer\Desktop\schon gelesen zu sortieren.odt
2014-06-07 22:59 - 2014-01-26 16:31 - 00000000 ____D () C:\Users\Computer\Desktop\wiki artikel für Kindle
2014-06-07 12:55 - 2014-05-24 16:34 - 00009604 _____ () C:\Users\Computer\Documents\24.05.2014.m3u8
2014-06-06 18:42 - 2014-05-22 15:50 - 00000000 ____D () C:\Users\Computer\Desktop\für Syavash
2014-06-06 18:39 - 2014-06-06 18:37 - 00000000 ____D () C:\Users\Computer\Desktop\Lyrics
2014-06-06 14:52 - 2014-02-04 17:20 - 738900975 _____ () C:\Windows\MEMORY.DMP
2014-06-06 14:52 - 2014-02-04 17:20 - 00000000 ____D () C:\Windows\Minidump
2014-06-05 23:58 - 2014-01-11 12:14 - 00132478 _____ () C:\Windows\PFRO.log
2014-06-05 21:33 - 2014-06-05 21:33 - 00045405 _____ () C:\Users\Computer\Desktop\FRST.txt
2014-06-05 21:31 - 2014-06-05 21:31 - 00000777 _____ () C:\Users\Computer\Desktop\JRT.txt
2014-06-05 21:19 - 2014-06-05 21:19 - 00000000 ____D () C:\Windows\ERUNT
2014-06-05 21:00 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\ShellNew
2014-06-05 20:59 - 2014-06-05 20:59 - 01016261 _____ (Thisisu) C:\Users\Computer\Downloads\JRT.exe
2014-06-05 20:24 - 2014-06-05 20:24 - 00002200 _____ () C:\Users\Computer\Desktop\mbam.txt
2014-06-05 19:59 - 2014-06-05 19:58 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-05 19:58 - 2014-06-05 19:58 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-05 19:58 - 2014-06-05 19:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-05 19:56 - 2014-06-05 19:55 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Computer\Downloads\mbam-setup-2.0.2.1012.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2010-12-08 12:36

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Alt 28.06.2014, 18:26   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Nach websearches Befall, was in AdwCleaner löschen? - Standard

Nach websearches Befall, was in AdwCleaner löschen?



Java udpaten, Windows updaten, da fehlt ein Servicepack.


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKU\S-1-5-21-2560161592-3816387559-2359114276-1000\...\Run: [UsowoLqera] => regsvr32.exe "C:\ProgramData\UsowoLqera.dat"
C:\ProgramData\UsowoLqera.dat
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.




Frisches FRST log bitte. Passwörter alle ändern.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Nach websearches Befall, was in AdwCleaner löschen?
programm, pup.optional.domaiq, pup.optional.newplayer.a, pup.optional.opencandy, pup.optional.qone8, pup.optional.scramblepacker.a, screenshots, trojan.fakems.ed, verknüpfungen, win32/downloadsponsor.a, win32/elex.ad, win32/thinknice.a, win32/thinknice.b, win32/thinknice.c, win64/thinknice.a, zusammen




Ähnliche Themen: Nach websearches Befall, was in AdwCleaner löschen?


  1. AdwCleaner kann gefundene Daten nicht löschen - Trojaner ?
    Plagegeister aller Art und deren Bekämpfung - 14.04.2015 (14)
  2. adwcleaner jeweils nach dem Durchlauf einer Rubrik neu starten?
    Antiviren-, Firewall- und andere Schutzprogramme - 08.03.2015 (5)
  3. Trj.CI.A befall, bitte um Hilfe bei der Auswertung ob ich etwas beim Löschen übersehen habe.
    Log-Analyse und Auswertung - 20.02.2015 (9)
  4. Adwcleaner kann datei nicht löschen
    Plagegeister aller Art und deren Bekämpfung - 02.02.2015 (39)
  5. websearches.com entfernen
    Plagegeister aller Art und deren Bekämpfung - 11.11.2014 (13)
  6. Proxy stellt sich immer auf 127.0.0.1:9880 nach hijack durch websearches
    Log-Analyse und Auswertung - 08.11.2014 (11)
  7. PC bootet nach Anwendung von ADWCleaner nicht mehr
    Log-Analyse und Auswertung - 30.10.2014 (10)
  8. AdwCleaner hat Dateien gefunden, löschen oder nicht?
    Log-Analyse und Auswertung - 24.09.2014 (12)
  9. websearches.com loswerden
    Log-Analyse und Auswertung - 04.09.2014 (1)
  10. Nach Installation von ADWCleaner geht gar nichts mehr.
    Plagegeister aller Art und deren Bekämpfung - 10.07.2014 (1)
  11. AdwCleaner vs. APPL/Downloader.Gen = alles ok! Aber wie werde ich nun AdwCleaner 3.212 wieder los?
    Plagegeister aller Art und deren Bekämpfung - 14.06.2014 (5)
  12. Malwarebytes findet Befall von Koobface und OpenCandy-AWL kann Dateien nicht löschen
    Log-Analyse und Auswertung - 16.04.2014 (8)
  13. nach Nutzung von AdwCleaner: Verlust von Windows XP Benutzerprofil
    Plagegeister aller Art und deren Bekämpfung - 05.01.2014 (4)
  14. Win 7: Nach Adwcleaner noch immer neue Adware
    Log-Analyse und Auswertung - 21.11.2013 (7)
  15. W7 Malware Befall – Rester löschen
    Log-Analyse und Auswertung - 11.09.2013 (14)
  16. Nach PC-Neuaufsetzen nach Adware-Befall - PC sauber?
    Plagegeister aller Art und deren Bekämpfung - 26.07.2013 (13)
  17. befall von viren und lassen sich nicht löschen,und pc ist langsam bitte logfile ansch
    Log-Analyse und Auswertung - 02.01.2008 (2)

Zum Thema Nach websearches Befall, was in AdwCleaner löschen? - Hallo zusammen, ich hab mir den Blue Stacks App Player installiert und mir so den websearches-Virus auf mein Win7 Notebook eingefangen. Ich hab diese Anleitung befolgt, um ihn wieder loszuwerden: - Nach websearches Befall, was in AdwCleaner löschen?...
Archiv
Du betrachtest: Nach websearches Befall, was in AdwCleaner löschen? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.