Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Bekomme "search.gadgetbox" nicht weg

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 15.06.2014, 16:49   #1
Frontschwein
 
Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



Habe mir den Schädling gadgetbox eingefangen. Internet sehr langsam.
Startseite nun nicht mehr google sondern gadgetbox.

Hatte erst Spybot laufen lassen, dann Malwarebytes. Zum Schluss nun FRST.

Hier die logs:

Frst:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-06-2014 02
Ran by wh (administrator) on WH-PC on 15-06-2014 17:27:28
Running from C:\Users\wh\Downloads
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0 apoEdition\ouservice\StarMoneyOnlineUpdate.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Play Touch\Touch Launcher\LauncherStarterCmd.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Touch Supporter\InputSupporterNLauncher.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Touch Supporter\InputSupporter.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Play Touch\Touch Launcher\LauncherStarter.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartRotation.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Easy Support Center\SSCKbdHk.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12661352 2011-08-01] (Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3424567567-1130603173-978095989-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566984 2014-04-25] (Safer-Networking Ltd.)
HKU\S-1-5-21-3424567567-1130603173-978095989-1000\...\MountPoints2: {5e394242-c7b7-11e3-af9f-24ec994b3939} - D:\LaunchU3.exe -a
AppInit_DLLs: C:\PROGRA~3\ASSIST~1\ASSIST~2.DLL => C:\PROGRA~3\ASSIST~1\ASSIST~2.DLL File Not Found
AppInit_DLLs-x32: c:\progra~3\assist~1\assist~1.dll => "c:\progra~3\assist~1\assist~1.dll" File Not Found
Lsa: [Notification Packages] scecli ConfigFilter
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.gboxapp.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.gboxapp.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.gboxapp.com/
BHO: NewiSSAVer - {8711D30F-7582-8372-36D2-F2B0BAC36D33} - C:\ProgramData\NewiSSAVer\RK9UOieO.x64.dll ()
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: NewiSSAVer - {8711D30F-7582-8372-36D2-F2B0BAC36D33} - C:\ProgramData\NewiSSAVer\RK9UOieO.dll ()
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2

FireFox:
========
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)

Chrome:
=======
CHR HomePage: hxxp://search.gboxapp.com/
CHR StartupUrls: "https://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-04]
CHR Extension: (Google Drive) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-04]
CHR Extension: (YouTube) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-04]
CHR Extension: (Google-Suche) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-04]
CHR Extension: (Google Wallet) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-04]
CHR Extension: (Google Mail) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-04]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0 apoEdition\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)

==================== Drivers (Whitelisted) ====================

S3 AX88772; C:\Windows\System32\DRIVERS\ax88772.sys [77312 2010-05-31] (ASIX Electronics Corp.)
R3 GTNDIS62; C:\Windows\System32\DRIVERS\Gtuhs62.sys [208384 2011-10-03] (Option N.V.)
R3 GTUHSBUS; C:\Windows\System32\DRIVERS\gtuhsbus.sys [214528 2011-10-03] (Option N.V.)
R3 GTUHSSER; C:\Windows\System32\DRIVERS\gtuhsser.sys [12032 2011-10-03] (Option N.V.)
R3 LSM303DLH; C:\Windows\System32\DRIVERS\LSM303DLH.sys [61040 2011-08-19] (STMicroelectronics)
R2 SGDrv; C:\Windows\System32\DRIVERS\SGdrv64.sys [7680 2011-04-11] (Phoenix Technologies Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-15 17:27 - 2014-06-15 17:27 - 00013039 _____ () C:\Users\wh\Downloads\FRST.txt
2014-06-15 17:27 - 2014-06-15 17:27 - 00000000 ____D () C:\FRST
2014-06-15 17:26 - 2014-06-15 17:26 - 02081792 _____ (Farbar) C:\Users\wh\Downloads\FRST64.exe
2014-06-15 16:44 - 2014-06-15 16:44 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-15 16:43 - 2014-06-15 16:43 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\wh\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-15 16:43 - 2014-06-15 16:43 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-06-15 16:43 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-06-15 16:43 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-06-15 16:43 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-06-15 14:22 - 2009-06-10 23:00 - 00000824 _____ () C:\windows\system32\Drivers\etc\hosts.20140615-142237.backup
2014-06-15 12:53 - 2014-06-15 12:53 - 00859992 _____ () C:\Users\wh\Downloads\snlTCNTplugins01.zip
2014-06-15 11:36 - 2009-06-10 23:00 - 00000824 _____ () C:\windows\system32\Drivers\etc\hosts.20140615-113648.backup
2014-06-15 00:50 - 2014-06-15 00:50 - 00000990 _____ () C:\windows\wininit.ini
2014-06-14 20:35 - 2014-06-15 11:34 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-14 20:35 - 2014-06-14 20:36 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-06-14 20:35 - 2014-06-14 20:35 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-14 20:35 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\windows\system32\sdnclean64.exe
2014-06-14 20:33 - 2014-06-14 20:33 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\wh\Downloads\spybot-2.3.exe
2014-06-12 20:31 - 2014-06-12 20:31 - 00000000 ____D () C:\ProgramData\NewiSSAVer
2014-06-10 20:09 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-10 20:09 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-10 20:09 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-10 20:09 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-10 20:09 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-06-10 20:09 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-10 20:09 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-06-10 20:09 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-10 20:09 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-06-10 20:09 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-10 20:09 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-10 20:09 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-06-10 20:09 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-06-10 20:09 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-06-10 20:09 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-06-10 20:09 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-06-10 20:09 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-10 20:09 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-10 20:09 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-10 20:09 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-06-10 20:09 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-10 20:09 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-10 20:09 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-10 20:09 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-06-10 20:09 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-10 20:09 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-06-10 20:09 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-06-10 20:09 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-06-10 20:09 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-10 20:09 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-06-10 20:09 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-06-10 20:09 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-06-10 20:09 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-10 20:09 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-06-10 20:09 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-06-10 20:09 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-06-10 20:09 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-10 20:09 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-06-10 20:09 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-10 20:09 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-06-10 20:09 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-06-10 20:09 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-06-10 20:09 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-06-10 20:09 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-10 20:09 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-06-10 20:09 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-06-10 20:09 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-06-10 20:09 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-10 20:09 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-06-10 20:09 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-10 20:09 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-06-10 20:09 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-06-10 20:09 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-06-10 20:09 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-06-10 20:09 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2014-06-10 20:09 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2014-06-10 20:09 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-06-10 20:09 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-06-10 20:09 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2014-06-10 20:09 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-06-10 20:09 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2014-06-10 20:09 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2014-06-10 20:09 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2014-06-10 20:09 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2014-06-10 20:09 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2014-06-10 20:09 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2014-06-09 11:09 - 2014-06-11 14:47 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-06-09 10:48 - 2014-06-09 10:48 - 00000056 _____ () C:\Users\wh\Downloads\heavy-metal.m3u
2014-06-03 21:33 - 2014-06-03 21:33 - 00003279 _____ () C:\Users\wh\Downloads\2-09399-g-06.AAM
2014-06-02 20:14 - 2014-06-02 20:14 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-r-06.AAM
2014-06-01 18:15 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2014-06-01 18:15 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2014-06-01 18:15 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2014-06-01 18:15 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2014-06-01 18:15 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2014-06-01 18:15 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2014-06-01 18:15 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2014-06-01 18:15 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2014-06-01 18:15 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2014-06-01 18:15 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2014-06-01 18:15 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2014-06-01 18:15 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-06-01 18:15 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-06-01 18:15 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-06-01 18:15 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2014-06-01 18:15 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2014-06-01 18:15 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\windows\SysWOW64\objsel.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\cngprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\windows\SysWOW64\adprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\capiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\dimsroam.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wincredprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-06-01 18:15 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2014-06-01 18:11 - 2014-06-09 10:40 - 00000000 ____D () C:\ProgramData\VirtualizedApplications
2014-06-01 16:12 - 2014-06-01 16:12 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-u-05.AAM
2014-05-31 17:37 - 2014-05-31 17:37 - 00003111 _____ () C:\Users\wh\Downloads\2-09384-r-06.AAM
2014-05-28 17:26 - 2014-05-28 17:26 - 00003279 _____ () C:\Users\wh\Downloads\2-09399-r-05.AAM
2014-05-25 12:23 - 2014-05-25 12:23 - 00003255 _____ () C:\Users\wh\Downloads\2-09399-u-04.AAM
2014-05-24 13:35 - 2014-06-15 16:53 - 00000000 ____D () C:\ProgramData\DigiSiAAVere
2014-05-23 20:33 - 2014-06-15 16:53 - 00000000 ____D () C:\ProgramData\ExxsTrauSavings
2014-05-22 20:02 - 2014-05-22 20:02 - 00000000 ____D () C:\ProgramData\Sun
2014-05-22 20:02 - 2014-05-22 20:02 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-22 20:01 - 2014-05-22 20:01 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-22 20:01 - 2014-05-22 20:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-22 20:01 - 2014-05-22 20:01 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-22 20:00 - 2014-05-22 20:00 - 00921512 _____ (Oracle Corporation) C:\Users\wh\Downloads\chromeinstall-7u55.exe
2014-05-22 19:53 - 2014-05-22 19:53 - 00003471 _____ () C:\Users\wh\Downloads\2-09399-r-04.AAM
2014-05-21 08:59 - 2014-05-21 08:59 - 00005593 _____ () C:\Users\wh\Downloads\wpkey_v1.4.7d.zip
2014-05-21 07:45 - 2014-05-21 07:45 - 00003375 _____ () C:\Users\wh\Downloads\2-09399-j-03.AAM
2014-05-21 07:45 - 2014-05-21 07:45 - 00003135 _____ () C:\Users\wh\Downloads\2-09399-u-03.AAM
2014-05-19 20:29 - 2014-05-19 20:29 - 00000000 ____D () C:\Users\wh\AppData\Roaming\SoftGrid Client
2014-05-19 20:29 - 2014-05-19 20:29 - 00000000 ____D () C:\Users\wh\AppData\Local\SoftGrid Client
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (Deutsch)
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2014-05-19 20:27 - 2014-05-19 20:30 - 00000000 ____D () C:\Users\wh\AppData\Roaming\TP
2014-05-16 23:30 - 2014-05-16 23:30 - 00003087 _____ () C:\Users\wh\Downloads\2-09399-j-36.AAM

==================== One Month Modified Files and Folders =======

2014-06-15 17:27 - 2014-06-15 17:27 - 00013039 _____ () C:\Users\wh\Downloads\FRST.txt
2014-06-15 17:27 - 2014-06-15 17:27 - 00000000 ____D () C:\FRST
2014-06-15 17:27 - 2013-08-28 23:14 - 00000000 ____D () C:\Users\wh\AppData\Local\Temp
2014-06-15 17:26 - 2014-06-15 17:26 - 02081792 _____ (Farbar) C:\Users\wh\Downloads\FRST64.exe
2014-06-15 17:12 - 2009-07-14 06:45 - 00021216 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-15 17:12 - 2009-07-14 06:45 - 00021216 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-15 17:11 - 2012-01-05 08:09 - 00700118 _____ () C:\windows\system32\perfh007.dat
2014-06-15 17:11 - 2012-01-05 08:09 - 00149968 _____ () C:\windows\system32\perfc007.dat
2014-06-15 17:11 - 2009-07-14 07:13 - 01622164 _____ () C:\windows\system32\PerfStringBackup.INI
2014-06-15 17:08 - 2012-01-04 09:25 - 01962745 _____ () C:\windows\WindowsUpdate.log
2014-06-15 17:05 - 2014-02-04 01:27 - 00001098 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-15 17:05 - 2012-01-04 09:30 - 00000000 ____D () C:\ProgramData\Samsung
2014-06-15 17:04 - 2014-04-06 00:05 - 00010987 _____ () C:\windows\setupact.log
2014-06-15 17:04 - 2014-04-06 00:05 - 00009142 _____ () C:\windows\PFRO.log
2014-06-15 17:04 - 2012-01-04 10:02 - 00000000 ____D () C:\windows\fi
2014-06-15 17:04 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-06-15 17:04 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\Registration
2014-06-15 16:53 - 2014-05-24 13:35 - 00000000 ____D () C:\ProgramData\DigiSiAAVere
2014-06-15 16:53 - 2014-05-23 20:33 - 00000000 ____D () C:\ProgramData\ExxsTrauSavings
2014-06-15 16:53 - 2014-03-23 19:42 - 00000000 ____D () C:\ProgramData\DealEEXpress
2014-06-15 16:53 - 2014-03-16 01:11 - 00000000 ____D () C:\ProgramData\safeweb
2014-06-15 16:53 - 2014-03-16 01:11 - 00000000 ____D () C:\Program Files (x86)\safeweb
2014-06-15 16:44 - 2014-06-15 16:44 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-15 16:43 - 2014-06-15 16:43 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\wh\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-15 16:43 - 2014-06-15 16:43 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-06-15 16:38 - 2014-02-04 01:27 - 00001102 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-15 13:34 - 2014-03-30 20:04 - 00000000 ____D () C:\ProgramData\Assistant
2014-06-15 12:53 - 2014-06-15 12:53 - 00859992 _____ () C:\Users\wh\Downloads\snlTCNTplugins01.zip
2014-06-15 12:46 - 2014-03-14 21:41 - 00000000 ____D () C:\Users\wh\AppData\Roaming\UseNeXT
2014-06-15 12:41 - 2014-03-14 21:41 - 00000000 ____D () C:\Users\wh\Documents\UseNeXT
2014-06-15 11:34 - 2014-06-14 20:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-15 00:50 - 2014-06-15 00:50 - 00000990 _____ () C:\windows\wininit.ini
2014-06-14 20:36 - 2014-06-14 20:35 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-06-14 20:35 - 2014-06-14 20:35 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-14 20:33 - 2014-06-14 20:33 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\wh\Downloads\spybot-2.3.exe
2014-06-12 20:31 - 2014-06-12 20:31 - 00000000 ____D () C:\ProgramData\NewiSSAVer
2014-06-12 20:31 - 2014-03-16 01:11 - 00000000 ____D () C:\ProgramData\8e2932845b0d7fdc
2014-06-11 15:02 - 2009-07-14 07:08 - 00011920 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-06-11 14:51 - 2014-03-05 15:54 - 00000000 ____D () C:\windows\system32\MRT
2014-06-11 14:49 - 2014-03-05 15:54 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-06-11 14:47 - 2014-06-09 11:09 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-06-10 20:03 - 2014-04-18 14:32 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0 apoEdition
2014-06-10 19:56 - 2013-08-28 23:15 - 00000000 ___RD () C:\Users\wh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-10 19:56 - 2013-08-28 23:15 - 00000000 ___RD () C:\Users\wh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-06-09 11:09 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-06-09 10:48 - 2014-06-09 10:48 - 00000056 _____ () C:\Users\wh\Downloads\heavy-metal.m3u
2014-06-09 10:40 - 2014-06-01 18:11 - 00000000 ____D () C:\ProgramData\VirtualizedApplications
2014-06-08 11:13 - 2014-06-10 20:09 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-10 20:09 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-03 21:33 - 2014-06-03 21:33 - 00003279 _____ () C:\Users\wh\Downloads\2-09399-g-06.AAM
2014-06-02 20:14 - 2014-06-02 20:14 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-r-06.AAM
2014-06-01 16:12 - 2014-06-01 16:12 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-u-05.AAM
2014-06-01 16:08 - 2014-02-08 03:03 - 00000000 ____D () C:\Users\wh\AppData\Roaming\Skype
2014-06-01 11:51 - 2013-08-29 00:04 - 00000000 ____D () C:\Users\wh\AppData\Roaming\vlc
2014-05-31 17:37 - 2014-05-31 17:37 - 00003111 _____ () C:\Users\wh\Downloads\2-09384-r-06.AAM
2014-05-30 12:21 - 2014-06-10 20:09 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-10 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-10 20:09 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-10 20:09 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-10 20:09 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-10 20:09 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-10 20:09 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-10 20:09 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-10 20:09 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-10 20:09 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-10 20:09 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-10 20:09 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-10 20:09 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-10 20:09 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-10 20:09 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-10 20:09 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-10 20:09 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-10 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-10 20:09 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-10 20:09 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-10 20:09 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-10 20:09 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-10 20:09 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-10 20:09 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-10 20:09 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-10 20:09 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-10 20:09 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-10 20:09 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-10 20:09 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-10 20:09 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-10 20:09 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-10 20:09 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-10 20:09 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-05-30 10:25 - 2014-03-16 11:45 - 00000000 ____D () C:\Users\wh\AppData\Local\CrashDumps
2014-05-30 10:24 - 2014-06-10 20:09 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-10 20:09 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-10 20:09 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-10 20:09 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-10 20:09 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-10 20:09 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-10 20:09 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-10 20:09 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-10 20:09 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-10 20:09 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-10 20:09 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-10 20:09 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-10 20:09 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-10 20:09 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-10 20:09 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-10 20:09 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-10 20:09 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-10 20:09 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-10 20:09 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-05-28 17:26 - 2014-05-28 17:26 - 00003279 _____ () C:\Users\wh\Downloads\2-09399-r-05.AAM
2014-05-25 12:23 - 2014-05-25 12:23 - 00003255 _____ () C:\Users\wh\Downloads\2-09399-u-04.AAM
2014-05-22 20:02 - 2014-05-22 20:02 - 00000000 ____D () C:\ProgramData\Sun
2014-05-22 20:02 - 2014-05-22 20:02 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-22 20:01 - 2014-05-22 20:01 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-22 20:01 - 2014-05-22 20:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-22 20:01 - 2014-05-22 20:01 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-22 20:00 - 2014-05-22 20:00 - 00921512 _____ (Oracle Corporation) C:\Users\wh\Downloads\chromeinstall-7u55.exe
2014-05-22 19:53 - 2014-05-22 19:53 - 00003471 _____ () C:\Users\wh\Downloads\2-09399-r-04.AAM
2014-05-21 08:59 - 2014-05-21 08:59 - 00005593 _____ () C:\Users\wh\Downloads\wpkey_v1.4.7d.zip
2014-05-21 07:45 - 2014-05-21 07:45 - 00003375 _____ () C:\Users\wh\Downloads\2-09399-j-03.AAM
2014-05-21 07:45 - 2014-05-21 07:45 - 00003135 _____ () C:\Users\wh\Downloads\2-09399-u-03.AAM
2014-05-19 20:30 - 2014-05-19 20:27 - 00000000 ____D () C:\Users\wh\AppData\Roaming\TP
2014-05-19 20:29 - 2014-05-19 20:29 - 00000000 ____D () C:\Users\wh\AppData\Roaming\SoftGrid Client
2014-05-19 20:29 - 2014-05-19 20:29 - 00000000 ____D () C:\Users\wh\AppData\Local\SoftGrid Client
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (Deutsch)
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2014-05-19 20:28 - 2012-01-04 09:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-05-19 20:28 - 2012-01-04 09:29 - 01649782 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2014-05-19 20:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-05-16 23:30 - 2014-05-16 23:30 - 00003087 _____ () C:\Users\wh\Downloads\2-09399-j-36.AAM

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-09 11:27

==================== End Of Log ============================





und Malwarebytes:


header>

<date>2014/06/15 16:45:10 +0200</date>

<logfile>mbam-log-2014-06-15 (16-44-52).xml</logfile>

<isadmin>yes</isadmin>

</header>


-<engine>

<version>2.00.2.1012</version>

<malware-database>v2014.06.15.03</malware-database>

<rootkit-database>v2014.06.02.01</rootkit-database>

<license>free</license>

<file-protection>disabled</file-protection>

<web-protection>disabled</web-protection>

<self-protection>disabled</self-protection>

</engine>


-<system>

<osversion>Windows 7 Service Pack 1</osversion>

<arch>x64</arch>

<username>wh</username>

<filesys>NTFS</filesys>

</system>


-<summary>

<type>threat</type>

<result>completed</result>

<objects>283570</objects>

<time>459</time>

<processes>1</processes>

<modules>0</modules>

<keys>58</keys>

<values>0</values>

<datas>0</datas>

<folders>1</folders>

<files>18</files>

<sectors>0</sectors>

</summary>


-<options>

<memory>enabled</memory>

<startup>enabled</startup>

<filesystem>enabled</filesystem>

<archives>enabled</archives>

<rootkits>disabled</rootkits>

<deeprootkit>disabled</deeprootkit>

<heuristics>enabled</heuristics>

<pup>enabled</pup>

<pum>enabled</pum>

</options>


-<items>


-<process>

<path>C:\ProgramData\SnowApp\SW-Booster\SW-Booster.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>delete-on-reboot</action>

<pid>3020</pid>

<hash>b50ad6a26a1167cf3ae7e154dc255ca4</hash>

</process>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\S-5121721648</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>b50ad6a26a1167cf3ae7e154dc255ca4</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\safewebo.safewebo</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\safewebo.safewebo.1.1</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\safewebo.safewebo</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\safewebo.safewebo.1.1</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{34A9B414-3293-B5DA-1593-4E442618C1DA}\INPROCSERVER32</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\DigiSauvEr.DigiSauvEr</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\DigiSauvEr.DigiSauvEr.6.7</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\DigiSauvEr.DigiSauvEr</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\DigiSauvEr.DigiSauvEr.6.7</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}\INPROCSERVER32</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\DealExPress.DealExPress</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\DealExPress.DealExPress.2.1</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealExPress.DealExPress</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealExPress.DealExPress.2.1</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}\INPROCSERVER32</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\EExstRaaSaavingus.EExstRaaSaavingus</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\EExstRaaSaavingus.EExstRaaSaavingus.4.2</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\EExstRaaSaavingus.EExstRaaSaavingus</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\EExstRaaSaavingus.EExstRaaSaavingus.4.2</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}\INPROCSERVER32</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{25F259ED-12F6-429F-5783-527C3E2F8586}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a31c5226e9920135c4ba3f0ec93819e7</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7223EDAC-E091-B3C1-BD91-B66CE557800F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>457a3b3d9dde1b1bd0aebb926899f010</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{C637A71C-A4B2-4B47-1B2A-1042A8D525A3}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>ead5a5d3b9c286b08fef2726639e966a</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{497C131E-2032-051B-B32A-C69A960FBB13}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>3b84770188f3dd596b1360ed37ca6799</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4820778D-AB0D-6D18-C316-52A6A0E1D507}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cbf4a0d82b5048ee8cf2490434cd2ed2</hash>

</key>


-<folder>

<path>C:\ProgramData\YoutubeAdblocker</path>

<vendor>PUP.Optional.YoutubeAdblocker.A</vendor>

<action>success</action>

<hash>97280870a8d363d350e4662753afdb25</hash>

</folder>


-<file>

<path>C:\ProgramData\SnowApp\SW-Booster\SW-Booster.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>delete-on-reboot</action>

<hash>b50ad6a26a1167cf3ae7e154dc255ca4</hash>

</file>


-<file>

<path>C:\Program Files (x86)\safeweb\r.x64.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</file>


-<file>

<path>C:\Program Files (x86)\safeweb\r.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</file>


-<file>

<path>C:\ProgramData\DigiSiAAVere\k_9XP5.x64.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</file>


-<file>

<path>C:\ProgramData\DigiSiAAVere\k_9XP5.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</file>


-<file>

<path>C:\ProgramData\DealEEXpress\0l4ge5cbC.x64.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</file>


-<file>

<path>C:\ProgramData\DealEEXpress\0l4ge5cbC.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</file>


-<file>

<path>C:\ProgramData\ExxsTrauSavings\0IX5N.x64.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</file>


-<file>

<path>C:\ProgramData\ExxsTrauSavings\0IX5N.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</file>


-<file>

<path>C:\ProgramData\DealEEXpress\0l4ge5cbC.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a31c5226e9920135c4ba3f0ec93819e7</hash>

</file>


-<file>

<path>C:\ProgramData\DigiSiAAVere\k_9XP5.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>457a3b3d9dde1b1bd0aebb926899f010</hash>

</file>


-<file>

<path>C:\ProgramData\ExxsTrauSavings\0IX5N.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>ead5a5d3b9c286b08fef2726639e966a</hash>

</file>


-<file>

<path>C:\ProgramData\safeweb\Fo.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>3b84770188f3dd596b1360ed37ca6799</hash>

</file>


-<file>

<path>C:\ProgramData\YoutubeAdblocker\9misNOTlm.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cbf4a0d82b5048ee8cf2490434cd2ed2</hash>

</file>


-<file>

<path>C:\Users\wh\Downloads\UltimateCodec.exe</path>

<vendor>PUP.Optional.InstallCore</vendor>

<action>success</action>

<hash>b30c91e7d9a24fe7ba9aaf9e966e768a</hash>

</file>


-<file>

<path>C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage</path>

<vendor>PUP.Optional.Superfish.A</vendor>

<action>success</action>

<hash>e6d9a7d17b00053111843f695ba79070</hash>

</file>


-<file>

<path>C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal</path>

<vendor>PUP.Optional.Superfish.A</vendor>

<action>success</action>

<hash>f7c8a0d82853a294aee77236cd3516ea</hash>

</file>


-<file>

<path>C:\Windows\Tasks\SW-Booster-S-5121721648.job</path>

<vendor>PUP.Optional.SWBooster.A</vendor>

<action>success</action>

<hash>c4fbc5b3df9c9a9c39f78d269072867a</hash>

</file>

</items>

</mbam-log>


Kann mir jemand helfen?

 

Themen zu Bekomme "search.gadgetbox" nicht weg
administrator, bingbar, browser, desktop, explorer, explorer.exe, free, google, helper, homepage, ics, internet, logfile, microsoft, realtek, registry, safer networking, schädling, secur, seite, services.exe, software, starmoney, svchost.exe, system, system32, tracker, win32, windows




Ähnliche Themen: Bekomme "search.gadgetbox" nicht weg


  1. Fehlerhinweis "Ungültiges Bild" unter WINDOWS 7: "C:\PROGRA~2\SEARCH~2\SEARCH~1\bin\VC32LO~1.DLL" +
    Log-Analyse und Auswertung - 19.04.2015 (9)
  2. Ich bekomme "positive finds ads" nicht von meinem Rechner
    Plagegeister aller Art und deren Bekämpfung - 03.03.2015 (7)
  3. es bleibt eine Maske " Driver restore " stehen, die bekomme ich nicht wieder weg.
    Log-Analyse und Auswertung - 13.02.2015 (1)
  4. Diverse Malware ("CoolSaleCoupon", "ddownlloaditkeep", "omiga-plus", "SaveSense", "SaleItCoupon"); lahmer PC & viel Werbung!
    Plagegeister aller Art und deren Bekämpfung - 11.01.2015 (16)
  5. Ich bekomme "Click to continue - smartshopping" nicht runter vom PC
    Log-Analyse und Auswertung - 06.11.2014 (1)
  6. Windows XP Nach Installation von HP Player immer zwei Startseiten beim Öffnen von Google chrome "start.iminent.com" und "Search gol"
    Log-Analyse und Auswertung - 08.10.2013 (5)
  7. "NAV-Links" und "Certified-Toolbar (Search)" rauben mir den letzten Nerv! Was tun?
    Log-Analyse und Auswertung - 23.08.2013 (8)
  8. Ich habe jetzt auch "Browse to Save" Werbebanner und bekomme diese nicht weg!
    Plagegeister aller Art und deren Bekämpfung - 04.02.2013 (20)
  9. Bekomme "Trojan-gameThief.win32.magania.bevf" nicht gebändigt
    Plagegeister aller Art und deren Bekämpfung - 21.10.2012 (1)
  10. Bekomme "Trojan-gameThief.win32.magania.bevf" nicht gebändigt
    Plagegeister aller Art und deren Bekämpfung - 16.10.2012 (29)
  11. Bekomme Meldung "Troj/JSRedir-HZ" und "MW:JS:JJ677"
    Plagegeister aller Art und deren Bekämpfung - 15.10.2012 (42)
  12. Bekomme "Trojan-gameThief.win32.magania.bevf" nicht gebändigt
    Alles rund um Windows - 19.08.2012 (2)
  13. bekomme Virus "TR/Crypt.ZPACK.Gen" nicht los
    Plagegeister aller Art und deren Bekämpfung - 04.05.2010 (10)
  14. Bekomme "Your Computer is infected" nicht weg!
    Plagegeister aller Art und deren Bekämpfung - 26.04.2009 (10)
  15. Bekomme "http://default.home/" und "ACCESS BLOCKED - VIRUS WARNING" nicht mehr los
    Log-Analyse und Auswertung - 16.01.2005 (5)
  16. Bekomme Hijack"Pleasure Zone" nicht weg! Hilfe!
    Log-Analyse und Auswertung - 20.07.2004 (1)
  17. Bekomme "Home Search" net weg!
    Plagegeister aller Art und deren Bekämpfung - 17.06.2004 (5)

Zum Thema Bekomme "search.gadgetbox" nicht weg - Habe mir den Schädling gadgetbox eingefangen. Internet sehr langsam. Startseite nun nicht mehr google sondern gadgetbox. Hatte erst Spybot laufen lassen, dann Malwarebytes. Zum Schluss nun FRST. Hier die logs: - Bekomme "search.gadgetbox" nicht weg...
Archiv
Du betrachtest: Bekomme "search.gadgetbox" nicht weg auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.