|
Plagegeister aller Art und deren Bekämpfung: Virus? Firefox öffnet unaufgefordert neue SeitenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
26.06.2014, 13:07 | #1 |
| Virus? Firefox öffnet unaufgefordert neue Seiten Hallo! Unser Latop ist relativ neu. Wir haben uns einige Programme aus dem Internet runtergeladen, dabei scheint sich ein Virus eingeschlichen zu haben. Unser Virusprogramm findet allerdings nichts. Und zwar öffnen sich beim surfen einfach Seiten. Meistens sind das Hinweise, wonach wir angblich z.B. den Media Player aktualisieren sollen. Ich denke allerdings nicht, dass der Media Player wirklich dafür verantwortlich ist. Ich hoffe, ich hab jetzt nicht zu viel geschrieben und ihr könnt mir helfen. Ich hätte gern schon irgendwas gescannt, falls ihr was braucht, aber ehrlich gesagt, seh ich hier noch nicht richtig durch, obwohl ihr mir schonmal geholfen habt. LG Tara |
26.06.2014, 13:30 | #2 |
/// the machine /// TB-Ausbilder | Virus? Firefox öffnet unaufgefordert neue Seiten hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
26.06.2014, 14:41 | #3 |
| Virus? Firefox öffnet unaufgefordert neue Seiten FRST - Editor
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014 Ran by sebastian (administrator) on GHOTS on 26-06-2014 15:38:10 Running from C:\Users\sebastian\Pictures Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe () C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe (Client Connect LTD) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (Client Connect LTD) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe (Client Connect LTD) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe (Reimage®) C:\Program Files\Reimage\Reimage Express\ReiGuard.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Runonce: [reimageexpresslqhf] - [X] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-398813873-3760832578-3833595727-1002\...\RunOnce: [Uninstall C:\Users\sebastian\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220\amd64] - C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\sebastian\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220\amd64" AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [220480 2014-06-23] (Client Connect LTD) AppInit_DLLs: C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL => C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL File Not Found AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation) AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [181568 2014-06-23] (Client Connect LTD) AppInit_DLLs-x32: c:\progra~2\amazon\amazon~1\\amazon~3.dll => "c:\progra~2\amazon\amazon~1\\amazon~3.dll" File Not Found AppInit_DLLs-x32: ,C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV= StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO: V-bates - {21EAF666-26B3-4a3c-ABD0-CA2F5A326744} - C:\Program Files\V-bates\Extension64.dll No File BHO: The Amazon 1Button App for IE - {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} - C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonAppIE64.dll No File BHO-x32: V-bates - {21EAF666-26B3-4a3c-ABD0-CA2F5A326744} - C:\Program Files\V-bates\Extension32.dll No File BHO-x32: The Amazon 1Button App for IE - {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} - C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonAppIE.dll No File Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default FF NewTab: hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0 FF DefaultSearchEngine: Trovi search FF SearchEngineOrder.1: Amazon FF SelectedSearchEngine: Trovi search FF Homepage: hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV= FF Keyword.URL: hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p23_serp_ff_de_display?ie=UTF8&tagbase=bds-p23&tag=bds-p23-serp-de-ff-21&tbrId=v1_abb-channel-23_71ca4b1b0fab486b8631b54e7091ae6a_39_1006_20140406_DE_ff_ab_adppi15&query= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\searchplugins\amazon.xml FF SearchPlugin: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\searchplugins\default-search.xml FF SearchPlugin: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\searchplugins\trovi-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\webssearches.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: MediaPlayerplus - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com [2014-05-21] FF Extension: Plus-HD-V1.3 - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\ba9147e3-ae8c-4ced-9c9a-240425bd7d8e@6ddffb66-c974-42d7-8752-9e6a4ec073b0.com [2014-06-26] FF Extension: Freeven Pro 1.3 - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\e20dc619-d8c4-48f1-ae07-641cefb43165@3c4d943f-ad97-4f6e-aa94-d9671175a3d0.com [2014-04-04] FF Extension: HQ-Video-Pro-1.9 - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com [2014-04-04] FF Extension: video MediaPlayer - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\ff806580-6db3-4c09-ba06-d6caf0e99172@8453cb25-7fef-4ed5-8934-b08be5605617.com [2014-06-26] FF Extension: BuenoSearch - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\ffxtlbr@buenosearch.com [2014-04-03] FF Extension: CoupExteNSion - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\jyaiu@yiyyw.org [2014-06-26] FF Extension: CostMin - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\qfswxw@rwqvf.edu [2014-06-19] FF Extension: Quick Start - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\quick_start@gmail.com [2014-06-19] FF Extension: Settings Manager - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\{34FA153F-3A2C-364C-E68F-3F8A21AA8D9D} [2014-06-19] FF Extension: Amazon 1Button App for Firefox - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\abb@amazon.com.xpi [2014-01-31] FF Extension: Adblock Plus - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-04] FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi FF HKCU\...\Firefox\Extensions: [{c1f9049a-3290-4967-9a3d-448f242ce94c}] - C:\Program Files (x86)\Re-markit Corp\158.xpi FF Extension: Re-markit - C:\Program Files (x86)\Re-markit Corp\158.xpi [2014-04-04] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19] CHR Extension: (No Name) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpieepnfhpcpkjklohnpmmmmdhcbmd [2014-06-19] ==================== Services (Whitelisted) ================= R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS) R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2832704 2014-06-23] (Client Connect LTD) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 ReimageRealTimeProtection; C:\Program Files\Reimage\Reimage Express\ReiGuard.exe [5100384 2014-04-27] (Reimage®) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation) S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X] S2 V-bates Updater; C:\Program Files\V-bates\ExtensionUpdaterService.exe [X] S2 vosr; C:\Users\sebastian\AppData\Roaming\VOPackage\VOsrv.exe [X] ==================== Drivers (Whitelisted) ==================== R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61120 2014-04-04] (StdLib) R3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-26 15:38 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST 2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express 2014-06-26 13:48 - 2014-06-26 13:48 - 00000000 ____D () C:\Program Files\Reimage 2014-06-26 13:47 - 2014-06-26 13:47 - 00000000 _____ () C:\END 2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini 2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml 2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe 2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-26 06:00 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\CCOupExettension 2014-06-21 22:36 - 2014-06-26 13:48 - 00000000 ____D () C:\Program Files (x86)\SearchProtect 2014-06-21 22:36 - 2014-06-21 22:36 - 00000000 ____D () C:\Users\sebastian\AppData\Local\SearchProtect 2014-06-20 18:08 - 2014-06-23 21:49 - 00002004 _____ () C:\Windows\PFRO.log 2014-06-19 17:35 - 2014-06-19 17:35 - 00000000 ____D () C:\Users\sebastian\AppData\Local\freeSOFTtoday 2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS 2014-06-19 17:31 - 2014-06-19 17:31 - 00000000 ____D () C:\ProgramData\374311380 2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-06-19 16:02 - 2014-06-26 12:26 - 00000000 ____D () C:\Users\sebastian\AppData\Local\PennyBee 2014-06-19 16:02 - 2014-06-19 16:02 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\Settings Manager 2014-06-19 16:02 - 2014-06-19 16:02 - 00000000 ____D () C:\Program Files (x86)\Settings Manager 2014-06-19 15:32 - 2014-06-19 15:32 - 00623616 _____ (Click Me In Limited) C:\Users\sebastian\AppData\Local\nsgF480.tmp 2014-06-19 15:32 - 2014-06-19 15:32 - 00002918 _____ () C:\Users\sebastian\AppData\Roaming\aps.scan.results 2014-06-19 15:32 - 2014-06-19 15:32 - 00001150 _____ () C:\Users\sebastian\AppData\Roaming\aps.scan.quick.results 2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB 2014-06-19 14:22 - 2014-06-26 12:33 - 00000000 ____D () C:\ProgramData\WindowsProtectManger 2014-06-19 14:22 - 2014-06-26 12:33 - 00000000 ____D () C:\ProgramData\IePluginServices 2014-06-19 14:22 - 2014-06-26 12:33 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-06-19 14:22 - 2014-06-26 12:29 - 00000000 ____D () C:\Program Files (x86)\video MediaPlayer 2014-06-19 14:22 - 2014-06-26 12:29 - 00000000 ____D () C:\Program Files (x86)\HQ-V1.3 2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\Documents\Optimizer Pro 2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\SupTab 2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\AppData\Local\globalUpdate 2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Program Files (x86)\globalUpdate 2014-06-19 14:21 - 2014-06-26 12:29 - 00000000 ____D () C:\Program Files (x86)\fst_de_47 2014-06-19 14:21 - 2014-06-26 12:29 - 00000000 ____D () C:\Program Files (x86)\CostMin 2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6 2014-06-19 14:21 - 2014-06-26 12:26 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage 2014-06-19 14:21 - 2014-06-25 06:38 - 00000000 ____D () C:\Users\sebastian\AppData\Local\fst_de_47 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Torch 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Chromatic Browser 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Torch 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Chromatic Browser 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Torch 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Chromatic Browser 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\CostMin ==================== One Month Modified Files and Folders ======= 2014-06-26 15:38 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST 2014-06-26 15:31 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache 2014-06-26 14:32 - 2014-04-06 16:22 - 01241162 _____ () C:\Windows\WindowsUpdate.log 2014-06-26 14:25 - 2014-04-03 19:25 - 00000318 _____ () C:\Windows\Tasks\AppCloudUpdater.job 2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002 2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express 2014-06-26 13:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-26 13:48 - 2014-06-26 13:48 - 00000000 ____D () C:\Program Files\Reimage 2014-06-26 13:48 - 2014-06-21 22:36 - 00000000 ____D () C:\Program Files (x86)\SearchProtect 2014-06-26 13:47 - 2014-06-26 13:47 - 00000000 _____ () C:\END 2014-06-26 13:46 - 2014-05-20 06:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 13:46 - 2014-04-04 19:29 - 00001450 _____ () C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-1.job 2014-06-26 13:45 - 2014-04-04 19:28 - 00002210 _____ () C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-4.job 2014-06-26 13:45 - 2014-04-04 19:27 - 00003146 _____ () C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-3.job 2014-06-26 13:44 - 2014-04-03 19:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini 2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB 2014-06-26 13:30 - 2014-04-04 19:29 - 00001346 _____ () C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-2.job 2014-06-26 13:29 - 2014-04-04 19:28 - 00001348 _____ () C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-1.job 2014-06-26 13:27 - 2014-04-04 19:27 - 00002366 _____ () C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-4.job 2014-06-26 13:26 - 2014-04-04 19:26 - 00002790 _____ () C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-3.job 2014-06-26 13:01 - 2014-04-04 19:25 - 00000410 _____ () C:\Windows\Tasks\Re-markit_wd.job 2014-06-26 13:01 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys 2014-06-26 12:59 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-26 12:58 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-06-26 12:57 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-26 12:39 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1 2014-06-26 12:39 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2 2014-06-26 12:33 - 2014-06-19 14:22 - 00000000 ____D () C:\ProgramData\WindowsProtectManger 2014-06-26 12:33 - 2014-06-19 14:22 - 00000000 ____D () C:\ProgramData\IePluginServices 2014-06-26 12:33 - 2014-06-19 14:22 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-06-26 12:32 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian 2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep 2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G 2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2014-06-26 12:29 - 2014-06-19 14:22 - 00000000 ____D () C:\Program Files (x86)\video MediaPlayer 2014-06-26 12:29 - 2014-06-19 14:22 - 00000000 ____D () C:\Program Files (x86)\HQ-V1.3 2014-06-26 12:29 - 2014-06-19 14:21 - 00000000 ____D () C:\Program Files (x86)\fst_de_47 2014-06-26 12:29 - 2014-06-19 14:21 - 00000000 ____D () C:\Program Files (x86)\CostMin 2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-06-26 12:27 - 2014-06-26 06:00 - 00000000 ____D () C:\ProgramData\CCOupExettension 2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6 2014-06-26 12:26 - 2014-06-19 16:02 - 00000000 ____D () C:\Users\sebastian\AppData\Local\PennyBee 2014-06-26 12:26 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage 2014-06-26 12:25 - 2014-04-06 15:58 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\Systweak 2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration 2014-06-25 06:38 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\fst_de_47 2014-06-24 19:59 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-06-23 21:49 - 2014-06-20 18:08 - 00002004 _____ () C:\Windows\PFRO.log 2014-06-21 22:36 - 2014-06-21 22:36 - 00000000 ____D () C:\Users\sebastian\AppData\Local\SearchProtect 2014-06-19 17:35 - 2014-06-19 17:35 - 00000000 ____D () C:\Users\sebastian\AppData\Local\freeSOFTtoday 2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS 2014-06-19 17:31 - 2014-06-19 17:31 - 00000000 ____D () C:\ProgramData\374311380 2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-06-19 16:02 - 2014-06-19 16:02 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\Settings Manager 2014-06-19 16:02 - 2014-06-19 16:02 - 00000000 ____D () C:\Program Files (x86)\Settings Manager 2014-06-19 15:32 - 2014-06-19 15:32 - 00623616 _____ (Click Me In Limited) C:\Users\sebastian\AppData\Local\nsgF480.tmp 2014-06-19 15:32 - 2014-06-19 15:32 - 00002918 _____ () C:\Users\sebastian\AppData\Roaming\aps.scan.results 2014-06-19 15:32 - 2014-06-19 15:32 - 00001150 _____ () C:\Users\sebastian\AppData\Roaming\aps.scan.quick.results 2014-06-19 15:32 - 2014-04-04 20:03 - 00000314 _____ () C:\Users\sebastian\AppData\Roaming\aps.uninstall.scan.results 2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\Documents\Optimizer Pro 2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\SupTab 2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\AppData\Local\globalUpdate 2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Program Files (x86)\globalUpdate 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Torch 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Chromatic Browser 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Torch 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Chromatic Browser 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Torch 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Chromatic Browser 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\CostMin 2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-06-09 12:00 - 2014-04-06 13:40 - 00000272 _____ () C:\Windows\Tasks\AppSafe.job 2014-05-31 07:16 - 2014-04-06 15:42 - 00703992 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-31 07:16 - 2014-04-06 15:42 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl Files to move or delete: ==================== C:\ProgramData\SetStretch.exe C:\ProgramData\SetStretch.VBS ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-24 19:53 ==================== End Of Log ============================ --- --- --- Addition - Editor Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-06-2014 Ran by sebastian at 2014-06-26 15:38:51 Running from C:\Users\sebastian\Pictures Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player Packages (HKCU\...\Adobe Flash Player Packages) (Version: - ) <==== ATTENTION Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 3.4.117.01527 - Alcor Micro Corp.) Alcor Micro USB Card Reader (x32 Version: 3.4.117.01527 - Alcor Micro Corp.) Hidden Amazon 1Button App (x32 Version: 1.0.4 - Amazon) Hidden ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.2.2 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 3.0.4 - ASUS) ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 2.1.4 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 2.01.0005 - ASUS) ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.5 - ASUS) ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5230.52 - CyberLink Corp.) ASUSDVD (x32 Version: 10.0.5230.52 - CyberLink Corp.) Hidden Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0030 - ASUS) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2884 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden Junk Mail filter update (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden LPT System Updater Service (x32 Version: 1.0.0.0 - LPT) Hidden <==== ATTENTION Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64) (Version: 1.0.0.0 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.15.2 (Version: 1.15.2 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.0325 - NVIDIA Corporation) Hidden NVIDIA PhysX System Software 9.13.0325 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0325 - NVIDIA Corporation) NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) Raccolta foto (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6804 - Realtek Semiconductor Corp.) Reimage Protector (HKLM\...\Reimage Protector) (Version: - Reimage) Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.15.10.118 - Client Connect LTD) <==== ATTENTION Shopping Helper Smartbar Engine (HKCU\...\{5455b53d-a019-4d5a-8501-2201234d0ae5}) (Version: 10.215.63.15249 - ReSoft Ltd.) <==== ATTENTION Windows Driver Package - ASUS (ATP) Mouse (01/10/2013 1.0.0.170) (HKLM\...\4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5) (Version: 01/10/2013 1.0.0.170 - ASUS) Windows Live (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.42.0 - ASUS) ==================== Restore Points ========================= 10-06-2014 21:03:02 Windows Update 19-06-2014 11:35:24 Geplanter Prüfpunkt 26-06-2014 10:18:57 Wiederherstellungsvorgang 26-06-2014 11:52:49 Reimage Express Restore Point ==================== Hosts content: ========================== 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {046AB098-8757-429F-A45A-34560CDE705F} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-11-28] (ASUS) Task: {118ECA63-B444-4C6B-ACDD-EA70001C2996} - System32\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-3 => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-3.exe <==== ATTENTION Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2D000AE6-50A7-4810-ABD9-94BD2A983C68} - \RegClean Pro No Task File <==== ATTENTION Task: {4FDAB20D-FBEB-428A-876B-260705A17E82} - System32\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-1 => C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-codedownloader.exe <==== ATTENTION Task: {50CA362E-DD77-492B-A3EF-CD7B44E39027} - \Re-markit Update No Task File <==== ATTENTION Task: {55C7CA32-C53F-45E8-BB08-1EA932922133} - System32\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-1 => C:\Program Files (x86)\HQVid8.1b\HQVid8.1b-codedownloader.exe <==== ATTENTION Task: {701AA13B-6D58-4923-9F4B-D7E32B1D6595} - System32\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-2 => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-2.exe <==== ATTENTION Task: {76E1069C-436A-4C90-AE56-36AA673F4A60} - System32\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-4 => C:\Program Files (x86)\MediaPlayerplus\b8e2dbf6-f651-4529-84b2-6113f5365cc5-4.exe <==== ATTENTION Task: {78C8EFD9-8BDD-4BFD-8251-7B3E62428EC8} - System32\Tasks\Systweak Support Dock => C:\Program Files (x86)\Systweak Support Dock\SystweakDock.exe Task: {79E86E45-CDE9-4F68-8D1B-1FD551407222} - System32\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-4 => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-4.exe <==== ATTENTION Task: {7B9522FD-40CE-4535-8AB6-C5D3E1ADA2A1} - System32\Tasks\ASUS Splendid ColorU => C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [2013-02-26] (ASUSTeK Computer Inc.) Task: {905FFE6D-70A6-44C1-9058-CD47BE06AA54} - \RegClean Pro_DEFAULT No Task File <==== ATTENTION Task: {90BF9536-DE52-4584-911B-074070AFE345} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2013-03-20] (ASUSTeK Computer Inc.) Task: {91CD476A-0DBB-44E4-B8E7-D06C9318CCB9} - \RegClean Pro_UPDATES No Task File <==== ATTENTION Task: {93A2B49F-56B4-4B5F-8313-064C4AACF124} - System32\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-3 => C:\Program Files (x86)\MediaPlayerplus\b8e2dbf6-f651-4529-84b2-6113f5365cc5-3.exe <==== ATTENTION Task: {A408F286-A6C0-4938-AC8C-2CA24BA9A79E} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {AEB90AA0-7FD5-422D-BACA-502B48554C29} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2013-06-19] (ASUS) Task: {B1EFB696-E8A9-45FC-90C1-FDAD4B903950} - System32\Tasks\ASUS InstantOn Config => C:\Program Files\ASUS\P4G\InsOnCfg.exe Task: {B3262ECA-6CA4-41CB-B62E-C1BFA8146D46} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {B680E34E-6844-4054-9EC3-39B382319F09} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.) Task: {BC1F14A4-2461-48B8-AAF2-FDDEF8769442} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {BF1FB413-5000-49CE-8A1B-36239E4C8FBC} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2013-03-20] (ASUSTeK Computer Inc.) Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {CCB636B3-A9F6-4AAB-AEF1-0F8F9B97D176} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-04-29] (AsusTek) Task: {D88F9953-CE70-4A07-9CB3-D2ACF8DAC4BE} - System32\Tasks\Re-markit_wd => C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe [2014-04-04] () <==== ATTENTION Task: {D9F25AF7-06A5-4BD6-B55E-DC91432DB33B} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-04-19] (Microsoft Corporation) Task: {E6C71457-35B0-4F6D-A5FB-2032C39053E0} - System32\Tasks\AppCloudUpdater => C:\Users\SEBAST~1\AppData\Roaming\APPCLO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {E7F4D682-CAC9-4421-B0D8-FE65B6535B13} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-06-26] (Microsoft Corporation) Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {F93511CC-728E-4A08-AEC7-0CAFAE9827C3} - System32\Tasks\AppSafe => C:\Program Files (x86)\AppSafe\AppSafe.exe <==== ATTENTION Task: {FF19C4A5-5389-41E7-AA7F-A5E0CC036656} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-20] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-1.job => C:\Program Files (x86)\HQVid8.1b\HQVid8.1b-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-2.job => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-2.exe <==== ATTENTION Task: C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-3.job => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-3.exe <==== ATTENTION Task: C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-4.job => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-4.exe <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AppCloudUpdater.job => C:\Users\SEBAST~1\AppData\Roaming\APPCLO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\AppSafe.job => C:\Program Files (x86)\AppSafe\AppSafe.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-1.job => C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-3.job => C:\Program Files (x86)\MediaPlayerplus\b8e2dbf6-f651-4529-84b2-6113f5365cc5-3.exe <==== ATTENTION Task: C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-4.job => C:\Program Files (x86)\MediaPlayerplus\b8e2dbf6-f651-4529-84b2-6113f5365cc5-4.exe <==== ATTENTION Task: C:\Windows\Tasks\Re-markit_wd.job => C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe <==== ATTENTION Task: C:\Windows\Tasks\temp_74d52b3c-be80-4a90-bd6c-4b7266540f32-2.job => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-2.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2013-12-10 08:13 - 2013-12-10 08:13 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2013-11-22 15:32 - 2013-10-23 10:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-06-19 22:49 - 2013-06-19 22:49 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll 2014-04-04 19:25 - 2014-04-04 19:25 - 00077312 _____ () C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe 2014-04-04 15:31 - 2014-04-04 15:31 - 00176048 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll 2013-06-28 11:18 - 2012-11-21 10:58 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll 2014-06-22 16:13 - 2014-05-20 06:49 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-12-10 08:13 - 2013-12-10 08:13 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll 2013-11-22 15:38 - 2012-06-25 12:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:373E1720 AlternateDataStreams: C:\ProgramData\Temp:AD022376 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= HKLM\...\StartupApproved\Run32: => "BingDesktop" HKCU\...\StartupApproved\Run: => "PC Speed Maximizer" HKCU\...\StartupApproved\Run: => "Optimizer Pro" ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/26/2014 02:00:00 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (1400) SRUJet: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\Windows\system32\SRU\SRU00237.log. Error: (06/26/2014 01:52:48 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {f972e5a7-0a7d-4c30-9fb6-dbe8a907663f} Error: (06/26/2014 01:38:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: regsvr32.exe, Version: 6.2.9200.16384, Zeitstempel: 0x5010a4f2 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16579, Zeitstempel: 0x51637f77 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000005612 ID des fehlerhaften Prozesses: 0x8ec Startzeit der fehlerhaften Anwendung: 0xregsvr32.exe0 Pfad der fehlerhaften Anwendung: regsvr32.exe1 Pfad des fehlerhaften Moduls: regsvr32.exe2 Berichtskennung: regsvr32.exe3 Vollständiger Name des fehlerhaften Pakets: regsvr32.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: regsvr32.exe5 Error: (06/26/2014 06:00:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 30.0.0.5269, Zeitstempel: 0x53914233 Name des fehlerhaften Moduls: mozalloc.dll, Version: 30.0.0.5269, Zeitstempel: 0x53911393 Ausnahmecode: 0x80000003 Fehleroffset: 0x0000141b ID des fehlerhaften Prozesses: 0xd14 Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Vollständiger Name des fehlerhaften Pakets: plugin-container.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: plugin-container.exe5 Error: (06/25/2014 05:42:28 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (06/23/2014 09:24:36 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (06/20/2014 07:53:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: svchost.exe_SSDPSRV, Version: 6.2.9200.16420, Zeitstempel: 0x505a9a4e Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16579, Zeitstempel: 0x51637f77 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000006b4f ID des fehlerhaften Prozesses: 0x654 Startzeit der fehlerhaften Anwendung: 0xsvchost.exe_SSDPSRV0 Pfad der fehlerhaften Anwendung: svchost.exe_SSDPSRV1 Pfad des fehlerhaften Moduls: svchost.exe_SSDPSRV2 Berichtskennung: svchost.exe_SSDPSRV3 Vollständiger Name des fehlerhaften Pakets: svchost.exe_SSDPSRV4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe_SSDPSRV5 Error: (06/20/2014 05:51:32 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: Bei der Aktivierung der App „Microsoft.BingFinance_8wekyb3d8bbwe!AppexFinance“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (06/20/2014 05:51:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (06/20/2014 05:21:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. System errors: ============= Error: (06/26/2014 00:59:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Service Component of VO" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/26/2014 00:35:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Service Component of VO" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/26/2014 00:19:47 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS) Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Error: (06/26/2014 00:19:47 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS) Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Error: (06/23/2014 09:51:05 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Search Protect Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/23/2014 09:49:05 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (06/23/2014 09:49:05 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (06/23/2014 09:49:01 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (06/23/2014 09:49:01 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (06/20/2014 07:53:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Zeitbroker" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office Sessions: ========================= Error: (06/26/2014 02:00:00 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost1400SRUJet: C:\Windows\system32\SRU\SRU00237.log-1811 (0xfffff8ed) Error: (06/26/2014 01:52:48 PM) (Source: VSS) (EventID: 8194) (User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {f972e5a7-0a7d-4c30-9fb6-dbe8a907663f} Error: (06/26/2014 01:38:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: regsvr32.exe6.2.9200.163845010a4f2ntdll.dll6.2.9200.1657951637f77c000000500000000000056128ec01cf91332d92125fC:\Windows\system32\regsvr32.exeC:\Windows\SYSTEM32\ntdll.dll6b6beba0-fd26-11e3-be84-bcee7bb99978 Error: (06/26/2014 06:00:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe30.0.0.526953914233mozalloc.dll30.0.0.526953911393800000030000141bd1401cf8f1c962465ffC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll70c47d56-fce6-11e3-be87-bcee7bb99978 Error: (06/25/2014 05:42:28 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (06/23/2014 09:24:36 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (06/20/2014 07:53:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: svchost.exe_SSDPSRV6.2.9200.16420505a9a4entdll.dll6.2.9200.1657951637f77c00000050000000000006b4f65401cf8ca1de67f183C:\Windows\system32\svchost.exeC:\Windows\SYSTEM32\ntdll.dllc7f8d47c-f8a3-11e3-be86-bcee7bb99978 Error: (06/20/2014 05:51:32 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: Microsoft.BingFinance_8wekyb3d8bbwe!AppexFinance-2144927141 Error: (06/20/2014 05:51:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2144927141 Error: (06/20/2014 05:21:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2144927141 ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 3981.57 MB Available physical RAM: 2141.06 MB Total Pagefile: 4685.57 MB Available Pagefile: 2803.07 MB Total Virtual: 8192 MB Available Virtual: 8191.76 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:149.97 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:258.34 GB) (Free:258.22 GB) NTFS Drive e: (zahni) (CDROM) (Total:0.69 GB) (Free:0.01 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 0FE4DC0A) Partition: GPT Partition Type. ==================== End Of Log ============================ |
27.06.2014, 07:27 | #4 |
/// the machine /// TB-Ausbilder | Virus? Firefox öffnet unaufgefordert neue Seiten Adware & Co. deinstallieren
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter: Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.06.2014, 16:32 | #5 |
| Virus? Firefox öffnet unaufgefordert neue Seiten Erledigt! Code:
ATTFilter ComboFix 14-06-27.01 - sebastian 27.06.2014 17:21:35.1.4 - x64 Microsoft Windows 8 6.2.9200.0.1252.49.1031.18.3982.2453 [GMT 2:00] ausgeführt von:: c:\users\sebastian\Downloads\ComboFix.exe AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\END c:\program files (x86)\CostMin c:\program files (x86)\CostMin\f0WXJ.dat c:\programdata\374311380 c:\programdata\374311380\BIT86EA.tmp c:\programdata\CostMin c:\programdata\CostMin\qbs3Z3.dat c:\programdata\SetStretch.exe c:\programdata\SetStretch.VBS c:\users\sebastian\AppData\Local\nsgF480.tmp c:\users\sebastian\AppData\Local\nsk8393.tmp c:\users\sebastian\AppData\Local\nstF1C.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2014-05-27 bis 2014-06-27 )))))))))))))))))))))))))))))) . . 2014-06-27 14:48 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AA55453C-46AD-4759-9DCA-8F9E4A1ED89D}\mpengine.dll 2014-06-27 14:45 . 2014-06-27 14:45 -------- d-----w- c:\program files (x86)\VS Revo Group 2014-06-26 15:32 . 2014-06-26 15:32 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2014-06-26 13:38 . 2014-06-26 13:39 -------- d-----w- C:\FRST 2014-06-26 11:56 . 2014-06-26 11:56 -------- d-----w- c:\users\sebastian\AppData\Local\Diagnostics 2014-06-26 11:48 . 2014-06-26 11:55 -------- d-----w- c:\programdata\Reimage Express 2014-06-26 10:52 . 2014-04-03 03:44 619008 ----a-w- c:\windows\system32\drivers\srv2.sys 2014-06-26 10:52 . 2014-04-03 11:19 328024 ----a-w- c:\windows\system32\drivers\Classpnp.sys 2014-06-26 10:52 . 2014-03-24 23:42 305152 ----a-w- c:\windows\SysWow64\wusa.exe 2014-06-26 10:52 . 2014-03-24 22:56 309760 ----a-w- c:\windows\system32\wusa.exe 2014-06-26 10:52 . 2014-04-03 11:22 2233176 ----a-w- c:\windows\system32\drivers\tcpip.sys 2014-06-26 10:52 . 2014-05-03 05:47 3246592 ----a-w- c:\windows\system32\rdpcorets.dll 2014-06-26 10:52 . 2014-05-03 03:34 235520 ----a-w- c:\windows\system32\rdpudd.dll 2014-06-26 10:52 . 2014-04-29 22:32 1301504 ----a-w- c:\windows\system32\gdi32.dll 2014-06-26 10:52 . 2014-04-29 22:22 1023488 ----a-w- c:\windows\SysWow64\gdi32.dll 2014-06-26 10:52 . 2014-03-07 00:47 1419264 ----a-w- c:\windows\SysWow64\msxml3.dll 2014-06-26 10:52 . 2014-03-07 00:08 1845760 ----a-w- c:\windows\system32\msxml3.dll 2014-06-26 04:00 . 2014-06-26 10:27 -------- d-----w- c:\programdata\CCOupExettension 2014-06-21 20:36 . 2014-06-27 15:12 -------- d-----w- c:\program files (x86)\SearchProtect 2014-06-20 08:30 . 2014-06-27 06:00 283312 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10242.bin 2014-06-19 15:35 . 2014-06-19 15:35 -------- d-----w- c:\users\sebastian\AppData\Local\freeSOFTtoday 2014-06-19 15:33 . 2014-06-19 15:33 -------- d-----w- c:\programdata\ASUS 2014-06-19 14:04 . 2014-06-19 14:04 -------- d-----w- c:\programdata\Microsoft SkyDrive 2014-06-19 14:02 . 2014-06-26 10:26 -------- d-----w- c:\users\sebastian\AppData\Local\PennyBee 2014-06-19 14:02 . 2014-06-19 14:02 -------- d-----w- c:\users\sebastian\AppData\Roaming\Settings Manager 2014-06-19 14:02 . 2014-06-19 14:02 -------- d-----w- c:\program files (x86)\Settings Manager 2014-06-19 12:29 . 2014-06-26 11:39 -------- d-----w- c:\programdata\CDB 2014-06-19 12:22 . 2014-06-19 12:22 -------- d-----w- c:\users\sebastian\AppData\Roaming\SupTab 2014-06-19 12:22 . 2014-06-26 10:33 -------- d-----w- c:\programdata\WindowsProtectManger 2014-06-19 12:22 . 2014-06-26 10:33 -------- d-----w- c:\programdata\IePluginServices 2014-06-19 12:22 . 2014-06-26 10:33 -------- d-----w- c:\program files (x86)\SupTab 2014-06-19 12:22 . 2014-06-19 12:22 -------- d-----w- c:\program files (x86)\globalUpdate 2014-06-19 12:22 . 2014-06-19 12:22 -------- d-----w- c:\users\sebastian\AppData\Local\globalUpdate 2014-06-19 12:22 . 2014-06-26 10:29 -------- d-----w- c:\program files (x86)\HQ-V1.3 2014-06-19 12:22 . 2014-06-26 10:29 -------- d-----w- c:\program files (x86)\video MediaPlayer 2014-06-19 12:22 . 2014-06-26 10:25 -------- d-----w- c:\users\sebastian\AppData\Roaming\webssearches . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-06-27 04:14 . 2014-04-03 16:49 62 ----a-w- c:\users\sebastian\AppData\Roaming\sp_data.sys 2014-06-26 10:55 . 2014-04-04 02:58 95414520 ----a-w- c:\windows\system32\MRT.exe 2014-06-19 07:37 . 2014-04-04 12:32 50784 ----a-w- c:\programdata\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin 2014-05-31 05:16 . 2014-04-06 13:42 703992 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-05-31 05:16 . 2014-04-06 13:42 105464 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-04-19 09:39 . 2014-05-06 03:14 628024 ----a-w- c:\windows\system32\NotificationUI.exe 2014-04-19 08:45 . 2014-05-06 03:14 693760 ----a-w- c:\windows\system32\WSShared.dll 2014-04-19 08:45 . 2014-05-06 03:14 163840 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-04-19 06:57 . 2014-05-06 03:14 566784 ----a-w- c:\windows\SysWow64\WSShared.dll 2014-04-19 06:57 . 2014-05-06 03:14 124928 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-04-12 09:27 . 2014-05-20 03:46 172888 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2014-04-12 09:10 . 2014-05-20 03:46 578048 ----a-w- c:\windows\system32\winlogon.exe 2014-04-12 09:09 . 2014-05-20 03:46 208896 ----a-w- c:\windows\system32\wdigest.dll 2014-04-12 09:09 . 2014-05-20 03:46 1043968 ----a-w- c:\windows\system32\usercpl.dll 2014-04-12 09:09 . 2014-05-20 03:46 94720 ----a-w- c:\windows\system32\TSpkg.dll 2014-04-12 09:09 . 2014-05-20 03:46 588288 ----a-w- c:\windows\system32\SHCore.dll 2014-04-12 09:08 . 2014-05-20 03:46 318464 ----a-w- c:\windows\system32\msv1_0.dll 2014-04-12 09:08 . 2014-05-20 03:46 1281536 ----a-w- c:\windows\system32\lsasrv.dll 2014-04-12 09:08 . 2014-05-20 03:46 439808 ----a-w- c:\windows\system32\lsm.dll 2014-04-12 09:08 . 2014-05-20 03:46 827904 ----a-w- c:\windows\system32\kerberos.dll 2014-04-12 09:07 . 2014-05-20 03:46 20480 ----a-w- c:\windows\system32\credssp.dll 2014-04-12 07:23 . 2014-05-20 03:46 178688 ----a-w- c:\windows\SysWow64\wdigest.dll 2014-04-12 07:23 . 2014-05-20 03:46 961536 ----a-w- c:\windows\SysWow64\usercpl.dll 2014-04-12 07:23 . 2014-05-20 03:46 76800 ----a-w- c:\windows\SysWow64\TSpkg.dll 2014-04-12 07:23 . 2014-05-20 03:46 452608 ----a-w- c:\windows\SysWow64\SHCore.dll 2014-04-12 07:23 . 2014-05-20 03:46 273920 ----a-w- c:\windows\SysWow64\msv1_0.dll 2014-04-12 07:22 . 2014-05-20 03:46 666624 ----a-w- c:\windows\SysWow64\kerberos.dll 2014-04-12 07:22 . 2014-05-20 03:46 17408 ----a-w- c:\windows\SysWow64\credssp.dll 2014-04-12 06:58 . 2014-05-20 03:46 14848 ----a-w- c:\windows\system32\workerdd.dll 2014-04-04 12:32 . 2014-04-04 12:32 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin 2014-04-04 03:07 . 2014-04-04 03:07 61120 ----a-w- c:\windows\system32\drivers\wStLibG64.sys 2014-04-03 16:48 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2014-04-03 09:08 . 2014-04-04 17:58 1176896 ----a-w- c:\users\sebastian\AppData\Local\AnyProtectScannerSetup.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2013-04-25 3187360] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2013-03-08 95192] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "SpUninstallCleanUp"="REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect" [X] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) "EnableCursorSuppression"= 1 (0x1) "ConsentPromptBehaviorUser"= 3 (0x3) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc] @="" . 3;4 CltMngSvc;Search Protect Service;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe [x] R2 0204171396638742mcinstcleanup;McAfee Application Installer Cleanup (0204171396638742);c:\users\SEBAST~1\AppData\Local\Temp\020417~1.EXE;c:\users\SEBAST~1\AppData\Local\Temp\020417~1.EXE [x] R2 V-bates Updater;V-bates Updater;c:\program files\V-bates\ExtensionUpdaterService.exe;c:\program files\V-bates\ExtensionUpdaterService.exe [x] R2 vosr;Service Component of VO;c:\users\sebastian\AppData\Roaming\VOPackage\VOsrv.exe;c:\users\sebastian\AppData\Roaming\VOPackage\VOsrv.exe [x] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x] R3 RTL8168;Realtek 8168 NT-Treiber;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x] S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S1 wStLibG64;wStLibG64;c:\windows\system32\drivers\wStLibG64.sys;c:\windows\SYSNATIVE\drivers\wStLibG64.sys [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files\ASUS\P4G\InsOnSrv.exe;c:\program files\ASUS\P4G\InsOnSrv.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AiCharger.sys [x] S3 ATP;ASUS Input Device;c:\windows\System32\drivers\AsusTP.sys;c:\windows\SYSNATIVE\drivers\AsusTP.sys [x] S3 cpuz134;cpuz134;c:\users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys;c:\users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x] S3 HIDSwitch;ASUS Wireless Radio Control;c:\windows\System32\drivers\AsHIDSwitch64.sys;c:\windows\SYSNATIVE\drivers\AsHIDSwitch64.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C63x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C63x64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}] 2013-12-21 06:04 215416 ----a-w- c:\program files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll . Inhalt des "geplante Tasks" Ordners . 2014-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-03 03:50] . 2014-06-27 c:\windows\Tasks\Re-markit_wd.job - c:\program files (x86)\Re-markit Corp\Re-markit_wd.exe [2014-04-04 17:25] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-11-21 171064] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-11-21 399416] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-12-12 13263072] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV= mDefault_Search_URL = hxxp://www.google.com mDefault_Page_URL = hxxp://www.google.com mStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.google.com uSearchAssistant = hxxp://www.google.com TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} - c:\program files\V-bates\Extension32.dll Toolbar-Locked - (no file) BHO-{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} - c:\program files\V-bates\Extension64.dll Toolbar-Locked - (no file) AddRemove-Activeris AntiMalware_is1 - c:\program files (x86)\Activeris AntiMalware\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) @SACL=(02 0000) . Zeit der Fertigstellung: 2014-06-27 17:28:40 ComboFix-quarantined-files.txt 2014-06-27 15:28 . Vor Suchlauf: 9 Verzeichnis(se), 160.733.929.472 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 160.450.875.392 Bytes frei . - - End Of File - - BC54B9EF8A4AB62FB86114D1547CC5B1 |
28.06.2014, 13:48 | #6 |
/// the machine /// TB-Ausbilder | Virus? Firefox öffnet unaufgefordert neue Seiten Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Virus? Firefox öffnet unaufgefordert neue Seiten |
28.06.2014, 21:26 | #7 |
| Virus? Firefox öffnet unaufgefordert neue Seiten mbam.txt Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 28.06.2014 Suchlauf-Zeit: 21:39:43 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.06.28.04 Rootkit Datenbank: v2014.06.23.02 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 8 CPU: x64 Dateisystem: NTFS Benutzer: sebastian Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 334712 Verstrichene Zeit: 11 Min, 21 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe, 2392, Löschen bei Neustart, [3f9596e73744171fc56c2d6d43bf16ea] Module: 0 (No malicious items detected) Registrierungsschlüssel: 33 PUP.Optional.SearchProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarantäne, [e9eb5a23a3d8f442d4c23e53798859a7], PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [fcd84934b2c90f27790a420b5fa39e62], PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, In Quarantäne, [fcd84934b2c90f27790a420b5fa39e62], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [34a06617186367cf0fa13512aa589868], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{708D0DD7-FBC0-4437-B525-C098F450A62C}, In Quarantäne, [e3f181fca3d8d95d3b73341319e9619f], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchHlpr, In Quarantäne, [4f85f08de893b1856b441d668082ef11], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchHlpr.1, In Quarantäne, [ddf70a73e09bbf7700af8bf860a221df], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchHlpr, In Quarantäne, [ddf70a73e09bbf7700af8bf860a221df], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchHlpr.1, In Quarantäne, [ddf70a73e09bbf7700af8bf860a221df], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchdskBnd, In Quarantäne, [399b3746cdaefe38f9b7394aaf5353ad], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchdskBnd.1, In Quarantäne, [e8ecbcc1334815214e625d26f60c20e0], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchdskBnd, In Quarantäne, [e8ecbcc1334815214e625d26f60c20e0], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchdskBnd.1, In Quarantäne, [e8ecbcc1334815214e625d26f60c20e0], PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\V-bates, In Quarantäne, [be163e3f156655e14bb3d0025ca6df21], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\esrv.buenosearchESrvc, In Quarantäne, [2fa5097492e9d66009803a93da28a759], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\esrv.buenosearchESrvc.1, In Quarantäne, [9e366f0eb5c6a88e3a4f0dc0ec16b050], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\buenosearch LTD, In Quarantäne, [3d97463791ea68ce1a6ca726be446b95], PUP.Optional.HQVid.A, HKLM\SOFTWARE\WOW6432NODE\HQVid8.1b, In Quarantäne, [8252a8d5b6c50d292d2cc6f738ca3dc3], PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\MediaPlayerplus, In Quarantäne, [a23258254c2f8fa720c4f3d04bb7659b], PUP.Optional.MegaBrowse.A, HKLM\SOFTWARE\WOW6432NODE\Mega Browse, In Quarantäne, [f8dc5924106bca6c4d0bdfe944be0cf4], PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\WOW6432NODE\V-bates, In Quarantäne, [4a8ad9a49edd8aac0fefb22037cb1de3], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.buenosearchESrvc, In Quarantäne, [05cff38abebd7eb8dfaa903d0200a55b], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.buenosearchESrvc.1, In Quarantäne, [def63a436219eb4b6a1f27a66c9615eb], PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\acfoobbgoakpihljnfedbcfaipcdlfhk, In Quarantäne, [8252a7d6235850e6ad215e92c53e25db], PUP.Optional.Linkury.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}, In Quarantäne, [12c20a73f388a78f21a23e7926dcd62a], PUP.Optional.VbatesHelper.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\V-bates Updater, In Quarantäne, [567eaad32a515dd9ac4fb71b05fddc24], PUP.Optional.Feven.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Freeven Pro 1.3, In Quarantäne, [e1f3700d5c1f84b24550a110ab57738d], PUP.Optional.HQVid.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQVid8.1b, In Quarantäne, [5381c2bbd4a70f27c2958934b15114ec], PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, In Quarantäne, [f1e308755e1d5dd95393982b44bef808], PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\buenosearch LTD, In Quarantäne, [805499e45a21a195dcab1cb1bf439b65], PUP.Optional.MegaBrowse.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Mega Browse, In Quarantäne, [fcd8cab3e39886b0fc5b18b03bc7f60a], PUP.Optional.HQVid.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQVid8.1b, In Quarantäne, [a52fa4d9a1daec4a97c0ba031ee47d83], PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, In Quarantäne, [6c68afce7cff77bf5f87d0f3b9490df3], Registrierungswerte: 1 PUP.Optional.QuickStart.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, quick_start@gmail.com, In Quarantäne, [5c783449dc9f92a46ac8cde2976b7e82] Registrierungsdaten: 8 PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[5480e39a1c5f1125d90aa5e5dc28c33d] PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[ffd5324bde9d7db9ba99ee9cae56b54b] PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS5PD3rJOgw1pGzhTiN_LeZ3h5uqN9RPSYE5jaU9HNvWzyB5Fd9mOdB-PM7Siu3UQ,,, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS5PD3rJOgw1pGzhTiN_LeZ3h5uqN9RPSYE5jaU9HNvWzyB5Fd9mOdB-PM7Siu3UQ,,),Ersetzt,[f8dc14692556e94d33217b0f73915fa1] PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[00d4b1cc6516979f72e05238a55f9a66] PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[775d2c510a71fc3a8cc9800ae81c8c74] PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[cd075825d4a70f2774e25139a85c629e] PUP.Optional.SnapDo.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[963ea1dc3a41c175f3fb4f31a262847c] PUP.Optional.Trovi.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV=),Ersetzt,[f1e3d2ab9eddfb3b31f1c8b857ad8c74] Ordner: 21 PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp, Löschen bei Neustart, [3f9596e73744171fc56c2d6d43bf16ea], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk, In Quarantäne, [8c48d8a577049b9b6a9f910a26dc51af], Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47\1.10, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], Adware.EoRezo, C:\Program Files (x86)\fst_de_47, In Quarantäne, [34a0cbb216656dc94821fba2689ab64a], PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\components, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\content, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [ab295429eb902511a350aefb778bda26], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [ab295429eb902511a350aefb778bda26], PUP.Optional.CrossRider.A, C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpieepnfhpcpkjklohnpmmmmdhcbmd, In Quarantäne, [4f85add01a611c1a68920a9f6c966c94], PUP.Optional.CrossRider.A, C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpieepnfhpcpkjklohnpmmmmdhcbmd\1.26.24_0, In Quarantäne, [4f85add01a611c1a68920a9f6c966c94], PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73], PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73], PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\update, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73], PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], Dateien: 55 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, Löschen bei Neustart, [e9eb5a23a3d8f442d4c23e53798859a7], PUP.Optional.SuperCoolApps, C:\Users\sebastian\Downloads\AdobeFlashPlayer.exe, In Quarantäne, [07cd0f6ea4d752e4d58e73a1ae56c040], PUP.Optional.DomalQ, C:\Users\sebastian\Downloads\Setup_V2.exe, In Quarantäne, [508483fa1764ea4c216aa29ba35d9e62], PUP.Optional.ReMarkIt.A, C:\Windows\Tasks\Re-markit_wd.job, In Quarantäne, [34a065184d2e6cca5062467ff40efc04], PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\158.crx, In Quarantäne, [3f9596e73744171fc56c2d6d43bf16ea], PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\158.xpi, In Quarantäne, [3f9596e73744171fc56c2d6d43bf16ea], PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe, Löschen bei Neustart, [3f9596e73744171fc56c2d6d43bf16ea], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\124.json, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\MessageBox.xml, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\uninstallDlg2.xml, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\bg.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\bg1.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\bk_shadow.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\button.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\button1.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\checkbox.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\checkbox_select.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\checked.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\close.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\loading_bg.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\loading_light.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\min.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\scrollbar.bmp, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\Thumbs.db, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\unchecked.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code1.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code2.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code3.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code4.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code5.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code6.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\Thumbs.db, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\upfst_de_47.cyl, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\user_profil.cyp, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47\1.10\cnf.cyl, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47\1.10\eorezo.cyl, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], Adware.EoRezo, C:\Program Files (x86)\fst_de_47\unins000.dat, In Quarantäne, [34a0cbb216656dc94821fba2689ab64a], Adware.EoRezo, C:\Program Files (x86)\fst_de_47\unins000.msg, In Quarantäne, [34a0cbb216656dc94821fba2689ab64a], PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\install.rdf, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF.xpt, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\content\overlay.xul, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [ab295429eb902511a350aefb778bda26], PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\1293297481.mxaddon, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\360-58360.crx, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\58360.crx, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\58360.xpi, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\59d0aba1-9438-4ba8-979a-e06b975a27f4.crx, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\background.html, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log\wprotectmanager_2014-06-19[14-22-42-729].log, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73], PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\1293297481.mxaddon, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\360-59599.crx, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\59599.crx, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\59599.xpi, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\background.html, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\d5da2132-5fc4-4df1-9e78-5533f7681ac1.crx, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.213 - Bericht erstellt am 28/06/2014 um 22:01:11 # Aktualisiert 23/06/2014 von Xplode # Betriebssystem : Windows 8 (64 bits) # Benutzername : sebastian - GHOTS # Gestartet von : C:\Users\sebastian\Downloads\adwcleaner_3.213.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : vosr Dienst Gelöscht : wStLibG64 ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\CCOupExettension Ordner Gelöscht : C:\Program Files (x86)\globalUpdate Ordner Gelöscht : C:\Program Files (x86)\Settings Manager Ordner Gelöscht : C:\Program Files (x86)\SupTab Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Chromatic Browser Ordner Gelöscht : C:\Users\Administrator\AppData\Local\torch Ordner Gelöscht : C:\Users\Gast\AppData\Local\Chromatic Browser Ordner Gelöscht : C:\Users\Gast\AppData\Local\torch Ordner Gelöscht : C:\Users\sebastian\AppData\Local\Chromatic Browser Ordner Gelöscht : C:\Users\sebastian\AppData\Local\Freesofttoday Ordner Gelöscht : C:\Users\sebastian\AppData\Local\Genesis Ordner Gelöscht : C:\Users\sebastian\AppData\Local\globalUpdate Ordner Gelöscht : C:\Users\sebastian\AppData\Local\PennyBee Ordner Gelöscht : C:\Users\sebastian\AppData\Local\torch Ordner Gelöscht : C:\Users\sebastian\AppData\LocalLow\DataMngr Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\AppCloudUpdater Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\AppSafe Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Settings Manager Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\SupTab Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Systweak Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppSafe Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage Ordner Gelöscht : C:\Users\sebastian\Documents\Optimizer Pro Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\Chromatic Browser Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\torch Datei Gelöscht : C:\Windows\System32\drivers\wStLibG64.sys Datei Gelöscht : C:\Users\sebastian\daemonprocess.txt Datei Gelöscht : C:\Users\sebastian\AppData\Local\AnyProtectScannerSetup.exe Datei Gelöscht : C:\Users\sebastian\AppData\Roaming\aps.scan.quick.results Datei Gelöscht : C:\Users\sebastian\AppData\Roaming\aps.scan.results Datei Gelöscht : C:\Users\sebastian\AppData\Roaming\aps.uninstall.scan.results ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{c1f9049a-3290-4967-9a3d-448f242ce94c}] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ActiverisAntiMalware_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ActiverisAntiMalware_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MegaBrowse_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MegaBrowse_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateMegaBrowse_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateMegaBrowse_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\utilMegaBrowse_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\utilMegaBrowse_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{67FCE87F-F3EF-4A3C-87C2-8BD46E68807B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4CC15FBA-46A4-4CB5-BFAF-F2335365AE76} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5B6E533F-F78F-4525-B316-312BAF1295D1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8322EB6E-B594-41F6-A30B-CF3F800E1874} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{67FCE87F-F3EF-4A3C-87C2-8BD46E68807B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E6772887-C1E1-405E-94BB-D8760A1CF8DF} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} Schlüssel Gelöscht : HKCU\Software\AnyProtect Schlüssel Gelöscht : HKCU\Software\AppCloudUpdater Schlüssel Gelöscht : HKCU\Software\AppSafe Schlüssel Gelöscht : HKCU\Software\genesis Schlüssel Gelöscht : HKLM\Software\AppSafe ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16921 -\\ Mozilla Firefox v30.0 (de) [ Datei : C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208\prefs.js ] -\\ Google Chrome v ************************* AdwCleaner[R1].txt - [8015 octets] - [28/06/2014 22:00:42] AdwCleaner[S1].txt - [7673 octets] - [28/06/2014 22:01:11] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [7733 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 8 x64 Ran by sebastian on 28.06.2014 at 22:08:38,81 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 28.06.2014 at 22:14:26,82 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02 Ran by sebastian (administrator) on GHOTS on 28-06-2014 22:20:41 Running from C:\Users\sebastian\Pictures Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19] ==================== Services (Whitelisted) ================= R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation) S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X] ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-28] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe 2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt 2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe 2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt 2014-06-28 22:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-28 22:00 - 2014-06-28 22:01 - 00000000 ____D () C:\AdwCleaner 2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe 2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt 2014-06-28 21:38 - 2014-06-28 22:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-28 21:37 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-28 21:37 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-28 21:36 - 2014-06-28 21:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt 2014-06-27 17:20 - 2014-06-27 17:28 - 00000000 ____D () C:\Qoobox 2014-06-27 17:20 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-27 17:20 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-27 17:20 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-27 17:19 - 2014-06-27 17:26 - 00000000 ____D () C:\Windows\erdnt 2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe 2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe 2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk 2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 15:38 - 2014-06-28 22:20 - 00000000 ____D () C:\FRST 2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express 2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini 2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml 2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe 2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-20 18:08 - 2014-06-28 22:03 - 00035110 _____ () C:\Windows\PFRO.log 2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS 2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB 2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator ==================== One Month Modified Files and Folders ======= 2014-06-28 22:20 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST 2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe 2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt 2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe 2014-06-28 22:06 - 2014-06-28 21:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt 2014-06-28 22:04 - 2014-04-06 16:22 - 01414287 _____ () C:\Windows\WindowsUpdate.log 2014-06-28 22:03 - 2014-06-20 18:08 - 00035110 _____ () C:\Windows\PFRO.log 2014-06-28 22:03 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys 2014-06-28 22:03 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-28 22:02 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-06-28 22:01 - 2014-06-28 22:00 - 00000000 ____D () C:\AdwCleaner 2014-06-28 22:01 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian 2014-06-28 22:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe 2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt 2014-06-28 21:54 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker 2014-06-28 21:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-06-28 21:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt 2014-06-27 17:28 - 2014-06-27 17:20 - 00000000 ____D () C:\Qoobox 2014-06-27 17:28 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default 2014-06-27 17:26 - 2014-06-27 17:19 - 00000000 ____D () C:\Windows\erdnt 2014-06-27 17:26 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini 2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe 2014-06-27 17:04 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe 2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk 2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-06-27 16:44 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1 2014-06-27 16:44 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2 2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache 2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002 2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express 2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini 2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB 2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep 2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G 2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6 2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration 2014-06-24 19:59 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS 2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator 2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-05-31 07:16 - 2014-04-06 15:42 - 00703992 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-31 07:16 - 2014-04-06 15:42 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\sebastian\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-24 19:53 ==================== End Of Log ============================ |
29.06.2014, 12:29 | #8 |
/// the machine /// TB-Ausbilder | Virus? Firefox öffnet unaufgefordert neue SeitenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.06.2014, 16:26 | #9 |
| Virus? Firefox öffnet unaufgefordert neue SeitenCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=d8612a777599594291c7c94102f69d8a # engine=18938 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2014-06-29 03:07:42 # local_time=2014-06-29 05:07:42 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 69762 8445351 0 0 # scanned=162766 # found=5 # cleaned=0 # scan_time=5027 sh=B814422F7EE1E98A56D8B9F17F0BB542F8E446E6 ft=1 fh=c71c001197996c13 vn="Win32/AnyProtect.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\sebastian\AppData\Local\AnyProtectScannerSetup.exe.vir" sh=F3AC96D68C2DBF10829ADEC639382DD25D6D6057 ft=1 fh=abbd31e397996c13 vn="Win32/AnyProtect.D evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\sebastian\AppData\Local\nstF1C.tmp.vir" sh=3947DC53990D4C0F5E5F655818233800CF9F601B ft=0 fh=0000000000000000 vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\10bb944.msi" sh=F4BBB551315DBE49911663D85F079AFE8B5F8F51 ft=1 fh=96414ff33da39282 vn="Variante von Win32/Toolbar.BitCocktail.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\update[1]" sh=F4BBB551315DBE49911663D85F079AFE8B5F8F51 ft=1 fh=96414ff33da39282 vn="Variante von Win32/Toolbar.BitCocktail.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\update[1]" Ich hab es runter geladen und gespeichert, wenn ich es aufführe, öffnet sich die DOS-Box und fordert mich auf, eine beliebige Taste zu drücken. Das hab ich getan, danach öffnete sich ein neues Fenster checkup - Editor mit Inhalt "UNSUPPORTED OPERATING SYSTEM! ABORTED!" FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02 Ran by sebastian (administrator) on GHOTS on 29-06-2014 17:24:15 Running from C:\Users\sebastian\Pictures Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe () C:\Users\sebastian\Downloads\SecurityCheck.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19] ==================== Services (Whitelisted) ================= R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation) S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X] ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-29] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-29 17:15 - 2014-06-29 17:15 - 00854367 _____ () C:\Users\sebastian\Downloads\SecurityCheck.exe 2014-06-29 15:38 - 2014-06-29 15:38 - 02347384 _____ (ESET) C:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe 2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe 2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt 2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe 2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt 2014-06-28 22:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-28 22:00 - 2014-06-28 22:01 - 00000000 ____D () C:\AdwCleaner 2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe 2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt 2014-06-28 21:38 - 2014-06-29 17:10 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-28 21:37 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-28 21:37 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-28 21:36 - 2014-06-28 21:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt 2014-06-27 17:20 - 2014-06-27 17:28 - 00000000 ____D () C:\Qoobox 2014-06-27 17:20 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-27 17:20 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-27 17:20 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-27 17:19 - 2014-06-27 17:26 - 00000000 ____D () C:\Windows\erdnt 2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe 2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe 2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk 2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 15:38 - 2014-06-29 17:24 - 00000000 ____D () C:\FRST 2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express 2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini 2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml 2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe 2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-20 18:08 - 2014-06-28 22:03 - 00035110 _____ () C:\Windows\PFRO.log 2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS 2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB 2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator ==================== One Month Modified Files and Folders ======= 2014-06-29 17:24 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST 2014-06-29 17:17 - 2014-04-06 16:22 - 01473215 _____ () C:\Windows\WindowsUpdate.log 2014-06-29 17:15 - 2014-06-29 17:15 - 00854367 _____ () C:\Users\sebastian\Downloads\SecurityCheck.exe 2014-06-29 17:10 - 2014-06-28 21:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-29 17:03 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-06-29 15:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-29 15:39 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1 2014-06-29 15:39 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2 2014-06-29 15:38 - 2014-06-29 15:38 - 02347384 _____ (ESET) C:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe 2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe 2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt 2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe 2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt 2014-06-28 22:03 - 2014-06-20 18:08 - 00035110 _____ () C:\Windows\PFRO.log 2014-06-28 22:03 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys 2014-06-28 22:03 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-28 22:02 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-06-28 22:01 - 2014-06-28 22:00 - 00000000 ____D () C:\AdwCleaner 2014-06-28 22:01 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian 2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe 2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt 2014-06-28 21:54 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker 2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-06-28 21:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt 2014-06-27 17:28 - 2014-06-27 17:20 - 00000000 ____D () C:\Qoobox 2014-06-27 17:28 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default 2014-06-27 17:26 - 2014-06-27 17:19 - 00000000 ____D () C:\Windows\erdnt 2014-06-27 17:26 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini 2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe 2014-06-27 17:04 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe 2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk 2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache 2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002 2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express 2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini 2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB 2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep 2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G 2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6 2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration 2014-06-24 19:59 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS 2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator 2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-05-31 07:16 - 2014-04-06 15:42 - 00703992 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-31 07:16 - 2014-04-06 15:42 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\sebastian\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-24 19:53 ==================== End Of Log ============================ Ich glaube aber, dass Problem ist schon behoben. Was sagst du zu dem Security Check. Das kann doch nicht richtig sein, oder? |
30.06.2014, 11:37 | #10 |
/// the machine /// TB-Ausbilder | Virus? Firefox öffnet unaufgefordert neue Seiten Security check ignorieren, ist ne Zicke. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.07.2014, 21:15 | #11 |
| Virus? Firefox öffnet unaufgefordert neue SeitenFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02 Ran by sebastian (administrator) on GHOTS on 01-07-2014 22:11:19 Running from C:\Users\sebastian\Pictures Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16683_none_62280e15510f8e79\TiWorker.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19] ==================== Services (Whitelisted) ================= R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation) S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X] ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-01] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-29 17:15 - 2014-06-29 17:15 - 00854367 _____ () C:\Users\sebastian\Downloads\SecurityCheck.exe 2014-06-29 15:38 - 2014-06-29 15:38 - 02347384 _____ (ESET) C:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe 2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe 2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt 2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe 2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt 2014-06-28 22:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-28 22:00 - 2014-06-28 22:01 - 00000000 ____D () C:\AdwCleaner 2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe 2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt 2014-06-28 21:38 - 2014-07-01 22:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-28 21:37 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-28 21:37 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-28 21:36 - 2014-06-28 21:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt 2014-06-27 17:20 - 2014-06-27 17:28 - 00000000 ____D () C:\Qoobox 2014-06-27 17:20 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-27 17:20 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-27 17:20 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-27 17:20 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-27 17:19 - 2014-06-27 17:26 - 00000000 ____D () C:\Windows\erdnt 2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe 2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe 2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk 2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 15:38 - 2014-07-01 22:11 - 00000000 ____D () C:\FRST 2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express 2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini 2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml 2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe 2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-20 18:08 - 2014-06-28 22:03 - 00035110 _____ () C:\Windows\PFRO.log 2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS 2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB 2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator ==================== One Month Modified Files and Folders ======= 2014-07-01 22:11 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST 2014-07-01 22:07 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-07-01 22:06 - 2014-06-28 21:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-29 17:17 - 2014-04-06 16:22 - 01479702 _____ () C:\Windows\WindowsUpdate.log 2014-06-29 17:15 - 2014-06-29 17:15 - 00854367 _____ () C:\Users\sebastian\Downloads\SecurityCheck.exe 2014-06-29 15:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-29 15:39 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1 2014-06-29 15:39 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2 2014-06-29 15:38 - 2014-06-29 15:38 - 02347384 _____ (ESET) C:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe 2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe 2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt 2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe 2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt 2014-06-28 22:03 - 2014-06-20 18:08 - 00035110 _____ () C:\Windows\PFRO.log 2014-06-28 22:03 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys 2014-06-28 22:03 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-28 22:02 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-06-28 22:01 - 2014-06-28 22:00 - 00000000 ____D () C:\AdwCleaner 2014-06-28 22:01 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian 2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe 2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt 2014-06-28 21:54 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker 2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-28 21:37 - 2014-06-28 21:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt 2014-06-27 17:28 - 2014-06-27 17:20 - 00000000 ____D () C:\Qoobox 2014-06-27 17:28 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default 2014-06-27 17:26 - 2014-06-27 17:19 - 00000000 ____D () C:\Windows\erdnt 2014-06-27 17:26 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini 2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe 2014-06-27 17:04 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe 2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk 2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache 2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002 2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express 2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini 2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB 2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep 2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G 2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6 2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration 2014-06-24 19:59 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS 2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator 2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent Some content of TEMP: ==================== C:\Users\sebastian\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-24 19:53 ==================== End Of Log ============================ Alles weitere mach ich dann gleich. Danke für deine Tipps und vorallem für deine Hilfe! Ihr habt mir hier schon zum 2. Mal sehr geholfen und ich hoffe, euch nicht so schnell wieder belästigen zu müssen. Sag mal, wären diese Schritte nicht auch allgemein sehr nützlich, wenn man schlechtes Zeug auf dem Laptop hat? |
02.07.2014, 14:45 | #12 |
/// the machine /// TB-Ausbilder | Virus? Firefox öffnet unaufgefordert neue Seiten Die sind immer ein wenig individuell. DU hast den letzten FRST Fix vergessen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.07.2014, 09:19 | #13 |
| Virus? Firefox öffnet unaufgefordert neue Seiten In meinem letzten Beitrag ist doch FRST Logfile. Da ich schon alles gelöscht habe, hab ichs neu runter geladen und schick dir beide Datein. Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-07-2014 01 Ran by sebastian at 2014-07-08 10:16:05 Running from C:\Users\sebastian\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 14 Plugin (HKLM-x32\...\{C4B32291-F7B2-4BEC-BA4D-4195676A08CC}) (Version: 14.0.0.125 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 3.4.117.01527 - Alcor Micro Corp.) Alcor Micro USB Card Reader (x32 Version: 3.4.117.01527 - Alcor Micro Corp.) Hidden Amazon 1Button App (x32 Version: 1.0.4 - Amazon) Hidden ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.2.2 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 3.0.4 - ASUS) ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 2.1.4 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 2.01.0005 - ASUS) ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.5 - ASUS) ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5230.52 - CyberLink Corp.) ASUSDVD (x32 Version: 10.0.5230.52 - CyberLink Corp.) Hidden Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0030 - ASUS) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2884 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden Junk Mail filter update (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64) (Version: 1.0.0.0 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.15.2 (Version: 1.15.2 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.0325 - NVIDIA Corporation) Hidden NVIDIA PhysX System Software 9.13.0325 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0325 - NVIDIA Corporation) NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) Raccolta foto (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6804 - Realtek Semiconductor Corp.) Windows Driver Package - ASUS (ATP) Mouse (01/10/2013 1.0.0.170) (HKLM\...\4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5) (Version: 01/10/2013 1.0.0.170 - ASUS) Windows Live (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.42.0 - ASUS) ==================== Restore Points ========================= 01-07-2014 21:12:47 Ende der Bereinigung 06-07-2014 04:04:23 Windows Update ==================== Hosts content: ========================== 2012-07-26 07:26 - 2014-06-27 17:26 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {046AB098-8757-429F-A45A-34560CDE705F} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-11-28] (ASUS) Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2D000AE6-50A7-4810-ABD9-94BD2A983C68} - \RegClean Pro No Task File <==== ATTENTION Task: {4397CA92-7DE8-4250-BBE2-99C5DA1F9CE4} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2013-03-20] (ASUSTeK Computer Inc.) Task: {50CA362E-DD77-492B-A3EF-CD7B44E39027} - \Re-markit Update No Task File <==== ATTENTION Task: {78C8EFD9-8BDD-4BFD-8251-7B3E62428EC8} - System32\Tasks\Systweak Support Dock => C:\Program Files (x86)\Systweak Support Dock\SystweakDock.exe Task: {7B9522FD-40CE-4535-8AB6-C5D3E1ADA2A1} - System32\Tasks\ASUS Splendid ColorU => C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [2013-02-26] (ASUSTeK Computer Inc.) Task: {905FFE6D-70A6-44C1-9058-CD47BE06AA54} - \RegClean Pro_DEFAULT No Task File <==== ATTENTION Task: {91CD476A-0DBB-44E4-B8E7-D06C9318CCB9} - \RegClean Pro_UPDATES No Task File <==== ATTENTION Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {AB04EEEE-ACAE-4EDA-9DDE-0C137A36FE63} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2013-03-20] (ASUSTeK Computer Inc.) Task: {AEB90AA0-7FD5-422D-BACA-502B48554C29} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2013-06-19] (ASUS) Task: {B1EFB696-E8A9-45FC-90C1-FDAD4B903950} - System32\Tasks\ASUS InstantOn Config => C:\Program Files\ASUS\P4G\InsOnCfg.exe Task: {B680E34E-6844-4054-9EC3-39B382319F09} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.) Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {CCB636B3-A9F6-4AAB-AEF1-0F8F9B97D176} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-04-29] (AsusTek) Task: {D9F25AF7-06A5-4BD6-B55E-DC91432DB33B} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-04-19] (Microsoft Corporation) Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {FF19C4A5-5389-41E7-AA7F-A5E0CC036656} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-01] (Adobe Systems Incorporated) Task: {FF7D8F78-0384-4DD4-AB53-F37847982188} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-06-26] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-10 08:13 - 2013-12-10 08:13 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2013-11-22 15:32 - 2013-10-23 10:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-11-22 15:38 - 2012-06-25 12:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-12-10 08:13 - 2013-12-10 08:13 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll 2014-06-26 17:32 - 2014-06-06 06:38 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:373E1720 AlternateDataStreams: C:\ProgramData\Temp:AD022376 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= HKLM\...\StartupApproved\Run32: => "BingDesktop" HKCU\...\StartupApproved\Run: => "PC Speed Maximizer" HKCU\...\StartupApproved\Run: => "Optimizer Pro" ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/05/2014 10:02:21 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: Bei der Aktivierung der App „Microsoft.XboxLIVEGames_8wekyb3d8bbwe!Microsoft.XboxLIVEGames“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/01/2014 11:45:22 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: Bei der Aktivierung der App „winstore_cw5n1h2txyewy!Windows.Store“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/01/2014 11:37:14 PM) (Source: MsiInstaller) (EventID: 1002) (User: NT-AUTORITÄT) Description: Nicht erwarteter oder fehlender Wert (Name: "PackageCode", Wert: "GUID") für Schlüssel "HKLM\Software\Classes\Installer\Products\B476F94747628E7478C965620AB6A219". Error: (07/01/2014 11:23:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: Bei der Aktivierung der App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/01/2014 11:22:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: Bei der Aktivierung der App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/01/2014 11:12:15 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/29/2014 05:19:25 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/29/2014 03:38:52 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/29/2014 03:38:50 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. System errors: ============= Error: (07/01/2014 11:47:42 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "ASLDR Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/01/2014 10:30:26 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (07/01/2014 10:28:29 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Microsoft Office Sessions: ========================= Error: (07/05/2014 10:02:21 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: Microsoft.XboxLIVEGames_8wekyb3d8bbwe!Microsoft.XboxLIVEGames-2144927151 Error: (07/01/2014 11:45:22 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: winstore_cw5n1h2txyewy!Windows.Store-2144927151 Error: (07/01/2014 11:37:14 PM) (Source: MsiInstaller) (EventID: 1002) (User: NT-AUTORITÄT) Description: PackageCodeGUIDHKLM\Software\Classes\Installer\Products\B476F94747628E7478C965620AB6A219(NULL)(NULL)(NULL) Error: (07/01/2014 11:23:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos-2144927151 Error: (07/01/2014 11:22:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS) Description: microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos-2144927151 Error: (07/01/2014 11:12:15 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe Error: (06/29/2014 05:19:25 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (06/29/2014 03:38:52 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe Error: (06/29/2014 03:38:50 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe CodeIntegrity Errors: =================================== Date: 2014-06-27 17:25:40.382 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 3981.57 MB Available physical RAM: 2137.54 MB Total Pagefile: 4877.57 MB Available Pagefile: 2783.35 MB Total Virtual: 8192 MB Available Virtual: 8191.77 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:155.24 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:258.34 GB) (Free:258.22 GB) NTFS Drive e: (zahni) (CDROM) (Total:0.69 GB) (Free:0.01 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 0FE4DC0A) Partition: GPT Partition Type. ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-07-2014 01 Ran by sebastian (administrator) on GHOTS on 08-07-2014 10:15:13 Running from C:\Users\sebastian\Downloads Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16683_none_62280e15510f8e79\TiWorker.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: NoScript - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-07-01] FF Extension: Adblock Edge - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2014-07-01] FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19] ==================== Services (Whitelisted) ================= R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation) S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X] ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] R3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-08 10:15 - 2014-07-08 10:15 - 00007760 _____ () C:\Users\sebastian\Downloads\FRST.txt 2014-07-08 10:15 - 2014-07-08 10:15 - 00000000 ____D () C:\FRST 2014-07-08 10:14 - 2014-07-08 10:14 - 02084352 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe 2014-07-06 06:05 - 2014-05-15 03:02 - 00059424 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-07-06 06:05 - 2014-05-15 00:43 - 03286528 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-07-06 06:05 - 2014-05-15 00:43 - 01623040 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-07-06 06:05 - 2014-05-15 00:43 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2014-07-06 06:05 - 2014-05-15 00:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2014-07-01 23:51 - 2014-07-01 23:51 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Adobe 2014-07-01 23:47 - 2014-07-01 23:47 - 00448512 _____ (OldTimer Tools) C:\Users\sebastian\Desktop\TFC.exe 2014-07-01 23:46 - 2014-07-01 23:46 - 00700980 _____ () C:\Users\sebastian\Downloads\adblock_edge-2.0.7-sm+an+tb+fx-windows.xpi 2014-07-01 23:37 - 2014-07-01 23:37 - 00000411 _____ () C:\Windows\SecuniaPackage.log 2014-07-01 23:35 - 2014-07-01 23:35 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Secunia PSI 2014-07-01 23:35 - 2014-07-01 23:35 - 00000000 ____D () C:\Program Files (x86)\Secunia 2014-06-28 22:08 - 2014-07-01 23:12 - 00000000 ____D () C:\Windows\ERUNT 2014-06-28 22:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-27 17:19 - 2014-06-27 17:26 - 00000000 ____D () C:\Windows\erdnt 2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express 2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini 2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml 2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe 2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-20 18:08 - 2014-06-28 22:03 - 00035110 _____ () C:\Windows\PFRO.log 2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS 2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB 2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator ==================== One Month Modified Files and Folders ======= 2014-07-08 10:15 - 2014-07-08 10:15 - 00007760 _____ () C:\Users\sebastian\Downloads\FRST.txt 2014-07-08 10:15 - 2014-07-08 10:15 - 00000000 ____D () C:\FRST 2014-07-08 10:14 - 2014-07-08 10:14 - 02084352 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe 2014-07-08 10:14 - 2014-04-06 16:22 - 01846805 _____ () C:\Windows\WindowsUpdate.log 2014-07-07 16:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-07-07 15:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-06 06:08 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-07-05 10:01 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1 2014-07-05 10:01 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2 2014-07-01 23:51 - 2014-07-01 23:51 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Adobe 2014-07-01 23:47 - 2014-07-01 23:47 - 00448512 _____ (OldTimer Tools) C:\Users\sebastian\Desktop\TFC.exe 2014-07-01 23:46 - 2014-07-01 23:46 - 00700980 _____ () C:\Users\sebastian\Downloads\adblock_edge-2.0.7-sm+an+tb+fx-windows.xpi 2014-07-01 23:37 - 2014-07-01 23:37 - 00000411 _____ () C:\Windows\SecuniaPackage.log 2014-07-01 23:37 - 2014-05-01 08:41 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-01 23:35 - 2014-07-01 23:35 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Secunia PSI 2014-07-01 23:35 - 2014-07-01 23:35 - 00000000 ____D () C:\Program Files (x86)\Secunia 2014-07-01 23:12 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-07-01 22:38 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-07-01 22:30 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini 2014-06-28 22:03 - 2014-06-20 18:08 - 00035110 _____ () C:\Windows\PFRO.log 2014-06-28 22:03 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys 2014-06-28 22:03 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-28 22:02 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-06-28 22:01 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian 2014-06-28 21:54 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker 2014-06-27 17:28 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default 2014-06-27 17:26 - 2014-06-27 17:19 - 00000000 ____D () C:\Windows\erdnt 2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache 2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002 2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express 2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini 2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB 2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep 2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G 2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6 2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration 2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS 2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator 2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-05 10:17 ==================== End Of Log ============================ Ich hab deine Tipps auch umgesetzt, allerdings musste ich Noscript wieder deaktivieren, da einige Sachen nicht mehr richtig angezeigt wurden. |
09.07.2014, 08:10 | #14 |
/// the machine /// TB-Ausbilder | Virus? Firefox öffnet unaufgefordert neue Seiten Du musst in NoScript nur die Scripte zulassen. Du hast den Fix immer noch vergessen. Ich rede nicht von einem FRST Scan, sondern von dem Fix!
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2014, 08:58 | #15 |
| Virus? Firefox öffnet unaufgefordert neue Seiten Jetzt hab ichs verstanden. Wenn ich aber Fix klicke, öffnet sich ein Fenster, was mir sagt: No fixlist.txt found. The fixlist.txt should be in the same folder/directory the tool is located. Muss ich da vielleicht noch was umbenennen? |