|
Plagegeister aller Art und deren Bekämpfung: Greener Web Virus auf meinem LaptopWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.08.2014, 09:09 | #1 |
| Greener Web Virus auf meinem Laptop Hallo Leute, seit einiger Zeit bekomme ich aufdringliche Werbung auf allen Webseiten. Da steht "greenweb" bei jeder Werbung. Egal ob ich Chrome, Firefox oder den Internet Explorer verwende. Dann habe ich "greenweb" gegoogelt und kam dann auf dieses Seite. Ich nutze Windows 7. Ich habe zwar im Forum dieses Thema gefunden aber ich habe mich nicht getraut selbst was zu machen. Bitte hilft mir. Auf einem anderen Computer habe ich den Superfish Virus. Da eröffne ich aber später noch ein Thema wenn das in Ordnung ist. vielen Dank im voraus. |
03.08.2014, 09:39 | #2 |
/// TB-Ausbilder | Greener Web Virus auf meinem LaptopMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
03.08.2014, 10:16 | #3 |
| Greener Web Virus auf meinem LaptopCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:2-08-2014 Ran by Acar at 2014-08-03 11:08:01 Running from C:\Users\Acar\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) „Windows Live Essentials“ (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden „Windows Live“ fotogalerija (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Apple Application Support (HKLM\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 5.60.48.55 - Broadcom Corporation) CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden Easy Display Manager (HKLM\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.) Easy Network Manager (HKLM\...\{8732818E-CA78-4ACB-B077-22311BF4C0E4}) (Version: 4.4.7 - Samsung) Easy Resolution Manager (HKLM\...\{A8DDD59F-1413-40BD-B61C-77A0BDB2B22B}) (Version: 1.1.0 - Samsung) EasyBatteryManager (HKLM\...\{607DA1C8-34EC-4D7A-AD83-F8E5C70736DF}) (Version: 4.0.0.4 - Samsung) Facebook Video Calling 2.0.0.447 (HKLM\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) Fotogalerija Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Google Chrome (HKCU\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.) Greener Web (HKLM\...\Greener Web) (Version: 2014.06.20.181102 - Greener Web) <==== ATTENTION Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.2567 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) iTunes (HKLM\...\{0718A90E-93AA-49AF-A4FE-0165ACD91DF0}) (Version: 11.2.2.3 - Apple Inc.) Java 7 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 27.0.1 (x86 de) (HKLM\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Podstawowe programy Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Raccolta foto di Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.33.1125.2010 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6257 - Realtek Semiconductor Corp.) Samsung AnyWeb Print (HKLM\...\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 1.1.21.0 - Samsung Electronics Co., Ltd.) Samsung AnyWeb Print (Version: 1.0 - Samsung Electronics Co., Ltd.) Hidden Samsung Recovery Solution 5 (HKLM\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.0.8 - Samsung) Samsung Support Center (HKLM\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.21 - Samsung) Samsung Universal Print Driver (HKLM\...\Samsung Universal Print Driver) (Version: 2.01.06.00:16 - Samsung Electronics Co., Ltd.) Samsung Universal Scan Driver (HKLM\...\Samsung Universal Scan Driver) (Version: 1.2.1.0 - Samsung Electronics Co., Ltd.) Samsung Update Plus (HKLM\...\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.0.17 - Samsung Electronics Co., Ltd.) Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SRS Premium Sound Control Panel (HKLM\...\{2998191E-A35E-47E2-BE38-7702C731D722}) (Version: 1.10.1000 - SRS Labs, Inc.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.22.0 - Synaptics Incorporated) VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7000 - Broadcom Corporation) Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live fotoattēlu galerija (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogaléria (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Foto-galerija (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotoğraf Galerisi (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galeria de Fotos (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galerija fotografija (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 사진 갤러리 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 필수 패키지 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 照片库 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 软件包 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WindowsProtectManger20.0.0.401 (HKLM\...\WindowsProtectManger) (Version: 20.0.0.401 - Fuyu LIMITED) <==== ATTENTION WinRAR 5.01 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) Συλλογή φωτογραφιών του Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотоальбом Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Chrome\Application\36.0.1985.125\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\Acar\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}\localserver32 -> C:\Users\Acar\AppData\Local\Facebook\Video\Skype\FacebookVideoCallingProxy.exe (Skype Limited) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{BB6410D8-F879-4184-9C5C-6A02D16AE0B3}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{CA1073A2-5F3F-4445-8E5E-7109BDCEDDBE}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\Acar\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{D5A55D2D-C59D-42C3-A5BF-4C08EEE74339}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.7\psuser.dll No File ==================== Restore Points ========================= 29-06-2014 10:05:04 Windows Update 04-07-2014 13:37:49 Windows Update 13-07-2014 13:58:42 Windows Update 13-07-2014 16:43:08 Windows Update 19-07-2014 17:02:15 Windows Update 20-07-2014 10:32:43 Windows Update 30-07-2014 20:51:22 Windows Update 01-08-2014 22:14:59 Windows Update 02-08-2014 21:57:26 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1253A645-A1AB-4E76-8324-4FEB83806BA9} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2010-12-23] (Samsung Electronics Co., Ltd.) Task: {17312E53-7D20-4608-B125-5F82DBA14B88} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core => C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-23] (Facebook Inc.) Task: {2DCDB768-49A6-4E68-A7EC-AE39A5CC8ECE} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-13] (Adobe Systems Incorporated) Task: {2E9669F6-29FB-4B8F-A461-23720B681426} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [2010-08-27] (Samsung Electronics) Task: {339C0E55-02B7-42AB-AF00-87719D7749E5} - System32\Tasks\SRS Premium Sound => C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel.exe [2010-11-29] (SRS Labs, Inc.) Task: {4B2DC75D-9CB8-41BE-9F9C-87FB1FF849C1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core => C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe [2013-12-23] (Google Inc.) Task: {62545B81-44A4-49FB-B30B-0D104CF21547} - System32\Tasks\MovieColorEnhancer => C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe Task: {747EC4C0-78AB-45AD-BBC5-4FF89E9110B2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: {787A967C-73D0-432F-AB22-6B4B515B9BDB} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2010-11-23] (SAMSUNG Electronics) Task: {79E7BD23-C7EB-4206-8A99-692F0093F1BD} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA => C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe [2013-12-23] (Google Inc.) Task: {8751545B-3040-4ADA-B3C6-D0E6DD3653E7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {896D83FB-3F42-4318-A742-6E0D58DD1E44} - System32\Tasks\IdlePowerSave => C:\windows\Idle\DetectIdleTask.exe [2010-07-31] (TODO: <회사 이름>) Task: {AE4F5993-4ED8-45E0-B7DC-1906C914B8E3} - System32\Tasks\advSRS5 => C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-11-17] (SEC) Task: {B0BF0B64-276C-4BAE-981B-9D1E23C019A4} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA => C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-23] (Facebook Inc.) Task: {C89E64DC-1123-41E3-B260-3432DF7F870F} - System32\Tasks\WifiManager => C:\Program Files\Samsung\Easy Display Manager\WifiManager.exe [2011-01-04] (Samsung Electronics Co., Ltd.) Task: {E43A9534-00C9-4B16-B5C6-194C0862F420} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core.job => C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA.job => C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core.job => C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA.job => C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-22 21:40 - 2008-06-05 01:53 - 00026624 _____ () C:\windows\System32\spd__l.dll 2014-02-12 21:58 - 2014-02-12 21:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-12 21:58 - 2014-02-12 21:58 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-12-22 21:41 - 2010-04-21 01:45 - 00552960 _____ () C:\windows\system32\SnMinDrv.dll 2014-06-20 20:11 - 2014-08-03 00:01 - 00323360 _____ () C:\Program Files\Greener Web\updateGreenerWeb.exe 2014-06-20 22:50 - 2014-08-02 23:56 - 00323360 _____ () C:\Program Files\Greener Web\bin\utilGreenerWeb.exe 2011-01-06 08:56 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll 2014-07-13 15:55 - 2014-07-29 16:42 - 00239392 _____ () C:\Program Files\Greener Web\bin\GreenerWeb.PurBrowse.exe 2014-06-20 22:52 - 2014-08-02 06:36 - 00096544 _____ () C:\Program Files\Greener Web\bin\GreenerWeb.BrowserAdapter.exe 2014-06-20 22:52 - 2014-08-02 06:35 - 00195360 _____ () C:\Program Files\Greener Web\bin\GreenerWebBAApp.dll 2014-07-20 13:16 - 2014-07-15 11:24 - 08537928 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll 2014-07-20 13:16 - 2014-07-15 11:24 - 00353096 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll 2014-07-20 13:16 - 2014-07-15 11:24 - 01732936 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll 2014-04-18 13:49 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll 2014-04-18 13:49 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll 2014-07-20 13:16 - 2014-07-15 11:24 - 14664008 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\windows\pss\Bluetooth.lnk.CommonStartup MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: Google Update => "C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: HotKeysCmds => C:\windows\system32\hkcmd.exe MSCONFIG\startupreg: IgfxTray => C:\windows\system32\igfxtray.exe MSCONFIG\startupreg: Microsoft Default Manager => "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume MSCONFIG\startupreg: Norton Online Backup => C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe MSCONFIG\startupreg: Persistence => C:\windows\system32\igfxpers.exe MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21632300 Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 21632300 Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21615857 Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 21615857 Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 65625503 Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 65625503 Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/26/2014 07:26:09 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x81000101). System errors: ============= Error: (08/03/2014 09:07:34 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/02/2014 11:53:32 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/01/2014 06:44:22 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} Error: (08/01/2014 04:31:50 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (07/28/2014 00:40:04 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (07/27/2014 06:10:37 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (07/22/2014 05:41:15 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (07/20/2014 07:14:19 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (07/20/2014 07:11:46 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (07/20/2014 01:25:00 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst btwdins erreicht. Microsoft Office Sessions: ========================= Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21632300 Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 21632300 Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21615857 Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 21615857 Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 65625503 Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 65625503 Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/26/2014 07:26:09 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: C:\windows\system32\svchost.exe -k netsvcsWindows Update0x81000101 ==================== Memory info =========================== Percentage of memory in use: 84% Total physical RAM: 1013.3 MB Available physical RAM: 152.97 MB Total Pagefile: 2133.3 MB Available Pagefile: 913.74 MB Total Virtual: 2047.88 MB Available Virtual: 1912.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:87 GB) (Free:41.75 GB) NTFS Drive d: () (Fixed) (Total:128.85 GB) (Free:128.73 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 233 GB) (Disk ID: C8210F99) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=87 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=129 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=17 GB) - (Type=27) ==================== End Of Log ============================ |
03.08.2014, 11:00 | #4 |
/// TB-Ausbilder | Greener Web Virus auf meinem Laptop Servus, fehlt noch die FRST.txt... |
03.08.2014, 11:03 | #5 |
| Greener Web Virus auf meinem LaptopFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:2-08-2014 Ran by Acar (administrator) on ACAR-NETBOOK on 03-08-2014 11:05:47 Running from C:\Users\Acar\Desktop Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Fuyu LIMITED) C:\ProgramData\WindowsProtectManger\wprotectmanager.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe () C:\Program Files\Greener Web\updateGreenerWeb.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe () C:\Program Files\Greener Web\bin\utilGreenerWeb.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\WifiManager.exe (Intel Corporation) C:\Windows\System32\igfxext.exe () C:\Program Files\Greener Web\bin\GreenerWeb.PurBrowse.exe () C:\Program Files\Greener Web\bin\GreenerWeb.BrowserAdapter.exe (Google Inc.) C:\Users\Acar\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Acar\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Acar\AppData\Local\Google\Chrome\Application\chrome.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (Samsung Electronics) C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Google Inc.) C:\Users\Acar\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Acar\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\RunOnce: [ Malwarebytes Anti-Malware ] => C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [532040 2013-04-04] (Malwarebytes Corporation) HKU\S-1-5-21-2338033741-1917138375-3194134120-1000\...\Run: [Facebook Update] => C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-12-23] (Facebook Inc.) HKU\S-1-5-21-2338033741-1917138375-3194134120-1000\...\Run: [Google Update] => C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-12-23] (Google Inc.) AppInit_DLLs: C:\PROGRA~1\SupTab\SEARCH~1.DLL => C:\PROGRA~1\SupTab\SEARCH~1.DLL File Not Found ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1403293646&from=cor&uid=HitachiXHTS543225A7A384_E2021342GZB4AJGZB4AJX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1403293646&from=cor&uid=HitachiXHTS543225A7A384_E2021342GZB4AJGZB4AJX&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.sweet-page.com/?type=scpp&ts=1404048594&from=cor&uid=HitachiXHTS543225A7A384_E2021342GZB4AJGZB4AJX SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: W2PBrowser Class -> {AA609D72-8482-4076-8991-8CDAE5B93BCB} -> C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll () BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Acar\AppData\Roaming\Mozilla\Firefox\Profiles\cr2lszyt.default FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Acar\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Acar\AppData\Roaming\Mozilla\Firefox\Profiles\cr2lszyt.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} [2014-03-04] Chrome: ======= CHR HomePage: hxxp://www.google.de/ CHR StartupUrls: "hxxp://google.de/" CHR Extension: (ProxFlow) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2013-12-23] CHR Extension: (Download Button) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\alakoggmijiicdlcjjeakffojoinhlpg [2013-12-23] CHR Extension: (Google Docs) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-23] CHR Extension: (Google Drive) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-23] CHR Extension: (Turn Off the Lights) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-12-23] CHR Extension: (YouTube) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-23] CHR Extension: (Google Cast) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2014-06-20] CHR Extension: (Adblock Plus) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-12-23] CHR Extension: (Videostream for Google Chromecast™) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2014-06-20] CHR Extension: (Google-Suche) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-23] CHR Extension: (Photo Zoom for Facebook) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2013-12-23] CHR Extension: (FlashBlock) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gofhjkjmkpinhpoiabjplobcaignabnl [2013-12-23] CHR Extension: (Auto Replay for YouTube™) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2013-12-23] CHR Extension: (Webcam Toy) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2013-12-23] CHR Extension: (convert2mp3.net Online Video Converter) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmhoigapbeidamhadadmpbhpaodamjce [2013-12-23] CHR Extension: (AdSweep) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\milkhonmecplandlkfbjplfbdenjlkmp [2013-12-23] CHR Extension: (Google Wallet) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-23] CHR Extension: (Google Chrome to Phone Extension) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2013-12-23] CHR Extension: (Google Mail) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-23] CHR Extension: (Canvas Rider) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk [2013-12-23] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED) S3 Samsung UPD Service; C:\windows\System32\SUPDSvc.exe [131888 2010-08-09] (Samsung Electronics CO., LTD.) R2 Update Greener Web; C:\Program Files\Greener Web\updateGreenerWeb.exe [323360 2014-08-03] () R2 Util Greener Web; C:\Program Files\Greener Web\bin\utilGreenerWeb.exe [323360 2014-08-02] () R2 WindowsProtectManger; C:\ProgramData\WindowsProtectManger\wprotectmanager.exe [591776 2014-06-12] (Fuyu LIMITED) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 BTWAMPFL; C:\windows\System32\DRIVERS\btwampfl.sys [300584 2010-09-21] (Broadcom Corporation.) R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw; C:\windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw.sys [52928 2014-06-19] (StdLib) R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}w; C:\windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w.sys [52928 2014-06-23] (StdLib) S3 clwvd; system32\DRIVERS\clwvd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-03 11:05 - 2014-08-03 11:06 - 00012726 _____ () C:\Users\Acar\Desktop\FRST.txt 2014-08-03 11:05 - 2014-08-03 11:06 - 00000000 ____D () C:\FRST 2014-08-03 11:04 - 2014-08-03 11:04 - 01084928 _____ (Farbar) C:\Users\Acar\Desktop\FRST.exe 2014-08-03 09:55 - 2014-08-03 09:55 - 00001071 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-03 09:55 - 2014-08-03 09:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware 2014-08-03 09:55 - 2014-08-03 09:55 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-03 09:55 - 2014-08-03 09:55 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-08-03 09:55 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-08-03 09:53 - 2014-08-03 09:54 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Acar\Desktop\mbam-setup-1.75.0.1300.exe 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ___RD () C:\Program Files\Skype 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-08-02 00:17 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2014-08-02 00:17 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe 2014-08-02 00:17 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll 2014-08-02 00:17 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll 2014-08-02 00:16 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll 2014-08-02 00:16 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\windows\system32\wups.dll 2014-08-02 00:16 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll 2014-08-02 00:16 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll 2014-08-02 00:16 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe 2014-08-02 00:05 - 2014-08-02 00:05 - 00000000 ____D () C:\Users\Acar\AppData\Local\Windows Live 2014-08-01 06:52 - 2014-08-01 06:54 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Acar\Desktop\mbam-setup-2.0.2.1012.exe 2014-08-01 06:42 - 2014-08-02 23:54 - 00000000 ____D () C:\Users\Acar\Desktop\bILDER 2014-07-27 18:18 - 2014-07-27 18:19 - 00001878 _____ () C:\Users\Acar\Desktop\Chrome.lnk 2014-07-19 19:02 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\osk.exe 2014-07-19 19:02 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-07-13 16:01 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-07-13 16:01 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-07-13 16:01 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-07-13 16:01 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-07-13 16:01 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-07-13 16:01 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-07-13 16:01 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-07-13 16:01 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-07-13 16:01 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-07-13 16:01 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-07-13 16:01 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-07-13 16:01 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-07-13 16:01 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-07-13 16:01 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-07-13 16:00 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-07-13 16:00 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-07-13 16:00 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-07-13 16:00 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-07-13 16:00 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2014-07-13 16:00 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-07-13 16:00 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-07-13 16:00 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-07-13 16:00 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-07-13 16:00 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-07-13 16:00 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-07-13 16:00 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-07-13 16:00 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-07-13 16:00 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-07-13 16:00 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-07-13 16:00 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-07-13 15:59 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll 2014-07-13 15:59 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys 2014-07-13 15:58 - 2014-06-30 03:40 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-07-13 15:58 - 2014-06-30 03:36 - 00302592 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-07-13 15:55 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-03 11:06 - 2014-08-03 11:05 - 00012726 _____ () C:\Users\Acar\Desktop\FRST.txt 2014-08-03 11:06 - 2014-08-03 11:05 - 00000000 ____D () C:\FRST 2014-08-03 11:04 - 2014-08-03 11:04 - 01084928 _____ (Farbar) C:\Users\Acar\Desktop\FRST.exe 2014-08-03 10:58 - 2011-01-06 08:40 - 01589054 _____ () C:\windows\WindowsUpdate.log 2014-08-03 10:26 - 2013-12-23 01:13 - 00001116 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA.job 2014-08-03 10:26 - 2013-12-23 01:13 - 00001064 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core.job 2014-08-03 10:13 - 2014-03-04 01:10 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-08-03 09:55 - 2014-08-03 09:55 - 00001071 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-03 09:55 - 2014-08-03 09:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware 2014-08-03 09:55 - 2014-08-03 09:55 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-03 09:55 - 2014-08-03 09:55 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-08-03 09:54 - 2014-08-03 09:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Acar\Desktop\mbam-setup-1.75.0.1300.exe 2014-08-03 09:15 - 2013-12-23 19:10 - 00000924 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA.job 2014-08-03 09:15 - 2009-07-14 06:34 - 00010272 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-03 09:15 - 2009-07-14 06:34 - 00010272 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-03 09:08 - 2009-07-14 04:04 - 00000505 _____ () C:\windows\win.ini 2014-08-03 09:07 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-08-03 09:07 - 2009-07-14 06:39 - 00042602 _____ () C:\windows\setupact.log 2014-08-03 09:06 - 2014-06-20 21:49 - 00000000 ____D () C:\Program Files\Greener Web 2014-08-03 09:06 - 2011-01-06 10:27 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-03 00:06 - 2013-12-22 21:53 - 00000000 ____D () C:\ProgramData\Skype 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ___RD () C:\Program Files\Skype 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-08-03 00:04 - 2011-01-06 10:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-02 23:54 - 2014-08-01 06:42 - 00000000 ____D () C:\Users\Acar\Desktop\bILDER 2014-08-02 23:53 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\de-DE 2014-08-02 01:02 - 2013-12-23 20:00 - 00000000 ____D () C:\Users\Acar\AppData\Roaming\Skype 2014-08-02 00:15 - 2013-12-23 19:10 - 00000902 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core.job 2014-08-02 00:06 - 2013-12-23 20:44 - 00000000 ____D () C:\Users\Acar\AppData\Roaming\skypePM 2014-08-02 00:05 - 2014-08-02 00:05 - 00000000 ____D () C:\Users\Acar\AppData\Local\Windows Live 2014-08-01 06:54 - 2014-08-01 06:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Acar\Desktop\mbam-setup-2.0.2.1012.exe 2014-08-01 06:43 - 2009-07-26 22:06 - 01618320 _____ () C:\windows\system32\PerfStringBackup.INI 2014-07-27 18:19 - 2014-07-27 18:18 - 00001878 _____ () C:\Users\Acar\Desktop\Chrome.lnk 2014-07-27 18:15 - 2014-06-20 21:47 - 00000000 ____D () C:\Program Files\SupTab 2014-07-20 19:14 - 2009-07-14 06:33 - 00259256 _____ () C:\windows\system32\FNTCACHE.DAT 2014-07-19 18:46 - 2014-05-24 22:15 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-07-13 18:49 - 2013-12-22 23:17 - 00000000 ____D () C:\windows\system32\MRT 2014-07-13 18:45 - 2013-12-22 23:17 - 93585272 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-07-13 00:13 - 2014-03-04 01:10 - 00699056 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe 2014-07-13 00:13 - 2014-03-04 01:10 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\Acar\AppData\Local\Temp\JDSetup130477671127458543.exe C:\Users\Acar\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Acar\AppData\Local\Temp\MSN4E40.exe C:\Users\Acar\AppData\Local\Temp\vlc-2.1.3-win32.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\windows\explorer.exe => File is digitally signed C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-29 11:45 ==================== End Of Log ============================ |
03.08.2014, 11:08 | #6 |
/// TB-Ausbilder | Greener Web Virus auf meinem Laptop Servus, deinstalliere als Erstes über die Systemsteuerung: Malwarebytes' Anti-Malware 1.75 Dann geht es so weiter: Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3
Bitte poste mit deiner nächsten Antwort
|
03.08.2014, 12:10 | #7 |
| Greener Web Virus auf meinem Laptop AdwareCleaner Code:
ATTFilter # AdwCleaner v3.302 - Bericht erstellt am 03/08/2014 um 12:16:47 # Aktualisiert 30/07/2014 von Xplode # Betriebssystem : Windows 7 Starter Service Pack 1 (32 bits) # Benutzername : Acar - ACAR-NETBOOK # Gestartet von : C:\Users\Acar\Desktop\adwcleaner_3.302.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : IePluginServices [#] Dienst Gelöscht : Update Greener Web [#] Dienst Gelöscht : Util Greener Web Dienst Gelöscht : WindowsProtectManger Dienst Gelöscht : {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw Dienst Gelöscht : {a3f28269-ad17-41a8-b032-3e0313ef8979}w ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\IePluginServices Ordner Gelöscht : C:\ProgramData\WindowsProtectManger [!] Ordner Gelöscht : C:\Program Files\Greener Web Ordner Gelöscht : C:\Program Files\SupTab [!] Ordner Gelöscht : C:\Program Files\Greener Web Ordner Gelöscht : C:\Users\Acar\AppData\Local\Temp\Greener Web Ordner Gelöscht : C:\Users\Acar\AppData\Local\Temp\OCS Datei Gelöscht : C:\windows\system32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw.sys Datei Gelöscht : C:\windows\system32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w.sys Datei Gelöscht : C:\Users\Acar\AppData\Roaming\Mozilla\Firefox\Profiles\cr2lszyt.default\foxydeal.sqlite Datei Gelöscht : C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage Datei Gelöscht : C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk Verknüpfung Desinfiziert : C:\Users\Acar\Desktop\Chrome App Launcher.lnk Verknüpfung Desinfiziert : C:\Users\Acar\Desktop\Videostream for Google Chromecast™.lnk Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk Verknüpfung Desinfiziert : C:\Users\Acar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Acar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Chrome App Launcher.lnk Verknüpfung Desinfiziert : C:\Users\Acar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Acar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\Videostream for Google Chromecast™.lnk Verknüpfung Desinfiziert : C:\Users\Acar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Verknüpfung Desinfiziert : C:\Users\Acar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Acar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command Schlüssel Gelöscht : HKCU\Software\Greener Web Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKLM\Software\Greener Web Schlüssel Gelöscht : HKLM\Software\SupDp Schlüssel Gelöscht : HKLM\Software\SupTab Schlüssel Gelöscht : HKLM\Software\supWindowsProtectManger Schlüssel Gelöscht : HKLM\Software\sweet-pageSoftware Schlüssel Gelöscht : HKLM\Software\Wpm Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Greener Web Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowsProtectManger Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~1\SupTab\SEARCH~1.DLL Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4 ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17207 Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] -\\ Mozilla Firefox v27.0.1 (de) [ Datei : C:\Users\Acar\AppData\Roaming\Mozilla\Firefox\Profiles\cr2lszyt.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [7361 octets] - [03/08/2014 12:12:47] AdwCleaner[S0].txt - [5178 octets] - [03/08/2014 12:16:47] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5238 octets] ########## Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 03.08.2014 Suchlauf-Zeit: 12:30:02 Logdatei: MWBY.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.08.03.02 Rootkit Datenbank: v2014.08.01.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: Acar Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 263147 Verstrichene Zeit: 16 Min, 30 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 3 PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [a589d3ef6f0c3ef81657ca9b33cfb44c], PUP.Optional.GreenerWeb.A, HKLM\SOFTWARE\Greener Web, In Quarantäne, [9a94546ee09b989e334cc81419e923dd], PUP.Optional.SuperFish.A, HKU\S-1-5-21-2338033741-1917138375-3194134120-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, In Quarantäne, [200e378b4239e6505670f3e4be4411ef], Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 1 PUP.Optional.SearchHijacker.A, C:\Users\Acar\AppData\Local\Temp\is1201216051\4917F1FD_stp\June10_www.sweet-page.com.exe, In Quarantäne, [78b6932f3546112562b634646c95a060], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:2-08-2014 Ran by Acar at 2014-08-03 13:02:50 Running from C:\Users\Acar\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) „Windows Live Essentials“ (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden „Windows Live“ fotogalerija (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Apple Application Support (HKLM\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 5.60.48.55 - Broadcom Corporation) CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden Easy Display Manager (HKLM\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.) Easy Network Manager (HKLM\...\{8732818E-CA78-4ACB-B077-22311BF4C0E4}) (Version: 4.4.7 - Samsung) Easy Resolution Manager (HKLM\...\{A8DDD59F-1413-40BD-B61C-77A0BDB2B22B}) (Version: 1.1.0 - Samsung) EasyBatteryManager (HKLM\...\{607DA1C8-34EC-4D7A-AD83-F8E5C70736DF}) (Version: 4.0.0.4 - Samsung) Facebook Video Calling 2.0.0.447 (HKLM\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) Fotogalerija Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Google Chrome (HKCU\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.2567 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) iTunes (HKLM\...\{0718A90E-93AA-49AF-A4FE-0165ACD91DF0}) (Version: 11.2.2.3 - Apple Inc.) Java 7 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 27.0.1 (x86 de) (HKLM\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Podstawowe programy Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Raccolta foto di Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.33.1125.2010 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6257 - Realtek Semiconductor Corp.) Samsung AnyWeb Print (HKLM\...\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 1.1.21.0 - Samsung Electronics Co., Ltd.) Samsung AnyWeb Print (Version: 1.0 - Samsung Electronics Co., Ltd.) Hidden Samsung Recovery Solution 5 (HKLM\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.0.8 - Samsung) Samsung Support Center (HKLM\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.21 - Samsung) Samsung Universal Print Driver (HKLM\...\Samsung Universal Print Driver) (Version: 2.01.06.00:16 - Samsung Electronics Co., Ltd.) Samsung Universal Scan Driver (HKLM\...\Samsung Universal Scan Driver) (Version: 1.2.1.0 - Samsung Electronics Co., Ltd.) Samsung Update Plus (HKLM\...\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.0.17 - Samsung Electronics Co., Ltd.) Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SRS Premium Sound Control Panel (HKLM\...\{2998191E-A35E-47E2-BE38-7702C731D722}) (Version: 1.10.1000 - SRS Labs, Inc.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.22.0 - Synaptics Incorporated) VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7000 - Broadcom Corporation) Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live fotoattēlu galerija (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogaléria (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Foto-galerija (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotoğraf Galerisi (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galeria de Fotos (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galerija fotografija (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 사진 갤러리 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 필수 패키지 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 照片库 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 软件包 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinRAR 5.01 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) Συλλογή φωτογραφιών του Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотоальбом Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Chrome\Application\36.0.1985.125\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\Acar\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}\localserver32 -> C:\Users\Acar\AppData\Local\Facebook\Video\Skype\FacebookVideoCallingProxy.exe (Skype Limited) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{BB6410D8-F879-4184-9C5C-6A02D16AE0B3}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{CA1073A2-5F3F-4445-8E5E-7109BDCEDDBE}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\Acar\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{D5A55D2D-C59D-42C3-A5BF-4C08EEE74339}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2338033741-1917138375-3194134120-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Acar\AppData\Local\Google\Update\1.3.24.7\psuser.dll No File ==================== Restore Points ========================= 29-06-2014 10:05:04 Windows Update 04-07-2014 13:37:49 Windows Update 13-07-2014 13:58:42 Windows Update 13-07-2014 16:43:08 Windows Update 19-07-2014 17:02:15 Windows Update 20-07-2014 10:32:43 Windows Update 30-07-2014 20:51:22 Windows Update 01-08-2014 22:14:59 Windows Update 02-08-2014 21:57:26 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1253A645-A1AB-4E76-8324-4FEB83806BA9} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2010-12-23] (Samsung Electronics Co., Ltd.) Task: {17312E53-7D20-4608-B125-5F82DBA14B88} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core => C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-23] (Facebook Inc.) Task: {2DCDB768-49A6-4E68-A7EC-AE39A5CC8ECE} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-13] (Adobe Systems Incorporated) Task: {2E9669F6-29FB-4B8F-A461-23720B681426} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [2010-08-27] (Samsung Electronics) Task: {339C0E55-02B7-42AB-AF00-87719D7749E5} - System32\Tasks\SRS Premium Sound => C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel.exe [2010-11-29] (SRS Labs, Inc.) Task: {4B2DC75D-9CB8-41BE-9F9C-87FB1FF849C1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core => C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe [2013-12-23] (Google Inc.) Task: {62545B81-44A4-49FB-B30B-0D104CF21547} - System32\Tasks\MovieColorEnhancer => C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe Task: {747EC4C0-78AB-45AD-BBC5-4FF89E9110B2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: {787A967C-73D0-432F-AB22-6B4B515B9BDB} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2010-11-23] (SAMSUNG Electronics) Task: {79E7BD23-C7EB-4206-8A99-692F0093F1BD} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA => C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe [2013-12-23] (Google Inc.) Task: {8751545B-3040-4ADA-B3C6-D0E6DD3653E7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {896D83FB-3F42-4318-A742-6E0D58DD1E44} - System32\Tasks\IdlePowerSave => C:\windows\Idle\DetectIdleTask.exe [2010-07-31] (TODO: <회사 이름>) Task: {AE4F5993-4ED8-45E0-B7DC-1906C914B8E3} - System32\Tasks\advSRS5 => C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-11-17] (SEC) Task: {B0BF0B64-276C-4BAE-981B-9D1E23C019A4} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA => C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-23] (Facebook Inc.) Task: {C89E64DC-1123-41E3-B260-3432DF7F870F} - System32\Tasks\WifiManager => C:\Program Files\Samsung\Easy Display Manager\WifiManager.exe [2011-01-04] (Samsung Electronics Co., Ltd.) Task: {E43A9534-00C9-4B16-B5C6-194C0862F420} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core.job => C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA.job => C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core.job => C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA.job => C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-22 21:40 - 2008-06-05 01:53 - 00026624 _____ () C:\windows\System32\spd__l.dll 2014-02-12 21:58 - 2014-02-12 21:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-12 21:58 - 2014-02-12 21:58 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-12-22 21:41 - 2010-04-21 01:45 - 00552960 _____ () C:\windows\system32\SnMinDrv.dll 2011-01-06 08:56 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll 2014-07-20 13:16 - 2014-07-15 11:24 - 08537928 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll 2014-07-20 13:16 - 2014-07-15 11:24 - 00353096 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll 2014-07-20 13:16 - 2014-07-15 11:24 - 01732936 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll 2014-04-18 13:49 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll 2014-04-18 13:49 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\Acar\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\windows\pss\Bluetooth.lnk.CommonStartup MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: Google Update => "C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: HotKeysCmds => C:\windows\system32\hkcmd.exe MSCONFIG\startupreg: IgfxTray => C:\windows\system32\igfxtray.exe MSCONFIG\startupreg: Microsoft Default Manager => "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume MSCONFIG\startupreg: Norton Online Backup => C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe MSCONFIG\startupreg: Persistence => C:\windows\system32\igfxpers.exe MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21632300 Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 21632300 Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21615857 Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 21615857 Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 65625503 Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 65625503 Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/26/2014 07:26:09 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x81000101). System errors: ============= Error: (08/03/2014 00:50:35 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/03/2014 00:49:19 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (08/03/2014 00:21:32 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/03/2014 09:07:34 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/02/2014 11:53:32 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/01/2014 06:44:22 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} Error: (08/01/2014 04:31:50 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (07/28/2014 00:40:04 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (07/27/2014 06:10:37 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (07/22/2014 05:41:15 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Microsoft Office Sessions: ========================= Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21632300 Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 21632300 Error: (08/01/2014 01:15:15 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21615857 Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 21615857 Error: (08/01/2014 01:14:59 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 65625503 Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 65625503 Error: (07/27/2014 01:40:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/26/2014 07:26:09 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: C:\windows\system32\svchost.exe -k netsvcsWindows Update0x81000101 ==================== Memory info =========================== Percentage of memory in use: 66% Total physical RAM: 1013.3 MB Available physical RAM: 344.37 MB Total Pagefile: 2037.3 MB Available Pagefile: 1196.13 MB Total Virtual: 2047.88 MB Available Virtual: 1936.17 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:87 GB) (Free:41.78 GB) NTFS Drive d: () (Fixed) (Total:128.85 GB) (Free:128.73 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 233 GB) (Disk ID: C8210F99) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=87 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=129 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=17 GB) - (Type=27) ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:2-08-2014 Ran by Acar (administrator) on ACAR-NETBOOK on 03-08-2014 13:01:19 Running from C:\Users\Acar\Desktop Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\WifiManager.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Samsung Electronics) C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe (Google Inc.) C:\Users\Acar\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Acar\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Acar\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Acar\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKU\S-1-5-21-2338033741-1917138375-3194134120-1000\...\Run: [Facebook Update] => C:\Users\Acar\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-12-23] (Facebook Inc.) HKU\S-1-5-21-2338033741-1917138375-3194134120-1000\...\Run: [Google Update] => C:\Users\Acar\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-12-23] (Google Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: W2PBrowser Class -> {AA609D72-8482-4076-8991-8CDAE5B93BCB} -> C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll () BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Acar\AppData\Roaming\Mozilla\Firefox\Profiles\cr2lszyt.default FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Acar\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Acar\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Acar\AppData\Roaming\Mozilla\Firefox\Profiles\cr2lszyt.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} [2014-03-04] Chrome: ======= CHR HomePage: hxxp://www.google.de/ CHR StartupUrls: "hxxp://google.de/" CHR Extension: (ProxFlow) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2013-12-23] CHR Extension: (Download Button) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\alakoggmijiicdlcjjeakffojoinhlpg [2013-12-23] CHR Extension: (Google Docs) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-23] CHR Extension: (Google Drive) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-23] CHR Extension: (Turn Off the Lights) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-12-23] CHR Extension: (YouTube) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-23] CHR Extension: (Google Cast) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2014-06-20] CHR Extension: (Adblock Plus) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-12-23] CHR Extension: (Videostream for Google Chromecast™) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2014-06-20] CHR Extension: (Google-Suche) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-23] CHR Extension: (Photo Zoom for Facebook) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2013-12-23] CHR Extension: (FlashBlock) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gofhjkjmkpinhpoiabjplobcaignabnl [2013-12-23] CHR Extension: (Auto Replay for YouTube™) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2013-12-23] CHR Extension: (Webcam Toy) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2013-12-23] CHR Extension: (convert2mp3.net Online Video Converter) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmhoigapbeidamhadadmpbhpaodamjce [2013-12-23] CHR Extension: (AdSweep) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\milkhonmecplandlkfbjplfbdenjlkmp [2013-12-23] CHR Extension: (Google Wallet) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-23] CHR Extension: (Google Chrome to Phone Extension) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2013-12-23] CHR Extension: (Google Mail) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-23] CHR Extension: (Canvas Rider) - C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk [2013-12-23] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Samsung UPD Service; C:\windows\System32\SUPDSvc.exe [131888 2010-08-09] (Samsung Electronics CO., LTD.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 BTWAMPFL; C:\windows\System32\DRIVERS\btwampfl.sys [300584 2010-09-21] (Broadcom Corporation.) S3 clwvd; system32\DRIVERS\clwvd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-03 12:49 - 2014-08-03 12:49 - 00001818 _____ () C:\Users\Acar\Desktop\MWBY.txt 2014-08-03 12:27 - 2014-08-03 12:28 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-03 12:27 - 2014-08-03 12:27 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-03 12:27 - 2014-08-03 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-03 12:27 - 2014-08-03 12:27 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-08-03 12:27 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-08-03 12:27 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-08-03 12:27 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-08-03 12:25 - 2014-08-03 12:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Acar\Desktop\mbam-setup-2.0.2.1012 (1).exe 2014-08-03 12:24 - 2014-08-03 12:24 - 00005318 _____ () C:\Users\Acar\Desktop\AdwCleaner[S0].txt 2014-08-03 12:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\system32\sqlite3.dll 2014-08-03 12:12 - 2014-08-03 12:18 - 00000000 ____D () C:\AdwCleaner 2014-08-03 12:11 - 2014-08-03 12:11 - 01361309 _____ () C:\Users\Acar\Desktop\adwcleaner_3.302.exe 2014-08-03 11:08 - 2014-08-03 11:09 - 00031110 _____ () C:\Users\Acar\Desktop\Addition.txt 2014-08-03 11:05 - 2014-08-03 13:01 - 00010614 _____ () C:\Users\Acar\Desktop\FRST.txt 2014-08-03 11:05 - 2014-08-03 13:01 - 00000000 ____D () C:\FRST 2014-08-03 11:04 - 2014-08-03 11:04 - 01084928 _____ (Farbar) C:\Users\Acar\Desktop\FRST.exe 2014-08-03 09:55 - 2014-08-03 12:27 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-03 09:53 - 2014-08-03 09:54 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Acar\Desktop\mbam-setup-1.75.0.1300.exe 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ___RD () C:\Program Files\Skype 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-08-02 00:17 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2014-08-02 00:17 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe 2014-08-02 00:17 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll 2014-08-02 00:17 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll 2014-08-02 00:16 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll 2014-08-02 00:16 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\windows\system32\wups.dll 2014-08-02 00:16 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll 2014-08-02 00:16 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll 2014-08-02 00:16 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe 2014-08-02 00:05 - 2014-08-02 00:05 - 00000000 ____D () C:\Users\Acar\AppData\Local\Windows Live 2014-08-01 06:52 - 2014-08-01 06:54 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Acar\Desktop\mbam-setup-2.0.2.1012.exe 2014-08-01 06:42 - 2014-08-02 23:54 - 00000000 ____D () C:\Users\Acar\Desktop\bILDER 2014-07-27 18:18 - 2014-07-27 18:19 - 00001878 _____ () C:\Users\Acar\Desktop\Chrome.lnk 2014-07-19 19:02 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\osk.exe 2014-07-19 19:02 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-07-13 16:01 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-07-13 16:01 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-07-13 16:01 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-07-13 16:01 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-07-13 16:01 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-07-13 16:01 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-07-13 16:01 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-07-13 16:01 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-07-13 16:01 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-07-13 16:01 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-07-13 16:01 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-07-13 16:01 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-07-13 16:01 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-07-13 16:01 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-07-13 16:00 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-07-13 16:00 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-07-13 16:00 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-07-13 16:00 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-07-13 16:00 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2014-07-13 16:00 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-07-13 16:00 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-07-13 16:00 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-07-13 16:00 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-07-13 16:00 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-07-13 16:00 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-07-13 16:00 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-07-13 16:00 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-07-13 16:00 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-07-13 16:00 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-07-13 16:00 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-07-13 15:59 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll 2014-07-13 15:59 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll 2014-07-13 15:59 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys 2014-07-13 15:58 - 2014-06-30 03:40 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-07-13 15:58 - 2014-06-30 03:36 - 00302592 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-07-13 15:55 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-03 13:01 - 2014-08-03 11:05 - 00010614 _____ () C:\Users\Acar\Desktop\FRST.txt 2014-08-03 13:01 - 2014-08-03 11:05 - 00000000 ____D () C:\FRST 2014-08-03 12:57 - 2009-07-14 06:34 - 00010272 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-03 12:57 - 2009-07-14 06:34 - 00010272 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-03 12:54 - 2011-01-06 08:40 - 01603769 _____ () C:\windows\WindowsUpdate.log 2014-08-03 12:50 - 2013-12-23 00:55 - 00277164 _____ () C:\windows\PFRO.log 2014-08-03 12:50 - 2011-01-06 10:38 - 00000000 ____D () C:\windows\cs 2014-08-03 12:50 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-08-03 12:50 - 2009-07-14 06:39 - 00042714 _____ () C:\windows\setupact.log 2014-08-03 12:49 - 2014-08-03 12:49 - 00001818 _____ () C:\Users\Acar\Desktop\MWBY.txt 2014-08-03 12:28 - 2014-08-03 12:27 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-03 12:27 - 2014-08-03 12:27 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-03 12:27 - 2014-08-03 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-03 12:27 - 2014-08-03 12:27 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-08-03 12:27 - 2014-08-03 09:55 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-03 12:26 - 2014-08-03 12:25 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Acar\Desktop\mbam-setup-2.0.2.1012 (1).exe 2014-08-03 12:26 - 2013-12-23 01:13 - 00001116 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA.job 2014-08-03 12:24 - 2014-08-03 12:24 - 00005318 _____ () C:\Users\Acar\Desktop\AdwCleaner[S0].txt 2014-08-03 12:22 - 2014-06-21 16:06 - 00001650 _____ () C:\Users\Acar\Desktop\Videostream for Google Chromecast™.lnk 2014-08-03 12:22 - 2014-06-20 22:10 - 00001492 _____ () C:\Users\Acar\Desktop\Chrome App Launcher.lnk 2014-08-03 12:18 - 2014-08-03 12:12 - 00000000 ____D () C:\AdwCleaner 2014-08-03 12:17 - 2014-03-04 01:03 - 00001023 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-08-03 12:17 - 2014-03-04 01:03 - 00001011 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-08-03 12:17 - 2013-12-23 01:14 - 00000000 ____D () C:\Users\Acar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-08-03 12:17 - 2013-12-22 22:07 - 00001150 _____ () C:\Users\Acar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-08-03 12:17 - 2009-07-14 04:04 - 00000505 _____ () C:\windows\win.ini 2014-08-03 12:16 - 2014-06-20 21:49 - 00000000 ____D () C:\Program Files\Greener Web 2014-08-03 12:15 - 2013-12-23 19:10 - 00000924 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000UA.job 2014-08-03 12:13 - 2014-03-04 01:10 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-08-03 12:11 - 2014-08-03 12:11 - 01361309 _____ () C:\Users\Acar\Desktop\adwcleaner_3.302.exe 2014-08-03 11:09 - 2014-08-03 11:08 - 00031110 _____ () C:\Users\Acar\Desktop\Addition.txt 2014-08-03 11:04 - 2014-08-03 11:04 - 01084928 _____ (Farbar) C:\Users\Acar\Desktop\FRST.exe 2014-08-03 10:26 - 2013-12-23 01:13 - 00001064 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core.job 2014-08-03 09:54 - 2014-08-03 09:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Acar\Desktop\mbam-setup-1.75.0.1300.exe 2014-08-03 09:06 - 2011-01-06 10:27 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-03 00:06 - 2013-12-22 21:53 - 00000000 ____D () C:\ProgramData\Skype 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ___RD () C:\Program Files\Skype 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-08-03 00:05 - 2014-08-03 00:05 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-08-03 00:04 - 2011-01-06 10:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-02 23:54 - 2014-08-01 06:42 - 00000000 ____D () C:\Users\Acar\Desktop\bILDER 2014-08-02 23:53 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\de-DE 2014-08-02 01:02 - 2013-12-23 20:00 - 00000000 ____D () C:\Users\Acar\AppData\Roaming\Skype 2014-08-02 00:15 - 2013-12-23 19:10 - 00000902 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2338033741-1917138375-3194134120-1000Core.job 2014-08-02 00:06 - 2013-12-23 20:44 - 00000000 ____D () C:\Users\Acar\AppData\Roaming\skypePM 2014-08-02 00:05 - 2014-08-02 00:05 - 00000000 ____D () C:\Users\Acar\AppData\Local\Windows Live 2014-08-01 06:54 - 2014-08-01 06:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Acar\Desktop\mbam-setup-2.0.2.1012.exe 2014-08-01 06:43 - 2009-07-26 22:06 - 01618320 _____ () C:\windows\system32\PerfStringBackup.INI 2014-07-27 18:19 - 2014-07-27 18:18 - 00001878 _____ () C:\Users\Acar\Desktop\Chrome.lnk 2014-07-20 19:14 - 2009-07-14 06:33 - 00259256 _____ () C:\windows\system32\FNTCACHE.DAT 2014-07-19 18:46 - 2014-05-24 22:15 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-07-13 18:49 - 2013-12-22 23:17 - 00000000 ____D () C:\windows\system32\MRT 2014-07-13 18:45 - 2013-12-22 23:17 - 93585272 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-07-13 00:13 - 2014-03-04 01:10 - 00699056 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe 2014-07-13 00:13 - 2014-03-04 01:10 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\Acar\AppData\Local\Temp\JDSetup130477671127458543.exe C:\Users\Acar\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Acar\AppData\Local\Temp\MSN4E40.exe C:\Users\Acar\AppData\Local\Temp\Quarantine.exe C:\Users\Acar\AppData\Local\Temp\vlc-2.1.3-win32.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\windows\explorer.exe => File is digitally signed C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-29 11:45 ==================== End Of Log ============================ |
03.08.2014, 12:18 | #8 |
/// TB-Ausbilder | Greener Web Virus auf meinem Laptop Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 3 h) dauern. Im Anschluss entfernen wir alle verwendeten Tools und ich gebe dir noch ein paar Tipps mit auf den Weg. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File C:\Program Files\Greener Web Reboot: end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 ESET Online Scanner
Schritt 3 Downloade Dir bitte SecurityCheck und:
Schritt 4 Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit) | SystemLook (64 bit)
Bitte poste mit deiner nächsten Antwort
|
03.08.2014, 15:02 | #9 |
| Greener Web Virus auf meinem Laptop FRST Logfile: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:2-08-2014 Ran by Acar at 2014-08-03 13:24:10 Run:1 Running from C:\Users\Acar\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** start Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File C:\Program Files\Greener Web Reboot: end ***************** HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value deleted successfully. "HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => Key not found. C:\Program Files\Greener Web => Moved successfully. The system needed a reboot. ==== End of Fixlog ==== Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=6316426ab8778f439e9adee8ab427e19 # engine=19476 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-08-03 01:06:54 # local_time=2014-08-03 03:06:54 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 53873 158702405 0 0 # scanned=120753 # found=24 # cleaned=0 # scan_time=5527 sh=53083BEC6BA91F0AC29441CAF1D52A785C3CF629 ft=1 fh=f4bf2edc463addb1 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\$Recycle.Bin\S-1-5-21-2338033741-1917138375-3194134120-1000\$RBS80MG.exe" sh=15F5DE338D6C225334E725ED3C92F202746C378F ft=1 fh=7971f9e28c3585b0 vn="Win32/BrowseFox.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\GreenerWebUninstall.exe.vir" sh=B3C4979C2FF898B476347EB5698759B4D31BED5D ft=1 fh=62acf448b1e227d1 vn="Variante von Win32/BrowseFox.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\updateGreenerWeb.exe.vir" sh=1CCB034B2E0F93A8A9D1925A03195345828E6732 ft=1 fh=992efbd899fdd498 vn="Variante von Win32/BrowseFox.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\GreenerWeb.BrowserAdapter.exe.vir" sh=15E0A66BC099D02C964F249E1496C8F9DAC0AB99 ft=1 fh=5f0698277ea453ea vn="Variante von Win32/BrowseFox.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\GreenerWeb.PurBrowse.exe.vir" sh=B3C4979C2FF898B476347EB5698759B4D31BED5D ft=1 fh=62acf448b1e227d1 vn="Variante von Win32/BrowseFox.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\utilGreenerWeb.exe.vir" sh=63531B576059F2665F0B2CF790508EDADA4FD182 ft=1 fh=ee307c57b6958867 vn="Variante von Win32/BrowseFox.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\{a3f28269-ad17-41a8-b032-3e0313ef8979}.dll.vir" sh=77ACC5EB926142A5B17BFFC54B3F27A0720CABC8 ft=1 fh=dd549ffa0db0b18e vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\plugins\GreenerWeb.Bromon.dll.vir" sh=A4F01445EDDE4BE5BB936D8F8D71200FBCB61131 ft=1 fh=440f80dc4fc85b3b vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\plugins\GreenerWeb.BroStats.dll.vir" sh=5BF1789BFA3D4BAD6D9B1B7887C9A3B8C35A16FE ft=1 fh=215a459f775393d2 vn="möglicherweise Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\plugins\GreenerWeb.BrowserAdapterS.dll.vir" sh=71151A6F73AA5A8E6E39881B8BA45FE59BED61B5 ft=1 fh=f4840804546354c9 vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\plugins\GreenerWeb.CompatibilityChecker.dll.vir" sh=AC63963DDB34E9C483633D1EB156F0084BFC5D0A ft=1 fh=ce3fc1bfa01191dc vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\plugins\GreenerWeb.FeSvc.dll.vir" sh=1458F903BFAEF9598BD39D570464B93EDFDEBCFC ft=1 fh=1af7f31de785e1d3 vn="Variante von MSIL/BrowseFox.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\plugins\GreenerWeb.FFUpdate.dll.vir" sh=4E3B8ED4B239D0A832C92A6F367E45C5ADEB106F ft=1 fh=3854dba660c50101 vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Greener Web\bin\plugins\GreenerWeb.PurBrowse.dll.vir" sh=C7C0F42A23562AA6DCCD60326FD8CC2AA41B5448 ft=1 fh=c053642cee9f3def vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SupTab\DpInterface32.dll.vir" sh=9DC13DB9C123270C2356ED410128E11D5ADF7C6E ft=1 fh=023ab782f0a9b07d vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SupTab.dll.vir" sh=56659F7FF1F1FA7906A77228E315F65F38BCEF73 ft=1 fh=0ff759dfc352fd03 vn="Variante von Win32/ELEX.AD evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir" sh=251A3803C9AB15C6EAF576250F78DC4CC1D843F7 ft=1 fh=bbd71f22d491c083 vn="Variante von Win32/ELEX.AM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\WindowsProtectManger\wprotectmanager.exe.vir" sh=08A0C25B0BF40535697C1C584ACCDA490D6BC882 ft=1 fh=dbe7f66a50ce49ed vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Acar\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=1CCB034B2E0F93A8A9D1925A03195345828E6732 ft=1 fh=992efbd899fdd498 vn="Variante von Win32/BrowseFox.I evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\Greener Web\bin\GreenerWeb.BrowserAdapter.exe" sh=63531B576059F2665F0B2CF790508EDADA4FD182 ft=1 fh=ee307c57b6958867 vn="Variante von Win32/BrowseFox.M evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\Greener Web\bin\{a3f28269-ad17-41a8-b032-3e0313ef8979}.dll" sh=3E6A0EA5377C84825172B6E60A39B69DA23A5AA6 ft=1 fh=3086bf72a5c73221 vn="Variante von Win32/DomaIQ.BI evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Acar\AppData\Local\Google\Chrome\User Data\Default\File System\000\t\00\00000000" sh=51997E82EA59B7BD8B8AB0A29DB1DB2C206367AD ft=1 fh=94edffc38116c41f vn="Variante von Win32/InstallCore.LN evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Acar\AppData\Local\Temp\JDSetup130477671127458543.exe" sh=CB09C3AFD247010033535E6F4665A558C053263B ft=1 fh=4eb020c61d8f9c6a vn="Win32/BrowseFox.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Acar\AppData\Local\Temp\is1201216051\592CACBD_stp\GreenerWeb_is.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.85 Windows 7 Service Pack 1 x86 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` CCleaner Java 7 Update 45 Java version out of Date! Adobe Flash Player 14.0.0.145 Mozilla Firefox 27.0.1 Firefox out of Date! Google Chrome 35.0.1916.153 Google Chrome 36.0.1985.125 ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff Log created at 15:55 on 03/08/2014 by Acar Administrator - Elevation successful ========== folderfind ========== Searching for "*Greener Web*" C:\AdwCleaner\Quarantine\C\Program Files\Greener Web d------ [10:16 03/08/2014] C:\AdwCleaner\Quarantine\C\Users\Acar\AppData\Local\Temp\Greener Web d------ [10:17 03/08/2014] C:\FRST\Quarantine\C\Program Files\Greener Web d------ [19:49 20/06/2014] ========== regfind ========== Searching for "Greener Web" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}\InprocServer32] @="C:\Program Files\Greener Web\bin\{a3f28269-ad17-41a8-b032-3e0313ef8979}.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}\1.0\0\win32] @="C:\Program Files\Greener Web\bin\{a3f28269-ad17-41a8-b032-3e0313ef8979}.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}\1.0\HELPDIR] @="C:\Program Files\Greener Web\bin" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Update Greener Web] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Util Greener Web] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\eventlog\Application\Update Greener Web] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\eventlog\Application\Util Greener Web] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Update Greener Web] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Util Greener Web] Searching for " " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Live\Common] "PCModel"="NC210/NC110 " -= EOF =- Geändert von Misterix1 (03.08.2014 um 15:46 Uhr) |
03.08.2014, 15:20 | #10 |
/// TB-Ausbilder | Greener Web Virus auf meinem Laptop Servus, du solltest einen Fix mit FRST durchführen, keinen Scan... Anleitung gelesen |
03.08.2014, 21:15 | #11 |
| Greener Web Virus auf meinem Laptop Sorry falsche kopie Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:2-08-2014 Ran by Acar at 2014-08-03 13:24:10 Run:1 Running from C:\Users\Acar\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** start Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File C:\Program Files\Greener Web Reboot: end ***************** HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value deleted successfully. "HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => Key not found. C:\Program Files\Greener Web => Moved successfully. The system needed a reboot. ==== End of Fixlog ==== |
04.08.2014, 09:31 | #12 |
/// TB-Ausbilder | Greener Web Virus auf meinem Laptop Reste entfernen Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Update Greener Web DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Util Greener Web Reboot: end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1 Du verwendest veraltete Software auf deinem Rechner, was ein Sicherheitsrisiko darstellt. Daher solltest du veraltete Software deinstallieren und anschließend die aktuellste Version installieren. Folge dem Pfad Start > Systemsteuerung > Sofware / Programme deinstallieren. Deinstalliere die folgenden Programme von deinem Rechner:
Downloade und installiere dir bitte nun:Starte deinen Rechner nach der Installation neu auf. Schritt 2 Die Reihenfolge ist hier entscheidend.
Schritt 3 Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Performance
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
05.08.2014, 08:41 | #13 |
| Greener Web Virus auf meinem Laptop Bevor ich den fixlog.txt hier posten konnte hat das Programme delfix alles gelöscht. Aber es scheint alles sauber zu sein. Keine unerwünschte Werbung mehr Ich benutze eher Google Chrome statt Firefox. Java ist nun bei 8 / 11 DELFIX hat alles andere erledigt. noscript und adblocker installiert secunia online installiert Malmware Bytes und Adware Cleaner 1 x die Wochen benutzen Bleibt nur noch zu fragen, welches Antiviren Software ist effektiv und trotzdem Systemressourcen schonend? Hab nur ein Netbook. Und der ist nicht gerade ein Alienware Avira Antivir nervt mich schon manchmal mit seinen plötzlich auftauchenden Systemcheck !! Das verlangsamt mein Netbook obwohl ich nur surfen will, dauert während dessen alles ewig !! Ist Avast besser? Danke nochmal für deine Kompetente Hilfe. Alles gute |
05.08.2014, 10:25 | #14 | |
/// TB-Ausbilder | Greener Web Virus auf meinem LaptopZitat:
Ich bin froh, dass wir helfen konnten In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest: Lob, Kritik und Wünsche Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank! Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |