|
Plagegeister aller Art und deren Bekämpfung: click compare und co. werd ich einfach nicht los :(((Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
31.08.2014, 19:19 | #1 |
| click compare und co. werd ich einfach nicht los :((( hallo zusammen, ich lese hier im board seit fast 2 wochen mit. zu diesem zeitpunkt ist mir aufgefallen das ich ständig auf irgendwelche gewinnspiele etc. umgeleitet werde. ein bisschen gegoogelt und schlau gemacht. siehe da, von click compare befallen. darauf hin habe ich hier 2-3 lösungswege versucht nachzuempfinden. einige programme drüber laufen lassen. zum schluss wurde immer nichts mehr gefunden. wenn ich dann am folgenden tag den pc wieder einschalte. wer meldet sich? klar, clickcompare. so langsam bin ich jetzt am verzweifeln. könnte sich jemand erbamren und mir und die arme greifen. alternativ sammel ich spenden für eine neue hdd danke schon mal! |
31.08.2014, 20:30 | #2 |
/// the machine /// TB-Ausbilder | click compare und co. werd ich einfach nicht los :((( Hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
01.09.2014, 06:15 | #3 |
| click compare und co. werd ich einfach nicht los :((( guten morgen,
__________________gesagt, getan... hier die frst.txt: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2014 02 Ran by Udi (administrator) on DESKTOP on 01-09-2014 07:09:00 Running from C:\Users\Udi\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\IVT Corporation\BlueSoleil\BTNtService.exe (HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe () C:\Users\Udi\AppData\Local\CloudStation\bin\cloud.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Users\Udi\AppData\Local\CloudStation\bin\client-win.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe () C:\Program Files (x86)\IVT Corporation\BlueSoleil\StartSkysolSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe () C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe () C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM\...\Run: [] => [X] HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe [8886592 2014-08-27] () HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2252800 2011-11-05] (VIA) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113296 2010-03-30] (NEC Electronics Corporation) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-15] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\Run: [Start WingMan Profiler] => [X] HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [4910912 2011-08-02] (DT Soft Ltd) HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.) HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: E - E:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: G - G:\CDSETUP.EXE HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: {13a8d5c8-2143-11e3-af47-001583165968} - E:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: {13a8d5e3-2143-11e3-af47-001583165968} - E:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: {5fd61432-2073-11e3-81b4-806e6f6e6963} - E:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: {5fd61471-2073-11e3-81b4-001583165968} - E:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: {91481b32-07a7-11e1-b6b6-806e6f6e6963} - I:\autorun.exe HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: {be0c337a-05ed-11e4-b9b6-001583165968} - E:\LaunchU3.exe HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: {c498bb0a-209e-11e3-9735-001583165968} - E:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: {c498bb1e-209e-11e3-9735-001583165968} - E:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\MountPoints2: {efe7a395-ca91-11e2-ad14-001583165968} - E:\HTC_Sync_Manager_PC.exe Lsa: [Authentication Packages] msv1_0 relog_ap Startup: C:\Users\Udi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CloudStation.lnk ShortcutTarget: CloudStation.lnk -> C:\Users\Udi\AppData\Local\CloudStation\bin\cloud.exe () ShellIconOverlayIdentifiers: 01UnsuppModule -> {AEB16659-2125-4ADA-A4AB-45EE21E86469} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 02SyncingModule -> {48AB5ADA-36B1-4137-99C9-2BD97F8788AB} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 03SyncedModule -> {472CE1AD-5D53-4BCF-A1FB-3982A5F55138} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 04ReadOnlyModule -> {A433C3E0-8B24-40EB-93C3-4B10D9959F58} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3ECA9489B59BCC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default FF NewTab: about:blank FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Keyword.URL: hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_9&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: synology.com/SurveillancePlugin -> C:\Program Files (x86)\Synology\SurveillancePlugin\1.0.0.423\npSurveillancePlugin.dll (Synology) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Browser Safety - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\abs@avira.com [2014-08-30] FF Extension: ProxTube - Unblock YouTube - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\ich@maltegoetz.de [2013-12-11] FF Extension: WOT - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-08-30] FF Extension: FoxLingo - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66} [2013-12-04] FF Extension: Adblock Plus - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-30] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-07-22] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-07-22] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-07-22] Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG) R2 BlueSoleil Hid Service; C:\Program Files (x86)\IVT Corporation\BlueSoleil\BTNtService.exe [166520 2007-12-27] () R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136192 2009-11-12] (HP) [File not signed] R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-03-11] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-03-11] (Hewlett-Packard Co.) [File not signed] R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe [706864 2014-08-27] () R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed] R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.) R2 Start BT in service; C:\Program Files (x86)\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [51816 2007-12-27] () R2 TryAndDecideService; C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [498792 2007-12-03] () R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248736 2014-02-25] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2014-08-21] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2014-08-21] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2014-08-21] (BitDefender) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-08-15] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-08-15] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-08-15] (Avira Operations GmbH & Co. KG) R1 BdfNdisf; c:\program files\lavasoft\ad-aware antivirus\firewall engine\1.6.0.0\drivers\bdfndisf6.sys [93160 2014-07-10] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfwfpf.sys [102992 2014-07-10] (BitDefender LLC) R3 BlueletAudio; C:\Windows\System32\DRIVERS\blueletaudio.sys [37896 2007-06-24] (IVT Corporation.) R3 BlueletAudio; C:\Windows\SysWOW64\DRIVERS\blueletaudio.sys [37896 2007-06-24] (IVT Corporation.) R3 BlueletSCOAudio; C:\Windows\System32\DRIVERS\BlueletSCOAudio.sys [37384 2007-06-24] (IVT Corporation.) R3 BlueletSCOAudio; C:\Windows\SysWOW64\DRIVERS\BlueletSCOAudio.sys [37384 2007-06-24] (IVT Corporation.) R3 BT; C:\Windows\System32\DRIVERS\btnetdrv.sys [25360 2007-03-05] (IVT Corporation.) R3 BT; C:\Windows\SysWOW64\DRIVERS\btnetdrv.sys [25360 2007-03-05] (IVT Corporation.) R3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [47368 2007-06-24] (IVT Corporation.) R3 Btcsrusb; C:\Windows\SysWOW64\Drivers\btcusb.sys [47368 2007-06-24] (IVT Corporation.) R0 BTHidEnum; C:\Windows\System32\Drivers\vbtenum.sys [24976 2007-03-05] (IVT Corporation.) R0 BTHidEnum; C:\Windows\SysWOW64\Drivers\vbtenum.sys [24976 2007-03-05] (IVT Corporation.) R0 BTHidMgr; C:\Windows\System32\Drivers\BTHidMgr.sys [49680 2007-03-05] (IVT Corporation.) R0 BTHidMgr; C:\Windows\SysWOW64\Drivers\BTHidMgr.sys [49680 2007-03-05] (IVT Corporation.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [270912 2011-11-05] (DT Soft Ltd) R3 gzflt; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.0.56\gzflt.sys [150256 2014-07-10] (BitDefender LLC) S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (HTC, Corporation) [File not signed] R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] () S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd) S3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [389240 2014-07-10] (BitDefender S.R.L.) R3 VComm; C:\Windows\System32\DRIVERS\VComm.sys [47120 2007-03-05] (IVT Corporation.) R3 VComm; C:\Windows\SysWOW64\DRIVERS\VComm.sys [47120 2007-03-05] (IVT Corporation.) R3 VcommMgr; C:\Windows\System32\Drivers\VcommMgr.sys [63248 2007-03-05] (IVT Corporation.) R3 VcommMgr; C:\Windows\SysWOW64\Drivers\VcommMgr.sys [63248 2007-03-05] (IVT Corporation.) R3 VHidMinidrv; C:\Windows\System32\drivers\VHIDMini.sys [23184 2007-03-05] (IVT Corporation.) R3 VHidMinidrv; C:\Windows\SysWOW64\drivers\VHIDMini.sys [23184 2007-03-05] (IVT Corporation.) S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-01 07:09 - 2014-09-01 07:09 - 00019954 _____ () C:\Users\Udi\Desktop\FRST.txt 2014-09-01 07:08 - 2014-09-01 07:08 - 02104832 _____ (Farbar) C:\Users\Udi\Desktop\FRST64.exe 2014-08-30 23:29 - 2014-08-30 23:35 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-30 23:29 - 2014-08-30 23:29 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Avira 2014-08-30 23:28 - 2014-08-30 23:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-30 23:28 - 2014-08-30 23:34 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-30 23:28 - 2014-08-30 23:29 - 00000000 ____D () C:\ProgramData\Avira 2014-08-30 23:28 - 2014-08-15 10:30 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-08-30 23:28 - 2014-08-15 10:30 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-08-30 23:28 - 2014-08-15 10:30 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-08-30 23:21 - 2014-08-31 00:34 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-08-30 23:21 - 2014-08-30 23:22 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-08-30 23:21 - 2014-08-30 23:21 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk 2014-08-30 23:21 - 2014-08-30 23:21 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-08-30 23:21 - 2014-08-30 23:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 2014-08-30 23:21 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2014-08-30 22:37 - 2014-08-30 22:37 - 00000000 ____D () C:\ProgramData\BitDefender 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\LavasoftStatistics 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2014-08-30 22:30 - 2014-07-10 14:09 - 02084072 _____ (Bitdefender) C:\Windows\system32\bdnc.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 01061776 _____ (BitDefender S.R.L.) C:\Windows\system32\bdsmtpp.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00209984 _____ (BitDefender) C:\Windows\system32\BdFirewallSDK.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00195016 _____ (BitDefender) C:\Windows\system32\httproxy.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00156936 _____ () C:\Windows\system32\bdfwcore.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00155912 _____ (BitDefender S.R.L.) C:\Windows\system32\bdpop3p.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00122928 _____ (BitDefender) C:\Windows\system32\OEMbdpredir.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00096160 _____ (BitDefender) C:\Windows\system32\bdpredir.dll 2014-08-30 22:29 - 2014-09-01 07:05 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Users\Udi\AppData\Local\adawarebp 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Program Files\Lavasoft 2014-08-30 22:28 - 2014-08-30 22:28 - 00000000 ____D () C:\Program Files (x86)\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-08-30 22:26 - 2014-08-30 23:27 - 00000000 ____D () C:\Users\Udi\Desktop\Viren 2014-08-30 21:58 - 2014-08-30 21:58 - 00000000 ____D () C:\Windows\ERUNT 2014-08-30 21:39 - 2014-08-30 21:39 - 01016261 _____ (Thisisu) C:\Users\Udi\Desktop\JRT.exe 2014-08-30 21:38 - 2014-08-30 23:16 - 00000000 ____D () C:\AdwCleaner 2014-08-30 21:28 - 2014-08-30 22:20 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-30 21:28 - 2014-08-30 21:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-30 21:28 - 2014-08-30 21:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-30 21:28 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-30 21:28 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-30 21:28 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-30 21:18 - 2014-09-01 07:09 - 00000000 ____D () C:\FRST 2014-08-30 21:16 - 2014-08-30 22:11 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-08-30 11:20 - 2014-08-30 11:20 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 12:29 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-28 12:29 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-28 12:29 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-08-21 12:30 - 2014-08-21 12:30 - 00727592 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00601360 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00261056 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys 2014-08-21 09:43 - 2014-08-21 09:43 - 06052529 _____ (Tim Kosse) C:\Users\Udi\Downloads\FileZilla_3.9.0.3_win32-setup.exe 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-16 16:27 - 2014-08-16 16:27 - 00000000 ____D () C:\Users\Udi\AppData\Local\Adobe 2014-08-14 15:25 - 2014-08-14 15:18 - 00110314 ____N () C:\Users\Udi\Desktop\wachat_20140814.txt 2014-08-14 15:25 - 1970-01-01 01:59 - 00062754 ____N () C:\Users\Udi\Desktop\wachat_20140814.xlsx 2014-08-14 15:15 - 2014-08-14 19:47 - 00000000 ____D () C:\adb 2014-08-13 13:22 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-13 13:22 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-13 13:22 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-13 13:22 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-13 13:22 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-13 13:22 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-13 13:22 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-13 13:22 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-13 12:37 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-13 12:37 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-13 12:33 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-13 12:33 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-13 12:33 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-13 12:33 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-13 12:33 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-13 12:33 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-13 12:33 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-13 12:33 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-13 12:33 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-13 12:33 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-13 12:33 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-13 12:32 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-13 12:32 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-13 12:32 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-13 12:32 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-13 12:32 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-13 12:32 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-13 12:32 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-13 12:32 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-13 12:32 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-13 12:32 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-13 12:32 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-13 12:32 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-13 12:32 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-13 12:32 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-13 12:32 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-13 12:32 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-13 12:32 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-13 12:32 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-13 12:32 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-13 12:32 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-13 12:32 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-13 12:32 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-13 12:32 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-13 12:32 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-13 12:32 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-13 12:32 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-13 12:32 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-13 12:32 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-13 12:32 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-13 12:32 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-13 12:32 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-13 12:32 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-13 12:32 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-13 12:32 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-13 12:32 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-13 12:32 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-13 12:32 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-13 12:32 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-13 12:32 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-13 12:32 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-13 12:32 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-13 12:32 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-13 12:32 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-13 12:32 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-13 12:32 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-13 12:32 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-13 12:32 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-13 12:32 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-13 12:32 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-13 12:32 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-13 12:32 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-13 12:32 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-13 12:32 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-13 12:32 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-13 12:32 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-13 12:32 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-13 12:32 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-13 12:28 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-13 12:28 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-13 12:27 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-13 12:27 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-12 21:49 - 2014-08-12 21:50 - 00000001 ____R () C:\Users\Udi\serverport 2014-08-12 21:49 - 2014-08-12 21:49 - 00000000 ____D () C:\Users\Udi\.jivex 2014-08-05 18:25 - 2014-08-05 18:25 - 01538102 _____ () C:\Users\Udi\Desktop\Oscam Konfiguration.zip 2014-08-04 20:15 - 2014-08-04 20:15 - 06004615 _____ (Tim Kosse) C:\Users\Udi\Downloads\FileZilla_3.9.0.2_win32-setup.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-01 07:09 - 2014-09-01 07:09 - 00019954 _____ () C:\Users\Udi\Desktop\FRST.txt 2014-09-01 07:09 - 2014-08-30 21:18 - 00000000 ____D () C:\FRST 2014-09-01 07:08 - 2014-09-01 07:08 - 02104832 _____ (Farbar) C:\Users\Udi\Desktop\FRST64.exe 2014-09-01 07:05 - 2014-08-30 22:29 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection 2014-09-01 07:05 - 2013-10-12 19:52 - 00000000 ___RD () C:\Users\Udi\Cloud Station 2014-09-01 07:05 - 2013-10-12 19:17 - 00000000 ____D () C:\Users\Udi\AppData\Local\CloudStation 2014-09-01 07:05 - 2009-07-14 06:51 - 00587313 _____ () C:\Windows\setupact.log 2014-09-01 07:04 - 2012-09-15 15:40 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-09-01 07:04 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-31 21:37 - 2011-11-05 14:18 - 01769162 _____ () C:\Windows\WindowsUpdate.log 2014-08-31 14:55 - 2009-07-14 06:45 - 00022048 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-31 14:55 - 2009-07-14 06:45 - 00022048 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-31 14:54 - 2009-07-14 19:58 - 24321076 _____ () C:\Windows\system32\perfh007.dat 2014-08-31 14:54 - 2009-07-14 19:58 - 07612528 _____ () C:\Windows\system32\perfc007.dat 2014-08-31 14:54 - 2009-07-14 07:13 - 00006292 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-31 00:36 - 2011-11-05 15:31 - 00352460 _____ () C:\Windows\PFRO.log 2014-08-31 00:34 - 2014-08-30 23:21 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-08-30 23:35 - 2014-08-30 23:29 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-30 23:34 - 2014-08-30 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-30 23:34 - 2014-08-30 23:28 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-30 23:29 - 2014-08-30 23:29 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Avira 2014-08-30 23:29 - 2014-08-30 23:28 - 00000000 ____D () C:\ProgramData\Avira 2014-08-30 23:27 - 2014-08-30 22:26 - 00000000 ____D () C:\Users\Udi\Desktop\Viren 2014-08-30 23:22 - 2014-08-30 23:21 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-08-30 23:21 - 2014-08-30 23:21 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk 2014-08-30 23:21 - 2014-08-30 23:21 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-08-30 23:21 - 2014-08-30 23:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 2014-08-30 23:16 - 2014-08-30 21:38 - 00000000 ____D () C:\AdwCleaner 2014-08-30 22:37 - 2014-08-30 22:37 - 00000000 ____D () C:\ProgramData\BitDefender 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\LavasoftStatistics 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Users\Udi\AppData\Local\adawarebp 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Program Files\Lavasoft 2014-08-30 22:28 - 2014-08-30 22:28 - 00000000 ____D () C:\Program Files (x86)\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-08-30 22:20 - 2014-08-30 21:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-30 22:11 - 2014-08-30 21:16 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-08-30 21:58 - 2014-08-30 21:58 - 00000000 ____D () C:\Windows\ERUNT 2014-08-30 21:39 - 2014-08-30 21:39 - 01016261 _____ (Thisisu) C:\Users\Udi\Desktop\JRT.exe 2014-08-30 21:28 - 2014-08-30 21:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-30 21:28 - 2014-08-30 21:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-30 21:24 - 2013-06-01 12:02 - 00000000 ____D () C:\Program Files (x86)\HTC 2014-08-30 21:23 - 2012-05-26 17:11 - 00105928 _____ () C:\Windows\DPINST.LOG 2014-08-30 11:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Cursors 2014-08-30 11:20 - 2014-08-30 11:20 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 20:03 - 2009-07-14 06:45 - 00357080 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-24 15:44 - 2014-02-20 22:33 - 00000000 ____D () C:\Users\Udi\Documents\FIFA 14 2014-08-24 14:20 - 2014-02-16 14:31 - 00000000 ____D () C:\ProgramData\Origin 2014-08-24 14:20 - 2014-02-16 14:30 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-08-23 12:19 - 2013-09-27 18:07 - 00000000 ____D () C:\Program Files (x86)\Synology 2014-08-23 04:07 - 2014-08-28 12:29 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-23 03:45 - 2014-08-28 12:29 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-23 02:59 - 2014-08-28 12:29 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-08-21 12:30 - 2014-08-21 12:30 - 00727592 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00601360 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00261056 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys 2014-08-21 09:48 - 2011-11-05 19:09 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\FileZilla 2014-08-21 09:47 - 2013-08-10 00:00 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\vlc 2014-08-21 09:43 - 2014-08-21 09:43 - 06052529 _____ (Tim Kosse) C:\Users\Udi\Downloads\FileZilla_3.9.0.3_win32-setup.exe 2014-08-21 09:43 - 2011-11-05 19:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2014-08-21 09:43 - 2011-11-05 19:08 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-16 16:27 - 2014-08-16 16:27 - 00000000 ____D () C:\Users\Udi\AppData\Local\Adobe 2014-08-16 11:39 - 2012-04-15 21:04 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-08-16 11:39 - 2011-11-05 14:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-08-15 10:30 - 2014-08-30 23:28 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-08-15 10:30 - 2014-08-30 23:28 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-08-15 10:30 - 2014-08-30 23:28 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-08-15 10:02 - 2011-11-05 14:18 - 00000000 ____D () C:\Users\Udi\AppData\Local\VirtualStore 2014-08-14 19:47 - 2014-08-14 15:15 - 00000000 ____D () C:\adb 2014-08-14 15:18 - 2014-08-14 15:25 - 00110314 ____N () C:\Users\Udi\Desktop\wachat_20140814.txt 2014-08-13 21:06 - 2013-05-19 17:05 - 00000000 ____D () C:\Windows\rescache 2014-08-13 18:44 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-13 13:26 - 2013-07-29 14:44 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-13 13:25 - 2012-04-20 18:45 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-13 13:22 - 2014-05-06 21:03 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-12 21:50 - 2014-08-12 21:49 - 00000001 ____R () C:\Users\Udi\serverport 2014-08-12 21:49 - 2014-08-12 21:49 - 00000000 ____D () C:\Users\Udi\.jivex 2014-08-12 21:49 - 2011-11-05 14:18 - 00000000 ____D () C:\Users\Udi 2014-08-07 11:34 - 2014-05-19 20:38 - 00001102 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-08-07 04:06 - 2014-08-13 12:27 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 04:01 - 2014-08-13 12:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-05 18:25 - 2014-08-05 18:25 - 01538102 _____ () C:\Users\Udi\Desktop\Oscam Konfiguration.zip 2014-08-05 09:20 - 2011-11-05 17:05 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-08-04 20:15 - 2014-08-04 20:15 - 06004615 _____ (Tim Kosse) C:\Users\Udi\Downloads\FileZilla_3.9.0.2_win32-setup.exe 2014-08-03 22:06 - 2012-04-20 21:13 - 00000000 ____D () C:\Users\Udi\AppData\Local\Downloaded Installations Some content of TEMP: ==================== C:\Users\Gast\AppData\Local\Temp\AskSLib.dll C:\Users\Udi\AppData\Local\Temp\avgnt.exe C:\Users\Udi\AppData\Local\Temp\JiveXViewerStart1407872996.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-28 12:42 ==================== End Of Log ============================ und die addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-08-2014 02 Ran by Udi at 2014-09-01 07:14:27 Running from C:\Users\Udi\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Ad-Aware Antivirus (Enabled - Up to date) {D87B6541-12A1-DAEA-0033-9B8057AAB996} AS: Ad-Aware Antivirus (Enabled - Up to date) {631A84A5-349B-D564-3A83-A0F22C2DF32B} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} FW: Ad-Aware Firewall (Disabled) {E040E464-58CE-DBB2-2B6C-32B5A979FEED} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 4.2.1 - Hewlett-Packard) Hidden Acronis*True*Image*Home (HKLM-x32\...\{633A06C3-B709-479A-AAB3-5EE94AD9EE4B}) (Version: 11.0.8064 - Acronis) Ad-Aware Antivirus (HKLM\...\{E39A80AE-0CC0-43EE-AB6B-BE11DC4F969F}_AdAwareUpdater) (Version: 11.3.6321.0 - Lavasoft) AdAwareInstaller (Version: 11.3.6321.0 - Lavasoft) Hidden AdAwareUpdater (Version: 11.3.6321.0 - Lavasoft) Hidden Adobe Flash Player 11 ActiveX 64-bit (HKLM\...\Adobe Flash Player ActiveX) (Version: 11.0.1.152 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.179 - Adobe Systems Incorporated) Adobe Reader XI (11.0.03) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated) AntimalwareEngine (Version: 3.0.0.56 - Lavasoft) Hidden AntispamEngine (Version: 2.4.2158.0 - Lavasoft) Hidden aTube Catcher (HKLM-x32\...\aTube Catcher) (Version: 2.9.1462 - DsNET Corp) AvcEngine (Version: 3.10.7820.0 - Lavasoft) Hidden Avira (HKLM-x32\...\{e67154a7-9cc5-4167-b782-f3982bc6c70d}) (Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.6.570 - Avira) Bluesoleil2.7.0.13 VoIP Release 071227 (HKLM-x32\...\{8F85CC2C-4B26-4CF6-B835-DC59BCEDD287}) (Version: 2.7.0.13 VoIP Release 071227 - IVT Corporation) Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.41.3.0173 - DT Soft Ltd) DeviceDiscovery (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden DeviceManagementQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden dreamboxEDIT -- The one and only settings editor for your Dreambox (HKLM-x32\...\dreamboxEDIT) (Version: - ) FIFA 14 (HKLM-x32\...\{AA7A2800-1E75-4240-855B-03AFF8E5171E}) (Version: 1.0.0.7 - Electronic Arts) FileZilla Client 3.9.0.3 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.3 - Tim Kosse) FirewallEngine (Version: 1.6.0.0 - Lavasoft) Hidden HP LaserJet M2727 MFP Series 5.2 (HKLM\...\{3A915D43-FD4F-4e4f-BEF7-B75C160B0236}) (Version: 5.2 - HP) hppFaxDrvM2727 (x32 Version: 003.100.00001 - Hewlett-Packard) Hidden hppFaxUtility (x32 Version: 001.001.00017 - Ihr Firmenname) Hidden hppFonts (x32 Version: 001.001.00056 - Hewlett-Packard) Hidden hppLaserJetService (x32 Version: 001.200.00001 - Hewlett-Packard) Hidden hppLJM2727 (x32 Version: 000.102.00101 - Hewlett-Packard) Hidden hppManualsM2727 (x32 Version: 000.002.00001 - Ihr Firmenname) Hidden hppScanTo (x32 Version: 003.103.00004 - Ihr Firmenname) Hidden hppSendFaxM2727 (x32 Version: 003.000.00001 - Ihr Firmenname) Hidden hppTLBXFXM2727 (x32 Version: 001.005.00009 - Hewlett-Packard) Hidden hpzTLBXFX (x32 Version: 005.009.00181 - Hewlett-Packard) Hidden IsoBuster 1.5 (HKLM-x32\...\IsoBuster_is1) (Version: 1.5 - Smart Projects) Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.218 (HKLM\...\{BBBE35B2-9349-3C48-BD3D-F574B17C7924}) (Version: 9.0.21022.218 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft) Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) NEC Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}) (Version: 1.0.20.0 - NEC Electronics Corporation) NEC Electronics USB 3.0 Host Controller Driver (x32 Version: 1.0.20.0 - NEC Electronics Corporation) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.8 - Notepad++ Team) Nur Entfernen der CopyTrans Suite möglich (HKCU\...\CopyTrans Suite) (Version: 2.37 - WindSolutions) NVIDIA 3D Vision Controller-Treiber 306.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 306.23 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation) NVIDIA Grafiktreiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.108.688 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.12.0604 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.12.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0604 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 311.06 (Version: 311.06 - NVIDIA Corporation) Hidden NVIDIA Update 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.11.3 - NVIDIA Corporation) Hidden OnlineThreatsEngine (Version: 2.2.3.0 - Lavasoft) Hidden Origin (HKLM-x32\...\Origin) (Version: 9.4.5.195 - Electronic Arts, Inc.) Platform (x32 Version: 1.34 - VIA Technologies, Inc.) Hidden Product_Min_QFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden Realtek 8136 8168 8169 Ethernet Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0005 - Realtek) SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.16.0 - SAMSUNG Electronics Co., Ltd.) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.) SurveillancePlugin (HKLM-x32\...\{B4637DBD-7E8E-46D4-BC9C-EC1C9F1DC561}) (Version: 1.0.0.423 - Synology) Synology Assistant (remove only) (HKLM-x32\...\Synology Assistant) (Version: - ) Synology Cloud Station (remove only) (HKCU\...\Synology CloudStation) (Version: - ) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.31064 - TeamViewer) UltraISO Premium V9.6 (HKLM-x32\...\UltraISO_is1) (Version: - ) VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.) VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN) WebReg (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden WingMan Software (HKLM-x32\...\{435673AB-6821-416D-806A-E477DFA60A42}) (Version: 4.20 - Logitech) WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - ) Yahoo! Detect (HKLM-x32\...\YTdetect) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3126206505-700066600-3835712815-1001_Classes\CLSID\{2C4A5D61-009C-4561-9A33-6AFD542FD237}\InprocServer32 -> C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\ContextMenu.dll () CustomCLSID: HKU\S-1-5-21-3126206505-700066600-3835712815-1001_Classes\CLSID\{472CE1AD-5D53-4BCF-A1FB-3982A5F55138}\InprocServer32 -> C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) CustomCLSID: HKU\S-1-5-21-3126206505-700066600-3835712815-1001_Classes\CLSID\{48AB5ADA-36B1-4137-99C9-2BD97F8788AB}\InprocServer32 -> C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) CustomCLSID: HKU\S-1-5-21-3126206505-700066600-3835712815-1001_Classes\CLSID\{A433C3E0-8B24-40EB-93C3-4B10D9959F58}\InprocServer32 -> C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) CustomCLSID: HKU\S-1-5-21-3126206505-700066600-3835712815-1001_Classes\CLSID\{AEB16659-2125-4ADA-A4AB-45EE21E86469}\InprocServer32 -> C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ==================== Restore Points ========================= ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {217509FD-A65B-48FB-8F4E-450B914B86A3} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {245B3DE7-C129-4986-A1ED-D08EBD9E6345} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {D77DC77D-B886-4BD8-A010-E60D33D935DF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe ==================== Loaded Modules (whitelisted) ============= 2012-09-15 15:39 - 2013-01-18 17:00 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2007-12-27 16:39 - 2007-12-27 16:39 - 00166520 _____ () C:\Program Files (x86)\IVT Corporation\BlueSoleil\BTNtService.exe 2014-05-01 21:29 - 2014-05-01 21:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 02745168 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareShellExtension.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 03396400 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\RCF.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00123744 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\boost_filesystem-vc100-mt-1_55.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00024408 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\boost_system-vc100-mt-1_55.dll 2011-11-05 19:10 - 2005-06-07 13:26 - 00043008 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll 2014-04-02 15:32 - 2014-04-02 15:32 - 00909312 _____ () C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\ContextMenu.dll 2014-05-12 11:49 - 2014-05-12 11:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2014-08-27 12:32 - 2014-08-27 12:32 - 00706864 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe 2014-08-27 12:53 - 2014-08-27 12:53 - 00103768 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\boost_thread-vc100-mt-1_55.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00033624 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\boost_chrono-vc100-mt-1_55.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00055648 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\boost_date_time-vc100-mt-1_55.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 11947856 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareServiceKernel.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00788824 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\boost_regex-vc100-mt-1_55.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00734536 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareActivation.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 02167640 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareApplicationUpdater.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00813896 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareGamingMode.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00098624 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareReset.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00120128 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTime.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00943960 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareDefinitionsUpdater.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00869224 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareDefinitionsUpdaterScheduler.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 01105224 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareIgnoreList.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00247624 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareQuarantine.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00988504 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareAntiMalwareEngine.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00212824 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareAntiRootkitEngine.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 01172816 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareScannerHistory.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 01277248 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareScanner.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00035160 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\boost_timer-vc100-mt-1_55.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00975192 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareScannerScheduler.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 01109336 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareRealTimeProtection.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00229200 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareIncompatibles.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00891720 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareAntiSpam.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00843088 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareAntiPhishing.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 03090768 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareParentalControl.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 02624848 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareWebProtection.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 01067344 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareEmailProtection.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 01290584 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareNetworkProtection.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 01004352 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwarePromo.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00343880 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareFeedback.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 02787160 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareThreatWorkAlliance.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 01238848 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwarePinCode.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 01004864 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareNotice.dll 2014-08-27 12:52 - 2014-08-27 12:52 - 00928072 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareAvcEngine.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00154944 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\SecurityCenter.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00156936 _____ () C:\Windows\system32\bdfwcore.dll 2014-07-10 14:09 - 2014-08-31 00:18 - 00766976 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Online Threats Engine\2.2.3.0\definitions\loc1\ashttpbr.mdl 2014-07-10 14:09 - 2014-08-31 00:18 - 00556032 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Online Threats Engine\2.2.3.0\definitions\loc1\ashttpdsp.mdl 2014-07-10 14:09 - 2014-08-31 00:18 - 02575360 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Online Threats Engine\2.2.3.0\definitions\loc1\ashttpph.mdl 2014-07-10 14:09 - 2014-08-31 00:18 - 01306112 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Online Threats Engine\2.2.3.0\definitions\loc1\ashttprbl.mdl 2014-08-27 12:53 - 2014-08-27 12:53 - 08886592 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe 2014-08-27 12:53 - 2014-08-27 12:53 - 00500056 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\boost_locale-vc100-mt-1_55.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 02101568 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\HtmlFramework.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00066872 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\DllStorage.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00832848 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTrayDefaultSkin.dll 2014-08-27 12:53 - 2014-08-27 12:53 - 00811328 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\Localization.dll 2014-06-11 16:08 - 2014-06-11 16:08 - 03774880 _____ () C:\Users\Udi\AppData\Local\CloudStation\bin\cloud.exe 2011-11-05 18:01 - 2011-11-05 18:00 - 00071680 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll 2011-11-05 18:01 - 2011-11-05 18:00 - 00379392 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll 2011-11-05 18:01 - 2011-11-05 18:00 - 00098816 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\VMicApi.dll 2011-11-05 18:01 - 2011-11-05 18:00 - 47601664 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Skin.dll 2014-06-11 16:09 - 2014-06-11 16:09 - 10111448 _____ () C:\Users\Udi\AppData\Local\CloudStation\bin\client-win.exe 2007-12-27 16:39 - 2007-12-27 16:39 - 00051816 _____ () C:\Program Files (x86)\IVT Corporation\BlueSoleil\StartSkysolSvc.exe 2007-12-03 12:26 - 2007-12-03 12:26 - 00498792 _____ () C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe 2014-02-25 03:28 - 2014-02-25 03:28 - 00248736 _____ () C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe 2014-08-30 23:21 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2014-08-30 23:21 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2014-08-30 23:21 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2014-08-30 23:21 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2014-08-30 23:21 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2013-05-31 11:15 - 2013-05-31 11:15 - 01259320 _____ () C:\Users\Udi\AppData\Local\CloudStation\bin\libsqlite3-0.dll 2013-05-31 11:15 - 2013-05-31 11:15 - 00043008 _____ () C:\Users\Udi\AppData\Local\CloudStation\bin\libgcc_s_dw2-1.dll 2014-03-24 05:18 - 2014-03-24 05:18 - 02554368 _____ () C:\Users\Udi\AppData\Local\CloudStation\bin\QtCore4.dll 2014-03-24 05:18 - 2014-03-24 05:18 - 09824768 _____ () C:\Users\Udi\AppData\Local\CloudStation\bin\QtGui4.dll 2014-03-24 05:18 - 2014-03-24 05:18 - 01218048 _____ () C:\Users\Udi\AppData\Local\CloudStation\bin\QtNetwork4.dll 2013-05-31 11:15 - 2013-05-31 11:15 - 01599298 _____ () C:\Users\Udi\AppData\Local\CloudStation\bin\icuuc50.dll 2013-05-31 11:15 - 2013-05-31 11:15 - 00879630 _____ () C:\Users\Udi\AppData\Local\CloudStation\bin\libstdc++-6.dll 2013-05-31 11:15 - 2013-05-31 11:15 - 20803927 _____ () C:\Users\Udi\AppData\Local\CloudStation\bin\icudt50.dll 2014-08-30 23:29 - 2014-08-04 14:20 - 00052472 _____ () C:\Users\Udi\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2014-08-04 14:20 - 2014-08-04 14:20 - 00139056 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll 2014-08-04 14:20 - 2014-08-04 14:20 - 00067832 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2014-07-22 19:14 - 2014-07-22 19:14 - 03800688 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-08-16 11:39 - 2014-08-16 11:39 - 17048240 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader - Schnellstart.lnk => C:\Windows\pss\Adobe Reader - Schnellstart.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk => C:\Windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup MSCONFIG\startupreg: Acronis Scheduler2 Service => "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" MSCONFIG\startupreg: AcronisTimounterMonitor => C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: HP LaserJet M2727 MFP Series Fax => C:\Program Files (x86)\HP\hp LaserJet M2727\hppfaxprintersrv.exe "HP LaserJet M2727 MFP Series Fax" MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: ToolBoxFX => "C:\Program Files (x86)\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on MSCONFIG\startupreg: TrueImageMonitor.exe => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe MSCONFIG\startupreg: UpdatePPShortCut => "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0" MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (09/01/2014 07:10:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (09/01/2014 07:10:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (09/01/2014 07:10:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/31/2014 04:19:23 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Beschreibung = Geplanter Prüfpunkt; Fehler = 0x80070422). Error: (08/31/2014 02:54:36 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/31/2014 02:54:36 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/31/2014 02:54:36 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/31/2014 00:35:34 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" ; Beschreibung = Säuberung (Spybot - Search & Destroy 2.4, Administratorrechte); Fehler = 0x80070422). Error: (08/31/2014 00:20:20 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Beschreibung = Geplanter Prüfpunkt; Fehler = 0x80070422). Error: (08/30/2014 11:21:21 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. System errors: ============= Error: (09/01/2014 07:07:12 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (09/01/2014 07:07:12 AM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/31/2014 02:50:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/31/2014 02:50:49 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/30/2014 11:18:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/30/2014 11:18:56 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/30/2014 10:42:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/30/2014 10:42:36 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/30/2014 10:11:07 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= Error: (09/01/2014 07:10:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (09/01/2014 07:10:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (09/01/2014 07:10:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (08/31/2014 04:19:23 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreationGeplanter Prüfpunkt0x80070422 Error: (08/31/2014 02:54:36 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (08/31/2014 02:54:36 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (08/31/2014 02:54:36 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (08/31/2014 00:35:34 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" Säuberung (Spybot - Search & Destroy 2.4, Administratorrechte)0x80070422 Error: (08/31/2014 00:20:20 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreationGeplanter Prüfpunkt0x80070422 Error: (08/30/2014 11:21:21 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl8F20300004D070000 CodeIntegrity Errors: =================================== Date: 2012-05-05 17:17:25.973 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\DBoxBoot\PACKET.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-05-05 17:17:25.927 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\DBoxBoot\PACKET.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: AMD Phenom(tm) II X4 905e Processor Percentage of memory in use: 45% Total physical RAM: 4095.18 MB Available physical RAM: 2231.29 MB Total Pagefile: 8188.53 MB Available Pagefile: 6001.14 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:53.19 GB) (Free:3.08 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Daten) (Fixed) (Total:58.59 GB) (Free:58.31 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: D72ED05E) Partition 1: (Active) - (Size=53.2 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=58.6 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
01.09.2014, 14:47 | #4 |
/// the machine /// TB-Ausbilder | click compare und co. werd ich einfach nicht los :((( hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.09.2014, 16:41 | #5 |
| click compare und co. werd ich einfach nicht los :((( hallo, also beschwert hat er sich wegen antivir und spybot. antivir war jedoch auf jeden fall deaktiviert (der kleine schirm war geschlossen) und spybot läuft bei mir nicht im hintergrund mit. hier ist das logfile: Code:
ATTFilter ComboFix 14-08-31.01 - Udi 01.09.2014 16:56:39.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4095.2285 [GMT 2:00] ausgeführt von:: c:\users\Udi\Desktop\ComboFix.exe AV: Ad-Aware Antivirus *Enabled/Updated* {D87B6541-12A1-DAEA-0033-9B8057AAB996} AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} FW: Ad-Aware Firewall *Disabled* {E040E464-58CE-DBB2-2B6C-32B5A979FEED} SP: Ad-Aware Antivirus *Enabled/Updated* {631A84A5-349B-D564-3A83-A0F22C2DF32B} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Udi\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll c:\users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\search-metadata.json . . ((((((((((((((((((((((( Dateien erstellt von 2014-08-01 bis 2014-09-01 )))))))))))))))))))))))))))))) . . 2014-09-01 15:04 . 2014-09-01 15:04 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2014-08-30 21:29 . 2014-08-30 21:35 -------- d-----w- c:\programdata\Package Cache 2014-08-30 21:29 . 2014-08-30 21:29 -------- d-----w- c:\users\Udi\AppData\Roaming\Avira 2014-08-30 21:28 . 2014-08-15 08:30 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2014-08-30 21:28 . 2014-08-15 08:30 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-08-30 21:28 . 2014-08-15 08:30 117712 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-08-30 21:28 . 2014-08-30 21:34 -------- d-----w- c:\program files (x86)\Avira 2014-08-30 21:28 . 2014-08-30 21:29 -------- d-----w- c:\programdata\Avira 2014-08-30 21:21 . 2013-09-20 08:49 21040 ----a-w- c:\windows\system32\sdnclean64.exe 2014-08-30 21:21 . 2014-08-30 22:34 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2014-08-30 21:21 . 2014-08-30 21:22 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2 2014-08-30 20:37 . 2014-08-30 20:37 -------- d-----w- c:\programdata\BitDefender 2014-08-30 20:30 . 2014-07-10 12:09 2084072 ----a-w- c:\windows\system32\bdnc.dll 2014-08-30 20:30 . 2014-07-10 12:08 195016 ----a-w- c:\windows\system32\httproxy.dll 2014-08-30 20:30 . 2014-07-10 12:08 155912 ----a-w- c:\windows\system32\bdpop3p.dll 2014-08-30 20:30 . 2014-07-10 12:08 122928 ----a-w- c:\windows\system32\OEMbdpredir.dll 2014-08-30 20:30 . 2014-07-10 12:08 96160 ----a-w- c:\windows\system32\bdpredir.dll 2014-08-30 20:30 . 2014-07-10 12:08 209984 ----a-w- c:\windows\system32\BdFirewallSDK.dll 2014-08-30 20:30 . 2014-07-10 12:08 156936 ----a-w- c:\windows\system32\bdfwcore.dll 2014-08-30 20:30 . 2014-07-10 12:08 1061776 ----a-w- c:\windows\system32\bdsmtpp.dll 2014-08-30 20:29 . 2014-08-30 20:29 -------- d-----w- c:\program files\Lavasoft 2014-08-30 20:29 . 2014-09-01 14:12 -------- d-----w- c:\programdata\Ad-Aware Browsing Protection 2014-08-30 20:29 . 2014-08-30 20:29 -------- d-----w- c:\users\Udi\AppData\Local\adawarebp 2014-08-30 20:28 . 2014-08-30 20:28 -------- d-----w- c:\program files (x86)\Lavasoft 2014-08-30 20:27 . 2014-08-30 20:27 -------- d-----w- c:\users\Udi\AppData\Roaming\Lavasoft 2014-08-30 20:27 . 2014-08-30 20:27 -------- d-----w- c:\program files\Common Files\Lavasoft 2014-08-30 20:27 . 2014-08-30 20:27 -------- d-----w- c:\programdata\Lavasoft 2014-08-30 19:58 . 2014-08-30 19:58 -------- d-----w- c:\windows\ERUNT 2014-08-30 19:38 . 2014-08-30 21:16 -------- d-----w- C:\AdwCleaner 2014-08-30 19:28 . 2014-08-30 20:20 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-08-30 19:28 . 2014-08-30 19:28 -------- d-----w- c:\program files (x86)\ Malwarebytes Anti-Malware 2014-08-30 19:28 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-08-30 19:28 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-08-30 19:28 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-08-30 19:18 . 2014-09-01 05:15 -------- d-----w- C:\FRST 2014-08-30 19:16 . 2014-08-30 20:11 -------- d-----w- c:\program files (x86)\VS Revo Group 2014-08-30 09:20 . 2014-08-30 09:20 -------- d-----w- c:\programdata\Malwarebytes 2014-08-29 08:27 . 2014-08-21 03:43 11319192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3607AA77-71B5-4B00-8A61-9744B4B9C54D}\mpengine.dll 2014-08-28 10:29 . 2014-08-23 02:07 404480 ----a-w- c:\windows\system32\gdi32.dll 2014-08-28 10:29 . 2014-08-23 01:45 311808 ----a-w- c:\windows\SysWow64\gdi32.dll 2014-08-28 10:29 . 2014-08-23 00:59 3163648 ----a-w- c:\windows\system32\win32k.sys 2014-08-21 10:30 . 2014-08-21 10:30 727592 ----a-w- c:\windows\system32\drivers\avc3.sys 2014-08-21 10:30 . 2014-08-21 10:30 601360 ----a-w- c:\windows\system32\drivers\avckf.sys 2014-08-21 10:30 . 2014-08-21 10:30 261056 ----a-w- c:\windows\system32\drivers\avchv.sys 2014-08-21 10:30 . 2014-08-21 10:30 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll 2014-08-17 20:52 . 2014-08-17 20:52 -------- d-----w- c:\program files\Microsoft Silverlight 2014-08-17 20:52 . 2014-08-17 20:52 -------- d-----w- c:\program files (x86)\Microsoft Silverlight 2014-08-16 14:27 . 2014-08-16 14:27 -------- d-----w- c:\users\Udi\AppData\Local\Adobe 2014-08-14 13:15 . 2014-08-14 17:47 -------- d-----w- C:\adb 2014-08-13 11:22 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll 2014-08-13 11:22 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe 2014-08-13 11:22 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll 2014-08-13 11:22 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe 2014-08-13 11:22 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll 2014-08-13 11:22 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll 2014-08-13 11:22 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe 2014-08-13 11:22 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe 2014-08-13 10:37 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDYAK.DLL 2014-08-13 10:37 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDTAT.DLL 2014-08-13 10:37 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDRU1.DLL 2014-08-13 10:37 . 2014-07-09 02:03 6656 ----a-w- c:\windows\system32\KBDRU.DLL 2014-08-13 10:37 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDBASH.DLL 2014-08-13 10:37 . 2014-07-09 01:31 7168 ----a-w- c:\windows\SysWow64\KBDYAK.DLL 2014-08-13 10:37 . 2014-07-09 01:31 6656 ----a-w- c:\windows\SysWow64\KBDBASH.DLL 2014-08-13 10:33 . 2014-07-16 03:23 2048 ----a-w- c:\windows\system32\tzres.dll 2014-08-13 10:33 . 2014-07-16 02:46 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2014-08-13 10:33 . 2014-06-03 10:02 3241984 ----a-w- c:\windows\system32\msi.dll 2014-08-13 10:33 . 2014-06-03 09:29 2363392 ----a-w- c:\windows\SysWow64\msi.dll 2014-08-13 10:33 . 2014-06-03 10:02 112064 ----a-w- c:\windows\system32\consent.exe 2014-08-13 10:33 . 2014-06-03 10:02 504320 ----a-w- c:\windows\system32\msihnd.dll 2014-08-13 10:33 . 2014-06-03 10:02 1941504 ----a-w- c:\windows\system32\authui.dll 2014-08-13 10:33 . 2014-06-03 09:29 337408 ----a-w- c:\windows\SysWow64\msihnd.dll 2014-08-13 10:33 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\SysWow64\authui.dll 2014-08-13 10:33 . 2014-06-16 02:10 985536 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2014-08-13 10:33 . 2014-06-25 02:05 14175744 ----a-w- c:\windows\system32\shell32.dll 2014-08-13 10:28 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll 2014-08-13 10:28 . 2014-07-14 01:40 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll 2014-08-13 10:27 . 2014-08-07 02:06 529920 ----a-w- c:\windows\system32\aepdu.dll 2014-08-13 10:27 . 2014-08-07 02:01 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-08-12 19:49 . 2014-08-12 19:49 -------- d-----w- c:\users\Udi\.jivex . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-08-16 09:39 . 2012-04-15 19:04 699568 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-08-16 09:39 . 2011-11-05 12:24 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-08-13 11:25 . 2012-04-20 16:45 99218768 ----a-w- c:\windows\system32\MRT.exe 2014-08-05 07:20 . 2011-11-05 15:05 270496 ------w- c:\windows\system32\MpSigStub.exe 2014-07-10 12:09 . 2014-07-10 12:09 389240 ----a-w- c:\windows\system32\drivers\Trufos.sys 2014-07-10 12:08 . 2014-07-10 12:08 93160 ----a-w- c:\windows\system32\drivers\BdfNdisf6.sys 2014-06-18 02:18 . 2014-07-10 15:36 692736 ----a-w- c:\windows\system32\osk.exe 2014-06-18 01:51 . 2014-07-10 15:36 646144 ----a-w- c:\windows\SysWow64\osk.exe 2014-06-06 10:10 . 2014-07-10 15:36 624128 ----a-w- c:\windows\system32\qedit.dll 2014-06-06 09:44 . 2014-07-10 15:36 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-06-05 14:45 . 2014-07-10 15:34 1460736 ----a-w- c:\windows\system32\lsasrv.dll 2014-06-05 14:26 . 2014-07-10 15:34 22016 ----a-w- c:\windows\SysWow64\secur32.dll 2014-06-05 14:25 . 2014-07-10 15:34 96768 ----a-w- c:\windows\SysWow64\sspicli.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912] "Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2014-06-24 4566952] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2011-11-05 2252800] "NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-03-30 113296] "Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-09-27 559696] "SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2014-06-24 4101576] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-08-15 751184] "Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2014-08-04 161584] . c:\users\Udi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ CloudStation.lnk - c:\users\Udi\AppData\Local\CloudStation\bin\cloud.exe [2014-6-11 3774880] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\lavasoft\ad-aware antivirus\firewall engine\1.6.0.0\drivers\bdfndisf6.sys;c:\program files\lavasoft\ad-aware antivirus\firewall engine\1.6.0.0\drivers\bdfndisf6.sys [x] S1 bdfwfpf;bdfwfpf;c:\program files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfwfpf.sys;c:\program files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfwfpf.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x] S2 HP LaserJet Service;HP LaserJet Service;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [x] S2 LavasoftAdAwareService11;Ad-Aware Service 11;c:\program files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe;c:\program files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe [x] S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x] S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x] S2 Start BT in service;Start BT in service;c:\program files (x86)\IVT Corporation\BlueSoleil\StartSkysolSvc.exe;c:\program files (x86)\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] S2 UsbClientService;UsbClientService;c:\program files (x86)\Synology\Assistant\UsbClientService.exe;c:\program files (x86)\Synology\Assistant\UsbClientService.exe [x] S3 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys;c:\windows\SYSNATIVE\DRIVERS\avc3.sys [x] S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys;c:\windows\SYSNATIVE\DRIVERS\avchv.sys [x] S3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys;c:\windows\SYSNATIVE\DRIVERS\avckf.sys [x] S3 busenum;Synology Virtual USB Hub;c:\windows\system32\DRIVERS\busenum.sys;c:\windows\SYSNATIVE\DRIVERS\busenum.sys [x] S3 gzflt;gzflt;c:\program files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.0.56\gzflt.sys;c:\program files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.0.56\gzflt.sys [x] S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\01UnsuppModule] @="{AEB16659-2125-4ADA-A4AB-45EE21E86469}" [HKEY_CLASSES_ROOT\CLSID\{AEB16659-2125-4ADA-A4AB-45EE21E86469}] 2014-04-02 13:32 2765312 ----a-w- c:\users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\02SyncingModule] @="{48AB5ADA-36B1-4137-99C9-2BD97F8788AB}" [HKEY_CLASSES_ROOT\CLSID\{48AB5ADA-36B1-4137-99C9-2BD97F8788AB}] 2014-04-02 13:32 2765312 ----a-w- c:\users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\03SyncedModule] @="{472CE1AD-5D53-4BCF-A1FB-3982A5F55138}" [HKEY_CLASSES_ROOT\CLSID\{472CE1AD-5D53-4BCF-A1FB-3982A5F55138}] 2014-04-02 13:32 2765312 ----a-w- c:\users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\04ReadOnlyModule] @="{A433C3E0-8B24-40EB-93C3-4B10D9959F58}" [HKEY_CLASSES_ROOT\CLSID\{A433C3E0-8B24-40EB-93C3-4B10D9959F58}] 2014-04-02 13:32 2765312 ----a-w- c:\users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184] "AdAwareTray"="c:\program files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe" [2014-08-27 8886592] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm uSearchAssistant = www.google.com IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ FF - prefs.js: keyword.URL - hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_9&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q= . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-Start WingMan Profiler - (no file) Notify-SDWinLogon - SDWinLogon.dll HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\IVT Corporation\BlueSoleil\BTNtService.exe c:\program files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe c:\program files (x86)\TeamViewer\Version9\TeamViewer.exe c:\program files (x86)\TeamViewer\Version9\tv_w32.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-09-01 17:16:59 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-09-01 15:16 . Vor Suchlauf: 3.110.207.488 Bytes frei Nach Suchlauf: 2.976.231.424 Bytes frei . - - End Of File - - 4A697DEDCABAC6FEDF5BAA8A27CFBF99 A36C5E4F47E84449FF07ED3517B43A31 |
02.09.2014, 11:48 | #6 |
/// the machine /// TB-Ausbilder | click compare und co. werd ich einfach nicht los :((( Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> click compare und co. werd ich einfach nicht los :((( |
02.09.2014, 23:55 | #7 |
| click compare und co. werd ich einfach nicht los :((( nur kurz zur info. mbam hat keine fehler gefunden (aber das wirst du sicher in den log files sehen). das problem besteht aber noch. hier die log files: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 03.09.2014 Suchlauf-Zeit: 00:24:36 Logdatei: mamb.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.09.02.10 Rootkit Datenbank: v2014.08.21.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Udi Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 386565 Verstrichene Zeit: 8 Min, 3 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.308 - Bericht erstellt am 03/09/2014 um 00:42:30 # Aktualisiert 20/08/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Udi - DESKTOP # Gestartet von : C:\Users\Udi\Desktop\adwcleaner_3.308.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\foxydeal.sqlite ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\adawarebp ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17239 -\\ Mozilla Firefox v31.0 (x86 de) [ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\o5ibmjkx.default\prefs.js ] [ Datei : C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\prefs.js ] ************************* AdwCleaner[R0].txt - [4108 octets] - [30/08/2014 21:39:44] AdwCleaner[R1].txt - [3148 octets] - [30/08/2014 23:07:19] AdwCleaner[R2].txt - [3208 octets] - [30/08/2014 23:08:07] AdwCleaner[R3].txt - [1490 octets] - [03/09/2014 00:36:46] AdwCleaner[S0].txt - [3965 octets] - [30/08/2014 21:48:54] AdwCleaner[S1].txt - [3269 octets] - [30/08/2014 23:16:06] AdwCleaner[S2].txt - [1365 octets] - [03/09/2014 00:42:30] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1425 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Udi on 03.09.2014 at 0:45:52,81 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted the following from C:\Users\Udi\AppData\Roaming\mozilla\firefox\profiles\iom7ztdk.default\prefs.js user_pref("keyword.URL", "hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_9&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q="); ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 03.09.2014 at 0:50:39,08 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2014 02 Ran by Udi (administrator) on DESKTOP on 03-09-2014 00:51:28 Running from C:\Users\Udi\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\IVT Corporation\BlueSoleil\BTNtService.exe (HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe () C:\Program Files (x86)\IVT Corporation\BlueSoleil\StartSkysolSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe () C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe () C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe () C:\Users\Udi\AppData\Local\CloudStation\bin\cloud.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe () C:\Users\Udi\AppData\Local\CloudStation\bin\client-win.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe [8886592 2014-08-27] () HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2252800 2011-11-05] (VIA) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113296 2010-03-30] (NEC Electronics Corporation) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-15] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [4910912 2011-08-02] (DT Soft Ltd) Lsa: [Authentication Packages] msv1_0 relog_ap Startup: C:\Users\Udi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CloudStation.lnk ShortcutTarget: CloudStation.lnk -> C:\Users\Udi\AppData\Local\CloudStation\bin\cloud.exe () ShellIconOverlayIdentifiers: 01UnsuppModule -> {AEB16659-2125-4ADA-A4AB-45EE21E86469} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 02SyncingModule -> {48AB5ADA-36B1-4137-99C9-2BD97F8788AB} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 03SyncedModule -> {472CE1AD-5D53-4BCF-A1FB-3982A5F55138} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 04ReadOnlyModule -> {A433C3E0-8B24-40EB-93C3-4B10D9959F58} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3ECA9489B59BCC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default FF NewTab: about:blank FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: synology.com/SurveillancePlugin -> C:\Program Files (x86)\Synology\SurveillancePlugin\1.0.0.423\npSurveillancePlugin.dll (Synology) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Browser Safety - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\abs@avira.com [2014-08-30] FF Extension: ProxTube - Unblock YouTube - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\ich@maltegoetz.de [2013-12-11] FF Extension: WOT - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-08-30] FF Extension: FoxLingo - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66} [2013-12-04] FF Extension: Adblock Plus - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-30] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-07-22] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-07-22] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-07-22] Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG) R2 BlueSoleil Hid Service; C:\Program Files (x86)\IVT Corporation\BlueSoleil\BTNtService.exe [166520 2007-12-27] () R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136192 2009-11-12] (HP) [File not signed] R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-03-11] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-03-11] (Hewlett-Packard Co.) [File not signed] R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe [706864 2014-08-27] () R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed] R2 Start BT in service; C:\Program Files (x86)\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [51816 2007-12-27] () R2 TryAndDecideService; C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [498792 2007-12-03] () R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248736 2014-02-25] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2014-08-21] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2014-08-21] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2014-08-21] (BitDefender) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-08-15] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-08-15] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-08-15] (Avira Operations GmbH & Co. KG) R1 BdfNdisf; c:\program files\lavasoft\ad-aware antivirus\firewall engine\1.6.0.0\drivers\bdfndisf6.sys [93160 2014-07-10] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfwfpf.sys [102992 2014-07-10] (BitDefender LLC) R3 BlueletAudio; C:\Windows\System32\DRIVERS\blueletaudio.sys [37896 2007-06-24] (IVT Corporation.) R3 BlueletAudio; C:\Windows\SysWOW64\DRIVERS\blueletaudio.sys [37896 2007-06-24] (IVT Corporation.) R3 BlueletSCOAudio; C:\Windows\System32\DRIVERS\BlueletSCOAudio.sys [37384 2007-06-24] (IVT Corporation.) R3 BlueletSCOAudio; C:\Windows\SysWOW64\DRIVERS\BlueletSCOAudio.sys [37384 2007-06-24] (IVT Corporation.) R3 BT; C:\Windows\System32\DRIVERS\btnetdrv.sys [25360 2007-03-05] (IVT Corporation.) R3 BT; C:\Windows\SysWOW64\DRIVERS\btnetdrv.sys [25360 2007-03-05] (IVT Corporation.) R3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [47368 2007-06-24] (IVT Corporation.) R3 Btcsrusb; C:\Windows\SysWOW64\Drivers\btcusb.sys [47368 2007-06-24] (IVT Corporation.) R0 BTHidEnum; C:\Windows\System32\Drivers\vbtenum.sys [24976 2007-03-05] (IVT Corporation.) R0 BTHidEnum; C:\Windows\SysWOW64\Drivers\vbtenum.sys [24976 2007-03-05] (IVT Corporation.) R0 BTHidMgr; C:\Windows\System32\Drivers\BTHidMgr.sys [49680 2007-03-05] (IVT Corporation.) R0 BTHidMgr; C:\Windows\SysWOW64\Drivers\BTHidMgr.sys [49680 2007-03-05] (IVT Corporation.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [270912 2011-11-05] (DT Soft Ltd) R3 gzflt; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.0.56\gzflt.sys [150256 2014-07-10] (BitDefender LLC) S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (HTC, Corporation) [File not signed] R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] () S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd) S3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [389240 2014-07-10] (BitDefender S.R.L.) R3 VComm; C:\Windows\System32\DRIVERS\VComm.sys [47120 2007-03-05] (IVT Corporation.) R3 VComm; C:\Windows\SysWOW64\DRIVERS\VComm.sys [47120 2007-03-05] (IVT Corporation.) R3 VcommMgr; C:\Windows\System32\Drivers\VcommMgr.sys [63248 2007-03-05] (IVT Corporation.) R3 VcommMgr; C:\Windows\SysWOW64\Drivers\VcommMgr.sys [63248 2007-03-05] (IVT Corporation.) R3 VHidMinidrv; C:\Windows\System32\drivers\VHIDMini.sys [23184 2007-03-05] (IVT Corporation.) R3 VHidMinidrv; C:\Windows\SysWOW64\drivers\VHIDMini.sys [23184 2007-03-05] (IVT Corporation.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-03 00:51 - 2014-09-03 00:51 - 00017286 _____ () C:\Users\Udi\Desktop\FRST.txt 2014-09-03 00:50 - 2014-09-03 00:50 - 00001018 _____ () C:\Users\Udi\Desktop\JRT.txt 2014-09-03 00:44 - 2014-09-03 00:44 - 01016261 _____ (Thisisu) C:\Users\Udi\Desktop\JRT.exe 2014-09-03 00:43 - 2014-09-03 00:43 - 00001505 _____ () C:\Users\Udi\Desktop\AdwCleaner[S2].txt 2014-09-03 00:36 - 2014-09-03 00:36 - 01364531 _____ () C:\Users\Udi\Desktop\adwcleaner_3.308.exe 2014-09-03 00:33 - 2014-09-03 00:33 - 00001155 _____ () C:\Users\Udi\Desktop\mamb.txt 2014-09-03 00:23 - 2014-09-03 00:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-03 00:23 - 2014-09-03 00:23 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-03 00:23 - 2014-09-03 00:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-03 00:23 - 2014-09-03 00:23 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-03 00:23 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-09-03 00:23 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-09-03 00:23 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-09-03 00:22 - 2014-09-03 00:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Udi\Desktop\mbam-setup-2.0.2.1012.exe 2014-09-02 09:35 - 2014-09-02 09:35 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-09-01 20:15 - 2014-09-01 20:15 - 00169371 _____ () C:\Users\Udi\Desktop\bookmarks-2014-09-01.json 2014-09-01 17:38 - 2014-09-01 17:38 - 00000085 _____ () C:\Windows\wininit.ini 2014-09-01 17:17 - 2014-09-01 17:17 - 00024356 _____ () C:\ComboFix.txt 2014-09-01 16:54 - 2014-09-01 17:17 - 00000000 ____D () C:\Qoobox 2014-09-01 16:54 - 2014-09-01 17:14 - 00000000 ____D () C:\Windows\erdnt 2014-09-01 16:54 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-09-01 16:54 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-09-01 16:54 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-09-01 16:54 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-09-01 16:54 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-09-01 16:54 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-09-01 16:54 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-09-01 16:54 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-09-01 16:51 - 2014-09-01 16:51 - 05576326 ____R (Swearware) C:\Users\Udi\Desktop\ComboFix.exe 2014-09-01 07:08 - 2014-09-01 07:08 - 02104832 _____ (Farbar) C:\Users\Udi\Desktop\FRST64.exe 2014-08-30 23:29 - 2014-08-30 23:35 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-30 23:29 - 2014-08-30 23:29 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Avira 2014-08-30 23:28 - 2014-08-30 23:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-30 23:28 - 2014-08-30 23:34 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-30 23:28 - 2014-08-30 23:29 - 00000000 ____D () C:\ProgramData\Avira 2014-08-30 23:28 - 2014-08-15 10:30 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-08-30 23:28 - 2014-08-15 10:30 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-08-30 23:28 - 2014-08-15 10:30 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-08-30 23:21 - 2014-09-01 19:59 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-08-30 23:21 - 2014-09-01 17:38 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-08-30 23:21 - 2014-08-30 23:21 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-08-30 22:37 - 2014-08-30 22:37 - 00000000 ____D () C:\ProgramData\BitDefender 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\LavasoftStatistics 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2014-08-30 22:30 - 2014-07-10 14:09 - 02084072 _____ (Bitdefender) C:\Windows\system32\bdnc.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 01061776 _____ (BitDefender S.R.L.) C:\Windows\system32\bdsmtpp.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00209984 _____ (BitDefender) C:\Windows\system32\BdFirewallSDK.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00195016 _____ (BitDefender) C:\Windows\system32\httproxy.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00156936 _____ () C:\Windows\system32\bdfwcore.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00155912 _____ (BitDefender S.R.L.) C:\Windows\system32\bdpop3p.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00122928 _____ (BitDefender) C:\Windows\system32\OEMbdpredir.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00096160 _____ (BitDefender) C:\Windows\system32\bdpredir.dll 2014-08-30 22:29 - 2014-09-03 00:43 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Users\Udi\AppData\Local\adawarebp 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Program Files\Lavasoft 2014-08-30 22:28 - 2014-08-30 22:28 - 00000000 ____D () C:\Program Files (x86)\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-08-30 22:26 - 2014-08-30 23:27 - 00000000 ____D () C:\Users\Udi\Desktop\Viren 2014-08-30 21:58 - 2014-08-30 21:58 - 00000000 ____D () C:\Windows\ERUNT 2014-08-30 21:38 - 2014-09-03 00:42 - 00000000 ____D () C:\AdwCleaner 2014-08-30 21:18 - 2014-09-03 00:51 - 00000000 ____D () C:\FRST 2014-08-30 21:16 - 2014-08-30 22:11 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-08-30 11:20 - 2014-08-30 11:20 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 12:29 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-28 12:29 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-28 12:29 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-08-21 12:30 - 2014-08-21 12:30 - 00727592 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00601360 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00261056 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys 2014-08-21 09:43 - 2014-08-21 09:43 - 06052529 _____ (Tim Kosse) C:\Users\Udi\Downloads\FileZilla_3.9.0.3_win32-setup.exe 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-16 16:27 - 2014-08-16 16:27 - 00000000 ____D () C:\Users\Udi\AppData\Local\Adobe 2014-08-14 15:25 - 2014-08-14 15:18 - 00110314 ____N () C:\Users\Udi\Desktop\wachat_20140814.txt 2014-08-14 15:25 - 1970-01-01 01:59 - 00062754 ____N () C:\Users\Udi\Desktop\wachat_20140814.xlsx 2014-08-14 15:15 - 2014-08-14 19:47 - 00000000 ____D () C:\adb 2014-08-13 13:22 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-13 13:22 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-13 13:22 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-13 13:22 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-13 13:22 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-13 13:22 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-13 13:22 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-13 13:22 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-13 12:37 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-13 12:37 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-13 12:33 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-13 12:33 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-13 12:33 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-13 12:33 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-13 12:33 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-13 12:33 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-13 12:33 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-13 12:33 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-13 12:33 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-13 12:33 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-13 12:33 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-13 12:32 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-13 12:32 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-13 12:32 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-13 12:32 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-13 12:32 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-13 12:32 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-13 12:32 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-13 12:32 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-13 12:32 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-13 12:32 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-13 12:32 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-13 12:32 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-13 12:32 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-13 12:32 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-13 12:32 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-13 12:32 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-13 12:32 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-13 12:32 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-13 12:32 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-13 12:32 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-13 12:32 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-13 12:32 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-13 12:32 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-13 12:32 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-13 12:32 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-13 12:32 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-13 12:32 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-13 12:32 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-13 12:32 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-13 12:32 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-13 12:32 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-13 12:32 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-13 12:32 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-13 12:32 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-13 12:32 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-13 12:32 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-13 12:32 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-13 12:32 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-13 12:32 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-13 12:32 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-13 12:32 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-13 12:32 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-13 12:32 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-13 12:32 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-13 12:32 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-13 12:32 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-13 12:32 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-13 12:32 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-13 12:32 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-13 12:32 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-13 12:32 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-13 12:32 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-13 12:32 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-13 12:32 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-13 12:32 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-13 12:32 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-13 12:32 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-13 12:28 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-13 12:28 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-13 12:27 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-13 12:27 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-12 21:49 - 2014-08-12 21:50 - 00000001 ____R () C:\Users\Udi\serverport 2014-08-12 21:49 - 2014-08-12 21:49 - 00000000 ____D () C:\Users\Udi\.jivex 2014-08-05 18:25 - 2014-08-05 18:25 - 01538102 _____ () C:\Users\Udi\Desktop\Oscam Konfiguration.zip 2014-08-04 20:15 - 2014-08-04 20:15 - 06004615 _____ (Tim Kosse) C:\Users\Udi\Downloads\FileZilla_3.9.0.2_win32-setup.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-03 00:51 - 2014-09-03 00:51 - 00017286 _____ () C:\Users\Udi\Desktop\FRST.txt 2014-09-03 00:51 - 2014-08-30 21:18 - 00000000 ____D () C:\FRST 2014-09-03 00:50 - 2014-09-03 00:50 - 00001018 _____ () C:\Users\Udi\Desktop\JRT.txt 2014-09-03 00:50 - 2009-07-14 19:58 - 24438756 _____ () C:\Windows\system32\perfh007.dat 2014-09-03 00:50 - 2009-07-14 19:58 - 07650016 _____ () C:\Windows\system32\perfc007.dat 2014-09-03 00:50 - 2009-07-14 07:13 - 00006292 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-03 00:50 - 2009-07-14 06:45 - 00022048 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-03 00:50 - 2009-07-14 06:45 - 00022048 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-03 00:44 - 2014-09-03 00:44 - 01016261 _____ (Thisisu) C:\Users\Udi\Desktop\JRT.exe 2014-09-03 00:43 - 2014-09-03 00:43 - 00001505 _____ () C:\Users\Udi\Desktop\AdwCleaner[S2].txt 2014-09-03 00:43 - 2014-08-30 22:29 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection 2014-09-03 00:43 - 2013-10-12 19:52 - 00000000 ___RD () C:\Users\Udi\Cloud Station 2014-09-03 00:43 - 2012-09-15 15:40 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-09-03 00:43 - 2011-11-05 15:31 - 00356402 _____ () C:\Windows\PFRO.log 2014-09-03 00:43 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-03 00:43 - 2009-07-14 06:51 - 00593865 _____ () C:\Windows\setupact.log 2014-09-03 00:42 - 2014-08-30 21:38 - 00000000 ____D () C:\AdwCleaner 2014-09-03 00:42 - 2011-11-05 14:18 - 01855241 _____ () C:\Windows\WindowsUpdate.log 2014-09-03 00:36 - 2014-09-03 00:36 - 01364531 _____ () C:\Users\Udi\Desktop\adwcleaner_3.308.exe 2014-09-03 00:33 - 2014-09-03 00:33 - 00001155 _____ () C:\Users\Udi\Desktop\mamb.txt 2014-09-03 00:23 - 2014-09-03 00:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-03 00:23 - 2014-09-03 00:23 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-03 00:23 - 2014-09-03 00:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-03 00:23 - 2014-09-03 00:23 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-03 00:22 - 2014-09-03 00:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Udi\Desktop\mbam-setup-2.0.2.1012.exe 2014-09-02 15:29 - 2013-10-12 19:17 - 00000000 ____D () C:\Users\Udi\AppData\Local\CloudStation 2014-09-02 09:35 - 2014-09-02 09:35 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-09-01 20:15 - 2014-09-01 20:15 - 00169371 _____ () C:\Users\Udi\Desktop\bookmarks-2014-09-01.json 2014-09-01 19:59 - 2014-08-30 23:21 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-09-01 17:38 - 2014-09-01 17:38 - 00000085 _____ () C:\Windows\wininit.ini 2014-09-01 17:38 - 2014-08-30 23:21 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-09-01 17:17 - 2014-09-01 17:17 - 00024356 _____ () C:\ComboFix.txt 2014-09-01 17:17 - 2014-09-01 16:54 - 00000000 ____D () C:\Qoobox 2014-09-01 17:14 - 2014-09-01 16:54 - 00000000 ____D () C:\Windows\erdnt 2014-09-01 17:06 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-09-01 16:51 - 2014-09-01 16:51 - 05576326 ____R (Swearware) C:\Users\Udi\Desktop\ComboFix.exe 2014-09-01 07:08 - 2014-09-01 07:08 - 02104832 _____ (Farbar) C:\Users\Udi\Desktop\FRST64.exe 2014-08-30 23:35 - 2014-08-30 23:29 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-30 23:34 - 2014-08-30 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-30 23:34 - 2014-08-30 23:28 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-30 23:29 - 2014-08-30 23:29 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Avira 2014-08-30 23:29 - 2014-08-30 23:28 - 00000000 ____D () C:\ProgramData\Avira 2014-08-30 23:27 - 2014-08-30 22:26 - 00000000 ____D () C:\Users\Udi\Desktop\Viren 2014-08-30 23:21 - 2014-08-30 23:21 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-08-30 22:37 - 2014-08-30 22:37 - 00000000 ____D () C:\ProgramData\BitDefender 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\LavasoftStatistics 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Users\Udi\AppData\Local\adawarebp 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Program Files\Lavasoft 2014-08-30 22:28 - 2014-08-30 22:28 - 00000000 ____D () C:\Program Files (x86)\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-08-30 22:11 - 2014-08-30 21:16 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-08-30 21:58 - 2014-08-30 21:58 - 00000000 ____D () C:\Windows\ERUNT 2014-08-30 21:24 - 2013-06-01 12:02 - 00000000 ____D () C:\Program Files (x86)\HTC 2014-08-30 21:23 - 2012-05-26 17:11 - 00105928 _____ () C:\Windows\DPINST.LOG 2014-08-30 11:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Cursors 2014-08-30 11:20 - 2014-08-30 11:20 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 20:03 - 2009-07-14 06:45 - 00357080 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-24 15:44 - 2014-02-20 22:33 - 00000000 ____D () C:\Users\Udi\Documents\FIFA 14 2014-08-24 14:20 - 2014-02-16 14:31 - 00000000 ____D () C:\ProgramData\Origin 2014-08-24 14:20 - 2014-02-16 14:30 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-08-23 12:19 - 2013-09-27 18:07 - 00000000 ____D () C:\Program Files (x86)\Synology 2014-08-23 04:07 - 2014-08-28 12:29 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-23 03:45 - 2014-08-28 12:29 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-23 02:59 - 2014-08-28 12:29 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-08-21 12:30 - 2014-08-21 12:30 - 00727592 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00601360 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00261056 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys 2014-08-21 09:48 - 2011-11-05 19:09 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\FileZilla 2014-08-21 09:47 - 2013-08-10 00:00 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\vlc 2014-08-21 09:43 - 2014-08-21 09:43 - 06052529 _____ (Tim Kosse) C:\Users\Udi\Downloads\FileZilla_3.9.0.3_win32-setup.exe 2014-08-21 09:43 - 2011-11-05 19:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2014-08-21 09:43 - 2011-11-05 19:08 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-16 16:27 - 2014-08-16 16:27 - 00000000 ____D () C:\Users\Udi\AppData\Local\Adobe 2014-08-16 11:39 - 2012-04-15 21:04 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-08-16 11:39 - 2011-11-05 14:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-08-15 10:30 - 2014-08-30 23:28 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-08-15 10:30 - 2014-08-30 23:28 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-08-15 10:30 - 2014-08-30 23:28 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-08-15 10:02 - 2011-11-05 14:18 - 00000000 ____D () C:\Users\Udi\AppData\Local\VirtualStore 2014-08-14 19:47 - 2014-08-14 15:15 - 00000000 ____D () C:\adb 2014-08-14 15:18 - 2014-08-14 15:25 - 00110314 ____N () C:\Users\Udi\Desktop\wachat_20140814.txt 2014-08-13 21:06 - 2013-05-19 17:05 - 00000000 ____D () C:\Windows\rescache 2014-08-13 18:44 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-13 13:26 - 2013-07-29 14:44 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-13 13:25 - 2012-04-20 18:45 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-13 13:22 - 2014-05-06 21:03 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-12 21:50 - 2014-08-12 21:49 - 00000001 ____R () C:\Users\Udi\serverport 2014-08-12 21:49 - 2014-08-12 21:49 - 00000000 ____D () C:\Users\Udi\.jivex 2014-08-12 21:49 - 2011-11-05 14:18 - 00000000 ____D () C:\Users\Udi 2014-08-07 11:34 - 2014-05-19 20:38 - 00001102 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-08-07 04:06 - 2014-08-13 12:27 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 04:01 - 2014-08-13 12:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-05 18:25 - 2014-08-05 18:25 - 01538102 _____ () C:\Users\Udi\Desktop\Oscam Konfiguration.zip 2014-08-05 09:20 - 2011-11-05 17:05 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-08-04 20:15 - 2014-08-04 20:15 - 06004615 _____ (Tim Kosse) C:\Users\Udi\Downloads\FileZilla_3.9.0.2_win32-setup.exe Some content of TEMP: ==================== C:\Users\Udi\AppData\Local\Temp\avgnt.exe C:\Users\Udi\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-28 12:42 ==================== End Of Log ============================ |
03.09.2014, 14:06 | #8 |
/// the machine /// TB-Ausbilder | click compare und co. werd ich einfach nicht los :(((ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.09.2014, 08:49 | #9 |
| click compare und co. werd ich einfach nicht los :((( ganz kurze frage: ich habe eine nas im netzwerk. ist das auch betroffen? muss es beim scannen mit ausgewählt werden? hier die logs: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=df8671e464ca254d8464d0e65cf77738 # engine=19984 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2014-09-03 10:56:39 # local_time=2014-09-04 12:56:39 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 99 6243 1693596 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 354258 161414849 0 0 # scanned=150905 # found=12 # cleaned=0 # scan_time=3569 sh=6123291DCA7A24959F3403B03AD3E0DA64CD584B ft=0 fh=0000000000000000 vn="Variante von Win32/Bundled.Toolbar.Ask.F potenziell unsichere Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\apn\APN-Stub\ATU4\APNIC.7z.vir" sh=42E7E3A5697A90ED25AE4E9A904ADD3D7BB9EFD4 ft=1 fh=5fc5977116a952a6 vn="Variante von Win32/Bundled.Toolbar.Ask.F potenziell unsichere Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\apn\APN-Stub\ATU4\APNIC.dll.vir" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Udi\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=395EFA475333AD69CAA9B3C936077F19C18E9D8D ft=1 fh=e04f965664c1032e vn="Variante von Win32/Toolbar.Visicom.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll" sh=3519A17B76B6113C56EAFA45761AFDC404D3FDB1 ft=1 fh=b32fdf6a2c32fa5c vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawaretb.dll" sh=66362D70954A79040858B9C743EBAAD8CD218D50 ft=1 fh=ba9c22da21ab1c66 vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe" sh=66362D70954A79040858B9C743EBAAD8CD218D50 ft=1 fh=ba9c22da21ab1c66 vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\o5ibmjkx.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}\dtUser.exe" sh=AB5AF3EA656463D17E2019ADD0C6C064A3DD42E5 ft=1 fh=9ae7f7a1e25447d0 vn="Variante von Win32/InstallShare.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Udi\AppData\Local\InstallShare\2_5354_installer.exe" sh=71435DDB11E00D0243380C4902324853FE4ECE8F ft=1 fh=12b0cd2dde452d65 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ApnIC[1].0" sh=40E49124AD0B55A25F947333CA88E9D0BC30A7E3 ft=1 fh=e26ad988592b2af9 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5\ApnIC[1].0" sh=71435DDB11E00D0243380C4902324853FE4ECE8F ft=1 fh=12b0cd2dde452d65 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ApnIC[1].0" sh=40E49124AD0B55A25F947333CA88E9D0BC30A7E3 ft=1 fh=e26ad988592b2af9 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5\ApnIC[1].0" Code:
ATTFilter Results of screen317's Security Check version 0.99.87 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Ad-Aware Antivirus Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 45 Java version out of Date! Adobe Flash Player 14.0.0.179 Adobe Reader XI Mozilla Firefox (32.0) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.3.6321.0\AdAwareService.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.3.6321.0\AdAwareTray.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2014 02 Ran by Udi (administrator) on DESKTOP on 04-09-2014 09:32:43 Running from C:\Users\Udi\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\IVT Corporation\BlueSoleil\BTNtService.exe (HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe () C:\Program Files (x86)\IVT Corporation\BlueSoleil\StartSkysolSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe () C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe () C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe () C:\Users\Udi\AppData\Local\CloudStation\bin\cloud.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Users\Udi\AppData\Local\CloudStation\bin\client-win.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe [8886592 2014-08-27] () HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2252800 2011-11-05] (VIA) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113296 2010-03-30] (NEC Electronics Corporation) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-15] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-3126206505-700066600-3835712815-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [4910912 2011-08-02] (DT Soft Ltd) Lsa: [Authentication Packages] msv1_0 relog_ap Startup: C:\Users\Udi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CloudStation.lnk ShortcutTarget: CloudStation.lnk -> C:\Users\Udi\AppData\Local\CloudStation\bin\cloud.exe () ShellIconOverlayIdentifiers: 01UnsuppModule -> {AEB16659-2125-4ADA-A4AB-45EE21E86469} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 02SyncingModule -> {48AB5ADA-36B1-4137-99C9-2BD97F8788AB} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 03SyncedModule -> {472CE1AD-5D53-4BCF-A1FB-3982A5F55138} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) ShellIconOverlayIdentifiers: 04ReadOnlyModule -> {A433C3E0-8B24-40EB-93C3-4B10D9959F58} => C:\Users\Udi\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3ECA9489B59BCC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default FF NewTab: about:blank FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: synology.com/SurveillancePlugin -> C:\Program Files (x86)\Synology\SurveillancePlugin\1.0.0.423\npSurveillancePlugin.dll (Synology) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Browser Safety - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\abs@avira.com [2014-08-30] FF Extension: ProxTube - Unblock YouTube - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\ich@maltegoetz.de [2013-12-11] FF Extension: WOT - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-08-30] FF Extension: FoxLingo - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66} [2013-12-04] FF Extension: Adblock Plus - C:\Users\Udi\AppData\Roaming\Mozilla\Firefox\Profiles\iom7ztdk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-30] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-09-03] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-09-03] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-09-03] Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG) R2 BlueSoleil Hid Service; C:\Program Files (x86)\IVT Corporation\BlueSoleil\BTNtService.exe [166520 2007-12-27] () R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136192 2009-11-12] (HP) [File not signed] R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-03-11] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-03-11] (Hewlett-Packard Co.) [File not signed] R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe [706864 2014-08-27] () S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed] S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed] R2 Start BT in service; C:\Program Files (x86)\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [51816 2007-12-27] () R2 TryAndDecideService; C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [498792 2007-12-03] () R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248736 2014-02-25] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2014-08-21] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2014-08-21] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2014-08-21] (BitDefender) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-08-15] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-08-15] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-08-15] (Avira Operations GmbH & Co. KG) R1 BdfNdisf; c:\program files\lavasoft\ad-aware antivirus\firewall engine\1.6.0.0\drivers\bdfndisf6.sys [93160 2014-07-10] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfwfpf.sys [102992 2014-07-10] (BitDefender LLC) R3 BlueletAudio; C:\Windows\System32\DRIVERS\blueletaudio.sys [37896 2007-06-24] (IVT Corporation.) R3 BlueletAudio; C:\Windows\SysWOW64\DRIVERS\blueletaudio.sys [37896 2007-06-24] (IVT Corporation.) R3 BlueletSCOAudio; C:\Windows\System32\DRIVERS\BlueletSCOAudio.sys [37384 2007-06-24] (IVT Corporation.) R3 BlueletSCOAudio; C:\Windows\SysWOW64\DRIVERS\BlueletSCOAudio.sys [37384 2007-06-24] (IVT Corporation.) R3 BT; C:\Windows\System32\DRIVERS\btnetdrv.sys [25360 2007-03-05] (IVT Corporation.) R3 BT; C:\Windows\SysWOW64\DRIVERS\btnetdrv.sys [25360 2007-03-05] (IVT Corporation.) R3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [47368 2007-06-24] (IVT Corporation.) R3 Btcsrusb; C:\Windows\SysWOW64\Drivers\btcusb.sys [47368 2007-06-24] (IVT Corporation.) R0 BTHidEnum; C:\Windows\System32\Drivers\vbtenum.sys [24976 2007-03-05] (IVT Corporation.) R0 BTHidEnum; C:\Windows\SysWOW64\Drivers\vbtenum.sys [24976 2007-03-05] (IVT Corporation.) R0 BTHidMgr; C:\Windows\System32\Drivers\BTHidMgr.sys [49680 2007-03-05] (IVT Corporation.) R0 BTHidMgr; C:\Windows\SysWOW64\Drivers\BTHidMgr.sys [49680 2007-03-05] (IVT Corporation.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [270912 2011-11-05] (DT Soft Ltd) R3 gzflt; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.0.56\gzflt.sys [150256 2014-07-10] (BitDefender LLC) S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (HTC, Corporation) [File not signed] R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] () S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd) S3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [389240 2014-07-10] (BitDefender S.R.L.) R3 VComm; C:\Windows\System32\DRIVERS\VComm.sys [47120 2007-03-05] (IVT Corporation.) R3 VComm; C:\Windows\SysWOW64\DRIVERS\VComm.sys [47120 2007-03-05] (IVT Corporation.) R3 VcommMgr; C:\Windows\System32\Drivers\VcommMgr.sys [63248 2007-03-05] (IVT Corporation.) R3 VcommMgr; C:\Windows\SysWOW64\Drivers\VcommMgr.sys [63248 2007-03-05] (IVT Corporation.) R3 VHidMinidrv; C:\Windows\System32\drivers\VHIDMini.sys [23184 2007-03-05] (IVT Corporation.) R3 VHidMinidrv; C:\Windows\SysWOW64\drivers\VHIDMini.sys [23184 2007-03-05] (IVT Corporation.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-04 09:32 - 2014-09-04 09:32 - 00017527 _____ () C:\Users\Udi\Desktop\FRST.txt 2014-09-04 09:32 - 2014-09-04 09:32 - 00001000 _____ () C:\Users\Udi\Desktop\sc.txt 2014-09-04 08:39 - 2014-09-04 08:39 - 00854417 _____ () C:\Users\Udi\Desktop\SecurityCheck.exe 2014-09-03 23:53 - 2014-09-04 00:56 - 00003767 _____ () C:\Users\Udi\Desktop\eset.txt 2014-09-03 23:52 - 2014-09-03 23:53 - 02347384 _____ (ESET) C:\Users\Udi\Desktop\esetsmartinstaller_deu.exe 2014-09-03 23:09 - 2014-09-03 23:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-03 00:44 - 2014-09-03 00:44 - 01016261 _____ (Thisisu) C:\Users\Udi\Desktop\JRT.exe 2014-09-03 00:36 - 2014-09-03 00:36 - 01364531 _____ () C:\Users\Udi\Desktop\adwcleaner_3.308.exe 2014-09-03 00:23 - 2014-09-03 00:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-03 00:23 - 2014-09-03 00:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-03 00:23 - 2014-09-03 00:23 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-03 00:23 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-09-03 00:23 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-09-03 00:23 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-09-03 00:22 - 2014-09-03 00:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Udi\Desktop\mbam-setup-2.0.2.1012.exe 2014-09-02 09:35 - 2014-09-02 09:35 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-09-01 20:15 - 2014-09-01 20:15 - 00169371 _____ () C:\Users\Udi\Desktop\bookmarks-2014-09-01.json 2014-09-01 17:38 - 2014-09-01 17:38 - 00000085 _____ () C:\Windows\wininit.ini 2014-09-01 17:17 - 2014-09-01 17:17 - 00024356 _____ () C:\ComboFix.txt 2014-09-01 16:54 - 2014-09-01 17:17 - 00000000 ____D () C:\Qoobox 2014-09-01 16:54 - 2014-09-01 17:14 - 00000000 ____D () C:\Windows\erdnt 2014-09-01 16:54 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-09-01 16:54 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-09-01 16:54 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-09-01 16:54 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-09-01 16:54 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-09-01 16:54 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-09-01 16:54 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-09-01 16:54 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-09-01 16:51 - 2014-09-01 16:51 - 05576326 ____R (Swearware) C:\Users\Udi\Desktop\ComboFix.exe 2014-09-01 07:08 - 2014-09-01 07:08 - 02104832 _____ (Farbar) C:\Users\Udi\Desktop\FRST64.exe 2014-08-30 23:29 - 2014-08-30 23:35 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-30 23:29 - 2014-08-30 23:29 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Avira 2014-08-30 23:28 - 2014-08-30 23:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-30 23:28 - 2014-08-30 23:34 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-30 23:28 - 2014-08-30 23:29 - 00000000 ____D () C:\ProgramData\Avira 2014-08-30 23:28 - 2014-08-15 10:30 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-08-30 23:28 - 2014-08-15 10:30 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-08-30 23:28 - 2014-08-15 10:30 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-08-30 23:21 - 2014-09-01 19:59 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-08-30 23:21 - 2014-09-01 17:38 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-08-30 23:21 - 2014-08-30 23:21 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-08-30 22:37 - 2014-08-30 22:37 - 00000000 ____D () C:\ProgramData\BitDefender 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\LavasoftStatistics 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2014-08-30 22:30 - 2014-07-10 14:09 - 02084072 _____ (Bitdefender) C:\Windows\system32\bdnc.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 01061776 _____ (BitDefender S.R.L.) C:\Windows\system32\bdsmtpp.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00209984 _____ (BitDefender) C:\Windows\system32\BdFirewallSDK.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00195016 _____ (BitDefender) C:\Windows\system32\httproxy.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00156936 _____ () C:\Windows\system32\bdfwcore.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00155912 _____ (BitDefender S.R.L.) C:\Windows\system32\bdpop3p.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00122928 _____ (BitDefender) C:\Windows\system32\OEMbdpredir.dll 2014-08-30 22:30 - 2014-07-10 14:08 - 00096160 _____ (BitDefender) C:\Windows\system32\bdpredir.dll 2014-08-30 22:29 - 2014-09-03 23:44 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Users\Udi\AppData\Local\adawarebp 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Program Files\Lavasoft 2014-08-30 22:28 - 2014-08-30 22:28 - 00000000 ____D () C:\Program Files (x86)\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-08-30 22:26 - 2014-09-03 00:55 - 00000000 ____D () C:\Users\Udi\Desktop\Viren 2014-08-30 21:58 - 2014-08-30 21:58 - 00000000 ____D () C:\Windows\ERUNT 2014-08-30 21:38 - 2014-09-03 00:42 - 00000000 ____D () C:\AdwCleaner 2014-08-30 21:18 - 2014-09-04 09:32 - 00000000 ____D () C:\FRST 2014-08-30 21:16 - 2014-08-30 22:11 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-08-30 11:20 - 2014-08-30 11:20 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 12:29 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-28 12:29 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-28 12:29 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-08-21 12:30 - 2014-08-21 12:30 - 00727592 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00601360 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00261056 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys 2014-08-21 09:43 - 2014-08-21 09:43 - 06052529 _____ (Tim Kosse) C:\Users\Udi\Downloads\FileZilla_3.9.0.3_win32-setup.exe 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-16 16:27 - 2014-08-16 16:27 - 00000000 ____D () C:\Users\Udi\AppData\Local\Adobe 2014-08-14 15:25 - 2014-08-14 15:18 - 00110314 ____N () C:\Users\Udi\Desktop\wachat_20140814.txt 2014-08-14 15:25 - 1970-01-01 01:59 - 00062754 ____N () C:\Users\Udi\Desktop\wachat_20140814.xlsx 2014-08-14 15:15 - 2014-08-14 19:47 - 00000000 ____D () C:\adb 2014-08-13 13:22 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-13 13:22 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-13 13:22 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-13 13:22 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-13 13:22 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-13 13:22 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-13 13:22 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-13 13:22 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-13 12:37 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-13 12:37 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-13 12:37 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-13 12:37 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-13 12:33 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-13 12:33 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-13 12:33 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-13 12:33 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-13 12:33 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-13 12:33 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-13 12:33 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-13 12:33 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-13 12:33 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-13 12:33 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-13 12:33 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-13 12:32 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-13 12:32 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-13 12:32 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-13 12:32 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-13 12:32 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-13 12:32 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-13 12:32 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-13 12:32 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-13 12:32 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-13 12:32 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-13 12:32 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-13 12:32 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-13 12:32 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-13 12:32 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-13 12:32 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-13 12:32 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-13 12:32 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-13 12:32 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-13 12:32 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-13 12:32 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-13 12:32 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-13 12:32 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-13 12:32 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-13 12:32 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-13 12:32 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-13 12:32 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-13 12:32 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-13 12:32 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-13 12:32 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-13 12:32 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-13 12:32 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-13 12:32 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-13 12:32 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-13 12:32 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-13 12:32 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-13 12:32 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-13 12:32 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-13 12:32 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-13 12:32 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-13 12:32 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-13 12:32 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-13 12:32 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-13 12:32 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-13 12:32 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-13 12:32 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-13 12:32 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-13 12:32 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-13 12:32 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-13 12:32 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-13 12:32 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-13 12:32 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-13 12:32 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-13 12:32 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-13 12:32 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-13 12:32 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-13 12:32 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-13 12:32 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-13 12:28 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-13 12:28 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-13 12:27 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-13 12:27 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-12 21:49 - 2014-08-12 21:50 - 00000001 ____R () C:\Users\Udi\serverport 2014-08-12 21:49 - 2014-08-12 21:49 - 00000000 ____D () C:\Users\Udi\.jivex 2014-08-05 18:25 - 2014-08-05 18:25 - 01538102 _____ () C:\Users\Udi\Desktop\Oscam Konfiguration.zip ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-04 09:32 - 2014-09-04 09:32 - 00017527 _____ () C:\Users\Udi\Desktop\FRST.txt 2014-09-04 09:32 - 2014-09-04 09:32 - 00001000 _____ () C:\Users\Udi\Desktop\sc.txt 2014-09-04 09:32 - 2014-08-30 21:18 - 00000000 ____D () C:\FRST 2014-09-04 09:32 - 2009-07-14 06:51 - 00598457 _____ () C:\Windows\setupact.log 2014-09-04 08:39 - 2014-09-04 08:39 - 00854417 _____ () C:\Users\Udi\Desktop\SecurityCheck.exe 2014-09-04 08:30 - 2011-11-05 14:18 - 01946241 _____ () C:\Windows\WindowsUpdate.log 2014-09-04 00:56 - 2014-09-03 23:53 - 00003767 _____ () C:\Users\Udi\Desktop\eset.txt 2014-09-03 23:53 - 2014-09-03 23:52 - 02347384 _____ (ESET) C:\Users\Udi\Desktop\esetsmartinstaller_deu.exe 2014-09-03 23:51 - 2009-07-14 06:45 - 00022048 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-03 23:51 - 2009-07-14 06:45 - 00022048 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-03 23:50 - 2009-07-14 19:58 - 24512306 _____ () C:\Windows\system32\perfh007.dat 2014-09-03 23:50 - 2009-07-14 19:58 - 07673446 _____ () C:\Windows\system32\perfc007.dat 2014-09-03 23:50 - 2009-07-14 07:13 - 00006292 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-03 23:45 - 2012-06-06 20:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-03 23:44 - 2014-08-30 22:29 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection 2014-09-03 23:44 - 2013-10-12 19:52 - 00000000 ___RD () C:\Users\Udi\Cloud Station 2014-09-03 23:44 - 2013-10-12 19:17 - 00000000 ____D () C:\Users\Udi\AppData\Local\CloudStation 2014-09-03 23:44 - 2012-09-15 15:40 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-09-03 23:44 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-03 23:09 - 2014-09-03 23:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-03 13:01 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-09-03 00:55 - 2014-08-30 22:26 - 00000000 ____D () C:\Users\Udi\Desktop\Viren 2014-09-03 00:44 - 2014-09-03 00:44 - 01016261 _____ (Thisisu) C:\Users\Udi\Desktop\JRT.exe 2014-09-03 00:43 - 2011-11-05 15:31 - 00356402 _____ () C:\Windows\PFRO.log 2014-09-03 00:42 - 2014-08-30 21:38 - 00000000 ____D () C:\AdwCleaner 2014-09-03 00:36 - 2014-09-03 00:36 - 01364531 _____ () C:\Users\Udi\Desktop\adwcleaner_3.308.exe 2014-09-03 00:23 - 2014-09-03 00:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-03 00:23 - 2014-09-03 00:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-03 00:23 - 2014-09-03 00:23 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-03 00:22 - 2014-09-03 00:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Udi\Desktop\mbam-setup-2.0.2.1012.exe 2014-09-02 09:35 - 2014-09-02 09:35 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-09-01 20:15 - 2014-09-01 20:15 - 00169371 _____ () C:\Users\Udi\Desktop\bookmarks-2014-09-01.json 2014-09-01 19:59 - 2014-08-30 23:21 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-09-01 17:38 - 2014-09-01 17:38 - 00000085 _____ () C:\Windows\wininit.ini 2014-09-01 17:38 - 2014-08-30 23:21 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-09-01 17:17 - 2014-09-01 17:17 - 00024356 _____ () C:\ComboFix.txt 2014-09-01 17:17 - 2014-09-01 16:54 - 00000000 ____D () C:\Qoobox 2014-09-01 17:14 - 2014-09-01 16:54 - 00000000 ____D () C:\Windows\erdnt 2014-09-01 17:06 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-09-01 16:51 - 2014-09-01 16:51 - 05576326 ____R (Swearware) C:\Users\Udi\Desktop\ComboFix.exe 2014-09-01 07:08 - 2014-09-01 07:08 - 02104832 _____ (Farbar) C:\Users\Udi\Desktop\FRST64.exe 2014-08-30 23:35 - 2014-08-30 23:29 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-30 23:34 - 2014-08-30 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-30 23:34 - 2014-08-30 23:28 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-30 23:29 - 2014-08-30 23:29 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Avira 2014-08-30 23:29 - 2014-08-30 23:28 - 00000000 ____D () C:\ProgramData\Avira 2014-08-30 23:21 - 2014-08-30 23:21 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-08-30 22:37 - 2014-08-30 22:37 - 00000000 ____D () C:\ProgramData\BitDefender 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\LavasoftStatistics 2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Users\Udi\AppData\Local\adawarebp 2014-08-30 22:29 - 2014-08-30 22:29 - 00000000 ____D () C:\Program Files\Lavasoft 2014-08-30 22:28 - 2014-08-30 22:28 - 00000000 ____D () C:\Program Files (x86)\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-08-30 22:27 - 2014-08-30 22:27 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-08-30 22:11 - 2014-08-30 21:16 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-08-30 21:58 - 2014-08-30 21:58 - 00000000 ____D () C:\Windows\ERUNT 2014-08-30 21:24 - 2013-06-01 12:02 - 00000000 ____D () C:\Program Files (x86)\HTC 2014-08-30 21:23 - 2012-05-26 17:11 - 00105928 _____ () C:\Windows\DPINST.LOG 2014-08-30 11:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Cursors 2014-08-30 11:20 - 2014-08-30 11:20 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 20:03 - 2009-07-14 06:45 - 00357080 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-24 15:44 - 2014-02-20 22:33 - 00000000 ____D () C:\Users\Udi\Documents\FIFA 14 2014-08-24 14:20 - 2014-02-16 14:31 - 00000000 ____D () C:\ProgramData\Origin 2014-08-24 14:20 - 2014-02-16 14:30 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-08-23 12:19 - 2013-09-27 18:07 - 00000000 ____D () C:\Program Files (x86)\Synology 2014-08-23 04:07 - 2014-08-28 12:29 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-23 03:45 - 2014-08-28 12:29 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-23 02:59 - 2014-08-28 12:29 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-08-21 12:30 - 2014-08-21 12:30 - 00727592 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00601360 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys 2014-08-21 12:30 - 2014-08-21 12:30 - 00261056 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys 2014-08-21 09:48 - 2011-11-05 19:09 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\FileZilla 2014-08-21 09:47 - 2013-08-10 00:00 - 00000000 ____D () C:\Users\Udi\AppData\Roaming\vlc 2014-08-21 09:43 - 2014-08-21 09:43 - 06052529 _____ (Tim Kosse) C:\Users\Udi\Downloads\FileZilla_3.9.0.3_win32-setup.exe 2014-08-21 09:43 - 2011-11-05 19:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2014-08-21 09:43 - 2011-11-05 19:08 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-17 22:52 - 2014-08-17 22:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-16 16:27 - 2014-08-16 16:27 - 00000000 ____D () C:\Users\Udi\AppData\Local\Adobe 2014-08-16 11:39 - 2012-04-15 21:04 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-08-16 11:39 - 2011-11-05 14:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-08-15 10:30 - 2014-08-30 23:28 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-08-15 10:30 - 2014-08-30 23:28 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-08-15 10:30 - 2014-08-30 23:28 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-08-15 10:02 - 2011-11-05 14:18 - 00000000 ____D () C:\Users\Udi\AppData\Local\VirtualStore 2014-08-14 19:47 - 2014-08-14 15:15 - 00000000 ____D () C:\adb 2014-08-14 15:18 - 2014-08-14 15:25 - 00110314 ____N () C:\Users\Udi\Desktop\wachat_20140814.txt 2014-08-13 21:06 - 2013-05-19 17:05 - 00000000 ____D () C:\Windows\rescache 2014-08-13 18:44 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-13 13:26 - 2013-07-29 14:44 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-13 13:25 - 2012-04-20 18:45 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-13 13:22 - 2014-05-06 21:03 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-12 21:50 - 2014-08-12 21:49 - 00000001 ____R () C:\Users\Udi\serverport 2014-08-12 21:49 - 2014-08-12 21:49 - 00000000 ____D () C:\Users\Udi\.jivex 2014-08-12 21:49 - 2011-11-05 14:18 - 00000000 ____D () C:\Users\Udi 2014-08-07 11:34 - 2014-05-19 20:38 - 00001102 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-08-07 04:06 - 2014-08-13 12:27 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 04:01 - 2014-08-13 12:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-05 18:25 - 2014-08-05 18:25 - 01538102 _____ () C:\Users\Udi\Desktop\Oscam Konfiguration.zip 2014-08-05 09:20 - 2011-11-05 17:05 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\Udi\AppData\Local\Temp\avgnt.exe C:\Users\Udi\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-28 12:42 ==================== End Of Log ============================ --- --- --- aber ja, das problem habe ich nach wie vor noch. eset hat auch noch 6 probleme gefunden. kannst du mir kurz sagen, was du aus den logs raus liest? danke! |
04.09.2014, 14:50 | #10 |
/// the machine /// TB-Ausbilder | click compare und co. werd ich einfach nicht los :((( Naja, Malware eben. Java updaten. Nas kannste im Nachgang scannen mit deinem AV Programm oder so. In welchem Browser besteht das Problem?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.09.2014, 18:56 | #11 |
| click compare und co. werd ich einfach nicht los :((( java update funktioniert nicht. egal ob ich die aktuelle version lade und installiere oder ob ich aus der installierten version updaten will. kommt immer fehlermeldung: ...problem beim dekomprimieren... in firefox. kannst du mir sagen was ich drauf an trojaner etc? |
05.09.2014, 12:39 | #12 |
/// the machine /// TB-Ausbilder | click compare und co. werd ich einfach nicht los :((( Das war Adware, jede Menge Adware. Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen Java auch mit Revo deinstallieren, dann Java neu laden und installieren.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.09.2014, 16:47 | #13 |
| click compare und co. werd ich einfach nicht los :((( und die ist dann nach der Neuinstallation von firefox weg? denn eset hat ja noch eine menge gefunden. aber nichts entfernt. |
06.09.2014, 12:14 | #14 |
/// the machine /// TB-Ausbilder | click compare und co. werd ich einfach nicht los :((( wir haben vorher schon ne Menge entfernt, aber im Firefox Profil steckt noch was.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.09.2014, 14:03 | #15 |
| click compare und co. werd ich einfach nicht los :((( firefox Neuinstallation habe ich gemacht. und warte jetzt ab ob die fehler noch kommen. wie kann ich prüfen ob die plagegeister der letzten eset scannung weg sind? einfach noch mal durchführen? vielen dank schon mal!!! |
Themen zu click compare und co. werd ich einfach nicht los :((( |
click compare, folgende, folgenden, gefunde, langsam, programme, spenden, trojaner, umgeleitet, versucht, win32/bundled.toolbar.ask, win32/bundled.toolbar.ask.f, win32/downloadsponsor.a, win32/installshare.a, win32/toolbar.visicom.a, win32/toolbar.visicom.b, win32/toolbar.visicom.c, wochen, zusammen |