|
Plagegeister aller Art und deren Bekämpfung: Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
21.10.2014, 15:05 | #1 |
| Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Foxydeal weist auf Gutscheine hin - kein Bedarf. Entfernung jedoch bislang gescheitert. Werter Helfer, werte Admins, Mods und Supporter, dürfte ich Sie heute höchst hilfreich um Ihre Stellungnahmen bitten? Vorsorglich vielen Dank: Heute durchgeführt 3. AdwCleaner (nichts gefunden) 2. Malwarebytes Anti-Malware (nichts gefunden) 1. ESET Online Scanner (5 Objekte gefunden & entfernt) 4. FoxyDeal entfernen Firefox: über »Add-ons | Erweiterungen - about:config - ... > keine Einträge auf Foxydeal lautend gefunden Trotzdem Foxydeal Gutscheinangebote in Top unterschiedlicher Seiten >>> Ausserdem: Ist 'chrome://adblockplus/content/ui/firstRun.html' wirklich so gut? Auf meinem Rechner geht beim browsen immer ein neuer Tab automatisch mit auf der dann chrome://adblockplus/content/ui/firstRun.html in der Adresszeile stehen hat. Handlungsbedarf oder auf System belassen? Ratschlag höflichst erbeten - lieben Dank an den ehrlichen Ratgeber. Es grüßt sandsonne |
21.10.2014, 15:21 | #2 |
/// the machine /// TB-Ausbilder | Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
21.10.2014, 18:43 | #3 |
| Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Hi und erst einmal: Danke schöne!
__________________FRST FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-10-2014 Ran by Kerstin (administrator) on USER1011-PC on 21-10-2014 19:26:12 Running from C:\Users\Kerstin\Desktop Loaded Profiles: Kerstin & (Available profiles: Kerstin & Administrator) Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (NEC Electronics Corporation) C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (AVM Berlin) C:\Program Files\avmwlanstick\FRITZWLanMini.exe (Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Brother Industries, Ltd.) C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe (Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NUSB3MON] => C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-11-20] (NEC Electronics Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [AVMWlanClient] => C:\Program Files\avmwlanstick\FRITZWLANMini.exe [283136 2007-02-02] (AVM Berlin) HKLM\...\Run: [BrMfcWnd] => C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.) HKLM\...\Run: [ControlCenter3] => C:\Program Files\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-07] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG) HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1 HKLM\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-3467251772-538213018-3341465458-1001\...\Policies\Explorer: [TaskbarNoNotification] 1 HKU\S-1-5-21-3467251772-538213018-3341465458-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [TaskbarNoNotification] 1 Startup: C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKCU - {AFF5BEFB-01AB-4CF5-9CB1-6B3AF075A3F7} URL = hxxp://www.ant.com/search?s=browser&q={searchTerms} BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default FF Homepage: hxxp://google.de FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Browser Safety - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\abs@avira.com [2014-09-30] FF Extension: StumbleUpon - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\toolbar@stumbleupon.com [2014-08-24] FF Extension: AdBeaver - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\adbeaver@adbeaver.org.xpi [2014-08-12] FF Extension: Firebug - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\firebug@software.joehewitt.com.xpi [2014-07-27] FF Extension: Adblock Plus - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-24] Chrome: ======= CHR Profile: C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-27] CHR Extension: (Google Drive) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-27] CHR Extension: (YouTube) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-27] CHR Extension: (Google-Suche) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-27] CHR Extension: (Securita Scout) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfkilfadjoneaheacgmkahfgcjchkpad [2014-07-26] CHR Extension: (Google Wallet) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-27] CHR Extension: (Google Mail) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-27] CHR HKLM\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Users\Kerstin\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx [2014-07-26] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-07] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-07] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG) R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed] S2 PDFProFiltSrv; C:\Program Files\Nuance\PDF Professional 8\PDFProFiltSrv.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-17] (Avira Operations GmbH & Co. KG) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [265088 2007-01-26] (AVM GmbH) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2012-12-07] (GFI Software) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-10-21] (Malwarebytes Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-11] (Avira GmbH) S3 catchme; \??\C:\Users\Kerstin\AppData\Local\Temp\catchme.sys [X] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-21 19:26 - 2014-10-21 19:26 - 00012235 _____ () C:\Users\Kerstin\Desktop\FRST.txt 2014-10-21 19:25 - 2014-10-21 19:25 - 01102336 _____ (Farbar) C:\Users\Kerstin\Desktop\FRST.exe 2014-10-21 14:16 - 2014-10-21 14:16 - 01962496 _____ () C:\Users\Kerstin\Desktop\AdwCleaner_4.001.exe 2014-10-21 07:11 - 2014-10-21 07:11 - 02347384 _____ (ESET) C:\Users\Kerstin\Desktop\esetsmartinstaller_deu.exe 2014-10-21 06:12 - 2014-10-21 06:13 - 00000000 ____D () C:\872aa2902dec1781c81b66193cdca3a3 2014-10-20 06:37 - 2014-10-20 06:38 - 00000000 ____D () C:\df4bb4adb4370d6ab0455d9fe960ecff 2014-10-18 19:04 - 2014-10-18 19:04 - 00000000 ____D () C:\6a254c2f794a30d76ef52f 2014-10-17 19:21 - 2014-10-17 19:21 - 00000000 ____D () C:\6ee1dee45d33015e79b28f5acba707 2014-10-17 12:37 - 2014-10-17 12:37 - 00259687 _____ () C:\Users\Kerstin\AppData\Local\recently-used.xbel 2014-10-17 10:53 - 2014-10-17 11:25 - 00056660 _____ () C:\Users\Kerstin\Desktop\test.html 2014-10-17 10:53 - 2014-10-17 10:53 - 00224574 _____ () C:\Users\Kerstin\Desktop\DOCTYPE html.htm 2014-10-17 06:48 - 2014-10-17 06:49 - 00000000 ____D () C:\8d90e9dfbe1a709c7a4810c71d47 2014-10-16 20:54 - 2014-10-16 20:54 - 00000000 ____D () C:\a2c5b95ff2b43e344d799e 2014-10-16 06:37 - 2014-10-10 03:44 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-10-16 06:37 - 2014-10-10 03:44 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-10-16 06:37 - 2014-10-10 03:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-10-16 06:37 - 2014-09-29 02:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-16 06:36 - 2014-10-07 04:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-16 06:36 - 2014-09-26 00:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-10-16 06:36 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-10-16 06:36 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-16 06:36 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-16 06:36 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-16 06:36 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-16 06:36 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-10-16 06:36 - 2014-09-19 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-16 06:36 - 2014-09-19 03:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-10-16 06:36 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-10-16 06:36 - 2014-09-19 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-16 06:36 - 2014-09-19 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-10-16 06:36 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-10-16 06:36 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-16 06:36 - 2014-09-19 02:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-16 06:36 - 2014-09-19 02:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-16 06:36 - 2014-09-19 02:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-16 06:36 - 2014-09-19 02:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-10-16 06:36 - 2014-09-19 02:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-10-16 06:36 - 2014-09-19 02:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-10-16 06:36 - 2014-09-19 02:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-10-16 06:36 - 2014-09-19 02:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-10-16 06:36 - 2014-09-19 02:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-10-16 06:36 - 2014-09-19 02:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-16 06:36 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-16 06:36 - 2014-09-19 02:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-10-16 06:36 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-16 06:36 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-16 06:36 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-10-16 06:36 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-10-16 06:36 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-10-16 06:36 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-10-16 06:36 - 2014-07-17 03:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-10-16 06:36 - 2014-07-17 03:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-10-16 06:36 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-10-16 06:36 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-10-16 06:36 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-16 06:36 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-16 06:36 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-16 06:35 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-15 16:57 - 2014-10-20 12:38 - 00000000 ____D () C:\Users\Kerstin\Desktop\Neuer Ordner 2014-10-15 09:53 - 2014-10-20 08:30 - 00000000 ____D () C:\Users\Kerstin\Desktop\xmas 2014-10-15 09:53 - 2014-10-15 12:26 - 00000000 ____D () C:\Users\Kerstin\Desktop\xmasdemos 2014-10-15 08:53 - 2014-10-21 14:21 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-15 08:15 - 2014-10-15 08:15 - 02705000 _____ () C:\Users\Kerstin\Downloads\mp3tagv264setup.exe 2014-10-13 14:22 - 2014-10-13 15:57 - 00027057 _____ () C:\Users\Kerstin\Desktop\Weihnachtsansagen_Business.html 2014-10-13 07:59 - 2014-10-13 07:59 - 00000000 ____D () C:\Users\Kerstin\Desktop\Weihnachtsansagen_Business 2014-10-08 09:06 - 2014-10-08 09:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Kerstin\Downloads\revosetup95.exe 2014-10-06 09:02 - 2014-10-06 13:06 - 00000000 ____D () C:\Program Files\svnet 2014-10-06 09:02 - 2014-10-06 09:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\svnet 2014-10-06 09:02 - 2005-10-05 13:43 - 00266307 _____ (Dart Communications) C:\Windows\system32\DartWebASP.dll 2014-10-06 09:02 - 2005-09-29 15:59 - 00221184 _____ (Dart Communications) C:\Windows\system32\DartSock.dll 2014-10-06 09:02 - 2005-09-29 15:59 - 00147456 _____ (Dart Communications) C:\Windows\system32\DartWeb.dll 2014-10-06 09:02 - 2005-09-29 15:59 - 00122880 _____ (Dart Communications) C:\Windows\system32\DartWebUtil.dll 2014-10-06 09:02 - 2005-08-03 17:35 - 00507904 _____ (ComponentOne LLC) C:\Windows\system32\vsrpt8.ocx 2014-10-06 09:02 - 2005-07-22 14:03 - 00163840 _____ (Dart Communications) C:\Windows\system32\DartSecure2.dll 2014-10-06 09:02 - 2005-07-22 14:02 - 00155648 _____ (Dart Communications) C:\Windows\system32\DartCertificate.dll 2014-10-06 09:02 - 2004-09-17 13:28 - 01114112 _____ (ComponentOne LLC) C:\Windows\system32\tdbl8.ocx 2014-10-06 09:02 - 2004-08-30 18:41 - 01060864 _____ (ComponentOne LLC) C:\Windows\system32\tdbg8.ocx 2014-10-06 09:02 - 2004-07-26 17:02 - 00192512 _____ (ComponentOne) C:\Windows\system32\vsvport8.ocx 2014-10-06 09:02 - 2004-07-26 17:01 - 00417792 _____ (ComponentOne) C:\Windows\system32\vsprint8.ocx 2014-10-06 09:02 - 2004-07-26 11:51 - 00311296 _____ (ComponenetOne) C:\Windows\system32\c1sizer.ocx 2014-10-06 09:02 - 2003-11-10 17:32 - 00790528 _____ (Polar sales@polarsoftware.com www.polarsoftware.com) C:\Windows\system32\polarcrypto.dll 2014-10-06 09:02 - 2002-02-27 16:24 - 00794304 _____ (Data Dynamics) C:\Windows\system32\Actbar2.ocx 2014-10-06 09:02 - 2000-10-15 19:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\MSJINT35.DLL 2014-10-06 09:02 - 1999-09-28 22:42 - 01050896 _____ (Microsoft Corporation) C:\Windows\system32\msjet35.dll 2014-10-06 09:02 - 1999-08-25 15:57 - 00415504 _____ (Microsoft Corporation) C:\Windows\system32\msrepl35.dll 2014-10-06 09:02 - 1998-04-24 00:00 - 00368912 _____ (Microsoft Corporation) C:\Windows\system32\vbar332.dll 2014-10-06 09:02 - 1998-04-24 00:00 - 00252176 _____ (Microsoft Corporation) C:\Windows\system32\Msrd2x35.dll 2014-10-06 09:02 - 1998-04-24 00:00 - 00024848 _____ (Microsoft Corporation) C:\Windows\system32\MSJTER35.DLL 2014-10-06 08:52 - 2014-10-06 08:52 - 14086762 _____ () C:\Users\Kerstin\Downloads\Setup.exe 2014-10-05 14:05 - 2014-10-05 14:08 - 00014430 _____ () C:\Users\Kerstin\arc.html 2014-10-05 14:05 - 2014-10-05 14:05 - 00000000 ____D () C:\Users\Kerstin\arc 2014-10-05 12:05 - 2014-10-05 12:05 - 00896928 _____ () C:\Users\Kerstin\Downloads\interior_architectural_sketches_icon_vector_163293.zip 2014-10-05 12:05 - 2014-10-05 12:05 - 00000000 ____D () C:\Users\Kerstin\Downloads\interior_architectural_sketches_icon_vector_163293 2014-10-01 05:55 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-09-30 15:50 - 2014-10-14 10:41 - 00000000 ____D () C:\Users\Kerstin\Desktop\Upload 2014-09-30 08:59 - 2014-09-30 09:01 - 69187542 _____ () C:\Users\Kerstin\Desktop\videoplayback.htm 2014-09-24 17:28 - 2014-09-24 17:28 - 00001141 _____ () C:\Users\Kerstin\Desktop\idee.txt 2014-09-24 07:42 - 2014-10-14 18:53 - 00000000 ____D () C:\Users\Kerstin\Desktop\WV 2014-09-24 06:29 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-21 19:26 - 2014-03-20 17:49 - 00000000 ____D () C:\FRST 2014-10-21 19:11 - 2012-04-18 08:12 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-21 14:18 - 2014-08-24 18:42 - 00000000 ____D () C:\Program Files\Avidemux 2.6 2014-10-21 14:00 - 2014-07-30 18:52 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-21 07:21 - 2014-03-20 17:02 - 00000000 ____D () C:\AdwCleaner 2014-10-21 06:15 - 2009-07-14 06:34 - 00025520 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-21 06:15 - 2009-07-14 06:34 - 00025520 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-21 06:13 - 2011-09-17 15:55 - 01826966 _____ () C:\Windows\WindowsUpdate.log 2014-10-21 06:08 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-21 06:08 - 2009-07-14 06:39 - 00482832 _____ () C:\Windows\setupact.log 2014-10-20 20:19 - 2012-12-07 19:58 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\FileZilla 2014-10-18 10:19 - 2012-02-23 19:10 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-10-17 19:19 - 2013-05-16 10:12 - 00000000 ____D () C:\Users\Kerstin\.gimp-2.8 2014-10-17 10:06 - 2012-03-01 18:45 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\CrashDumps 2014-10-17 07:46 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-10-17 07:09 - 2009-07-14 06:33 - 00514104 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-17 07:07 - 2014-04-30 20:02 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-10-17 06:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-10-17 06:38 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-10-16 20:52 - 2013-12-13 21:01 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-16 20:49 - 2011-09-17 20:44 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-10-15 11:57 - 2013-05-21 10:00 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Mp3tag 2014-10-15 06:21 - 2014-08-05 12:51 - 00000000 ____D () C:\ProgramData\Package Cache 2014-10-15 06:21 - 2013-02-11 11:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-10-15 06:21 - 2013-02-11 11:05 - 00000000 ____D () C:\Program Files\Avira 2014-10-10 12:29 - 2012-02-24 00:17 - 00000000 ____D () C:\Users\Kerstin\Desktop\Office Interim 2014-10-10 12:28 - 2013-01-21 19:40 - 00000000 ____D () C:\Users\Kerstin\Desktop\privat 2014-10-09 07:20 - 2011-09-17 17:03 - 00533164 _____ () C:\Windows\PFRO.log 2014-10-08 09:06 - 2014-07-29 12:55 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-10-07 16:26 - 2014-08-14 07:18 - 00000000 ____D () C:\Users\Kerstin\Desktop\Demos 2014-10-07 12:30 - 2013-05-06 12:30 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-10-07 12:30 - 2013-02-11 11:05 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-10-07 12:30 - 2013-02-11 11:05 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-10-05 14:08 - 2012-02-23 19:32 - 00000000 ____D () C:\Users\Kerstin 2014-09-30 07:04 - 2014-07-30 18:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-30 07:04 - 2014-07-30 18:51 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-09-24 08:11 - 2012-04-18 08:12 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-09-24 08:11 - 2012-02-13 23:15 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\Kerstin\AppData\Local\temp\avgnt.exe C:\Users\Kerstin\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-16 07:06 ==================== End Of Log ============================ ADDITION Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-10-2014 Ran by Kerstin at 2014-10-21 19:26:57 Running from C:\Users\Kerstin\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader X (10.1.7) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.7 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.) Audacity 2.0.3 (HKLM\...\Audacity_is1) (Version: 2.0.3 - Audacity Team) Avira (HKLM\...\{9bd9b85e-7792-483b-a318-cc51ff0877ed}) (Version: 1.1.22.50000 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.22.50000 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.306 - Avira) BeCyPDFMetaEdit (HKLM\...\BeCyPDFMetaEdit) (Version: 2.37.0 - Benjamin Bentmann) BurnAware Professional 6.2 (HKLM\...\BurnAware Professional_is1) (Version: - Burnaware) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.4003 - CDBurnerXP) CIB pdf brewer (HKLM\...\{461A4763-28B5-425A-AE3D-B9B54EDF0F21}) (Version: 2.6.0047 - CIB software GmbH) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden Document Trace Remover v3.6 (HKLM\...\Document Trace Remover_is1) (Version: 3.6 - Smart PC Solutions) ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - ) Exif Tag Remover 2.0 (HKLM\...\Exif Tag Remover_is1) (Version: - RL Vision) FileViewPro (HKLM\...\{29938C06-6962-4C27-A94C-25E4F424A665}_is1) (Version: 1.5 - Solvusoft Corporation) FileZilla Client 3.9.0.5 (HKLM\...\FileZilla Client) (Version: 3.9.0.5 - Tim Kosse) Firebird SQL Server - MAGIX Edition (HKLM\...\{6C5F8503-55D2-4398-858C-362B7A7AF51C}) (Version: 2.1.31.0 - MAGIX AG) Fotogalerie (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden GIMP 2.8.4 (HKLM\...\GIMP-2_is1) (Version: 2.8.4 - The GIMP Team) GPL Ghostscript (HKLM\...\GPL Ghostscript 9.04) (Version: 9.04 - Artifex Software Inc.) Hex-Editor MX (HKLM\...\{7FC7AD70-1DF3-4B84-9AA2-4FB680F45572}_is1) (Version: 6.0 - NEXT-Soft) Java 7 Update 40 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.400 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - ) Lexware büro easy 2005 (HKLM\...\{2F2E04D3-C0DA-4B9A-B2B4-234ED20A2385}) (Version: 12.0 - ) Lexware büro easy 2005 (Version: 12.00 - Lexware) Hidden Lexware online banking V 3.10 (HKLM\...\{D01F701A-1F23-494C-BE82-8A7441CADEEA}) (Version: - ) MAGIX Content und Soundpools (HKLM\...\MAGIX_GlobalContent) (Version: 1.0.0.0 - MAGIX AG) MAGIX Goya burnR (MSI) (HKLM\...\MAGIX_{B332E15B-243F-4F40-8530-1524F84230A0}) (Version: 4.3.2.0 - MAGIX AG) MAGIX Goya burnR (MSI) (Version: 4.3.2.0 - MAGIX AG) Hidden MAGIX Music Maker 2013 (HKLM\...\MAGIX_{3F5C2BC0-B7D7-4114-B273-3B1460B2452B}) (Version: 19.0.3.47 - MAGIX AG) MAGIX Music Maker 2013 (Version: 19.0.3.47 - MAGIX AG) Hidden MAGIX Music Maker 2013 Trial Soundpools (Version: 1.0.0.0 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Maker (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 33.0 (x86 de) (HKLM\...\Mozilla Firefox 33.0 (x86 de)) (Version: 33.0 - Mozilla) Mp3tag v2.55a (HKLM\...\Mp3tag) (Version: v2.55a - Florian Heidenreich) MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (Version: 16.4.1108.0727 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) NEC Electronics USB 3.0 Host Controller Driver (HKLM\...\InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}) (Version: 1.0.18.0 - NEC Electronics Corporation) NEC Electronics USB 3.0 Host Controller Driver (Version: 1.0.18.0 - NEC Electronics Corporation) Hidden Norton Internet Security (Version: 18.1.0.37 - Symantec Corporation) Hidden Notepad++ (HKLM\...\Notepad++) (Version: 6.4.1 - Notepad++ Team) Photo Common (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - ) Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Sagede.Shared.Elster.Setup (Version: 1.0.0.0.28 - Sage Software GmbH) Hidden sv.net (HKLM\...\sv.net) (Version: 14.1 - ITSG GmbH) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.29480 - TeamViewer) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VLC media player 2.1.0 (HKLM\...\VLC media player) (Version: 2.1.0 - VideoLAN) Winamp (HKLM\...\Winamp) (Version: 5.63 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows Live Communications Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden XNResourceEditor 3.0.0.1 (HKLM\...\XN Resource Editor_is1) (Version: - Colin Wilson) Yahoo! Detect (HKLM\...\YTdetect) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3467251772-538213018-3341465458-1001_Classes\CLSID\{3bc93e76-92f8-5fda-b676-5afee3735bf1}\InprocServer32 -> C:\Users\Kerstin\AppData\Local\ext_offermosquito\npOfferMosquitoIEHelper.dll No File CustomCLSID: HKU\S-1-5-21-3467251772-538213018-3341465458-1001_Classes\CLSID\{9000834c-c6c7-43ac-b8ee-dc9668f39a81}\localserver32 -> C:\Users\Kerstin\AppData\Local\Temp\{91814ec0-b5f0-11d2-80b9-00104b1f6cea}\IDriver.NonElevated.exe N (the data entry has 6 more characters). ==================== Restore Points ========================= 08-10-2014 07:08:29 Revo Uninstaller's restore point - Mozilla Firefox 32.0.3 (x86 de) 11-10-2014 11:37:14 Windows Update 16-10-2014 04:29:16 Windows Update 16-10-2014 18:46:22 Windows Update 17-10-2014 04:45:23 Windows Update 17-10-2014 17:20:45 Windows Update 18-10-2014 08:16:44 Windows Update 18-10-2014 17:03:45 Windows Update 20-10-2014 04:36:13 Windows Update 20-10-2014 18:22:19 Windows Update 21-10-2014 04:12:16 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2014-08-26 14:55 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {053C1ED7-2B23-4CF4-94FC-C2CF7D0DFE1D} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe Task: {0773E3BD-6045-4764-9264-EBF7F5649F71} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe Task: {1AFD32CC-E0EE-4337-BE4B-5DE195A6857A} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe Task: {4E01776C-30F4-4803-B09F-BED5962006D0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24] (Adobe Systems Incorporated) Task: {8806CE8D-40A8-4496-808A-6011FEF64F8C} - \plushd8.1-validator No Task File <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2012-07-26 14:07 - 2010-06-17 21:56 - 00116224 _____ () C:\Windows\System32\redmonnt.dll 2012-12-18 22:43 - 2009-02-27 17:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll 2014-09-06 18:44 - 2014-09-06 18:44 - 00035328 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll 2014-05-24 18:41 - 2014-05-24 18:41 - 00091648 _____ () C:\Program Files\FileZilla FTP Client\libgcc_s_sjlj-1.dll 2014-05-24 18:41 - 2014-05-24 18:41 - 00892416 _____ () C:\Program Files\FileZilla FTP Client\libstdc++-6.dll 2009-02-26 14:46 - 2009-02-26 14:46 - 00064344 _____ () C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll 2011-06-22 12:46 - 2011-06-22 12:46 - 00434016 _____ () C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll 2013-07-10 18:07 - 2013-07-10 18:07 - 00756888 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL 2014-10-21 14:21 - 2014-10-11 14:53 - 03649648 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-09-11 11:11 - 2014-09-11 11:11 - 16825520 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:18262EDA AlternateDataStreams: C:\ProgramData\TEMP:66D2723C AlternateDataStreams: C:\ProgramData\TEMP:6CC0D09A ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" MSCONFIG\startupreg: SpybotSD TeaTimer => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe ========================= Accounts: ========================== Administrator (S-1-5-21-3467251772-538213018-3341465458-500 - Administrator - Enabled) => C:\Users\Administrator Gast (S-1-5-21-3467251772-538213018-3341465458-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3467251772-538213018-3341465458-1003 - Limited - Enabled) Kerstin (S-1-5-21-3467251772-538213018-3341465458-1001 - Administrator - Enabled) => C:\Users\Kerstin ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/20/2014 00:43:46 PM) (Source: Brother BrLog) (EventID: 1001) (User: ) Description: WDLMW BrtWDLMW: [2014/10/20 12:43:46.770]: [00003676]: lperrcode->api = 1 , lperrcode->code = 2 Error: (10/20/2014 00:43:45 PM) (Source: Brother BrLog) (EventID: 1001) (User: ) Description: WDLMW BrtWDLMW: [2014/10/20 12:43:45.270]: [00003676]: lperrcode->api = 1 , lperrcode->code = 2 Error: (10/20/2014 00:43:43 PM) (Source: Brother BrLog) (EventID: 1001) (User: ) Description: WDLMW BrtWDLMW: [2014/10/20 12:43:43.768]: [00003676]: lperrcode->api = 1 , lperrcode->code = 2 Error: (10/20/2014 00:43:42 PM) (Source: Brother BrLog) (EventID: 1001) (User: ) Description: WDLMW BrtWDLMW: [2014/10/20 12:43:42.258]: [00003676]: lperrcode->api = 1 , lperrcode->code = 2 Error: (10/20/2014 00:43:40 PM) (Source: Brother BrLog) (EventID: 1001) (User: ) Description: WDLMW BrtWDLMW: [2014/10/20 12:43:40.629]: [00003676]: lperrcode->api = 1 , lperrcode->code = 2 Error: (10/20/2014 00:43:38 PM) (Source: Brother BrLog) (EventID: 1001) (User: ) Description: WDLMW BrtWDLMW: [2014/10/20 12:43:38.996]: [00003676]: lperrcode->api = 1 , lperrcode->code = 2 Error: (10/18/2014 10:19:33 AM) (Source: MsiInstaller) (EventID: 11712) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Enterprise 2007 -- Fehler 1712.Mindestens eine Datei, die zum Wiederherstellen des ursprünglichen Zustands des Computers erforderlich ist, wurde nicht gefunden. Das Wiederherstellen ist nicht möglich. Error: (10/18/2014 10:19:33 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Enterprise 2007 -- Fehler 2906.Interner Fehler. (C:\Config.Msi\31cb387.rbs ) Wenden Sie sich an den Microsoft-Produktsupport. Informationen zur Kontaktaufnahme mit dem Produktsupport finden Sie hier:PSS10R.CHM. Error: (10/18/2014 10:19:33 AM) (Source: MsiInstaller) (EventID: 11712) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Enterprise 2007 -- Fehler 1712.Mindestens eine Datei, die zum Wiederherstellen des ursprünglichen Zustands des Computers erforderlich ist, wurde nicht gefunden. Das Wiederherstellen ist nicht möglich. Error: (10/18/2014 10:19:33 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Enterprise 2007 -- Fehler 2906.Interner Fehler. (C:\Config.Msi\31cb38b.rbs ) Wenden Sie sich an den Microsoft-Produktsupport. Informationen zur Kontaktaufnahme mit dem Produktsupport finden Sie hier:PSS10R.CHM. System errors: ============= Error: (10/21/2014 06:13:25 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 4.5, 4.5.1 und 4.5.2 unter Windows 7, Windows Vista und Windows Server 2008 x86 (KB2972107) Error: (10/21/2014 06:08:24 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (10/20/2014 08:22:59 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 4.5, 4.5.1 und 4.5.2 unter Windows 7, Windows Vista und Windows Server 2008 x86 (KB2972107) Error: (10/20/2014 01:38:58 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/20/2014 01:38:52 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/20/2014 01:38:47 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/20/2014 01:38:42 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/20/2014 01:38:37 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/20/2014 01:38:32 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/20/2014 01:38:26 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Microsoft Office Sessions: ========================= Error: (08/06/2014 06:12:36 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6691.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 142 seconds with 0 seconds of active time. This session ended with a crash. Error: (06/17/2014 07:16:01 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6691.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 8108 seconds with 420 seconds of active time. This session ended with a crash. Error: (05/20/2014 00:36:47 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 3124 seconds with 1560 seconds of active time. This session ended with a crash. Error: (04/09/2014 11:32:19 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6690.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 13477 seconds with 1860 seconds of active time. This session ended with a crash. Error: (03/05/2014 09:09:06 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 2378 seconds with 420 seconds of active time. This session ended with a crash. Error: (01/12/2014 01:06:57 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 8572 seconds with 5400 seconds of active time. This session ended with a crash. Error: (11/24/2013 02:46:18 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (09/17/2013 08:58:24 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6679.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 40101 seconds with 540 seconds of active time. This session ended with a crash. Error: (08/28/2013 07:05:05 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 958 seconds with 240 seconds of active time. This session ended with a crash. Error: (08/13/2013 08:25:18 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 19809 seconds with 2160 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU E7500 @ 2.93GHz Percentage of memory in use: 54% Total physical RAM: 3293.24 MB Available physical RAM: 1498.63 MB Total Pagefile: 6584.77 MB Available Pagefile: 4389.32 MB Total Virtual: 2047.88 MB Available Virtual: 1909.04 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:367.21 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 069AB8B9) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
22.10.2014, 17:28 | #4 |
/// the machine /// TB-Ausbilder | Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Hi, Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.10.2014, 08:31 | #5 |
| Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Guten Morgen, Schrauber, Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.3.3 (10.21.2014:1) OS: Windows 7 Professional x86 Ran by Kerstin on 23.10.2014 at 9:28:52,66 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] "C:\Users\Kerstin\favorites\links\startfenster.lnk" ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Kerstin\AppData\Roaming\mozilla\firefox\profiles\dk53go6k.default\minidumps [12 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 23.10.2014 at 9:30:09,67 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
23.10.2014, 20:11 | #6 |
/// the machine /// TB-Ausbilder | Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Supi dann jetzt bitte ein frisches FRST log. Noch Probleme?
__________________ --> Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? |
24.10.2014, 06:15 | #7 |
| Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Guten Morgen Schrauber, adblocker ist weg, Foxydeal ist unverändert vorhanden - siehe Screenshot. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-10-2014 Ran by Kerstin (administrator) on USER1011-PC on 24-10-2014 07:12:25 Running from C:\Users\Kerstin\Desktop Loaded Profile: Kerstin (Available profiles: Kerstin & Administrator) Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (NEC Electronics Corporation) C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (AVM Berlin) C:\Program Files\avmwlanstick\FRITZWLanMini.exe (Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Brother Industries, Ltd.) C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe (MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NUSB3MON] => C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-11-20] (NEC Electronics Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [AVMWlanClient] => C:\Program Files\avmwlanstick\FRITZWLANMini.exe [283136 2007-02-02] (AVM Berlin) HKLM\...\Run: [BrMfcWnd] => C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.) HKLM\...\Run: [ControlCenter3] => C:\Program Files\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-07] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG) HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1 HKLM\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-3467251772-538213018-3341465458-1001\...\Policies\Explorer: [TaskbarNoNotification] 1 Startup: C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKCU - {AFF5BEFB-01AB-4CF5-9CB1-6B3AF075A3F7} URL = hxxp://www.ant.com/search?s=browser&q={searchTerms} BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default FF Homepage: hxxp://google.de FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Browser Safety - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\abs@avira.com [2014-09-30] FF Extension: StumbleUpon - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\toolbar@stumbleupon.com [2014-08-24] FF Extension: AdBeaver - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\adbeaver@adbeaver.org.xpi [2014-08-12] FF Extension: Firebug - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\firebug@software.joehewitt.com.xpi [2014-07-27] FF Extension: Adblock Plus - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-24] Chrome: ======= CHR Profile: C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-27] CHR Extension: (Google Drive) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-27] CHR Extension: (YouTube) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-27] CHR Extension: (Google-Suche) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-27] CHR Extension: (Securita Scout) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfkilfadjoneaheacgmkahfgcjchkpad [2014-07-26] CHR Extension: (Google Wallet) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-27] CHR Extension: (Google Mail) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-27] CHR HKLM\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Users\Kerstin\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx [2014-07-26] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-07] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-07] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG) R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed] S2 PDFProFiltSrv; C:\Program Files\Nuance\PDF Professional 8\PDFProFiltSrv.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-17] (Avira Operations GmbH & Co. KG) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [265088 2007-01-26] (AVM GmbH) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2012-12-07] (GFI Software) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-11] (Avira GmbH) S3 catchme; \??\C:\Users\Kerstin\AppData\Local\Temp\catchme.sys [X] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-24 07:12 - 2014-10-24 07:12 - 00000000 ____D () C:\Users\Kerstin\Desktop\FRST-OlderVersion 2014-10-23 20:56 - 2014-10-23 20:56 - 00000000 ____D () C:\bfda51dcdb5f96d8566b4b3b45b1fe84 2014-10-23 20:38 - 2014-10-23 20:38 - 00240150 _____ () C:\Users\Kerstin\AppData\Local\recently-used.xbel 2014-10-23 20:03 - 2014-10-23 20:03 - 00010323 _____ () C:\Users\Kerstin\Desktop\Mappe1.xlsx 2014-10-23 09:30 - 2014-10-23 09:30 - 00000845 _____ () C:\Users\Kerstin\Desktop\JRT.txt 2014-10-23 07:57 - 2014-10-23 07:58 - 00000000 ____D () C:\3516ff93fd8457635b41f3b53d06 2014-10-22 18:44 - 2014-10-22 18:45 - 00000000 ____D () C:\12121b05af7703899953af 2014-10-22 09:09 - 2014-10-22 09:09 - 02085838 _____ () C:\Users\Kerstin\Desktop\gantry_joomla_framework-4.1.26.zip 2014-10-22 06:09 - 2014-10-22 06:10 - 00000000 ____D () C:\85837a6d42f5a0b08a0265cc93ac 2014-10-21 21:04 - 2014-10-21 21:04 - 00000000 ____D () C:\35ab9b44d4d5a9d8ffa24ab6f363 2014-10-21 19:26 - 2014-10-24 07:12 - 00006047 _____ () C:\Users\Kerstin\Desktop\FRST.txt 2014-10-21 19:26 - 2014-10-21 19:27 - 00024868 _____ () C:\Users\Kerstin\Desktop\Addition.txt 2014-10-21 19:25 - 2014-10-24 07:12 - 01103360 _____ (Farbar) C:\Users\Kerstin\Desktop\FRST.exe 2014-10-21 06:12 - 2014-10-21 06:13 - 00000000 ____D () C:\872aa2902dec1781c81b66193cdca3a3 2014-10-20 06:37 - 2014-10-20 06:38 - 00000000 ____D () C:\df4bb4adb4370d6ab0455d9fe960ecff 2014-10-18 19:04 - 2014-10-18 19:04 - 00000000 ____D () C:\6a254c2f794a30d76ef52f 2014-10-17 19:21 - 2014-10-17 19:21 - 00000000 ____D () C:\6ee1dee45d33015e79b28f5acba707 2014-10-17 10:53 - 2014-10-17 11:25 - 00056660 _____ () C:\Users\Kerstin\Desktop\test.html 2014-10-17 06:48 - 2014-10-17 06:49 - 00000000 ____D () C:\8d90e9dfbe1a709c7a4810c71d47 2014-10-16 20:54 - 2014-10-16 20:54 - 00000000 ____D () C:\a2c5b95ff2b43e344d799e 2014-10-16 06:37 - 2014-10-10 03:44 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-10-16 06:37 - 2014-10-10 03:44 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-10-16 06:37 - 2014-10-10 03:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-10-16 06:37 - 2014-09-29 02:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-16 06:36 - 2014-10-07 04:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-16 06:36 - 2014-09-26 00:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-10-16 06:36 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-10-16 06:36 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-16 06:36 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-16 06:36 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-16 06:36 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-16 06:36 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-10-16 06:36 - 2014-09-19 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-16 06:36 - 2014-09-19 03:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-10-16 06:36 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-10-16 06:36 - 2014-09-19 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-16 06:36 - 2014-09-19 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-10-16 06:36 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-10-16 06:36 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-16 06:36 - 2014-09-19 02:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-16 06:36 - 2014-09-19 02:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-16 06:36 - 2014-09-19 02:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-16 06:36 - 2014-09-19 02:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-10-16 06:36 - 2014-09-19 02:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-10-16 06:36 - 2014-09-19 02:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-10-16 06:36 - 2014-09-19 02:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-10-16 06:36 - 2014-09-19 02:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-10-16 06:36 - 2014-09-19 02:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-10-16 06:36 - 2014-09-19 02:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-16 06:36 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-16 06:36 - 2014-09-19 02:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-10-16 06:36 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-16 06:36 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-16 06:36 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-10-16 06:36 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-10-16 06:36 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-10-16 06:36 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-10-16 06:36 - 2014-07-17 03:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-10-16 06:36 - 2014-07-17 03:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-10-16 06:36 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-10-16 06:36 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-10-16 06:36 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-10-16 06:36 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-16 06:36 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-16 06:36 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-16 06:35 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-15 16:57 - 2014-10-20 12:38 - 00000000 ____D () C:\Users\Kerstin\Desktop\Neuer Ordner 2014-10-15 09:53 - 2014-10-20 08:30 - 00000000 ____D () C:\Users\Kerstin\Desktop\xmas 2014-10-15 09:53 - 2014-10-15 12:26 - 00000000 ____D () C:\Users\Kerstin\Desktop\xmasdemos 2014-10-15 08:53 - 2014-10-21 14:21 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-15 08:15 - 2014-10-15 08:15 - 02705000 _____ () C:\Users\Kerstin\Downloads\mp3tagv264setup.exe 2014-10-13 14:22 - 2014-10-13 15:57 - 00027057 _____ () C:\Users\Kerstin\Desktop\Weihnachtsansagen_Business.html 2014-10-13 07:59 - 2014-10-13 07:59 - 00000000 ____D () C:\Users\Kerstin\Desktop\Weihnachtsansagen_Business 2014-10-08 09:06 - 2014-10-08 09:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Kerstin\Downloads\revosetup95.exe 2014-10-06 09:02 - 2014-10-06 13:06 - 00000000 ____D () C:\Program Files\svnet 2014-10-06 09:02 - 2014-10-06 09:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\svnet 2014-10-06 09:02 - 2005-10-05 13:43 - 00266307 _____ (Dart Communications) C:\Windows\system32\DartWebASP.dll 2014-10-06 09:02 - 2005-09-29 15:59 - 00221184 _____ (Dart Communications) C:\Windows\system32\DartSock.dll 2014-10-06 09:02 - 2005-09-29 15:59 - 00147456 _____ (Dart Communications) C:\Windows\system32\DartWeb.dll 2014-10-06 09:02 - 2005-09-29 15:59 - 00122880 _____ (Dart Communications) C:\Windows\system32\DartWebUtil.dll 2014-10-06 09:02 - 2005-08-03 17:35 - 00507904 _____ (ComponentOne LLC) C:\Windows\system32\vsrpt8.ocx 2014-10-06 09:02 - 2005-07-22 14:03 - 00163840 _____ (Dart Communications) C:\Windows\system32\DartSecure2.dll 2014-10-06 09:02 - 2005-07-22 14:02 - 00155648 _____ (Dart Communications) C:\Windows\system32\DartCertificate.dll 2014-10-06 09:02 - 2004-09-17 13:28 - 01114112 _____ (ComponentOne LLC) C:\Windows\system32\tdbl8.ocx 2014-10-06 09:02 - 2004-08-30 18:41 - 01060864 _____ (ComponentOne LLC) C:\Windows\system32\tdbg8.ocx 2014-10-06 09:02 - 2004-07-26 17:02 - 00192512 _____ (ComponentOne) C:\Windows\system32\vsvport8.ocx 2014-10-06 09:02 - 2004-07-26 17:01 - 00417792 _____ (ComponentOne) C:\Windows\system32\vsprint8.ocx 2014-10-06 09:02 - 2004-07-26 11:51 - 00311296 _____ (ComponenetOne) C:\Windows\system32\c1sizer.ocx 2014-10-06 09:02 - 2003-11-10 17:32 - 00790528 _____ (Polar sales@polarsoftware.com www.polarsoftware.com) C:\Windows\system32\polarcrypto.dll 2014-10-06 09:02 - 2002-02-27 16:24 - 00794304 _____ (Data Dynamics) C:\Windows\system32\Actbar2.ocx 2014-10-06 09:02 - 2000-10-15 19:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\MSJINT35.DLL 2014-10-06 09:02 - 1999-09-28 22:42 - 01050896 _____ (Microsoft Corporation) C:\Windows\system32\msjet35.dll 2014-10-06 09:02 - 1999-08-25 15:57 - 00415504 _____ (Microsoft Corporation) C:\Windows\system32\msrepl35.dll 2014-10-06 09:02 - 1998-04-24 00:00 - 00368912 _____ (Microsoft Corporation) C:\Windows\system32\vbar332.dll 2014-10-06 09:02 - 1998-04-24 00:00 - 00252176 _____ (Microsoft Corporation) C:\Windows\system32\Msrd2x35.dll 2014-10-06 09:02 - 1998-04-24 00:00 - 00024848 _____ (Microsoft Corporation) C:\Windows\system32\MSJTER35.DLL 2014-10-06 08:52 - 2014-10-06 08:52 - 14086762 _____ () C:\Users\Kerstin\Downloads\Setup.exe 2014-10-05 14:05 - 2014-10-05 14:08 - 00014430 _____ () C:\Users\Kerstin\arc.html 2014-10-05 14:05 - 2014-10-05 14:05 - 00000000 ____D () C:\Users\Kerstin\arc 2014-10-05 12:05 - 2014-10-05 12:05 - 00896928 _____ () C:\Users\Kerstin\Downloads\interior_architectural_sketches_icon_vector_163293.zip 2014-10-05 12:05 - 2014-10-05 12:05 - 00000000 ____D () C:\Users\Kerstin\Downloads\interior_architectural_sketches_icon_vector_163293 2014-10-01 05:55 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-09-30 15:50 - 2014-10-14 10:41 - 00000000 ____D () C:\Users\Kerstin\Desktop\Upload 2014-09-30 08:59 - 2014-09-30 09:01 - 69187542 _____ () C:\Users\Kerstin\Desktop\videoplayback.htm 2014-09-24 17:28 - 2014-09-24 17:28 - 00001141 _____ () C:\Users\Kerstin\Desktop\idee.txt 2014-09-24 07:42 - 2014-10-14 18:53 - 00000000 ____D () C:\Users\Kerstin\Desktop\WV 2014-09-24 06:29 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-24 07:12 - 2014-03-20 17:49 - 00000000 ____D () C:\FRST 2014-10-24 07:11 - 2012-04-18 08:12 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-24 06:20 - 2009-07-14 06:34 - 00025520 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-24 06:20 - 2009-07-14 06:34 - 00025520 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-24 06:12 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-24 06:12 - 2009-07-14 06:39 - 00483056 _____ () C:\Windows\setupact.log 2014-10-23 20:57 - 2011-09-17 15:55 - 01994370 _____ () C:\Windows\WindowsUpdate.log 2014-10-23 20:39 - 2012-12-07 19:58 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\FileZilla 2014-10-23 20:38 - 2013-05-16 10:12 - 00000000 ____D () C:\Users\Kerstin\.gimp-2.8 2014-10-23 17:43 - 2012-03-01 18:45 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\CrashDumps 2014-10-21 21:08 - 2011-09-17 17:03 - 00534212 _____ () C:\Windows\PFRO.log 2014-10-21 14:18 - 2014-08-24 18:42 - 00000000 ____D () C:\Program Files\Avidemux 2.6 2014-10-21 14:00 - 2014-07-30 18:52 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-21 07:21 - 2014-03-20 17:02 - 00000000 ____D () C:\AdwCleaner 2014-10-18 10:19 - 2012-02-23 19:10 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-10-17 07:46 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-10-17 07:09 - 2009-07-14 06:33 - 00514104 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-17 07:07 - 2014-04-30 20:02 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-10-17 06:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-10-17 06:38 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-10-16 20:52 - 2013-12-13 21:01 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-16 20:49 - 2011-09-17 20:44 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-10-15 11:57 - 2013-05-21 10:00 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Mp3tag 2014-10-15 06:21 - 2014-08-05 12:51 - 00000000 ____D () C:\ProgramData\Package Cache 2014-10-15 06:21 - 2013-02-11 11:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-10-15 06:21 - 2013-02-11 11:05 - 00000000 ____D () C:\Program Files\Avira 2014-10-10 12:29 - 2012-02-24 00:17 - 00000000 ____D () C:\Users\Kerstin\Desktop\Office Interim 2014-10-10 12:28 - 2013-01-21 19:40 - 00000000 ____D () C:\Users\Kerstin\Desktop\privat 2014-10-08 09:06 - 2014-07-29 12:55 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-10-07 16:26 - 2014-08-14 07:18 - 00000000 ____D () C:\Users\Kerstin\Desktop\Demos 2014-10-07 12:30 - 2013-05-06 12:30 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-10-07 12:30 - 2013-02-11 11:05 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-10-07 12:30 - 2013-02-11 11:05 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-10-05 14:08 - 2012-02-23 19:32 - 00000000 ____D () C:\Users\Kerstin 2014-10-02 15:53 - 2012-12-07 17:53 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-09-30 07:04 - 2014-07-30 18:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-30 07:04 - 2014-07-30 18:51 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-09-24 08:11 - 2012-04-18 08:12 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-09-24 08:11 - 2012-02-13 23:15 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\Kerstin\AppData\Local\temp\avgnt.exe C:\Users\Kerstin\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-16 07:06 ==================== End Of Log ============================ LG |
24.10.2014, 09:57 | #8 |
| Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Ich korrigiere: Adblocker wieder da: chrome://adblockplus/content/ui/firstRun.html |
24.10.2014, 18:14 | #9 |
/// the machine /// TB-Ausbilder | Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter FF Extension: StumbleUpon - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\toolbar@stumbleupon.com [2014-08-24] FF Extension: AdBeaver - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\adbeaver@adbeaver.org.xpi [2014-08-12] Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.10.2014, 19:28 | #10 |
| Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Guten Abend, Schrauber, recht herzlichen Dank erneut: Alle angeratenen Schritte sind nun absolviert inkl. zurücksetzen von Firefox. Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 23-10-2014 Ran by Kerstin at 2014-10-24 20:06:22 Run:1 Running from C:\Users\Kerstin\Desktop Loaded Profile: Kerstin (Available profiles: Kerstin & Administrator) Boot Mode: Normal ============================================== Content of fixlist: ***************** FF Extension: StumbleUpon - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\toolbar@stumbleupon.com [2014-08-24] FF Extension: AdBeaver - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\adbeaver@adbeaver.org.xpi [2014-08-12] ***************** C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\toolbar@stumbleupon.com => Moved successfully. C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\dk53go6k.default\Extensions\adbeaver@adbeaver.org.xpi => Moved successfully. ==== End of Fixlog ==== sandsonne |
25.10.2014, 14:55 | #11 |
/// the machine /// TB-Ausbilder | Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Noch PRobleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.10.2014, 14:42 | #12 |
| Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Hallo, Schrauber, nein, keine Probleme mehr. Ich bedanke mich wieder aufrichtig für die Hilfe die auch diesmal kontinuierlich und professionell, freundlich und hilfreich gewesen ist. Herzlichen Dank. (Spende kommt am Montag) |
27.10.2014, 09:40 | #13 |
/// the machine /// TB-Ausbilder | Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Foxydeal - Eigenaktivitäten bislang erfolglos / adblockplus lassen oder entfernen? |
about, adresszeile, anti-malware, automatisch, einträge, entfernen, entfernung, erbeten, firefox, foxydeal entfernen, malwarebytes, nichts, online, rechner, scan, scanner, system, tab, wirklich |