|
Log-Analyse und Auswertung: ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbeiWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
14.12.2014, 12:11 | #1 |
| ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbei Hallo Trojaner-Board, ich habe auf meinem Rechner ADWARE/InstallCore.Gen7 gefunden (siehe das Avira logfile). Ausserdem hat im browser die homepage Google nicht mehr funktioniert, sondern ich wurde beim Hochstarten sofort auf andere Werbeseiten umgeleitet. Das Hochstarten geht nach einem Malwarebytes Scan und Bereinigung schon wieder (ging aber nur mit Malwarebytes Chamelion). Jetzt bin ich unsicher, was noch nicht in Ordnung ist. Mit der Bitte um Unterstützung. MartinDetune -------------------- Hier die Logfiles: defogger: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 11:27 on 14/12/2014 (Jojo) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-12-2014 Ran by Jojo (administrator) on JOJOS_LAPTOP on 14-12-2014 11:31:44 Running from C:\Users\Jojo\Desktop Loaded Profiles: UpdatusUser & Jojo & (Available profiles: UpdatusUser & Jojo & Johannes) Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (Dritek System INC.) C:\Windows\RfBtnSvc64.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Atheros) C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\AutoUpdate.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-31] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-31] (Realtek Semiconductor) HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [64640 2012-07-31] () HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2864016 2012-08-11] (ELAN Microelectronics Corp.) HKLM-x32\...\Run: [BakupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [533056 2012-07-31] (NTI Corporation) HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [LManager] => [X] HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-11-25] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2599121855-505218769-2556464541-1001\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2599121855-505218769-2556464541-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2599121855-505218769-2556464541-1002\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKU\S-1-5-21-2599121855-505218769-2556464541-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKU\S-1-5-21-2599121855-505218769-2556464541-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1193176 2012-08-25] () HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation) AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation) Startup: C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2599121855-505218769-2556464541-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKU\S-1-5-21-2599121855-505218769-2556464541-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKU\S-1-5-21-2599121855-505218769-2556464541-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKU\S-1-5-21-2599121855-505218769-2556464541-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com URLSearchHook: HKU\S-1-5-21-2599121855-505218769-2556464541-1002 - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File URLSearchHook: HKU\S-1-5-21-2599121855-505218769-2556464541-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File URLSearchHook: HKU\S-1-5-21-2599121855-505218769-2556464541-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1393518228&from=air&uid=WDCXWD5000LPVT-22G33T0_WD-WX51C32S9768S9768 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1002 -> DefaultScope {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1002 -> {0AF3CBBD-ED36-4F9E-B854-5C0B8319BF7D} URL = SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0AF3CBBD-ED36-4F9E-B854-5C0B8319BF7D} URL = SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0AF3CBBD-ED36-4F9E-B854-5C0B8319BF7D} URL = hxxp://start.iminent.com/?appId=03A332DA-9F77-42CE-91A3-D44CF13DBC73&ref=toolbox&q={searchTerms} SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0AF3CBBD-ED36-4F9E-B854-5C0B8319BF7D} URL = hxxp://start.iminent.com/?appId=03A332DA-9F77-42CE-91A3-D44CF13DBC73&ref=toolbox&q={searchTerms} SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: IEOptimizer -> {10AD2C61-0898-4348-8600-14A342F22AC3} -> C:\Program Files (x86)\SavingsBull\IEOptimizer.dll () BHO-x32: No Name -> {84FF7BD6-B47F-46F8-9130-01B2696B36CB} -> No File BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= CHR Profile: C:\Users\Jojo\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (SaveClicker) - C:\Users\Jojo\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh [2014-02-27] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2014-11-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2014-11-25] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [207488 2012-07-31] (Qualcomm Atheros Commnucations) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-01-24] (Acer Incorporated) S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [466064 2012-07-30] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [659600 2012-07-31] (Acer Incorporated) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-07-31] (NTI Corporation) R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-08-25] (Dritek System INC.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16032 2014-09-22] (Microsoft Corporation) R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe [81536 2012-07-31] (Atheros) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-23] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-23] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-12-19] (Avira Operations GmbH & Co. KG) S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-07-31] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [93400 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-14] (Malwarebytes Corporation) R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-08-25] (Dritek System Inc.) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-14 11:31 - 2014-12-14 11:31 - 00018569 _____ () C:\Users\Jojo\Desktop\FRST.txt 2014-12-14 11:31 - 2014-12-14 11:31 - 00000000 ____D () C:\FRST 2014-12-14 11:30 - 2014-12-14 11:30 - 02119168 _____ (Farbar) C:\Users\Jojo\Desktop\FRST64.exe 2014-12-14 11:27 - 2014-12-14 11:27 - 00000470 _____ () C:\Users\Jojo\Desktop\defogger_disable.log 2014-12-14 11:27 - 2014-12-14 11:27 - 00000000 _____ () C:\Users\Jojo\defogger_reenable 2014-12-14 11:26 - 2014-12-14 11:26 - 00050477 _____ () C:\Users\Jojo\Desktop\Defogger.exe 2014-12-14 10:33 - 2014-12-14 11:13 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-12-14 10:33 - 2014-12-14 10:33 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-12-14 10:33 - 2014-12-14 10:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-12-14 10:33 - 2014-12-14 10:33 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-12-14 10:33 - 2014-12-14 10:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-12-14 10:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-12-14 10:33 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-12-14 10:28 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-12-14 10:27 - 2014-12-14 10:27 - 00000000 ____D () C:\Users\Jojo\Downloads\mbam-chameleon-3.1.7.0 2014-12-14 10:25 - 2014-12-14 10:20 - 04909382 _____ () C:\Users\Jojo\Downloads\mbam-chameleon-3.1.7.0.zip 2014-12-12 18:40 - 2014-12-12 18:40 - 00001141 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-11-28 20:43 - 2014-11-19 08:29 - 00582552 _____ (Microsoft Corporation) C:\Windows\system32\AutoUpdate.exe 2014-11-28 20:43 - 2014-11-19 08:29 - 00462760 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe 2014-11-28 20:27 - 2014-11-20 21:56 - 00713672 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-11-28 20:27 - 2014-11-20 21:56 - 00106440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-11-28 20:26 - 2014-11-28 20:26 - 00355840 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-24 22:44 - 2014-10-11 08:45 - 10115072 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-11-24 22:44 - 2014-10-11 08:44 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-11-24 22:44 - 2014-10-11 08:44 - 00393216 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-11-24 22:44 - 2014-10-11 08:43 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-11-24 22:44 - 2014-10-11 06:58 - 08858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-11-24 22:44 - 2014-10-11 06:57 - 02416640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-11-24 22:44 - 2014-10-11 06:57 - 00295424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-11-24 22:44 - 2014-10-11 06:56 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-11-24 22:44 - 2014-09-22 06:53 - 00035320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2014-11-24 22:44 - 2014-08-26 23:08 - 00270024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2014-11-24 22:17 - 2014-11-26 00:05 - 01183446 _____ () C:\Users\Johannes\Documents\Statistiken und Diagramme auswerten pp.pptx 2014-11-24 18:44 - 2014-10-18 09:44 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-24 18:44 - 2014-10-18 08:05 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-11-24 18:44 - 2014-10-11 08:44 - 03248640 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-11-24 18:44 - 2014-10-11 06:41 - 00713728 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-24 18:44 - 2014-10-11 06:41 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-24 18:44 - 2014-10-11 06:05 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2014-11-24 18:44 - 2014-10-11 06:04 - 00713728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-11-24 18:44 - 2014-10-03 02:21 - 00522728 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-24 18:44 - 2014-10-02 23:29 - 00783872 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-24 18:44 - 2014-10-02 23:29 - 00267264 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-24 18:44 - 2014-10-02 23:29 - 00169472 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll 2014-11-24 18:44 - 2014-10-02 00:05 - 04068864 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-24 18:44 - 2014-09-25 00:29 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-11-24 18:44 - 2014-09-25 00:29 - 00072192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll 2014-11-24 18:44 - 2014-09-25 00:01 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-24 18:44 - 2014-09-25 00:01 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll 2014-11-24 18:44 - 2014-09-13 07:24 - 02233152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-11-24 18:44 - 2014-09-06 01:46 - 00389176 _____ () C:\Windows\system32\ApnDatabase.xml 2014-11-24 18:44 - 2014-09-03 03:48 - 00457728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2014-11-24 18:44 - 2014-09-03 03:48 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2014-11-24 18:44 - 2014-09-03 03:22 - 00188928 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2014-11-24 18:44 - 2014-09-03 03:21 - 00623104 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2014-11-24 18:44 - 2014-09-03 03:21 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2014-11-24 18:44 - 2014-08-29 05:17 - 02043392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2014-11-24 18:44 - 2014-08-29 05:17 - 00227328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2014-11-24 18:44 - 2014-08-29 05:04 - 02837504 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-11-24 18:44 - 2014-08-29 05:04 - 00309248 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-11-24 18:44 - 2014-08-28 07:04 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSCOMEX.dll 2014-11-24 18:44 - 2014-08-28 07:04 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSAPI.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00616448 _____ (Microsoft Corporation) C:\Windows\system32\FXSAPI.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOMEX.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00432640 _____ (Microsoft Corporation) C:\Windows\system32\FXSTIFF.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\FXST30.dll 2014-11-24 18:44 - 2014-07-24 14:12 - 00328512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-11-24 18:43 - 2014-11-08 12:22 - 00238080 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-24 18:43 - 2014-11-08 12:21 - 00827904 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-24 18:43 - 2014-11-08 07:57 - 00187904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2014-11-24 18:43 - 2014-11-08 07:56 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-11-24 18:43 - 2014-10-26 02:56 - 02237952 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-11-24 18:43 - 2014-10-26 02:56 - 01409536 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-11-24 18:43 - 2014-10-26 02:56 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-11-24 18:43 - 2014-10-26 02:56 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-11-24 18:43 - 2014-10-26 02:56 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-11-24 18:43 - 2014-10-26 02:55 - 19284480 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-11-24 18:43 - 2014-10-26 02:55 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-11-24 18:43 - 2014-10-26 02:55 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-11-24 18:43 - 2014-10-26 02:55 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-11-24 18:43 - 2014-10-26 02:53 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-11-24 18:43 - 2014-10-26 01:36 - 01762816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 01181696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 13758464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-11-24 18:43 - 2014-10-26 01:34 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-11-24 18:43 - 2014-10-26 01:19 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-11-24 18:43 - 2014-10-26 01:13 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-11-24 18:43 - 2014-10-25 22:48 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-11-24 18:43 - 2014-10-23 13:47 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-24 18:43 - 2014-10-23 12:04 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-11-24 18:43 - 2014-10-11 09:35 - 00171840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-24 18:43 - 2014-10-11 08:44 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2014-11-24 18:43 - 2014-10-11 08:43 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-24 18:43 - 2014-10-11 06:57 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2014-11-24 18:43 - 2014-08-22 00:56 - 01418752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-11-24 18:43 - 2014-08-22 00:27 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-14 11:27 - 2013-01-15 21:36 - 00000000 ____D () C:\Users\Jojo 2014-12-14 11:11 - 2013-01-15 21:36 - 01881876 _____ () C:\Windows\WindowsUpdate.log 2014-12-14 11:08 - 2012-08-25 16:05 - 00000868 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-12-14 11:07 - 2012-08-25 16:43 - 00000000 ____D () C:\ProgramData\Norton 2014-12-14 11:07 - 2012-08-07 02:17 - 00053284 _____ () C:\Windows\system32\wpbbin.exe 2014-12-14 11:07 - 2012-08-03 18:14 - 00188154 _____ () C:\Windows\PFRO.log 2014-12-14 11:07 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-14 11:07 - 2012-07-26 06:26 - 00524288 ___SH () C:\Windows\system32\config\BBI 2014-12-14 11:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru 2014-12-14 10:28 - 2012-08-26 01:32 - 00753134 _____ () C:\Windows\system32\perfh007.dat 2014-12-14 10:28 - 2012-08-26 01:32 - 00155826 _____ () C:\Windows\system32\perfc007.dat 2014-12-14 10:28 - 2012-07-26 08:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-12 21:19 - 2014-02-27 17:44 - 00000000 ____D () C:\Program Files (x86)\SavingsBull 2014-12-12 18:40 - 2014-09-30 22:35 - 00000000 ____D () C:\ProgramData\Package Cache 2014-12-12 18:40 - 2013-06-11 21:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-12-12 18:40 - 2013-06-11 21:04 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ___RD () C:\Windows\ToastData 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Windows Defender 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-12-03 19:55 - 2013-03-17 20:04 - 00000000 ____D () C:\Users\Johannes\AppData\Local\CrashDumps 2014-12-03 19:52 - 2013-01-17 21:36 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-12-03 19:46 - 2013-01-19 20:58 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2599121855-505218769-2556464541-1003 2014-11-30 11:56 - 2012-07-26 08:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-11-28 20:23 - 2013-09-10 11:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-28 20:20 - 2013-01-22 20:47 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-24 22:45 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-11-24 18:57 - 2013-01-29 21:47 - 00000000 ____D () C:\ProgramData\Microsoft Help Some content of TEMP: ==================== C:\Users\Johannes\AppData\Local\Temp\avgnt.exe C:\Users\Jojo\AppData\Local\Temp\avgnt.exe C:\Users\Jojo\AppData\Local\Temp\ose00000.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-12 18:45 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-12-2014 Ran by Jojo at 2014-12-14 11:32:55 Running from C:\Users\Jojo\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) clear.fi SDK - Video 2 (x32 Version: 2.1.2308 - CyberLink Corp.) Hidden clear.fi SDK- Movie 2 (x32 Version: 2.1.2112 - CyberLink Corp.) Hidden Acer Backup Manager (HKLM-x32\...\InstallShield_{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}) (Version: 4.0.0.0053 - NTI Corporation) Acer Device Fast-lane (HKLM\...\{3F62D2FD-13C1-49A2-8B5D-47623D9460D7}) (Version: 1.00.3003 - Acer Incorporated) Acer Instant Update Service (HKLM\...\{B492663B-604B-4C9D-84A4-B17279167D4C}) (Version: 1.00.3012 - Acer Incorporated) Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.3003 - Acer Incorporated) Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3006 - Acer Incorporated) AcerCloud Docs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.00.3103 - Acer Incorporated) AcerCloud Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.02.2018 - Acer Incorporated) Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden Avira (HKLM-x32\...\{e7c7c227-b742-4878-9425-f09bbf9951db}) (Version: 1.1.27.25527 - Avira Operations & Co. KG) Avira (x32 Version: 1.1.27.25527 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.342 - Avira) Backup Manager v4 (x32 Version: 4.0.0.0053 - NTI Corporation) Hidden Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden clear.fi Media (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.02.2009 - Acer Incorporated) clear.fi Photo (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.01.3107 - Acer Incorporated) CyberLink MediaEspresso 6.5 (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.3103_44819 - CyberLink Corp.) Delicious: Emily's True Love Premium Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.8000.13 - Dolby Laboratories Inc) ETDWare PS/2-X64 11.6.4.001_WHQL (HKLM\...\Elantech) (Version: 11.6.4.001 - ELAN Microelectronic Corp.) Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.3002 - Acer Incorporated) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36354 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2828 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.0.1207 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden Launch Manager (HKLM-x32\...\LManager) (Version: 7.0.4 - Acer Inc.) Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.3002 - Acer Incorporated) Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation) Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MyWinLocker (Version: 4.0.14.35 - Egis Technology Inc.) Hidden MyWinLocker 4 (x32 Version: 4.0.14.35 - Egis Technology Inc.) Hidden MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.24 - Egis Technology Inc.) MyWinLocker Suite (x32 Version: 4.0.14.24 - Egis Technology Inc.) Hidden NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9008 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.9008 - NTI Corporation) Hidden NVIDIA Grafiktreiber 306.97 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.97 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.12.0613 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0613 - NVIDIA Corporation) NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation) Office Addin (HKLM-x32\...\{6D2BBE1D-E600-4695-BA37-0B0E605542CC}) (Version: 2.02.2008 - Acer) Office Addin 2003 (HKLM-x32\...\{1FCC073B-CC01-4443-AD20-E559F66E6E83}) (Version: 2.02.2008 - Acer) Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.204 - Ihr Firmenname) Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 11.05 - Qualcomm Atheros) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6690 - Realtek Semiconductor Corp.) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.8400.27023 - Realtek Semiconductor Corp.) SavingsBull (x32 Version: 1.0.0.0 - SavingsBull) Hidden <==== ATTENTION Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden Spotify (HKLM-x32\...\Spotify) (Version: 0.8.4.99.ga249b5f1 - Spotify AB) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.0.12 - Safer-Networking Ltd.) Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent) WildTangent Games App (x32 Version: 4.0.9.3 - WildTangent) Hidden Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 12-12-2014 22:03:18 Removed Norton Online Backup ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0B421432-A178-492F-8C4A-C2A115DA7CC6} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2012-07-11] (Egis Technology Inc.) Task: {2647C1A0-EF39-4F95-AC5B-C13E62CD9F0F} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2012-07-04] (CyberLink) Task: {5CC751CD-1F98-4DD7-8EC3-F5BB98BB2CD3} - System32\Tasks\iuEmailOutlookAgent => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe [2012-07-12] () Task: {5DC2E92A-C462-44B7-B15B-9002F34CF28F} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-04-16] (Intel Corporation) Task: {65F6918D-BA30-4CAB-A91A-3021EBB2F4B1} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-11-28] (Microsoft Corporation) Task: {6E665BE5-6135-4EE0-9495-43075DA5F0F7} - System32\Tasks\iuBrowserIEAgent => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe [2012-07-12] () Task: {6ECC70C2-BAA3-407A-9BE0-F2AD92FA06E1} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2012-06-22] () Task: {7B64B9C5-FEC7-49ED-B563-46206BDF5507} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {7F9A2D2A-E5F9-45B9-B07E-AFA465D2939D} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2012-07-13] () Task: {8E0A7A59-70EC-4874-A4EE-7349B312DB9D} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2012-07-30] (Acer Incorporated) Task: {9E5895B8-B7D0-4B21-9E70-4FD53089F55A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {B7195B0C-0A69-42EF-B1E9-DE934FE6C971} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [2012-07-31] (Acer Incorporated) Task: {C5E92218-31F7-4989-BCDA-F7F7211CBA77} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2012-07-11] (Egis Technology Inc.) Task: {DDDEE71A-8CAD-4E73-964D-EF7A697DB6B2} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {E6FED566-59F1-413C-9036-5CBC9FF9A4D3} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-04-16] (Intel Corporation) Task: {F13BB25A-2948-4CA4-B812-8CDF656A59E2} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============= 2012-04-16 13:45 - 2012-04-16 13:45 - 00119808 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe 2012-08-26 01:18 - 2012-08-08 07:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-07-31 16:45 - 2012-07-31 16:45 - 00384128 _____ () c:\Program Files (x86)\Bluetooth Suite\ContactsApi.dll 2012-07-31 16:40 - 2012-07-31 16:40 - 00020992 _____ () c:\Program Files (x86)\Bluetooth Suite\L10n\de-DE\BtTray.de-DE.dll 2012-07-12 15:01 - 2012-07-12 15:01 - 00025232 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe 2012-07-12 15:01 - 2012-07-12 15:01 - 00044176 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe 2012-07-31 00:04 - 2012-07-31 00:04 - 00465384 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll 2012-07-31 00:04 - 2012-07-31 00:04 - 00125504 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll 2012-07-31 00:04 - 2012-07-31 00:04 - 00155712 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\VolumeSnapshot.dll 2012-07-31 00:04 - 2012-07-31 00:04 - 00118336 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\Online.dll 2012-07-31 00:04 - 2012-07-31 00:04 - 01081408 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll 2012-07-31 00:04 - 2012-07-31 00:04 - 00052288 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\OsSettingPort.dll 2012-07-31 00:04 - 2012-07-31 00:04 - 00727616 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\OutlookShadow.dll 2013-01-17 21:36 - 2012-11-13 14:06 - 00108960 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-01-17 21:36 - 2012-11-13 14:06 - 00158624 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-01-17 21:36 - 2012-11-13 14:06 - 00416160 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-01-17 21:36 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-01-17 21:36 - 2012-11-13 14:06 - 00528288 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl 2011-08-15 19:12 - 2011-08-15 19:12 - 02603520 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll 2012-04-16 10:42 - 2012-04-16 10:42 - 00015872 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll 2011-08-15 19:12 - 2011-08-15 19:12 - 01006592 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll 2011-08-15 19:15 - 2011-08-15 19:15 - 00382464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll 2011-08-17 15:41 - 2011-08-17 15:41 - 00400384 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll 2011-08-17 15:48 - 2011-08-17 15:48 - 00322048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll 2011-08-17 15:48 - 2011-08-17 15:48 - 00195584 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll 2011-08-15 18:23 - 2011-08-15 18:23 - 00062464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll 2012-04-16 10:41 - 2012-04-16 10:41 - 00484864 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll 2012-04-16 10:56 - 2012-04-16 10:56 - 00500032 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll 2012-04-16 10:38 - 2012-04-16 10:38 - 00013824 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll 2011-07-19 15:05 - 2011-07-19 15:05 - 14978048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtWebKit4.dll 2011-08-15 19:17 - 2011-08-15 19:17 - 09224704 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtGui4.dll 2011-07-19 15:04 - 2011-07-19 15:04 - 00317952 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\phonon4.dll 2013-01-17 21:36 - 2012-11-13 14:06 - 00554400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl 2012-08-25 16:04 - 2012-06-25 09:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run32: => "Dolby Advanced Audio v2" ========================= Accounts: ========================== Administrator (S-1-5-21-2599121855-505218769-2556464541-500 - Administrator - Disabled) Gast (S-1-5-21-2599121855-505218769-2556464541-501 - Limited - Disabled) Johannes (S-1-5-21-2599121855-505218769-2556464541-1003 - Limited - Enabled) => C:\Users\Johannes Jojo (S-1-5-21-2599121855-505218769-2556464541-1002 - Administrator - Enabled) => C:\Users\Jojo UpdatusUser (S-1-5-21-2599121855-505218769-2556464541-1001 - Limited - Enabled) => C:\Users\UpdatusUser ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Bluetooth USB Module Description: Bluetooth USB Module Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Qualcomm Atheros Communications Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (12/14/2014 11:21:15 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 13c Startzeit: 01d017878bfd582a Endzeit: 4294967295 Anwendungspfad: C:\Windows\system32\wwahost.exe Berichts-ID: da3b94a7-837a-11e4-bea1-206a8ad599b6 Vollständiger Name des fehlerhaften Pakets: Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AppexFinance Error: (12/14/2014 11:20:39 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Jojos_Laptop) Description: Das Paket „Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe“ wurde beendet, da das Anhalten zu lange dauerte. Error: (12/12/2014 09:20:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Jojos_Laptop) Description: Bei der Aktivierung der App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (12/12/2014 09:20:57 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: b40 Startzeit: 01d016491641550d Endzeit: 4294967295 Anwendungspfad: C:\Windows\system32\wwahost.exe Berichts-ID: 5e100273-823c-11e4-be9f-206a8ad599b6 Vollständiger Name des fehlerhaften Pakets: microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Microsoft.WindowsLive.ModernPhotos Error: (12/12/2014 09:20:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: Jojos_Laptop) Description: Die App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error: (12/12/2014 07:01:46 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. Error: (12/12/2014 07:01:46 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. Error: (12/12/2014 07:01:46 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. Error: (12/12/2014 06:54:31 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. Error: (12/12/2014 06:54:31 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. System errors: ============= Error: (12/12/2014 10:01:20 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 70. Der Windows-SChannel-Fehlerstatus lautet: 105. Error: (12/12/2014 08:22:36 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 70. Der Windows-SChannel-Fehlerstatus lautet: 105. Error: (12/12/2014 08:05:53 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 70. Der Windows-SChannel-Fehlerstatus lautet: 105. Error: (12/12/2014 06:38:08 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde nicht richtig gestartet. Error: (12/03/2014 07:41:22 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Computer Backup (MyPC Backup)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/28/2014 08:23:00 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8007045b fehlgeschlagen: Update für Windows 8 für x64-Systeme (KB3003663) Error: (11/28/2014 08:23:00 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8007045b fehlgeschlagen: Update für Windows 8 für x64-Systeme (KB2976536) Error: (11/28/2014 08:23:00 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8007045b fehlgeschlagen: Update für Windows 8 für x64-Systeme (KB3008627) Error: (11/24/2014 10:49:06 PM) (Source: DCOM) (EventID: 10010) (User: Jojos_Laptop) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (11/24/2014 10:49:06 PM) (Source: DCOM) (EventID: 10010) (User: Jojos_Laptop) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Microsoft Office Sessions: ========================= Error: (12/14/2014 11:21:15 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.2.9200.1642013c01d017878bfd582a4294967295C:\Windows\system32\wwahost.exeda3b94a7-837a-11e4-bea1-206a8ad599b6Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbweAppexFinance Error: (12/14/2014 11:20:39 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Jojos_Laptop) Description: Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe Error: (12/12/2014 09:20:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Jojos_Laptop) Description: microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos-2144927142 Error: (12/12/2014 09:20:57 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.2.9200.16420b4001d016491641550d4294967295C:\Windows\system32\wwahost.exe5e100273-823c-11e4-be9f-206a8ad599b6microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbweMicrosoft.WindowsLive.ModernPhotos Error: (12/12/2014 09:20:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: Jojos_Laptop) Description: microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos Error: (12/12/2014 07:01:46 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.Manifest4 Error: (12/12/2014 07:01:46 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.Manifest4 Error: (12/12/2014 07:01:46 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\ExcelAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\ExcelAddIn2003.dll.Manifest4 Error: (12/12/2014 06:54:31 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.Manifest4 Error: (12/12/2014 06:54:31 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.Manifest4 ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz Percentage of memory in use: 49% Total physical RAM: 3891.59 MB Available physical RAM: 1950.18 MB Total Pagefile: 7475.59 MB Available Pagefile: 5156.51 MB Total Virtual: 8192 MB Available Virtual: 8191.78 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:452.25 GB) (Free:396.08 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: E74F9A2E) Partition: GPT Partition Type. ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-12-14 11:47:32 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000033 WDC_WD5000LPVT-22G33T0 rev.01.01A01 465,76GB Running: Gmer-19357.exe; Driver: C:\Users\Jojo\AppData\Local\Temp\fwdcrpow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\dwm.exe[952] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\dwm.exe[952] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\dwm.exe[952] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1304] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1304] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1304] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\nvvsvc.exe[1320] C:\Windows\system32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\nvvsvc.exe[1320] C:\Windows\system32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\nvvsvc.exe[1320] C:\Windows\system32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\nvvsvc.exe[1320] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f8b788177a 4 bytes [88, B7, F8, 07] .text C:\Windows\system32\nvvsvc.exe[1320] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f8b7881782 4 bytes [88, B7, F8, 07] .text C:\Windows\system32\taskhostex.exe[3160] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\taskhostex.exe[3160] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\taskhostex.exe[3160] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Windows\Explorer.EXE[3316] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\Explorer.EXE[3316] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\Explorer.EXE[3316] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3580] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3580] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3580] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\igfxext.exe[3620] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\igfxext.exe[3620] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\igfxext.exe[3620] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3912] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3912] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3912] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Windows\System32\igfxtray.exe[4236] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\System32\igfxtray.exe[4236] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\System32\igfxtray.exe[4236] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Windows\System32\hkcmd.exe[4288] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\System32\hkcmd.exe[4288] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\System32\hkcmd.exe[4288] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Windows\System32\igfxpers.exe[4320] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f8b788177a 4 bytes [88, B7, F8, 07] .text C:\Windows\System32\igfxpers.exe[4320] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f8b7881782 4 bytes [88, B7, F8, 07] .text C:\Windows\System32\igfxpers.exe[4320] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\System32\igfxpers.exe[4320] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\System32\igfxpers.exe[4320] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4352] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4352] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4352] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4408] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4408] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4408] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text c:\Program Files (x86)\Bluetooth Suite\BtTray.exe[4496] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text c:\Program Files (x86)\Bluetooth Suite\BtTray.exe[4496] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text c:\Program Files (x86)\Bluetooth Suite\BtTray.exe[4496] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text c:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4508] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text c:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4508] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text c:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4508] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text c:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4508] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007f8a9a61b32 4 bytes [A6, A9, F8, 07] .text c:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4508] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007f8a9a61b3a 4 bytes [A6, A9, F8, 07] .text C:\Program Files\Elantech\ETDCtrl.exe[4528] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Elantech\ETDCtrl.exe[4528] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Elantech\ETDCtrl.exe[4528] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4832] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4832] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4832] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[4612] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f8b788177a 4 bytes [88, B7, F8, 07] .text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[4612] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f8b7881782 4 bytes [88, B7, F8, 07] .text C:\Windows\system32\igfxsrvc.exe[5048] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\igfxsrvc.exe[5048] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\igfxsrvc.exe[5048] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\wbem\unsecapp.exe[3172] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\wbem\unsecapp.exe[3172] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Windows\system32\wbem\unsecapp.exe[3172] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe[4672] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8b2f11532 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe[4672] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8b2f1153a 4 bytes [F1, B2, F8, 07] .text C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe[4672] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8b2f1165a 4 bytes [F1, B2, F8, 07] ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [580:604] fffff960008a85e8 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 14.12.2014 Scan Time: 10:36:18 Logfile: 141214_malwarebytes_log.txt Administrator: Yes Version: 2.00.4.1028 Malware Database: v2014.12.14.03 Rootkit Database: v2014.12.08.03 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Enabled OS: Windows 8 CPU: x64 File System: NTFS User: Jojo Scan Type: Threat Scan Result: Completed Objects Scanned: 422962 Time Elapsed: 26 min, 16 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end) Code:
ATTFilter Avira Free Antivirus Erstellungsdatum der Reportdatei: Freitag, 12. Dezember 2014 23:51 Das Programm läuft als uneingeschränkte Vollversion. Online-Dienste stehen zur Verfügung. Lizenznehmer : Avira Antivirus Free Seriennummer : 0000149996-AVHOE-0000001 Plattform : Windows 8 Windowsversion : (plain) [6.2.9200] Boot Modus : Normal gebootet Benutzername : SYSTEM Computername : JOJOS_LAPTOP Versionsinformationen: BUILD.DAT : 14.0.7.342 92013 Bytes 23.10.2014 14:02:00 AVSCAN.EXE : 14.0.7.312 1015544 Bytes 25.11.2014 19:57:52 AVSCANRC.DLL : 14.0.7.308 64304 Bytes 25.11.2014 19:57:52 LUKE.DLL : 14.0.7.310 60664 Bytes 25.11.2014 19:59:06 AVSCPLR.DLL : 14.0.7.310 93488 Bytes 25.11.2014 19:57:53 REPAIR.DLL : 14.0.7.312 366328 Bytes 25.11.2014 19:57:47 REPAIR.RDF : 1.0.2.30 596694 Bytes 25.10.2014 10:27:57 AVREG.DLL : 14.0.7.310 264952 Bytes 25.11.2014 19:57:46 AVLODE.DLL : 14.0.7.312 563448 Bytes 25.11.2014 19:57:43 AVLODE.RDF : 14.0.4.54 78895 Bytes 12.12.2014 17:02:51 XBV00013.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:46 XBV00014.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:46 XBV00015.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:46 XBV00016.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:46 XBV00017.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:46 XBV00018.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:46 XBV00019.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:47 XBV00020.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:47 XBV00021.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:47 XBV00022.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:47 XBV00023.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:47 XBV00024.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:47 XBV00025.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:47 XBV00026.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:47 XBV00027.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:48 XBV00028.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:48 XBV00029.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:48 XBV00030.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:48 XBV00031.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:48 XBV00032.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:48 XBV00033.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:48 XBV00034.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:49 XBV00035.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:49 XBV00036.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:49 XBV00037.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:49 XBV00038.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:49 XBV00039.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:49 XBV00040.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:49 XBV00041.VDF : 8.11.165.190 2048 Bytes 07.08.2014 21:12:50 XBV00117.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:06 XBV00118.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:07 XBV00119.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:07 XBV00120.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:07 XBV00121.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:07 XBV00122.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:07 XBV00123.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:07 XBV00124.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:07 XBV00125.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:08 XBV00126.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:08 XBV00127.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:08 XBV00128.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:08 XBV00129.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:09 XBV00130.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:09 XBV00131.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:10 XBV00132.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:10 XBV00133.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:10 XBV00134.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:10 XBV00135.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:10 XBV00136.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:10 XBV00137.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00138.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00139.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00140.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00141.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00142.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00143.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00144.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00145.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00146.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00147.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00148.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00149.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:11 XBV00150.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00151.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00152.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00153.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00154.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00155.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00156.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00157.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00158.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00159.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00160.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00161.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00162.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00163.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:12 XBV00164.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00165.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00166.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00167.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00168.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00169.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00170.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00171.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00172.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00173.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00174.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00175.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00176.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:13 XBV00177.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:14 XBV00178.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:14 XBV00179.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:14 XBV00180.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:14 XBV00181.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:14 XBV00182.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:14 XBV00183.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:14 XBV00184.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:14 XBV00185.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:14 XBV00186.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:15 XBV00187.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:15 XBV00188.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:15 XBV00189.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:15 XBV00190.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:15 XBV00191.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:15 XBV00192.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:15 XBV00193.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:15 XBV00194.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:16 XBV00195.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:16 XBV00196.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:16 XBV00197.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:16 XBV00198.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:16 XBV00199.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:16 XBV00200.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:17 XBV00201.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:17 XBV00202.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:17 XBV00203.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:18 XBV00204.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:18 XBV00205.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:19 XBV00206.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:19 XBV00207.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:19 XBV00208.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:19 XBV00209.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:19 XBV00210.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:19 XBV00211.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:19 XBV00212.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:19 XBV00213.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:19 XBV00214.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:19 XBV00215.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00216.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00217.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00218.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00219.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00220.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00221.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00222.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00223.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00224.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00225.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00226.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00227.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:20 XBV00228.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00229.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00230.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00231.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00232.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00233.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00234.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00235.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00236.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00237.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00238.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00239.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00240.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00241.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:21 XBV00242.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:22 XBV00243.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:22 XBV00244.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:22 XBV00245.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:22 XBV00246.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:22 XBV00247.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:22 XBV00248.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:22 XBV00249.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:22 XBV00250.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:22 XBV00251.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:23 XBV00252.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:23 XBV00253.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:23 XBV00254.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:23 XBV00255.VDF : 8.11.190.32 2048 Bytes 03.12.2014 18:48:23 XBV00000.VDF : 7.11.70.0 66736640 Bytes 04.04.2013 09:00:13 XBV00001.VDF : 7.11.74.226 2201600 Bytes 30.04.2013 20:05:00 XBV00002.VDF : 7.11.80.60 2751488 Bytes 28.05.2013 20:05:20 XBV00003.VDF : 7.11.85.214 2162688 Bytes 21.06.2013 10:09:39 XBV00004.VDF : 7.11.91.176 3903488 Bytes 23.07.2013 18:49:21 XBV00005.VDF : 7.11.98.186 6822912 Bytes 29.08.2013 10:34:36 XBV00006.VDF : 7.11.139.38 15708672 Bytes 27.03.2014 13:52:53 XBV00007.VDF : 7.11.152.100 4193792 Bytes 02.06.2014 13:59:42 XBV00008.VDF : 8.11.165.192 4251136 Bytes 07.08.2014 21:12:33 XBV00009.VDF : 8.11.172.30 2094080 Bytes 15.09.2014 21:12:44 XBV00010.VDF : 8.11.178.32 1581056 Bytes 14.10.2014 21:35:52 XBV00011.VDF : 8.11.184.50 2178560 Bytes 11.11.2014 19:59:36 XBV00012.VDF : 8.11.190.32 1876992 Bytes 03.12.2014 18:47:57 XBV00042.VDF : 8.11.190.56 35840 Bytes 03.12.2014 18:47:57 XBV00043.VDF : 8.11.192.58 2048 Bytes 03.12.2014 18:47:57 XBV00044.VDF : 8.11.192.86 18944 Bytes 03.12.2014 17:02:52 XBV00045.VDF : 8.11.192.110 7680 Bytes 03.12.2014 17:02:52 XBV00046.VDF : 8.11.192.134 5120 Bytes 03.12.2014 17:02:52 XBV00047.VDF : 8.11.192.138 9216 Bytes 03.12.2014 17:02:52 XBV00048.VDF : 8.11.192.140 4608 Bytes 04.12.2014 17:02:52 XBV00049.VDF : 8.11.192.144 8192 Bytes 04.12.2014 17:02:53 XBV00050.VDF : 8.11.192.146 20480 Bytes 04.12.2014 17:02:53 XBV00051.VDF : 8.11.192.148 19456 Bytes 04.12.2014 17:02:53 XBV00052.VDF : 8.11.192.152 12800 Bytes 04.12.2014 17:02:53 XBV00053.VDF : 8.11.192.154 5120 Bytes 04.12.2014 17:02:53 XBV00054.VDF : 8.11.192.158 2048 Bytes 04.12.2014 17:02:53 XBV00055.VDF : 8.11.192.160 2048 Bytes 04.12.2014 17:02:53 XBV00056.VDF : 8.11.192.162 2048 Bytes 04.12.2014 17:02:53 XBV00057.VDF : 8.11.192.166 8192 Bytes 04.12.2014 17:02:54 XBV00058.VDF : 8.11.192.168 6144 Bytes 05.12.2014 17:02:54 XBV00059.VDF : 8.11.192.172 6144 Bytes 05.12.2014 17:02:54 XBV00060.VDF : 8.11.192.236 24064 Bytes 05.12.2014 17:02:54 XBV00061.VDF : 8.11.192.238 2048 Bytes 05.12.2014 17:02:54 XBV00062.VDF : 8.11.193.22 11776 Bytes 05.12.2014 17:02:54 XBV00063.VDF : 8.11.193.42 29696 Bytes 06.12.2014 17:02:54 XBV00064.VDF : 8.11.193.66 41472 Bytes 06.12.2014 17:02:55 XBV00065.VDF : 8.11.193.68 2048 Bytes 06.12.2014 17:02:55 XBV00066.VDF : 8.11.193.70 37888 Bytes 07.12.2014 17:02:56 XBV00067.VDF : 8.11.193.76 13824 Bytes 07.12.2014 17:02:56 XBV00068.VDF : 8.11.193.78 31744 Bytes 08.12.2014 17:02:56 XBV00069.VDF : 8.11.193.98 2048 Bytes 08.12.2014 17:02:56 XBV00070.VDF : 8.11.193.118 7680 Bytes 08.12.2014 17:02:57 XBV00071.VDF : 8.11.193.138 3584 Bytes 08.12.2014 17:02:57 XBV00072.VDF : 8.11.193.158 24064 Bytes 08.12.2014 17:02:57 XBV00073.VDF : 8.11.193.160 2048 Bytes 08.12.2014 17:02:57 XBV00074.VDF : 8.11.193.162 2048 Bytes 08.12.2014 17:02:57 XBV00075.VDF : 8.11.193.168 2560 Bytes 08.12.2014 17:02:57 XBV00076.VDF : 8.11.193.170 2048 Bytes 08.12.2014 17:02:58 XBV00077.VDF : 8.11.193.172 2048 Bytes 08.12.2014 17:02:58 XBV00078.VDF : 8.11.193.174 31232 Bytes 08.12.2014 17:02:58 XBV00079.VDF : 8.11.193.176 2048 Bytes 08.12.2014 17:02:58 XBV00080.VDF : 8.11.193.180 14336 Bytes 09.12.2014 17:02:58 XBV00081.VDF : 8.11.193.184 8192 Bytes 09.12.2014 17:02:59 XBV00082.VDF : 8.11.193.188 10240 Bytes 09.12.2014 17:02:59 XBV00083.VDF : 8.11.193.190 4096 Bytes 09.12.2014 17:02:59 XBV00084.VDF : 8.11.193.192 5120 Bytes 09.12.2014 17:02:59 XBV00085.VDF : 8.11.193.194 7680 Bytes 09.12.2014 17:02:59 XBV00086.VDF : 8.11.193.196 9216 Bytes 09.12.2014 17:02:59 XBV00087.VDF : 8.11.193.198 2048 Bytes 09.12.2014 17:02:59 XBV00088.VDF : 8.11.193.202 25088 Bytes 09.12.2014 17:03:00 XBV00089.VDF : 8.11.193.208 63488 Bytes 09.12.2014 17:03:00 XBV00090.VDF : 8.11.193.210 2048 Bytes 09.12.2014 17:03:01 XBV00091.VDF : 8.11.193.212 82432 Bytes 09.12.2014 17:03:01 XBV00092.VDF : 8.11.193.214 2048 Bytes 09.12.2014 17:03:01 XBV00093.VDF : 8.11.193.236 93696 Bytes 10.12.2014 17:03:02 XBV00094.VDF : 8.11.193.254 2048 Bytes 10.12.2014 17:03:02 XBV00095.VDF : 8.11.194.0 4608 Bytes 10.12.2014 17:03:02 XBV00096.VDF : 8.11.194.18 16896 Bytes 10.12.2014 17:03:02 XBV00097.VDF : 8.11.194.38 29696 Bytes 10.12.2014 17:03:02 XBV00098.VDF : 8.11.194.56 24576 Bytes 10.12.2014 17:03:23 XBV00099.VDF : 8.11.194.58 11776 Bytes 10.12.2014 17:03:23 XBV00100.VDF : 8.11.194.62 7680 Bytes 10.12.2014 17:03:23 XBV00101.VDF : 8.11.194.64 4096 Bytes 10.12.2014 17:03:23 XBV00102.VDF : 8.11.194.68 17408 Bytes 11.12.2014 17:03:23 XBV00103.VDF : 8.11.194.70 2048 Bytes 11.12.2014 17:03:23 XBV00104.VDF : 8.11.194.72 25600 Bytes 11.12.2014 17:03:24 XBV00105.VDF : 8.11.194.74 2048 Bytes 11.12.2014 17:03:24 XBV00106.VDF : 8.11.194.92 10240 Bytes 11.12.2014 17:03:24 XBV00107.VDF : 8.11.194.110 24064 Bytes 11.12.2014 17:03:24 XBV00108.VDF : 8.11.194.128 2048 Bytes 11.12.2014 17:03:24 XBV00109.VDF : 8.11.194.148 74752 Bytes 11.12.2014 17:03:25 XBV00110.VDF : 8.11.194.166 2048 Bytes 11.12.2014 17:03:25 XBV00111.VDF : 8.11.194.188 17920 Bytes 12.12.2014 17:03:25 XBV00112.VDF : 8.11.194.192 33280 Bytes 12.12.2014 17:03:25 XBV00113.VDF : 8.11.194.194 10752 Bytes 12.12.2014 17:03:25 XBV00114.VDF : 8.11.194.212 59904 Bytes 12.12.2014 17:03:26 XBV00115.VDF : 8.11.194.230 2048 Bytes 12.12.2014 17:03:26 XBV00116.VDF : 8.11.194.246 10240 Bytes 12.12.2014 17:03:26 LOCAL001.VDF : 8.11.194.246 116590592 Bytes 12.12.2014 17:03:49 Engineversion : 8.3.26.34 AEVDF.DLL : 8.3.1.6 133992 Bytes 30.09.2014 21:10:05 AESCRIPT.DLL : 8.2.2.38 543600 Bytes 12.12.2014 17:02:51 AESCN.DLL : 8.3.2.2 139456 Bytes 26.07.2014 13:57:14 AESBX.DLL : 8.2.20.24 1409224 Bytes 22.05.2014 21:44:39 AERDL.DLL : 8.2.1.16 743328 Bytes 02.11.2014 16:52:24 AEPACK.DLL : 8.4.0.56 789360 Bytes 28.11.2014 19:32:12 AEOFFICE.DLL : 8.3.1.8 350120 Bytes 28.11.2014 19:32:10 AEHEUR.DLL : 8.1.4.1442 7936880 Bytes 12.12.2014 17:02:25 AEHELP.DLL : 8.3.1.0 278728 Bytes 26.07.2014 13:56:55 AEGEN.DLL : 8.1.7.38 457576 Bytes 12.12.2014 17:02:08 AEEXP.DLL : 8.4.2.48 252776 Bytes 25.11.2014 19:57:29 AEEMU.DLL : 8.1.3.4 399264 Bytes 30.09.2014 21:09:42 AEDROID.DLL : 8.4.2.248 812968 Bytes 25.11.2014 19:57:31 AECORE.DLL : 8.3.3.0 244592 Bytes 25.11.2014 19:57:08 AEBB.DLL : 8.1.2.0 60448 Bytes 30.09.2014 21:09:40 AVWINLL.DLL : 14.0.7.308 25904 Bytes 25.11.2014 19:57:07 AVPREF.DLL : 14.0.7.308 52016 Bytes 25.11.2014 19:57:45 AVREP.DLL : 14.0.7.308 220976 Bytes 25.11.2014 19:57:46 AVARKT.DLL : 14.0.7.308 227632 Bytes 25.11.2014 19:57:33 AVEVTLOG.DLL : 14.0.7.310 184112 Bytes 25.11.2014 19:57:39 SQLITE3.DLL : 14.0.7.308 453936 Bytes 25.11.2014 19:59:23 AVSMTP.DLL : 14.0.7.308 79096 Bytes 25.11.2014 19:57:54 NETNT.DLL : 14.0.7.308 15152 Bytes 25.11.2014 19:59:07 RCIMAGE.DLL : 14.0.7.308 4865328 Bytes 25.11.2014 19:57:07 RCTEXT.DLL : 14.0.7.318 77048 Bytes 25.11.2014 19:57:07 Konfiguration für den aktuellen Suchlauf: Job Name..............................: AVGuardAsyncScan Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_548b4f14\guard_slideup.avp Protokollierung.......................: standard Primäre Aktion........................: Interaktiv Sekundäre Aktion......................: Quarantäne Durchsuche Masterbootsektoren.........: ein Durchsuche Bootsektoren...............: aus Durchsuche aktive Programme...........: ein Durchsuche Registrierung..............: aus Suche nach Rootkits...................: aus Integritätsprüfung von Systemdateien..: aus Prüfe alle Dateien....................: Alle Dateien Durchsuche Archive....................: ein Rekursionstiefe einschränken..........: 20 Archiv Smart Extensions...............: ein Makrovirenheuristik...................: ein Dateiheuristik........................: Vollständig Beginn des Suchlaufs: Freitag, 12. Dezember 2014 23:51 Der Suchlauf über gestartete Prozesse wird begonnen: Durchsuche Prozess 'svchost.exe' - '38' Modul(e) wurden durchsucht Durchsuche Prozess 'nvvsvc.exe' - '32' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '24' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '86' Modul(e) wurden durchsucht Durchsuche Prozess 'dwm.exe' - '58' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '179' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '46' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '72' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '68' Modul(e) wurden durchsucht Durchsuche Prozess 'WLANExt.exe' - '31' Modul(e) wurden durchsucht Durchsuche Prozess 'conhost.exe' - '12' Modul(e) wurden durchsucht Durchsuche Prozess 'spoolsv.exe' - '80' Modul(e) wurden durchsucht Durchsuche Prozess 'sched.exe' - '59' Modul(e) wurden durchsucht Durchsuche Prozess 'nvxdsync.exe' - '53' Modul(e) wurden durchsucht Durchsuche Prozess 'nvvsvc.exe' - '65' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '70' Modul(e) wurden durchsucht Durchsuche Prozess 'avguard.exe' - '113' Modul(e) wurden durchsucht Durchsuche Prozess 'adminservice.exe' - '27' Modul(e) wurden durchsucht Durchsuche Prozess 'CCDMonitorService.exe' - '36' Modul(e) wurden durchsucht Durchsuche Prozess 'dsiwmis.exe' - '31' Modul(e) wurden durchsucht Durchsuche Prozess 'HeciServer.exe' - '25' Modul(e) wurden durchsucht Durchsuche Prozess 'jhi_service.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'IScheduleSvc.exe' - '93' Modul(e) wurden durchsucht Durchsuche Prozess 'RfBtnSvc64.exe' - '27' Modul(e) wurden durchsucht Durchsuche Prozess 'SDFSSvc.exe' - '82' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '41' Modul(e) wurden durchsucht Durchsuche Prozess 'Ath_WlanAgent.exe' - '23' Modul(e) wurden durchsucht Durchsuche Prozess 'Avira.OE.ServiceHost.exe' - '104' Modul(e) wurden durchsucht Durchsuche Prozess 'SDUpdSvc.exe' - '78' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiprvse.exe' - '27' Modul(e) wurden durchsucht Durchsuche Prozess 'SDWSCSvc.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'taskhostex.exe' - '55' Modul(e) wurden durchsucht Durchsuche Prozess 'LMutilps32.exe' - '49' Modul(e) wurden durchsucht Durchsuche Prozess 'Explorer.EXE' - '188' Modul(e) wurden durchsucht Durchsuche Prozess 'LManager.exe' - '55' Modul(e) wurden durchsucht Durchsuche Prozess 'unsecapp.exe' - '41' Modul(e) wurden durchsucht Durchsuche Prozess 'avshadow.exe' - '27' Modul(e) wurden durchsucht Durchsuche Prozess 'MMDx64Fx.exe' - '45' Modul(e) wurden durchsucht Durchsuche Prozess 'igfxext.exe' - '38' Modul(e) wurden durchsucht Durchsuche Prozess 'ismagent.exe' - '101' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '34' Modul(e) wurden durchsucht Durchsuche Prozess 'nvtray.exe' - '52' Modul(e) wurden durchsucht Durchsuche Prozess 'ePowerTray.exe' - '60' Modul(e) wurden durchsucht Durchsuche Prozess 'SearchIndexer.exe' - '59' Modul(e) wurden durchsucht Durchsuche Prozess 'updateui.exe' - '48' Modul(e) wurden durchsucht Durchsuche Prozess 'ePowerSvc.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'igfxtray.exe' - '40' Modul(e) wurden durchsucht Durchsuche Prozess 'igfxsrvc.exe' - '40' Modul(e) wurden durchsucht Durchsuche Prozess 'hkcmd.exe' - '39' Modul(e) wurden durchsucht Durchsuche Prozess 'igfxpers.exe' - '47' Modul(e) wurden durchsucht Durchsuche Prozess 'RAVCpl64.exe' - '47' Modul(e) wurden durchsucht Durchsuche Prozess 'unsecapp.exe' - '41' Modul(e) wurden durchsucht Durchsuche Prozess 'RAVBg64.exe' - '49' Modul(e) wurden durchsucht Durchsuche Prozess 'ePowerEvent.exe' - '32' Modul(e) wurden durchsucht Durchsuche Prozess 'BtTray.exe' - '122' Modul(e) wurden durchsucht Durchsuche Prozess 'BtvStack.exe' - '96' Modul(e) wurden durchsucht Durchsuche Prozess 'ETDCtrl.exe' - '60' Modul(e) wurden durchsucht Durchsuche Prozess 'BackupManagerTray.exe' - '48' Modul(e) wurden durchsucht Durchsuche Prozess 'avcenter.exe' - '127' Modul(e) wurden durchsucht Durchsuche Prozess 'ETDCtrlHelper.exe' - '34' Modul(e) wurden durchsucht Durchsuche Prozess 'SDTray.exe' - '93' Modul(e) wurden durchsucht Durchsuche Prozess 'avgnt.exe' - '105' Modul(e) wurden durchsucht Durchsuche Prozess 'Avira.OE.Systray.exe' - '100' Modul(e) wurden durchsucht Durchsuche Prozess 'DeviceDetector.exe' - '44' Modul(e) wurden durchsucht Durchsuche Prozess 'iuBrowserIEAgent.exe' - '68' Modul(e) wurden durchsucht Durchsuche Prozess 'iuEmailOutlookAgent.exe' - '66' Modul(e) wurden durchsucht Durchsuche Prozess 'IntelMeFWService.exe' - '23' Modul(e) wurden durchsucht Durchsuche Prozess 'LMS.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'daemonu.exe' - '59' Modul(e) wurden durchsucht Durchsuche Prozess 'AutoUpdate.exe' - '64' Modul(e) wurden durchsucht Durchsuche Prozess 'AutoUpdate.exe' - '32' Modul(e) wurden durchsucht Durchsuche Prozess 'UNS.exe' - '65' Modul(e) wurden durchsucht Durchsuche Prozess 'PMMUpdate.exe' - '56' Modul(e) wurden durchsucht Durchsuche Prozess 'EgisUpdate.exe' - '49' Modul(e) wurden durchsucht Durchsuche Prozess 'SDUpdate.exe' - '105' Modul(e) wurden durchsucht Durchsuche Prozess 'SDWelcome.exe' - '100' Modul(e) wurden durchsucht Durchsuche Prozess 'msiexec.exe' - '63' Modul(e) wurden durchsucht Durchsuche Prozess 'taskeng.exe' - '41' Modul(e) wurden durchsucht Durchsuche Prozess 'iexplore.exe' - '97' Modul(e) wurden durchsucht Durchsuche Prozess 'IEXPLORE.EXE' - '125' Modul(e) wurden durchsucht Durchsuche Prozess 'FlashUtil_ActiveX.exe' - '64' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiprvse.exe' - '31' Modul(e) wurden durchsucht Durchsuche Prozess 'avscan.exe' - '107' Modul(e) wurden durchsucht Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '14' Modul(e) wurden durchsucht Durchsuche Prozess 'wininit.exe' - '15' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '14' Modul(e) wurden durchsucht Durchsuche Prozess 'winlogon.exe' - '30' Modul(e) wurden durchsucht Durchsuche Prozess 'services.exe' - '25' Modul(e) wurden durchsucht Durchsuche Prozess 'lsass.exe' - '58' Modul(e) wurden durchsucht Der Suchlauf über die ausgewählten Dateien wird begonnen: Beginne mit der Suche in 'C:\Users\Jojo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F37O5I9C\mbam-setup-2.0.4.1028_CB-DL-Manager.exe' C:\Users\Jojo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F37O5I9C\mbam-setup-2.0.4.1028_CB-DL-Manager.exe [FUND] Enthält Erkennungsmuster der Adware ADWARE/InstallCore.Gen7 Beginne mit der Desinfektion: C:\Users\Jojo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F37O5I9C\mbam-setup-2.0.4.1028_CB-DL-Manager.exe [FUND] Enthält Erkennungsmuster der Adware ADWARE/InstallCore.Gen7 [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '5191dcda.qua' verschoben! Ende des Suchlaufs: Freitag, 12. Dezember 2014 23:51 Benötigte Zeit: 00:06 Minute(n) Der Suchlauf wurde vollständig durchgeführt. 0 Verzeichnisse wurden überprüft 1122 Dateien wurden geprüft 1 Viren bzw. unerwünschte Programme wurden gefunden 0 Dateien wurden als verdächtig eingestuft 0 Dateien wurden gelöscht 0 Viren bzw. unerwünschte Programme wurden repariert 1 Dateien wurden in die Quarantäne verschoben 0 Dateien wurden umbenannt 0 Dateien konnten nicht durchsucht werden 1121 Dateien ohne Befall 3 Archive wurden durchsucht 0 Warnungen 1 Hinweise Die Suchergebnisse werden an den Guard übermittelt. |
14.12.2014, 12:13 | #2 |
/// the machine /// TB-Ausbilder | ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbei hi,
__________________Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
14.12.2014, 14:42 | #3 |
| ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbei Danke für die schnelle Antwort.
__________________Revo Uninstaller hat SavingsBull nicht gefunden, also habe ich es auch nicht deinstalliert. AdwCleaner ist durchgelaufen, hier das Logfile: Code:
ATTFilter # AdwCleaner v4.105 - Bericht erstellt am 14/12/2014 um 13:19:55 # Aktualisiert 08/12/2014 von Xplode # Database : 2014-12-13.4 [Live] # Betriebssystem : Windows 8 (64 bits) # Benutzername : Jojo - JOJOS_LAPTOP # Gestartet von : C:\Users\Jojo\Desktop\AdwCleaner_4.105.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\WPM Ordner Gelöscht : C:\Program Files (x86)\HiDefMedia Ordner Gelöscht : C:\Program Files (x86)\IminentToolbar Ordner Gelöscht : C:\Program Files (x86)\melondrea Ordner Gelöscht : C:\Program Files (x86)\SavingsBull Ordner Gelöscht : C:\Windows\Installer\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1} Ordner Gelöscht : C:\Users\Jojo\AppData\Local\Temp\AirInstaller Ordner Gelöscht : C:\Users\Jojo\AppData\Local\Temp\Iminent Ordner Gelöscht : C:\Users\Administrator\AppData\Local\torch Ordner Gelöscht : C:\Users\Gast\AppData\Local\torch Ordner Gelöscht : C:\Users\Johannes\AppData\Local\torch Ordner Gelöscht : C:\Users\Johannes\AppData\Local\Software Ordner Gelöscht : C:\Users\Johannes\AppData\LocalLow\IminentToolbar Ordner Gelöscht : C:\Users\Jojo\AppData\Local\torch Ordner Gelöscht : C:\Users\Jojo\AppData\Local\Software Ordner Gelöscht : C:\Users\Jojo\AppData\Roaming\awesomehp Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\torch Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh Ordner Gelöscht : C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh Ordner Gelöscht : C:\Users\Jojo\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh Ordner Gelöscht : C:\Users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh Ordner Gelöscht : C:\Users\Johannes\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh Ordner Gelöscht : C:\Users\Jojo\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10AD2C61-0898-4348-8600-14A342F22AC3} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10AD2C61-0898-4348-8600-14A342F22AC3} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{84FF7BD6-B47F-46F8-9130-01B2696B36CB}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB} Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Savings Bull Schlüssel Gelöscht : HKLM\SOFTWARE\awesomehpSoftware Schlüssel Gelöscht : HKLM\SOFTWARE\Iminent Schlüssel Gelöscht : HKLM\SOFTWARE\SavingsBullFilter Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Iminent Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\1708EDD6AB4EB164A86999D0AF0ABE1D Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\1708EDD6AB4EB164A86999D0AF0ABE1D Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C19AC53289098045B06B0DD1D37CBAB Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23D9E9D21B4E77E41B9F50DD22F24E20 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23EEA1F105A7F45449974D9B95E7AC89 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\26982796A8AFD1246B95E00265A95BF9 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42D92D0D75AFEF74297E03876C8D9D33 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50FFE845C555A6E4BADB7CB7A145BFEB Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\715A3348920B6534690067594BB69F60 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B7B13B037A7C2A42AC3E3EAF14D7107 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D05B2942E9CC80499F397F6114DFB35 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8591B8948E1C4A04F90505B3CDEE8555 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8D841C5FEC311624CB88D49DB3884FA7 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD04033484A18CA4CAB3EE59D39D756E Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD746BF3B3B3FD8409B86604BA85982A Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F355F0DB7A2E3A14B8E7A568FBA25937 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1708EDD6AB4EB164A86999D0AF0ABE1D ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.17148 -\\ Google Chrome v -\\ Comodo Dragon v ************************* AdwCleaner[R0].txt - [7683 octets] - [14/12/2014 12:53:15] AdwCleaner[R1].txt - [7743 octets] - [14/12/2014 13:05:11] AdwCleaner[R2].txt - [7803 octets] - [14/12/2014 13:12:42] AdwCleaner[S0].txt - [7494 octets] - [14/12/2014 13:19:55] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7554 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.0 (11.29.2014:1) OS: Windows 8 x64 Ran by Jojo on 14.12.2014 at 14:28:50,28 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 14.12.2014 at 14:30:29,78 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-12-2014 Ran by Jojo (administrator) on JOJOS_LAPTOP on 14-12-2014 14:31:46 Running from C:\Users\Jojo\Desktop Loaded Profiles: UpdatusUser & Jojo (Available profiles: UpdatusUser & Jojo & Johannes) Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (Dritek System INC.) C:\Windows\RfBtnSvc64.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Atheros) C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-31] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-31] (Realtek Semiconductor) HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [64640 2012-07-31] () HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2864016 2012-08-11] (ELAN Microelectronics Corp.) HKLM-x32\...\Run: [BakupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [533056 2012-07-31] (NTI Corporation) HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [LManager] => [X] HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-11-25] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2599121855-505218769-2556464541-1001\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2599121855-505218769-2556464541-1002\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation) AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation) Startup: C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2599121855-505218769-2556464541-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1002 -> {0AF3CBBD-ED36-4F9E-B854-5C0B8319BF7D} URL = BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= CHR Profile: C:\Users\Jojo\AppData\Local\Google\Chrome\User Data\Default CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2014-11-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2014-11-25] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [207488 2012-07-31] (Qualcomm Atheros Commnucations) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-01-24] (Acer Incorporated) S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [466064 2012-07-30] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [659600 2012-07-31] (Acer Incorporated) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-07-31] (NTI Corporation) R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-08-25] (Dritek System INC.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16032 2014-09-22] (Microsoft Corporation) R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe [81536 2012-07-31] (Atheros) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-23] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-23] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-12-19] (Avira Operations GmbH & Co. KG) S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-07-31] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [93400 2014-11-21] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-14] (Malwarebytes Corporation) R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-08-25] (Dritek System Inc.) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-14 14:30 - 2014-12-14 14:30 - 00000611 _____ () C:\Users\Jojo\Desktop\JRT.txt 2014-12-14 14:28 - 2014-12-14 14:28 - 00000000 ____D () C:\Windows\ERUNT 2014-12-14 14:27 - 2014-12-14 14:27 - 01707646 _____ (Thisisu) C:\Users\Jojo\Desktop\JRT.exe 2014-12-14 14:23 - 2014-12-14 14:23 - 00007706 _____ () C:\Users\Jojo\Desktop\AdwCleaner[S0].txt 2014-12-14 12:53 - 2014-12-14 13:20 - 00000000 ____D () C:\AdwCleaner 2014-12-14 12:51 - 2014-12-14 12:51 - 02166272 _____ () C:\Users\Jojo\Desktop\AdwCleaner_4.105.exe 2014-12-14 12:42 - 2014-12-14 12:42 - 00001268 _____ () C:\Users\Jojo\Desktop\Revo Uninstaller.lnk 2014-12-14 12:42 - 2014-12-14 12:42 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-12-14 12:36 - 2014-12-14 12:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Jojo\Downloads\revosetup95.exe 2014-12-14 12:00 - 2014-12-14 12:00 - 00000000 ____D () C:\Users\Jojo\AppData\Local\CrashDumps 2014-12-14 11:50 - 2014-12-14 11:50 - 00057300 _____ () C:\Users\Jojo\Desktop\AVSCAN-20141212-235109-6841C90B.LOG 2014-12-14 11:47 - 2014-12-14 11:47 - 00013281 _____ () C:\Users\Jojo\Desktop\Gmer.txt 2014-12-14 11:38 - 2014-12-14 11:38 - 00380416 _____ () C:\Users\Jojo\Desktop\Gmer-19357.exe 2014-12-14 11:32 - 2014-12-14 11:33 - 00031795 _____ () C:\Users\Jojo\Desktop\Addition.txt 2014-12-14 11:31 - 2014-12-14 14:31 - 00014700 _____ () C:\Users\Jojo\Desktop\FRST.txt 2014-12-14 11:31 - 2014-12-14 14:31 - 00000000 ____D () C:\FRST 2014-12-14 11:30 - 2014-12-14 11:30 - 02119168 _____ (Farbar) C:\Users\Jojo\Desktop\FRST64.exe 2014-12-14 11:27 - 2014-12-14 11:27 - 00000470 _____ () C:\Users\Jojo\Desktop\defogger_disable.log 2014-12-14 11:27 - 2014-12-14 11:27 - 00000000 _____ () C:\Users\Jojo\defogger_reenable 2014-12-14 11:26 - 2014-12-14 11:26 - 00050477 _____ () C:\Users\Jojo\Desktop\Defogger.exe 2014-12-14 10:33 - 2014-12-14 11:13 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-12-14 10:33 - 2014-12-14 10:33 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-12-14 10:33 - 2014-12-14 10:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-12-14 10:33 - 2014-12-14 10:33 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-12-14 10:33 - 2014-12-14 10:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-12-14 10:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-12-14 10:33 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-12-14 10:28 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-12-14 10:25 - 2014-12-14 10:20 - 04909382 _____ () C:\Users\Jojo\Desktop\mbam-chameleon-3.1.7.0.zip 2014-12-12 18:40 - 2014-12-12 18:40 - 00001141 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-11-28 20:43 - 2014-11-19 08:29 - 00582552 _____ (Microsoft Corporation) C:\Windows\system32\AutoUpdate.exe 2014-11-28 20:43 - 2014-11-19 08:29 - 00462760 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe 2014-11-28 20:27 - 2014-11-20 21:56 - 00713672 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-11-28 20:27 - 2014-11-20 21:56 - 00106440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-11-28 20:26 - 2014-11-28 20:26 - 00355840 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-24 22:44 - 2014-10-11 08:45 - 10115072 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-11-24 22:44 - 2014-10-11 08:44 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-11-24 22:44 - 2014-10-11 08:44 - 00393216 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-11-24 22:44 - 2014-10-11 08:43 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-11-24 22:44 - 2014-10-11 06:58 - 08858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-11-24 22:44 - 2014-10-11 06:57 - 02416640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-11-24 22:44 - 2014-10-11 06:57 - 00295424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-11-24 22:44 - 2014-10-11 06:56 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-11-24 22:44 - 2014-09-22 06:53 - 00035320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2014-11-24 22:44 - 2014-08-26 23:08 - 00270024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2014-11-24 22:17 - 2014-11-26 00:05 - 01183446 _____ () C:\Users\Johannes\Documents\Statistiken und Diagramme auswerten pp.pptx 2014-11-24 18:44 - 2014-10-18 09:44 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-24 18:44 - 2014-10-18 08:05 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-11-24 18:44 - 2014-10-11 08:44 - 03248640 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-11-24 18:44 - 2014-10-11 06:41 - 00713728 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-24 18:44 - 2014-10-11 06:41 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-24 18:44 - 2014-10-11 06:05 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2014-11-24 18:44 - 2014-10-11 06:04 - 00713728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-11-24 18:44 - 2014-10-03 02:21 - 00522728 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-24 18:44 - 2014-10-02 23:29 - 00783872 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-24 18:44 - 2014-10-02 23:29 - 00267264 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-24 18:44 - 2014-10-02 23:29 - 00169472 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll 2014-11-24 18:44 - 2014-10-02 00:05 - 04068864 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-24 18:44 - 2014-09-25 00:29 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-11-24 18:44 - 2014-09-25 00:29 - 00072192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll 2014-11-24 18:44 - 2014-09-25 00:01 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-24 18:44 - 2014-09-25 00:01 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll 2014-11-24 18:44 - 2014-09-13 07:24 - 02233152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-11-24 18:44 - 2014-09-06 01:46 - 00389176 _____ () C:\Windows\system32\ApnDatabase.xml 2014-11-24 18:44 - 2014-09-03 03:48 - 00457728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2014-11-24 18:44 - 2014-09-03 03:48 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2014-11-24 18:44 - 2014-09-03 03:22 - 00188928 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2014-11-24 18:44 - 2014-09-03 03:21 - 00623104 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2014-11-24 18:44 - 2014-09-03 03:21 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2014-11-24 18:44 - 2014-08-29 05:17 - 02043392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2014-11-24 18:44 - 2014-08-29 05:17 - 00227328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2014-11-24 18:44 - 2014-08-29 05:04 - 02837504 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-11-24 18:44 - 2014-08-29 05:04 - 00309248 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-11-24 18:44 - 2014-08-28 07:04 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSCOMEX.dll 2014-11-24 18:44 - 2014-08-28 07:04 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSAPI.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00616448 _____ (Microsoft Corporation) C:\Windows\system32\FXSAPI.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOMEX.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00432640 _____ (Microsoft Corporation) C:\Windows\system32\FXSTIFF.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\FXST30.dll 2014-11-24 18:44 - 2014-07-24 14:12 - 00328512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-11-24 18:43 - 2014-11-08 12:22 - 00238080 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-24 18:43 - 2014-11-08 12:21 - 00827904 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-24 18:43 - 2014-11-08 07:57 - 00187904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2014-11-24 18:43 - 2014-11-08 07:56 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-11-24 18:43 - 2014-10-26 02:56 - 02237952 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-11-24 18:43 - 2014-10-26 02:56 - 01409536 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-11-24 18:43 - 2014-10-26 02:56 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-11-24 18:43 - 2014-10-26 02:56 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-11-24 18:43 - 2014-10-26 02:56 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-11-24 18:43 - 2014-10-26 02:55 - 19284480 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-11-24 18:43 - 2014-10-26 02:55 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-11-24 18:43 - 2014-10-26 02:55 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-11-24 18:43 - 2014-10-26 02:55 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-11-24 18:43 - 2014-10-26 02:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-11-24 18:43 - 2014-10-26 02:53 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-11-24 18:43 - 2014-10-26 01:36 - 01762816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 01181696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-11-24 18:43 - 2014-10-26 01:35 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 13758464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-11-24 18:43 - 2014-10-26 01:34 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-11-24 18:43 - 2014-10-26 01:34 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-11-24 18:43 - 2014-10-26 01:19 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-11-24 18:43 - 2014-10-26 01:13 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-11-24 18:43 - 2014-10-25 22:48 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-11-24 18:43 - 2014-10-23 13:47 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-24 18:43 - 2014-10-23 12:04 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-11-24 18:43 - 2014-10-11 09:35 - 00171840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-24 18:43 - 2014-10-11 08:44 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2014-11-24 18:43 - 2014-10-11 08:43 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-24 18:43 - 2014-10-11 06:57 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2014-11-24 18:43 - 2014-08-22 00:56 - 01418752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-11-24 18:43 - 2014-08-22 00:27 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-14 14:22 - 2012-08-25 16:05 - 00000868 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-12-14 14:21 - 2012-08-07 02:17 - 00053284 _____ () C:\Windows\system32\wpbbin.exe 2014-12-14 14:21 - 2012-08-03 18:14 - 00188472 _____ () C:\Windows\PFRO.log 2014-12-14 14:21 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-14 14:21 - 2012-07-26 06:26 - 00524288 ___SH () C:\Windows\system32\config\BBI 2014-12-14 14:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru 2014-12-14 13:20 - 2013-01-15 21:36 - 01924138 _____ () C:\Windows\WindowsUpdate.log 2014-12-14 13:03 - 2012-08-25 16:05 - 00000870 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-12-14 12:20 - 2013-01-19 20:58 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2599121855-505218769-2556464541-1003 2014-12-14 11:27 - 2013-01-15 21:36 - 00000000 ____D () C:\Users\Jojo 2014-12-14 11:07 - 2012-08-25 16:43 - 00000000 ____D () C:\ProgramData\Norton 2014-12-14 10:28 - 2012-08-26 01:32 - 00753134 _____ () C:\Windows\system32\perfh007.dat 2014-12-14 10:28 - 2012-08-26 01:32 - 00155826 _____ () C:\Windows\system32\perfc007.dat 2014-12-14 10:28 - 2012-07-26 08:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-12 18:40 - 2014-09-30 22:35 - 00000000 ____D () C:\ProgramData\Package Cache 2014-12-12 18:40 - 2013-06-11 21:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-12-12 18:40 - 2013-06-11 21:04 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ___RD () C:\Windows\ToastData 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Windows Defender 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-12-03 19:55 - 2013-03-17 20:04 - 00000000 ____D () C:\Users\Johannes\AppData\Local\CrashDumps 2014-12-03 19:52 - 2013-01-17 21:36 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-11-30 11:56 - 2012-07-26 08:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-11-28 20:23 - 2013-09-10 11:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-28 20:20 - 2013-01-22 20:47 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-24 22:45 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-11-24 18:57 - 2013-01-29 21:47 - 00000000 ____D () C:\ProgramData\Microsoft Help Some content of TEMP: ==================== C:\Users\Johannes\AppData\Local\Temp\avgnt.exe C:\Users\Jojo\AppData\Local\Temp\avgnt.exe C:\Users\Jojo\AppData\Local\Temp\ose00000.exe C:\Users\Jojo\AppData\Local\Temp\Quarantine.exe C:\Users\Jojo\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-12 18:45 ==================== End Of Log ============================ Soweit die logfiles, danke nochmal für das schnelle Feedback. Viele Grüße, MartinDetune |
14.12.2014, 20:48 | #4 |
/// the machine /// TB-Ausbilder | ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbeiESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.12.2014, 22:47 | #5 |
| ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbei Hallo, danke wieder für das schnelle Feedback. Alles gemacht, Logfiles sind im Anhang. Viele Grüße, MartinDetune Hier das ESET log Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=d12f196e0d89f7499572c277d094c50a # engine=21551 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-12-15 05:40:08 # local_time=2014-12-15 06:40:08 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 51284 284045298 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 216584 78128119 0 0 # scanned=188414 # found=33 # cleaned=0 # scan_time=31492 sh=4C8D1854AA72DBF896AA1CC32A51DCC4CB2E6CAC ft=0 fh=0000000000000000 vn="Win32/AdWare.Adpeak.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SavingsBull\bootstrap.js.vir" sh=60B05812631F311E76964A51EFA1B77D8B9CABC9 ft=1 fh=c8d0fac17e540556 vn="Win32/AdWare.Adpeak.I Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SavingsBull\CustomActionInstall.vir" sh=8360F01C509182D1979F89DF347C152F44B4B4A8 ft=1 fh=8178fc5ad221d18e vn="Win32/AdWare.Adpeak.I Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SavingsBull\CustomActionUninstall.vir" sh=AE7038C74B0CC19A571A5748AB029F6B7A55F4D1 ft=1 fh=4393341c14bbcb80 vn="Win32/AdWare.Adpeak.I Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SavingsBull\IEOptimizer.dll.vir" sh=356514362FBAEDD2B76F8C35B75B9ED77B6B0F1F ft=1 fh=d19b12c9c8aaa781 vn="Win64/Adware.Adpeak.E Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SavingsBull\IEOptimizer64.dll.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\torch\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\torch\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Johannes\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Johannes\AppData\Local\torch\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Jojo\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Jojo\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Jojo\AppData\Local\torch\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\torch\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js.vir" sh=6B6105C0BF9C8942B523C7BC6279BF1D241909BA ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\temp\InstallFilter64.msi" sh=6205DDE47C041E3B67EFC540F89F24344835EE11 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\temp\t.msi" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\Users\Johannes\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js" sh=59FF95BA9B6D4C3C7801632BABD6908B70C14ED6 ft=1 fh=00f78a8700848542 vn="Variante von Win32/AirAdInstaller.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Johannes\Downloads\setup (1).exe" sh=D751BFCA957024D6EC589A20624B5D94F63F5262 ft=1 fh=7ac6a88100848542 vn="Variante von Win32/AirAdInstaller.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Johannes\Downloads\setup (2).exe" sh=94FF3CAE1E4A2614A15B38EA84CAF4F92175A44A ft=1 fh=6057d61b00848542 vn="Variante von Win32/AirAdInstaller.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Johannes\Downloads\setup.exe" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\Users\Jojo\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js" sh=123BAC37A0FB4242359EE60D88702EC94C576148 ft=1 fh=f8246b4ac96f5caa vn="Variante von Win32/Toolbar.Iminent.J evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Jojo\AppData\Local\Temp\Umbrella.exe32797530" sh=D3133937AB7FE2838939DEDA5C152DFFF46CCB67 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.EB Anwendung" ac=I fn="C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\caaadjnckogbfecoiapbalkooclmngdh\2.1\K65Vbu33mQo.js" sh=6205DDE47C041E3B67EFC540F89F24344835EE11 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Windows\Installer\60c3adf.msi" sh=39D8E3F939476AACB93221625C0362E36B2246A3 ft=0 fh=0000000000000000 vn="Variante von MSIL/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Temp\tmp100A.tmp" Code:
ATTFilter Results of screen317's Security Check version 0.99.91 x64 (UAC is enabled) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Windows Defender Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy ````````Process Check: objlist.exe by Laurent```````` Spybot Teatimer.exe is disabled! Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-12-2014 Ran by Jojo (administrator) on JOJOS_LAPTOP on 15-12-2014 22:35:35 Running from C:\Users\Jojo\Desktop Loaded Profiles: UpdatusUser & Jojo (Available profiles: UpdatusUser & Jojo & Johannes) Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (Dritek System INC.) C:\Windows\RfBtnSvc64.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Atheros) C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-31] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-31] (Realtek Semiconductor) HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [64640 2012-07-31] () HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2864016 2012-08-11] (ELAN Microelectronics Corp.) HKLM-x32\...\Run: [BakupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [533056 2012-07-31] (NTI Corporation) HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [LManager] => [X] HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-11-25] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2599121855-505218769-2556464541-1001\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2599121855-505218769-2556464541-1002\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation) AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation) Startup: C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2599121855-505218769-2556464541-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2599121855-505218769-2556464541-1002 -> {0AF3CBBD-ED36-4F9E-B854-5C0B8319BF7D} URL = BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= CHR Profile: C:\Users\Jojo\AppData\Local\Google\Chrome\User Data\Default CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2014-11-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2014-11-25] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [207488 2012-07-31] (Qualcomm Atheros Commnucations) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-01-24] (Acer Incorporated) S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [466064 2012-07-30] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [659600 2012-07-31] (Acer Incorporated) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-07-31] (NTI Corporation) R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-08-25] (Dritek System INC.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16032 2014-09-22] (Microsoft Corporation) R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe [81536 2012-07-31] (Atheros) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-23] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-23] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-12-19] (Avira Operations GmbH & Co. KG) S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-07-31] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [93400 2014-11-21] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-14] (Malwarebytes Corporation) R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-08-25] (Dritek System Inc.) R1 UimBus; C:\Windows\System32\drivers\UimBus.sys [102664 2014-05-19] () R1 Uim_DEVIM; C:\Windows\System32\drivers\uim_devim.sys [25992 2014-05-19] () R1 Uim_IM; C:\Windows\System32\drivers\uim_im.sys [700296 2014-05-19] () ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-15 22:32 - 2014-12-15 22:32 - 00852490 _____ () C:\Users\Jojo\Desktop\SecurityCheck.exe 2014-12-14 21:49 - 2014-12-14 21:49 - 02347384 _____ (ESET) C:\Users\Jojo\Downloads\esetsmartinstaller_deu.exe 2014-12-14 20:58 - 2014-12-14 20:58 - 00000000 ____D () C:\ProgramData\newbackup 2014-12-14 20:56 - 2014-12-14 20:56 - 00000000 ____D () C:\ProgramData\launcher 2014-12-14 20:56 - 2014-12-14 20:56 - 00000000 ____D () C:\ProgramData\ibackupvhd 2014-12-14 20:47 - 2014-12-14 20:48 - 00000795 _____ () C:\Windows\setupact.log 2014-12-14 20:45 - 2014-12-14 20:45 - 00000000 ____D () C:\ProgramData\rmbwizard 2014-12-14 20:44 - 2014-12-14 20:44 - 00002375 _____ () C:\Users\Public\Desktop\Paragon Backup and Recovery™ 2014 Free.lnk 2014-12-14 20:44 - 2014-12-14 20:44 - 00002207 _____ () C:\Users\Public\Desktop\Paragon Recovery Media Builder™.lnk 2014-12-14 20:43 - 2014-12-14 20:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paragon Backup and Recovery™ 2014 Free 2014-12-14 20:43 - 2014-12-14 20:43 - 00000000 ____D () C:\Program Files\Paragon Software 2014-12-14 20:41 - 2014-12-14 20:41 - 00000000 ____D () C:\Users\Jojo\AppData\Local\Downloaded Installations 2014-12-14 20:40 - 2014-12-14 20:40 - 00000000 ____D () C:\ProgramData\explauncher 2014-12-14 19:49 - 2014-12-14 20:36 - 417659040 _____ () C:\Users\Jojo\Downloads\br2014Free101.exe 2014-12-14 19:47 - 2014-12-15 20:49 - 00003718 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2014-12-14 19:47 - 2014-12-14 19:47 - 00003476 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon 2014-12-14 19:47 - 2014-12-14 19:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2014-12-14 19:47 - 2014-12-14 19:47 - 00000000 ____D () C:\ProgramData\Intel(R) Update Manager 2014-12-14 19:39 - 2014-10-09 05:00 - 01519104 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll 2014-12-14 19:39 - 2014-10-09 05:00 - 01484288 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe 2014-12-14 19:39 - 2014-10-09 05:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\vsstrace.dll 2014-12-14 19:39 - 2014-10-09 04:59 - 01195520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vssapi.dll 2014-12-14 19:39 - 2014-10-09 04:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vsstrace.dll 2014-12-14 17:09 - 2014-11-21 09:38 - 02237952 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-14 17:09 - 2014-11-21 09:38 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-12-14 17:09 - 2014-11-21 09:37 - 01409536 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-14 17:09 - 2014-11-21 09:37 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-12-14 17:09 - 2014-11-21 09:37 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 19283456 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 15400960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-14 17:09 - 2014-11-21 09:36 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-12-14 17:09 - 2014-11-21 09:35 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-14 17:09 - 2014-11-21 08:17 - 14364672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-12-14 17:09 - 2014-11-21 08:17 - 01762816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-12-14 17:09 - 2014-11-21 08:17 - 01181696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-12-14 17:09 - 2014-11-21 08:17 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-12-14 17:09 - 2014-11-21 08:17 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-12-14 17:09 - 2014-11-21 08:17 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 13758976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 02054656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-12-14 17:09 - 2014-11-21 08:16 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-12-14 17:09 - 2014-11-21 08:16 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-12-14 17:09 - 2014-11-21 08:00 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-14 17:09 - 2014-11-21 07:54 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-12-14 17:09 - 2014-11-21 05:30 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-12-14 17:09 - 2014-10-11 08:44 - 19764736 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-12-14 17:09 - 2014-10-11 06:57 - 17562112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-12-14 17:09 - 2014-10-09 04:59 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2014-12-14 17:09 - 2014-10-09 04:59 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2014-12-14 17:09 - 2014-10-09 04:58 - 00458240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2014-12-14 17:09 - 2014-09-22 06:38 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll 2014-12-14 17:09 - 2014-09-22 04:56 - 00513536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll 2014-12-14 17:07 - 2014-11-06 07:50 - 01627648 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-14 17:07 - 2014-11-06 06:03 - 01339392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-12-14 17:06 - 2014-10-30 08:20 - 01890816 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2014-12-14 17:06 - 2014-10-30 06:22 - 01569792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2014-12-14 14:32 - 2014-12-14 14:32 - 00033754 _____ () C:\Users\Jojo\Desktop\FRST1.txt 2014-12-14 14:30 - 2014-12-14 14:30 - 00000611 _____ () C:\Users\Jojo\Desktop\JRT.txt 2014-12-14 14:28 - 2014-12-14 14:28 - 00000000 ____D () C:\Windows\ERUNT 2014-12-14 14:27 - 2014-12-14 14:27 - 01707646 _____ (Thisisu) C:\Users\Jojo\Desktop\JRT.exe 2014-12-14 14:23 - 2014-12-14 14:23 - 00007706 _____ () C:\Users\Jojo\Desktop\AdwCleaner[S0].txt 2014-12-14 12:53 - 2014-12-14 13:20 - 00000000 ____D () C:\AdwCleaner 2014-12-14 12:51 - 2014-12-14 12:51 - 02166272 _____ () C:\Users\Jojo\Desktop\AdwCleaner_4.105.exe 2014-12-14 12:42 - 2014-12-14 12:42 - 00001268 _____ () C:\Users\Jojo\Desktop\Revo Uninstaller.lnk 2014-12-14 12:42 - 2014-12-14 12:42 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-12-14 12:36 - 2014-12-14 12:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Jojo\Downloads\revosetup95.exe 2014-12-14 12:00 - 2014-12-14 12:00 - 00000000 ____D () C:\Users\Jojo\AppData\Local\CrashDumps 2014-12-14 11:50 - 2014-12-14 11:50 - 00057300 _____ () C:\Users\Jojo\Desktop\AVSCAN-20141212-235109-6841C90B.LOG 2014-12-14 11:47 - 2014-12-14 11:47 - 00013281 _____ () C:\Users\Jojo\Desktop\Gmer.txt 2014-12-14 11:38 - 2014-12-14 11:38 - 00380416 _____ () C:\Users\Jojo\Desktop\Gmer-19357.exe 2014-12-14 11:32 - 2014-12-14 11:33 - 00031795 _____ () C:\Users\Jojo\Desktop\Addition.txt 2014-12-14 11:31 - 2014-12-15 22:35 - 00015058 _____ () C:\Users\Jojo\Desktop\FRST.txt 2014-12-14 11:31 - 2014-12-15 22:35 - 00000000 ____D () C:\FRST 2014-12-14 11:30 - 2014-12-14 11:30 - 02119168 _____ (Farbar) C:\Users\Jojo\Desktop\FRST64.exe 2014-12-14 11:27 - 2014-12-14 11:27 - 00000470 _____ () C:\Users\Jojo\Desktop\defogger_disable.log 2014-12-14 11:27 - 2014-12-14 11:27 - 00000000 _____ () C:\Users\Jojo\defogger_reenable 2014-12-14 11:26 - 2014-12-14 11:26 - 00050477 _____ () C:\Users\Jojo\Desktop\Defogger.exe 2014-12-14 10:33 - 2014-12-14 11:13 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-12-14 10:33 - 2014-12-14 10:33 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-12-14 10:33 - 2014-12-14 10:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-12-14 10:33 - 2014-12-14 10:33 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-12-14 10:33 - 2014-12-14 10:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-12-14 10:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-12-14 10:33 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-12-14 10:28 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-12-14 10:25 - 2014-12-14 10:20 - 04909382 _____ () C:\Users\Jojo\Desktop\mbam-chameleon-3.1.7.0.zip 2014-12-12 18:40 - 2014-12-12 18:40 - 00001141 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-11-28 20:43 - 2014-11-19 08:29 - 00582552 _____ (Microsoft Corporation) C:\Windows\system32\AutoUpdate.exe 2014-11-28 20:43 - 2014-11-19 08:29 - 00462760 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe 2014-11-28 20:27 - 2014-11-26 22:11 - 00714184 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-11-28 20:27 - 2014-11-26 22:11 - 00106440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-11-28 20:26 - 2014-11-28 20:26 - 00355840 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-24 22:44 - 2014-10-11 08:45 - 10115072 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-11-24 22:44 - 2014-10-11 08:44 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-11-24 22:44 - 2014-10-11 08:44 - 00393216 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-11-24 22:44 - 2014-10-11 08:43 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-11-24 22:44 - 2014-10-11 06:58 - 08858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-11-24 22:44 - 2014-10-11 06:57 - 02416640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-11-24 22:44 - 2014-10-11 06:57 - 00295424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-11-24 22:44 - 2014-10-11 06:56 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-11-24 22:44 - 2014-09-22 06:53 - 00035320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2014-11-24 22:44 - 2014-08-26 23:08 - 00270024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2014-11-24 22:17 - 2014-11-26 00:05 - 01183446 _____ () C:\Users\Johannes\Documents\Statistiken und Diagramme auswerten pp.pptx 2014-11-24 18:44 - 2014-10-18 09:44 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-24 18:44 - 2014-10-18 08:05 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-11-24 18:44 - 2014-10-11 08:44 - 03248640 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-11-24 18:44 - 2014-10-11 06:41 - 00713728 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-24 18:44 - 2014-10-11 06:41 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-24 18:44 - 2014-10-11 06:05 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2014-11-24 18:44 - 2014-10-11 06:04 - 00713728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-11-24 18:44 - 2014-10-03 02:21 - 00522728 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-24 18:44 - 2014-10-02 23:29 - 00783872 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-24 18:44 - 2014-10-02 23:29 - 00267264 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-24 18:44 - 2014-10-02 23:29 - 00169472 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll 2014-11-24 18:44 - 2014-10-02 00:05 - 04068864 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-24 18:44 - 2014-09-25 00:29 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-11-24 18:44 - 2014-09-25 00:29 - 00072192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll 2014-11-24 18:44 - 2014-09-25 00:01 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-24 18:44 - 2014-09-25 00:01 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll 2014-11-24 18:44 - 2014-09-13 07:24 - 02233152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-11-24 18:44 - 2014-09-06 01:46 - 00389176 _____ () C:\Windows\system32\ApnDatabase.xml 2014-11-24 18:44 - 2014-09-03 03:48 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2014-11-24 18:44 - 2014-09-03 03:22 - 00188928 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2014-11-24 18:44 - 2014-08-29 05:17 - 02043392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2014-11-24 18:44 - 2014-08-29 05:17 - 00227328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2014-11-24 18:44 - 2014-08-29 05:04 - 02837504 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-11-24 18:44 - 2014-08-29 05:04 - 00309248 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-11-24 18:44 - 2014-08-28 07:04 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSCOMEX.dll 2014-11-24 18:44 - 2014-08-28 07:04 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSAPI.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00616448 _____ (Microsoft Corporation) C:\Windows\system32\FXSAPI.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOMEX.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00432640 _____ (Microsoft Corporation) C:\Windows\system32\FXSTIFF.dll 2014-11-24 18:44 - 2014-08-28 06:59 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\FXST30.dll 2014-11-24 18:44 - 2014-07-24 14:12 - 00328512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-11-24 18:43 - 2014-11-08 12:22 - 00238080 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-24 18:43 - 2014-11-08 12:21 - 00827904 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-24 18:43 - 2014-11-08 07:57 - 00187904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2014-11-24 18:43 - 2014-11-08 07:56 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-11-24 18:43 - 2014-10-23 13:47 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-24 18:43 - 2014-10-23 12:04 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-11-24 18:43 - 2014-10-11 09:35 - 00171840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-24 18:43 - 2014-10-11 08:44 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2014-11-24 18:43 - 2014-10-11 08:43 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-24 18:43 - 2014-10-11 06:57 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2014-11-24 18:43 - 2014-08-22 00:56 - 01418752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-11-24 18:43 - 2014-08-22 00:27 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-19 04:31 - 2014-11-19 04:31 - 01217192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FM20.DLL ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-15 22:23 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru 2014-12-15 20:49 - 2012-08-25 15:58 - 00000000 ____D () C:\ProgramData\Intel 2014-12-15 07:16 - 2013-01-15 21:36 - 01548728 _____ () C:\Windows\WindowsUpdate.log 2014-12-15 07:07 - 2014-09-24 16:19 - 00000000 ___HD () C:\$Windows.~BT 2014-12-15 07:01 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-12-15 06:47 - 2012-07-26 08:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-12-14 21:49 - 2012-08-26 01:32 - 00753134 _____ () C:\Windows\system32\perfh007.dat 2014-12-14 21:49 - 2012-08-26 01:32 - 00155826 _____ () C:\Windows\system32\perfc007.dat 2014-12-14 21:49 - 2012-07-26 08:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-14 20:11 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\rescache 2014-12-14 19:48 - 2012-08-07 02:24 - 00000000 ____D () C:\Program Files (x86)\Intel 2014-12-14 19:45 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-14 19:44 - 2012-08-07 02:17 - 00053284 _____ () C:\Windows\system32\wpbbin.exe 2014-12-14 19:44 - 2012-08-03 18:14 - 00194136 _____ () C:\Windows\PFRO.log 2014-12-14 19:44 - 2012-07-26 06:26 - 00524288 ___SH () C:\Windows\system32\config\BBI 2014-12-14 19:43 - 2012-07-26 09:12 - 00000000 ___RD () C:\Windows\ToastData 2014-12-14 19:42 - 2013-01-29 21:47 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-12-14 19:41 - 2013-09-10 11:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-14 19:40 - 2013-01-22 20:47 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-12-14 12:20 - 2013-01-19 20:58 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2599121855-505218769-2556464541-1003 2014-12-14 11:27 - 2013-01-15 21:36 - 00000000 ____D () C:\Users\Jojo 2014-12-14 11:07 - 2012-08-25 16:43 - 00000000 ____D () C:\ProgramData\Norton 2014-12-12 18:40 - 2014-09-30 22:35 - 00000000 ____D () C:\ProgramData\Package Cache 2014-12-12 18:40 - 2013-06-11 21:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-12-12 18:40 - 2013-06-11 21:04 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Windows Defender 2014-12-12 18:30 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-12-03 19:55 - 2013-03-17 20:04 - 00000000 ____D () C:\Users\Johannes\AppData\Local\CrashDumps 2014-12-03 19:52 - 2013-01-17 21:36 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 Some content of TEMP: ==================== C:\Users\Johannes\AppData\Local\Temp\avgnt.exe C:\Users\Jojo\AppData\Local\Temp\avgnt.exe C:\Users\Jojo\AppData\Local\Temp\ose00000.exe C:\Users\Jojo\AppData\Local\Temp\Quarantine.exe C:\Users\Jojo\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-14 15:35 ==================== End Of Log ============================ --- --- --- --- --- --- |
16.12.2014, 21:15 | #6 |
/// the machine /// TB-Ausbilder | ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbei Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2599121855-505218769-2556464541-1001\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2599121855-505218769-2556464541-1002\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.google.com/chrome/answer/3296214?hl=de Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbei |
21.12.2014, 22:25 | #7 |
| ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbei Hallo, habe alle Schritte so befolgt, wie von Dir geschrieben. Ausnahmen: 1. Fixlog.txt wurde durch DelFix bereits gelöscht, so dass ich es nicht posten kann. Ist das ein Problem? 2. bei mir war Google Chrome nicht installiert, also habe ich es auch nicht deinstalliert und wieder installiert. Ist das (besonders 1.) ein Problem? Soll ich noch etwas machen, oder bin ich durch? Mit der Bitte um kurze Rückmeldung, Danke, MartinDetune |
22.12.2014, 17:14 | #8 |
/// the machine /// TB-Ausbilder | ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbei passt schon
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu ADWARE/InstallCore.Gen7 auf Rechner gefunden - Logfiles dazu anbei |
adware installcore.gen7 malware virus, adware/installcore.gen7, auswerten, awesomehp, awesomehp entfernen, computer, fehler 0x8007045b, fehlercode 22, fehlercode 70, homepage, installation, launch, msiexec.exe, msil/mypcbackup.a, refresh, registry, services.exe, software, svchost.exe, teredo, this device cannot start. (code10), this device is disabled. (code 22), win32/adware.adpeak.b, win32/adware.adpeak.i, win32/adware.multiplug.eb, win32/airadinstaller.a, win32/toolbar.iminent.j, win64/adware.adpeak.e |