![]() |
|
Log-Analyse und Auswertung: BitdefenderIS15 kann Adware.AdPeak.V nicht löschen.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() BitdefenderIS15 kann Adware.AdPeak.V nicht löschen. Moin moin, hoffe ich mache hier nix falsch, da es mein erster Beitrag ist. Ich bekomme seit ca 1 Woche immer wieder Werbesounds eingespielt, was mich dazu bewegt hat mein Bitdefender IS 15 einen System scan machen zu lassen. Es wurden 5 ungelöste Probleme gefunden.: 1. Adware.AdPeak.V (Desinfektion Fehlgeschlagen) 2. Application.Generic.1016845 (Problem Besteht noch) 3. Application.Generic. 1024105 (Problem Besteht noch) 4. Application.Generic. 1028214 (Problem Besteht noch) 5. Application.OptimizerPro.Q (Problem Besteht noch) Anfangs kam oft ein Fenster aufgepoppt Benutzerkontensteuerung das die Datei ss7.exe ausgeführt werden möchte. Programmname ss7.exe Herausgeber: Unbekannt Dateiursprung: Festplatte auf dem Computer Programmpfad: C:\Windows\Teamp\ss7.exe usw........ Dies hat Bitdefender glaube ich gelöst bekommen, habe über den Rettungsmodus einen scan gemacht und etwas gelöscht bekommen. Wenn ich mal Bitdefender von Autopilot auf normal stelle kommen alle paar sec Meldungen "Infizierte Web Ressource gefunden" FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2015 Ran by Jo (administrator) on JONEUPC on 05-01-2015 16:40:17 Running from E:\ Loaded Profile: Jo (Available profiles: Jo) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (FSPro Labs) C:\Windows\SysWOW64\fsproflt2.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe () C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe () C:\Users\Jo\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\odscanui.exe () C:\Users\Jo\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe () C:\Users\Jo\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe () C:\Users\Jo\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe () C:\Users\Jo\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (AppWork GmbH) C:\Program Files\JDownloader 2\JDownloader 2.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] () HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [CmPCIaudio] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\CMICNFG3.dll,CMICtrlWnd HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe [1626752 2014-11-24] (Bitdefender) HKLM-x32\...\Run: [XFastUSB] => C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5021448 2014-02-27] (FNet Co., Ltd.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-20] (Advanced Micro Devices, Inc.) HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\...\Run: [OscarEditor] => C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe [3325952 2012-02-22] () HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\...\Run: [Microsoft Office Outlook] => C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE [196440 2010-06-23] (Microsoft Corporation) HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\...\Run: [HitsBlender] => [X] HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\...\MountPoints2: H - H:\setup.exe /autorun HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\...\MountPoints2: {1d453e76-e6c0-11e1-813e-bc5ff43a70c4} - H:\setup.exe HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\...\MountPoints2: {2d3b6677-dbfa-11e1-bdae-bc5ff43a70c4} - E:\setup.exe -a HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\...\MountPoints2: {419c321a-04d0-11e2-ad9d-bc5ff43a70c4} - H:\setup.exe /autorun Startup: C:\Users\Jo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung SSD Magician.lnk ShortcutTarget: Samsung SSD Magician.lnk -> C:\Program Files (x86)\Samsung SSD Magician\Samsung SSD Magician.exe (Samsung Electronics.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=644c3855-1726-49e8-ba98-9a79cfa288b7&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms} HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/androidnews/ SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=644c3855-1726-49e8-ba98-9a79cfa288b7&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=644c3855-1726-49e8-ba98-9a79cfa288b7&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKU\S-1-5-21-2091203308-3088951350-3500837121-1000 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=644c3855-1726-49e8-ba98-9a79cfa288b7&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKU\S-1-5-21-2091203308-3088951350-3500837121-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3320845&octid=EB_ORIGINAL_CTID&ISID=MF59A80F1-D312-4B4E-A11E-BD9BBDF3119B&SearchSource=58&CUI=&UM=6&UP=SP2A3FB4C6-3691-4418-A54A-DD786892354C&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-2091203308-3088951350-3500837121-1000 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKU\S-1-5-21-2091203308-3088951350-3500837121-1000 -> {B224AA02-F7C8-3A2B-859F-560B80767E4A} URL = hxxp://kl.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=876&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.5.0&install_country=DE&install_date=20130306&user_guid=7606A6511D744730BAEC3397F653E13A&machine_id=e2800a63dffd9ccdf423fa695fdf3b50&browser=IE&os=win&os_version=6.1-x64-SP1&iesrc={referrer:source} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) BHO: Hotspot Shield Class -> {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -> No File BHO-x32: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Samsung BHO Class -> {AA609D72-8482-4076-8991-8CDAE5B93BCB} -> C:\Program Files (x86)\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll (Bitdefender) Toolbar: HKLM-x32 - loadtbs - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\Jo\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH) Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH) Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll (Bitdefender) Toolbar: HKU\S-1-5-21-2091203308-3088951350-3500837121-1000 -> No Name - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 -> C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext [2014-09-15] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-09-03] FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff [2014-09-15] FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext Chrome: ======= CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3320845&octid=EB_ORIGINAL_CTID&ISID=MF59A80F1-D312-4B4E-A11E-BD9BBDF3119B&SearchSource=55&CUI=&UM=6&UP=SP2A3FB4C6-3691-4418-A54A-DD786892354C&SSPV= CHR Profile: C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-22] CHR Extension: (MeinProspekt) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bboapklbfgchofdopiohcfhmaeghhgko [2014-05-10] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27] CHR Extension: (YouTube) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-20] CHR Extension: (Adblock Plus) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2012-07-22] CHR Extension: (Google-Suche) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-20] CHR Extension: (Dark Vibe) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkckeanhmkjaechlhllmapjaaglgpcbj [2014-07-14] CHR Extension: (Mini Radio Player) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffeaebedjghkdbccfenjbiilalegknlj [2013-04-17] CHR Extension: (FoxyProxy Standard) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcknhkkoolaabfmlnjonogaaifnjlfnp [2014-07-14] CHR Extension: (Hola Besseres Internet) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-09-23] CHR Extension: (Google Wallet) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29] CHR Extension: (Deutsch Englisch Übersetzer) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcknciadhimdlbjjfndidcgnhokfbgnd [2014-08-24] CHR Extension: (Google Mail) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-20] CHR HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Jo\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-09-22] CHR HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\Jo\AppData\Local\CRE\ngnjhfpfhadncgafgbneeljaginimmmk.crx [2012-07-22] CHR HKU\S-1-5-21-2091203308-3088951350-3500837121-1000\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Jo\AppData\Roaming\DVDVideoSoft\DVDVideoSoftBrowserExtension.crx [2012-11-24] CHR HKLM-x32\...\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - No Path CHR HKLM-x32\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\Jo\AppData\Local\CRE\ngnjhfpfhadncgafgbneeljaginimmmk.crx [2012-07-22] CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx [2014-02-22] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2015\bdparentalservice.exe [78144 2014-11-24] (Bitdefender) R2 fsproflt2; C:\Windows\SysWOW64\fsproflt2.exe [49512 2012-07-12] (FSPro Labs) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed] S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-20] (Intel Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903472 2014-12-19] (Electronic Arts) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2009-10-20] (CACE Technologies, Inc.) S3 Samsung UPD Service2; C:\Windows\System32\SUPDSvc2.exe [158208 2012-04-06] (Samsung Electronics) [File not signed] R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2014-11-24] (Bitdefender) R2 Verifies and fixes application compatibility issues; C:\Users\Jo\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe [87208 2014-12-30] () [File not signed] R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe [1527360 2014-11-24] (Bitdefender) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology) S3 asusgsb; C:\Windows\System32\drivers\asusgsb.sys [17792 2009-02-17] (ASUSTeK Computer Inc.) [File not signed] R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1288472 2014-11-24] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [263032 2014-11-24] (BitDefender) S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-05-16] (BitDefender) R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2013-11-13] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107080 2012-10-29] (BitDefender LLC) S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL) S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [29184 2009-08-13] (CSR, plc) R3 cmuda3; C:\Windows\System32\drivers\cmudax3.sys [1155072 2010-10-01] (C-Media Inc) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2014-10-18] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2014-02-27] (FNet Co., Ltd.) R0 FSProFilter2; C:\Windows\System32\Drivers\FSPFltd2.sys [57648 2011-06-03] (FSPro Labs) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC) S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [331264 2011-12-06] (Intel(R) Corporation) [File not signed] S3 IOMap; C:\Windows\system32\drivers\IOMap64.sys [23680 2010-02-22] (ASUSTeK Computer Inc.) R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] () R2 NPF; C:\Windows\System32\drivers\npf.sys [47632 2009-10-20] (CACE Technologies, Inc.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-05-01] (Duplex Secure Ltd.) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [452040 2014-11-24] (BitDefender S.R.L.) R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [102664 2014-05-19] () R1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [25992 2014-05-19] () R1 Uim_IM; C:\Windows\System32\DRIVERS\uim_im.sys [700296 2014-05-19] () S3 WsAudioDevice_383S(1); C:\Windows\System32\drivers\WsAudioDevice_383S(1).sys [29288 2014-07-31] (Wondershare) U3 agj7rxp9; C:\Windows\System32\Drivers\agj7rxp9.sys [0 ] (Microsoft Corporation) S3 athr; system32\DRIVERS\athrx.sys [X] S3 BTCFilterService; system32\DRIVERS\motfilt.sys [X] S1 EIO64; system32\DRIVERS\EIO64.sys [X] S3 motandroidusb; System32\Drivers\motoandroid.sys [X] S3 motccgp; system32\DRIVERS\motccgp.sys [X] S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [X] S3 MotDev; system32\DRIVERS\motodrv.sys [X] S3 motmodem; system32\DRIVERS\motmodem.sys [X] S3 MotoSwitchService; system32\DRIVERS\motswch.sys [X] S3 Motousbnet; system32\DRIVERS\Motousbnet.sys [X] S3 motusbdevice; system32\DRIVERS\motusbdevice.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-05 16:16 - 2015-01-05 16:16 - 00000000 __SHD () C:\Users\Jo\AppData\Local\EmieBrowserModeList 2015-01-05 07:06 - 2015-01-05 15:01 - 00000112 _____ () C:\Windows\setupact.log 2015-01-05 07:06 - 2015-01-05 07:06 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-04 23:03 - 2015-01-04 23:03 - 00035905 _____ () C:\Users\Jo\Desktop\Addition.txt 2015-01-04 23:03 - 2015-01-04 23:03 - 00031380 _____ () C:\Users\Jo\Desktop\FRST.txt 2015-01-04 23:00 - 2015-01-05 16:40 - 00000000 ____D () C:\FRST 2015-01-04 20:48 - 2015-01-04 20:48 - 00072122 _____ () C:\Users\Jo\Desktop\cc_20150104_204848.reg 2014-12-29 18:42 - 2015-01-05 15:21 - 00000000 ____D () C:\Users\Jo\AppData\Roaming\Compatibility Verifier 2014-12-28 20:20 - 2014-12-28 20:20 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2014-12-21 11:51 - 2014-12-21 11:51 - 00000000 ____D () C:\ProgramData\vsosdk 2014-12-21 11:14 - 2014-12-21 11:14 - 00000000 ____D () C:\Users\Jo\Documents\4Videosoft Studio 2014-12-21 11:13 - 2014-12-21 11:13 - 00000000 ____D () C:\Users\Jo\AppData\Local\4Videosoft Studio 2014-12-21 11:12 - 2014-12-21 11:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4Videosoft 2014-12-21 11:12 - 2014-12-21 11:12 - 00000000 ____D () C:\ProgramData\4Videosoft Studio 2014-12-21 11:12 - 2014-12-21 11:12 - 00000000 ____D () C:\Program Files (x86)\4Videosoft Studio 2014-12-20 18:00 - 2014-12-20 18:00 - 00000849 _____ () C:\Users\Jo\Desktop\Nappistar - Verknüpfung.lnk 2014-12-20 12:00 - 2014-12-20 12:00 - 00000000 ____D () C:\Users\Public\Documents\{F0489EF2-D393-4114-85BA-A94D71D89543} 2014-12-20 11:46 - 2014-12-20 11:46 - 00000859 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Napster 5.lnk 2014-12-20 11:46 - 2014-12-20 11:46 - 00000847 _____ () C:\Users\Public\Desktop\Napster 5.lnk 2014-12-20 11:46 - 2014-12-20 11:46 - 00000000 ____D () C:\Program Files (x86)\Napster 5 2014-12-20 11:40 - 2014-12-20 11:40 - 00002609 _____ () C:\Users\Public\Desktop\Napster Rienf Repair.lnk 2014-12-20 11:40 - 2014-12-20 11:40 - 00000000 ____D () C:\Users\Jo\AppData\Local\NapsterRienfRepair 2014-12-20 11:40 - 2014-12-20 11:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Napster Rienf Repair 2014-12-20 11:40 - 2014-12-20 11:40 - 00000000 ____D () C:\Program Files (x86)\NA 2014-12-15 20:33 - 2014-12-15 20:33 - 00000000 ____D () C:\Users\Jo\Documents\default 2014-12-13 10:46 - 2014-12-13 10:46 - 00000000 ____D () C:\Users\Jo\Desktop\up221 2014-12-10 22:01 - 2014-12-10 22:01 - 00000512 __RSH () C:\ProgramData\ntuser.pol 2014-12-10 22:00 - 2014-12-10 22:32 - 00000000 __SHD () C:\AI_RecycleBin 2014-12-10 19:31 - 2014-12-10 19:31 - 00000000 ____D () C:\Users\Jo\AppData\Local\hitsblender 2014-12-10 19:31 - 2014-12-10 19:31 - 00000000 ____D () C:\Program Files (x86)\HitsBlenderUpdater 2014-12-10 19:24 - 2014-12-10 19:24 - 00000000 ____D () C:\Program Files (x86)\DB6FA7A7-844E-4017-92E2-73FA405F7637 2014-12-10 19:21 - 2015-01-04 15:45 - 00000000 ____D () C:\Program Files\010 2014-12-10 19:21 - 2014-12-10 19:21 - 00000000 ____D () C:\Program Files\DB6FA7A7-844E-4017-92E2-73FA405F7637 2014-12-09 20:05 - 2014-12-10 22:32 - 00000000 ____D () C:\Program Files (x86)\Audials 2014-12-09 20:02 - 2014-12-09 20:02 - 00000000 ____D () C:\Users\Jo\AppData\Local\Tempaf33c2f9cc86c2a73dc08b44799b0616 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-05 16:24 - 2013-02-28 13:43 - 00000000 ____D () C:\Program Files\JDownloader 2 2015-01-05 16:17 - 2014-09-22 08:02 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-05 15:08 - 2009-07-14 05:45 - 00031776 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-05 15:08 - 2009-07-14 05:45 - 00031776 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-05 15:07 - 2011-04-12 08:43 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2015-01-05 15:07 - 2011-04-12 08:43 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2015-01-05 15:07 - 2009-07-14 06:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-05 15:04 - 2012-07-24 15:42 - 01796289 _____ () C:\Windows\WindowsUpdate.log 2015-01-05 15:01 - 2014-11-09 12:25 - 00372736 ___SH () C:\Users\Jo\Desktop\Thumbs.db 2015-01-05 15:01 - 2014-09-22 08:02 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-05 15:01 - 2014-08-24 13:32 - 00000432 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2015-01-05 15:01 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-04 20:50 - 2013-11-17 23:29 - 00000000 ____D () C:\Windows\Minidump 2015-01-04 20:50 - 2012-09-22 17:11 - 00000000 ____D () C:\Users\Jo\AppData\Roaming\DAEMON Tools Lite 2015-01-04 20:50 - 2012-07-23 11:04 - 00000000 ____D () C:\Program Files (x86)\Steam 2015-01-04 20:50 - 2012-03-14 12:10 - 00000000 ____D () C:\Windows\Panther 2015-01-04 20:31 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-04 18:54 - 2014-09-15 10:40 - 00000686 ____H () C:\bdr-cf01 2015-01-04 17:35 - 2014-09-22 08:10 - 00000000 ___RD () C:\Users\Jo\Google Drive 2015-01-04 16:09 - 2014-09-15 12:03 - 00253404 ____H () C:\bdr-ld01 2015-01-04 16:09 - 2014-09-15 12:03 - 00009216 ____H () C:\bdr-ld01.mbr 2015-01-04 15:46 - 2012-12-01 19:25 - 00003914 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{742037F3-38E2-4FC3-9720-FAA4E822EB23} 2014-12-30 23:03 - 2012-09-11 10:25 - 00000000 ____D () C:\ProgramData\Origin 2014-12-30 17:55 - 2012-09-11 10:25 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-12-30 01:01 - 2014-09-09 20:19 - 00000000 ____D () C:\ProgramData\Package Cache 2014-12-29 22:55 - 2012-10-25 17:58 - 00000000 ___RD () C:\Users\Jo\Downloads\Bitdefender Safepay 2014-12-21 14:17 - 2012-07-23 18:48 - 00000000 ____D () C:\Users\Jo\AppData\Roaming\vlc 2014-12-20 11:57 - 2012-12-18 17:23 - 00000000 ____D () C:\Users\Jo\AppData\Roaming\com.Rhapsody.Napster5 2014-12-20 11:45 - 2014-06-24 22:01 - 00000000 ____D () C:\Users\Jo\AppData\Local\Adobe 2014-12-11 09:18 - 2014-10-08 13:13 - 00002141 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-12-10 22:32 - 2012-12-18 19:41 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-12-10 22:23 - 2009-07-14 03:34 - 00000601 _____ () C:\Windows\win.ini 2014-12-10 21:33 - 2012-07-23 22:10 - 00000000 ____D () C:\Users\Jo\AppData\Roaming\FileZilla 2014-12-10 20:31 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\GroupPolicy 2014-12-10 18:41 - 2014-10-11 17:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-12-09 20:05 - 2012-12-18 19:41 - 00000000 ____D () C:\ProgramData\RapidSolution 2014-12-09 20:04 - 2012-12-18 19:40 - 00000000 ____D () C:\Users\Jo\AppData\Local\RapidSolution 2014-12-09 19:58 - 2012-07-20 08:52 - 00000000 ____D () C:\Users\Jo\AppData\Local\Deployment Some content of TEMP: ==================== C:\Users\Jo\AppData\Local\Temp\amazonicon_v10.exe C:\Users\Jo\AppData\Local\Temp\amazoninstallernircmdc.exe C:\Users\Jo\AppData\Local\Temp\Audials_Tunebite_Premium-Setup.exe C:\Users\Jo\AppData\Local\Temp\bBJ3E2UlbM.exe C:\Users\Jo\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpa0l6o1.dll C:\Users\Jo\AppData\Local\Temp\jre-8u25-windows-au.exe C:\Users\Jo\AppData\Local\Temp\optprosetup.exe C:\Users\Jo\AppData\Local\Temp\proxy_vole8491966454438958071.dll C:\Users\Jo\AppData\Local\Temp\sdan.exe C:\Users\Jo\AppData\Local\Temp\sdapk.exe C:\Users\Jo\AppData\Local\Temp\sdaspwn.exe C:\Users\Jo\AppData\Local\Temp\SRLDetectionLibrary6762623128406172098.dll C:\Users\Jo\AppData\Local\Temp\vlc-2.1.5-win32.exe C:\Users\Jo\AppData\Local\Temp\wBiRJxuqZ2.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-28 21:02 ==================== End Of Log ============================ --- --- --- Danke Schrauber Geändert von Jo85 (05.01.2015 um 16:46 Uhr) Grund: Falsch gemacht sorry |
Themen zu BitdefenderIS15 kann Adware.AdPeak.V nicht löschen. |
.dll, antivirus, bitdefender 2015, browser, computer, converter, defender, desktop, explorer, festplatte, firewall, flash player, format, google, home, hotspot, infizierte, musik, realtek, registry, rundll, scan, security, software, system, usb, windows |