![]() |
|
Plagegeister aller Art und deren Bekämpfung: verstellte Internet-SuchfunktionWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() verstellte Internet-Suchfunktion Hallo Schrauber, normalerweise nutze ich Mozilla und nutze No-Script, damit nicht ungefragt Skripte geöffnet werden. Bei meinem VPN-Zugang geht das nicht: für Journal-Recherche nutze ich Opera und das geht nur ohne No-Script, sonst kann ich mich nicht einloggen. Bei den Recherchen wurde ich gestern aufmerksam gemacht, dass ich meinen Flash-Player aktualiseren muss, (was ich bei mozilla bereits getan habe). Aus Dummheit habe ich da draufgeklickt und wurde zu einer Adobe-Seite geführt (ich weiss aber nicht, ob die echt war). Seit dem bin ich der Meinung, dass ich bei Eingabe von Suchbegiffen nur noch die Sachen finde, die ich garnicht suche. Hast Du eine Idee? Ein FRST-File habe ich hier schon gemacht: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-02-2015 Ran by Jane (administrator) on STUART on 08-02-2015 10:50:02 Running from D:\Jane\Privat\Computersicherheit Loaded Profiles: Jane & (Available profiles: Jane) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (FileOpen Systems Inc.) C:\Program Files\FileOpen\Services\FileOpenManagerService64.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Aladdin Knowledge Systems Ltd.) C:\Windows\System32\hasplms.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe () C:\ProgramData\MobileBrServ\mbbService.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NTI, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe () C:\Program Files (x86)\OpenVPN Technologies\PrivateTunnel\core\capiws.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (FileOpen Systems Inc.) C:\Program Files\FileOpen\Services\FileOpenBroker64.exe (Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Safe 15\SteganosBrowserMonitor.exe (FileHippo.com) C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Program Files (x86)\Nokia\Nokia Internet Modem\NokiaInternetModem_AppStart.exe (Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Safe 15\SteganosHotKeyService.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Safe 15\fredirstarter.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\winword.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\excel.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe Failed to access process -> dllhost.exe Failed to access process -> dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11101800 2010-07-29] (Realtek Semiconductor) HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324608 2010-06-10] (Alcor Micro Corp.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-18] (Synaptics Incorporated) HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860040 2011-01-05] (Acer Incorporated) HKLM\...\Run: [FileOpenBroker] => C:\Program Files\FileOpen\Services\FileOpenBroker64.exe [1092528 2012-10-17] (FileOpen Systems Inc.) HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-28] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-09-18] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-09-18] (Egis Technology Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340336 2010-09-28] (Egis Technology Inc.) HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [NokiaInternetModem_AppStart.exe] => C:\Program Files (x86)\Nokia\Nokia Internet Modem\NokiaInternetModem.exe [138368 2011-12-02] (Nokia) HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [134624 2014-07-23] (Check Point Software Technologies Ltd.) HKLM-x32\...\Run: [Steganos HotKeys] => C:\Program Files (x86)\Steganos Safe 15\SteganosHotKeyService.exe [99840 2013-09-24] (Steganos Software GmbH) HKLM-x32\...\Run: [SAFE15 File Redirection Starter] => C:\Program Files (x86)\Steganos Safe 15\fredirstarter.exe [17408 2014-02-21] (Steganos Software GmbH) HKU\S-1-5-21-2358124735-2455735417-86444415-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2010-11-26] (Acresso Corporation) HKU\S-1-5-21-2358124735-2455735417-86444415-1000\...\Run: [SAFE15 Browser Monitor] => C:\Program Files (x86)\Steganos Safe 15\SteganosBrowserMonitor.exe [70656 2014-02-21] (Steganos Software GmbH) HKU\S-1-5-21-2358124735-2455735417-86444415-1000\...\Run: [FileHippo.com] => C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [695808 2014-09-10] (FileHippo.com) HKU\S-1-5-21-2358124735-2455735417-86444415-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-2358124735-2455735417-86444415-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2010-11-26] (Acresso Corporation) HKU\S-1-5-21-2358124735-2455735417-86444415-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SAFE15 Browser Monitor] => C:\Program Files (x86)\Steganos Safe 15\SteganosBrowserMonitor.exe [70656 2014-02-21] (Steganos Software GmbH) HKU\S-1-5-21-2358124735-2455735417-86444415-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [FileHippo.com] => C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [695808 2014-09-10] (FileHippo.com) HKU\S-1-5-21-2358124735-2455735417-86444415-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jane\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jane\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jane\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jane\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jane\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jane\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jane\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2358124735-2455735417-86444415-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-2358124735-2455735417-86444415-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2358124735-2455735417-86444415-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-2358124735-2455735417-86444415-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{8BF89013-52EF-4306-AFD1-0F8F6B795861}: [NameServer] 139.7.30.125 139.7.30.126 FireFox: ======== FF ProfilePath: C:\Users\Jane\AppData\Roaming\Mozilla\Firefox\Profiles\clxpk72i.default-1381239029030 FF Homepage: hxxp://www.christianehohensee.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @cdisys.com/SafeView -> C:\Program Files (x86)\SafeView\npsfvw.dll (C.D.I. Systems (1992) Ltd.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Jane\AppData\Roaming\Mozilla\Firefox\Profiles\clxpk72i.default-1381239029030\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Jane\AppData\Roaming\Mozilla\Firefox\Profiles\clxpk72i.default-1381239029030\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Jane\AppData\Roaming\Mozilla\Firefox\Profiles\clxpk72i.default-1381239029030\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Jane\AppData\Roaming\Mozilla\Firefox\Profiles\clxpk72i.default-1381239029030\searchplugins\webde-suche.xml FF Extension: NoScript - C:\Users\Jane\AppData\Roaming\Mozilla\Firefox\Profiles\clxpk72i.default-1381239029030\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-10-08] FF Extension: Adblock Plus - C:\Users\Jane\AppData\Roaming\Mozilla\Firefox\Profiles\clxpk72i.default-1381239029030\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-03] FF Extension: DownThemAll! - C:\Users\Jane\AppData\Roaming\Mozilla\Firefox\Profiles\clxpk72i.default-1381239029030\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2013-10-08] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-30] FF HKU\S-1-5-21-2358124735-2455735417-86444415-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] FF HKU\S-1-5-21-2358124735-2455735417-86444415-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi Chrome: ======= CHR Profile: C:\Users\Jane\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Jane\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-04-20] CHR Extension: (Google Drive) - C:\Users\Jane\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-20] CHR Extension: (YouTube) - C:\Users\Jane\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-20] CHR Extension: (Google Search) - C:\Users\Jane\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-20] CHR Extension: (Chrome In-App Payments service) - C:\Users\Jane\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-03] CHR Extension: (Gmail) - C:\Users\Jane\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-20] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation) R2 FileOpenManagerService; C:\Program Files\FileOpen\Services\FileOpenManagerService64.exe [335288 2012-10-17] (FileOpen Systems Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [232288 2012-03-12] () R2 NTISchedulerSvc; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144640 2010-04-17] (NTI, Inc.) R2 OpenVPNAccessClient; C:\Program Files (x86)\OpenVPN Technologies\PrivateTunnel\core\capiws.exe [24064 2012-10-12] () [File not signed] S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [38200 2014-12-01] (The OpenVPN Project) S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015i\RpcAgentSrv.exe [73200 2014-12-17] (SiSoftware) [File not signed] R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [3596240 2014-07-23] (Check Point Software Technologies Ltd.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [93712 2014-07-03] (Check Point Software Technologies, Ltd.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-14] (Avira Operations GmbH & Co. KG) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-08] (Malwarebytes Corporation) S3 nokia_usb_modem_cdc_acm; C:\Windows\System32\DRIVERS\nokia_usb_modem_cdc_acm.sys [79872 2011-06-22] (Nokia) S3 nokia_usb_modem_cdc_ecm; C:\Windows\System32\DRIVERS\nokia_usb_modem_cdc_ecm.sys [58880 2011-06-22] (Nokia) S3 nokia_usb_modem_cpo; C:\Windows\System32\DRIVERS\nokia_usb_modem_cpo.sys [14336 2011-06-22] (Nokia) S3 nokia_usb_modem_ecm_enum; C:\Windows\System32\DRIVERS\nokia_usb_modem_ecm_enum.sys [56320 2011-06-22] (Nokia) S3 nokia_usb_modem_ecm_enum_filter; C:\Windows\System32\DRIVERS\nokia_usb_modem_ecm_enum_filter.sys [56320 2011-06-22] (Nokia) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2010-08-16] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2010-08-16] () S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015i\WNt600x64\Sandra.sys [23112 2009-08-07] (SiSoftware) R1 SLEE_18_DRIVER; C:\Windows\Sleen1864.sys [109144 2014-01-30] (Softwareentwicklung Remus - ArchiCrypt - ) R3 tapoas; C:\Windows\System32\DRIVERS\tapoas.sys [30720 2012-07-15] (The OpenVPN Project) R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [450456 2014-07-22] (Check Point Software Technologies Ltd.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-04 10:20 - 2015-02-04 10:20 - 00000093 _____ () C:\Windows\wininit.ini 2015-02-03 14:00 - 2015-02-04 09:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2015-02-03 11:47 - 2015-02-03 11:48 - 00237056 _____ () C:\Users\Jane\Desktop\STUNDEN2015-CH.xls 2015-02-01 22:27 - 2014-11-11 11:33 - 31389440 _____ (Mozilla) C:\Users\Jane\Downloads\Thunderbird Setup 34.0b1.exe 2015-02-01 19:48 - 2015-02-01 21:04 - 00007868 _____ () C:\Users\Jane\Desktop\Mircoarray-Überprüfungen der Pathways.txt 2015-02-01 06:46 - 2015-02-01 06:46 - 00000830 _____ () C:\Users\Jane\Documents\Mircoarray von Rho.txt 2015-02-01 01:03 - 2015-02-01 21:04 - 00025184 _____ () C:\Users\Jane\Desktop\Pathways Migration Neurosphären 110614.xlsx 2015-01-31 10:13 - 2015-01-31 10:13 - 00000000 ____D () C:\Users\Jane\Tracing 2015-01-31 10:08 - 2015-01-31 10:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-01-31 10:05 - 2015-01-31 10:05 - 46882112 _____ (Dropbox, Inc.) C:\Users\Jane\Downloads\Dropbox 3.0.5.exe 2015-01-31 10:02 - 2015-01-28 09:44 - 01548384 _____ (Skype Technologies S.A.) C:\Users\Jane\Downloads\SkypeSetup.exe 2015-01-30 21:04 - 2015-02-04 14:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-29 17:45 - 2015-01-29 17:45 - 00120688 _____ () C:\Users\Jane\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-27 04:32 - 2015-01-28 11:27 - 00000000 ____D () C:\Users\Jane\Desktop\alte Sachen 2015-01-26 17:36 - 2015-01-27 10:02 - 00000000 ____D () C:\Users\Jane\Desktop\Vortrag heute 2015-01-26 11:03 - 2015-01-31 10:08 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-01-14 08:39 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 08:39 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 08:39 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 08:39 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-14 08:39 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-14 08:38 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 08:38 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-01-14 08:38 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-01-14 08:38 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-01-14 08:38 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-14 08:38 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-14 08:38 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-14 08:38 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-13 22:51 - 2015-01-14 08:48 - 00000000 ____D () C:\Users\Jane\AppData\Local\Box Sync 2015-01-13 22:48 - 2015-01-13 22:51 - 00000000 ____D () C:\ProgramData\Package Cache 2015-01-13 22:43 - 2015-01-13 22:43 - 25790720 _____ (Box Inc.) C:\Users\Jane\Downloads\BoxSyncSetup.exe 2015-01-12 13:30 - 2015-02-07 19:11 - 00000000 ____D () C:\Users\Jane\Desktop\Neue Lit Masterarbeit 2015-01-11 11:31 - 2015-01-31 09:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SiSoftware 2015-01-11 11:31 - 2015-01-11 11:31 - 00000000 ____D () C:\Program Files\SiSoftware 2015-01-11 11:31 - 2014-11-26 06:30 - 14368768 _____ () C:\Users\Jane\AppData\Roaming\Sandra.mdb 2015-01-11 11:21 - 2015-01-11 11:21 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1 2015-01-11 10:59 - 2015-01-11 10:59 - 00000000 ____D () C:\Windows\en 2015-01-11 10:57 - 2015-01-11 10:57 - 00000000 ____D () C:\Windows\fi 2015-01-11 10:57 - 2015-01-11 10:57 - 00000000 ____D () C:\Windows\es 2015-01-11 10:57 - 2015-01-11 10:57 - 00000000 ____D () C:\Windows\el 2015-01-11 10:57 - 2015-01-11 10:57 - 00000000 ____D () C:\Windows\de 2015-01-11 10:57 - 2015-01-11 10:57 - 00000000 ____D () C:\Windows\da 2015-01-11 10:57 - 2015-01-11 10:57 - 00000000 ____D () C:\Windows\cs 2015-01-11 10:57 - 2015-01-11 10:57 - 00000000 ____D () C:\Windows\bg 2015-01-11 10:57 - 2015-01-11 10:57 - 00000000 ____D () C:\Windows\ar 2015-01-11 10:56 - 2015-01-11 10:56 - 00000000 ____D () C:\Windows\ro 2015-01-11 10:56 - 2015-01-11 10:56 - 00000000 ____D () C:\Windows\pl 2015-01-11 10:56 - 2015-01-11 10:56 - 00000000 ____D () C:\Windows\nl 2015-01-11 10:56 - 2015-01-11 10:56 - 00000000 ____D () C:\Windows\it 2015-01-11 10:56 - 2015-01-11 10:56 - 00000000 ____D () C:\Windows\hu 2015-01-11 10:56 - 2015-01-11 10:56 - 00000000 ____D () C:\Windows\hr 2015-01-11 10:56 - 2015-01-11 10:56 - 00000000 ____D () C:\Windows\he 2015-01-11 10:56 - 2015-01-11 10:56 - 00000000 ____D () C:\Windows\fr 2015-01-11 10:55 - 2015-01-11 10:55 - 00001269 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk 2015-01-11 10:55 - 2015-01-11 10:55 - 00000000 ____D () C:\Windows\tr 2015-01-11 10:55 - 2015-01-11 10:55 - 00000000 ____D () C:\Windows\th 2015-01-11 10:55 - 2015-01-11 10:55 - 00000000 ____D () C:\Windows\sv 2015-01-11 10:55 - 2015-01-11 10:55 - 00000000 ____D () C:\Windows\sl 2015-01-11 10:55 - 2015-01-11 10:55 - 00000000 ____D () C:\Windows\sk 2015-01-11 10:55 - 2015-01-11 10:55 - 00000000 ____D () C:\Windows\ru 2015-01-11 10:55 - 2015-01-11 10:55 - 00000000 ____D () C:\Windows\ca 2015-01-11 10:54 - 2015-01-11 10:54 - 00001338 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk 2015-01-11 10:32 - 2014-03-31 21:06 - 00058056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fssfltr.sys 2015-01-11 10:31 - 2015-01-11 10:32 - 00000000 ____D () C:\Program Files\Windows Live 2015-01-11 10:23 - 2014-04-17 12:38 - 01239752 _____ (Microsoft Corporation) C:\Users\Jane\Downloads\wlsetup-web.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-08 10:50 - 2015-01-03 20:26 - 00000000 ____D () C:\FRST 2015-02-08 10:37 - 2014-05-02 15:36 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-08 10:30 - 2012-01-07 08:40 - 00000384 _____ () C:\Windows\Tasks\Acer Registration - Data Sending task.job 2015-02-08 10:25 - 2012-04-13 07:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-02-08 10:24 - 2012-01-07 10:17 - 00000000 ____D () C:\Users\Jane\AppData\Roaming\Skype 2015-02-08 02:43 - 2012-01-05 12:52 - 01118538 _____ () C:\Windows\WindowsUpdate.log 2015-02-07 20:44 - 2012-01-23 16:33 - 00000000 ____D () C:\Users\Jane\AppData\Local\FreePDF_XP 2015-02-07 10:50 - 2009-07-14 05:45 - 00024656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-07 10:50 - 2009-07-14 05:45 - 00024656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-06 12:13 - 2013-10-26 19:33 - 03649536 ___SH () C:\Users\Jane\Desktop\Thumbs.db 2015-02-05 16:31 - 2014-08-15 09:51 - 00000000 ____D () C:\Users\Jane\AppData\Local\Adobe 2015-02-05 16:30 - 2012-04-13 07:24 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-05 16:30 - 2012-04-13 07:24 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-02-05 16:30 - 2012-01-07 11:08 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-02-04 20:59 - 2012-12-15 19:07 - 00131072 _____ () C:\Windows\system32\Ikeext.etl 2015-02-04 20:59 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-04 20:59 - 2009-07-14 05:51 - 00195635 _____ () C:\Windows\setupact.log 2015-02-04 14:02 - 2012-12-15 18:25 - 00006424 _____ () C:\Users\Jane\ovpntray.log 2015-02-04 14:02 - 2012-01-07 08:31 - 00000000 ____D () C:\Users\Jane 2015-02-04 14:01 - 2012-04-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-02-04 14:01 - 2010-11-21 04:47 - 02500824 _____ () C:\Windows\PFRO.log 2015-02-04 10:13 - 2014-07-11 19:27 - 01052672 ___SH () C:\Users\Jane\Downloads\Thumbs.db 2015-02-03 21:10 - 2014-11-02 20:59 - 00003848 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1383253405 2015-02-03 21:10 - 2013-10-31 22:03 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-02-02 18:49 - 2014-04-28 09:30 - 00000000 __RHD () C:\MSOCache 2015-02-01 22:32 - 2012-01-07 10:09 - 00002062 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk 2015-01-31 15:37 - 2014-10-13 22:58 - 00000000 ____D () C:\Users\Jane\Desktop\IVJ-Themen 2015-01-31 10:08 - 2011-08-25 14:23 - 00000000 ____D () C:\ProgramData\Skype 2015-01-28 14:29 - 2012-01-07 10:22 - 00000000 ____D () C:\Users\Jane\AppData\Roaming\Wise Disk Cleaner 2015-01-26 11:03 - 2011-08-25 15:12 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2015-01-22 13:27 - 2014-10-09 20:45 - 00000000 ____D () C:\Users\Jane\Desktop\Neuroartikel 2015-01-16 20:43 - 2011-08-25 14:08 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-01-16 20:37 - 2013-06-04 16:40 - 00000000 ____D () C:\Users\Jane\AppData\Local\Apps\2.0 2015-01-15 00:05 - 2013-08-15 07:00 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-15 00:00 - 2012-01-07 10:40 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-12 08:03 - 2009-07-14 05:45 - 00466480 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-11 13:34 - 2013-09-11 17:18 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2015-01-11 11:15 - 2012-01-07 10:09 - 00000000 ____D () C:\Users\Jane\AppData\Local\Thunderbird 2015-01-11 10:57 - 2011-08-25 15:25 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live 2015-01-11 10:46 - 2011-08-25 15:12 - 00001422 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk 2015-01-11 10:29 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2015-01-11 10:27 - 2011-08-25 15:08 - 00159353 _____ () C:\Windows\DirectX.log 2015-01-11 10:24 - 2012-01-07 08:31 - 00000000 ____D () C:\Users\Jane\AppData\Local\Windows Live 2015-01-09 12:29 - 2014-06-15 11:55 - 00000000 ____D () C:\Users\Jane\Desktop\Tiermodelle ==================== Files in the root of some directories ======= 2015-01-11 11:31 - 2014-11-26 06:30 - 14368768 _____ () C:\Users\Jane\AppData\Roaming\Sandra.mdb 2013-01-09 14:33 - 2015-01-05 15:43 - 0004608 _____ () C:\Users\Jane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2011-08-25 14:23 - 2010-03-02 22:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe Some content of TEMP: ==================== C:\Users\Jane\AppData\Local\Temp\avgnt.exe C:\Users\Jane\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= |
Themen zu verstellte Internet-Suchfunktion |
.dll, administrator, antivir, avira, browser, combofix, defender, desktop, down, explorer, firefox, flash player, google, home, homepage, internetsuche, mozilla, realtek, registry, security, software, svchost.exe, system, temp, usb, windows |