|
Plagegeister aller Art und deren Bekämpfung: db29.exe. kommt immer wieder trotz virenscan und quarantäneWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.02.2015, 21:45 | #1 |
| db29.exe. kommt immer wieder trotz virenscan und quarantäne hallo, avira hat den virus db29.exe (TR/FakeAV.1169920.6) festgestellt. Ab und zu taucht zusätlich zu dieser warnung die meldung über ADWARE/AdSuproot.99496 auf. Mein PC ist extrem langsam und das internet auch. In Quarantäne verschieben bringt nix da die Meldung über die beiden sachen immer wieder kommen. ich habe windows 7. Geändert von kleine20 (14.02.2015 um 21:51 Uhr) |
14.02.2015, 22:27 | #2 |
/// the machine /// TB-Ausbilder | db29.exe. kommt immer wieder trotz virenscan und quarantäne Hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
14.02.2015, 22:58 | #3 |
| db29.exe. kommt immer wieder trotz virenscan und quarantäne hallo, habe alles aus der hilfesuchendenanleitung gemacht. habe alle logs bin alles schritt für schritt durchgegangen.
__________________FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-02-2015 Ran by Kerstin (administrator) on KERSTIN-PC on 14-02-2015 22:08:13 Running from C:\Users\Kerstin\Downloads Loaded Profiles: Kerstin (Available profiles: Kerstin) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Spotify Ltd) C:\Users\Kerstin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe () C:\Program Files\004\rqpbhevlkc64.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe () C:\Users\Kerstin\Desktop\Defogger.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\updrgui.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [ESET-Phase2] => C:\ProgramData\ESET\ESET-phase2.exe [1100656 2010-11-10] () HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-01-27] (Apple Inc.) HKLM-x32\...\Run: [fst_de_7] => [X] HKLM-x32\...\Run: [Registry Helper] => "C:\Program Files (x86)\Registry Helper\RegistryHelper.Exe" /boot HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [Browser Infrastructure Helper] => C:\Users\Kerstin\AppData\Local\Smartbar\Application\SnapDo.exe startup HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [Spotify Web Helper] => C:\Users\Kerstin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-06-16] (Spotify Ltd) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [Spotify] => C:\Users\Kerstin\AppData\Roaming\Spotify\spotify.exe [6170168 2014-06-16] (Spotify Ltd) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\MountPoints2: {1359343c-d41d-11e3-9b93-00224d7b4b93} - E:\Startme.exe HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\MountPoints2: {36cd75b7-d3b9-11e3-8ef6-806e6f6e6963} - D:\auto.exe HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\MountPoints2: {e61beb75-02d0-11e4-b082-00224d7b4b93} - E:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.A11B02 PID_0083 GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_howCorPPPyzMfc8qrgBOhqWBn7kuAVVgEJVs0L86QrR_l8h9uutX0rgf97u6zEC5OFGSB1d7wjH6Oarpbx1exyiHUnMhhXy_o6EJJs4zfSUIz50GIpXGRBEJ1UbqhJFPvkmIaXdKWcFm&q={searchTerms} HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Start Page = Search HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = webssearches HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://syb.msn.com GIGA ANDROID | Android News, Tests und Anleitungen | androidnews.de HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://syb.msn.com HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_howCorPPPyzMfc8qrgBOhqWBn7kuAVVgEJVs0L86QrR_l8h9uutX0rgf97u6zEC5OFGSB1d7wjH6Oarpbx1exyiHUnMhhXy_o6EJJs4zfSUIz50GIpXGRBEJ1UbqhJFPvkmIaXdKWcFm&q={searchTerms} SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM -> {05B62290-31C8-45EC-99C6-F05963923521} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSBTDF&pc=MASB&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = hxxp://www.default-search.net/search?sid=492&aid=103&itype=a&ver=12521&tm=339&src=ds&p={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_howCorPPPyzMfc8qrgBOhqWBn7kuAVVgEJVs0L86QrR_l8h9uutX0rgf97u6zEC5OFGSB1d7wjH6Oarpbx1exyiHUnMhhXy_o6EJJs4zfSUIz50GIpXGRBEJ1UbqhJFPvkmIaXdKWcFl&q={searchTerms} SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_howCorPPPyzMfc8qrgBOhqWBn7kuAVVgEJVs0L86QrR_l8h9uutX0rgf97u6zEC5OFGSB1d7wjH6Oarpbx1exyiHUnMhhXy_o6EJJs4zfSUIz50GIpXGRBEJ1UbqhJFPvkmIaXdKWcFl&q={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2890383179-3499982190-3409672644-1001 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_howCorPPPyzMfc8qrgBOhqWBn7kuAVVgEJVs0L86QrR_l8h9uutX0rgf97u6zEC5OFGSB1d7wjH6Oarpbx1exyiHUnMhhXy_o6EJJs4zfSUIz50GIpXGRBEJ1UbqhJFPvkmIaXdKWcFm&q={searchTerms} SearchScopes: HKU\S-1-5-21-2890383179-3499982190-3409672644-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_howCorPPPyzMfc8qrgBOhqWBn7kuAVVgEJVs0L86QrR_l8h9uutX0rgf97u6zEC5OFGSB1d7wjH6Oarpbx1exyiHUnMhhXy_o6EJJs4zfSUIz50GIpXGRBEJ1UbqhJFPvkmIaXdKWcFm&q={searchTerms} BHO: Snap.DoEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: CouponDownloader -> {10AD2C61-0898-4348-8600-14A342F22AC3} -> C:\Program Files (x86)\Coupon Downloader\Coupon Downloader.dll () BHO-x32: Snap.DoEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe webssearches FireFox: ======== FF ProfilePath: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default FF SearchEngineOrder.1: default-search.net FF Homepage: hxxp://go.1und1.de/tb/mff_startpage|hxxp://www.giga.de/androidnews/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2890383179-3499982190-3409672644-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kerstin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-2890383179-3499982190-3409672644-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF user.js: detected! => C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\user.js FF SearchPlugin: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\ask-search.xml FF SearchPlugin: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\webssearches.xml FF Extension: Med Play Air ++ - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com [2015-01-01] FF Extension: SparPilot - Gutscheine & mehr... - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\sparpilot@sparpilot.com [2015-02-10] FF Extension: WEB.DE MailCheck - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\toolbar@web.de [2015-02-10] FF Extension: anonymoX - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\client@anonymox.net.xpi [2014-05-08] FF Extension: Trusted Shops Add-On für Firefox - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\jid1-PBNne26X1Kn6hQ@jetpack.xpi [2014-08-05] FF Extension: {0db9152f-2c09-4a6a-b006-6852e1787975} - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\{0db9152f-2c09-4a6a-b006-6852e1787975}.xpi [2015-02-10] FF HKLM\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox FF HKLM\...\Firefox\Extensions: [{01856272-60D2-48c0-8F8F-852C369B15A1}] - C:\Program Files\Slotomania Coin Expansion Pack\Firefox FF HKLM-x32\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox FF HKLM-x32\...\Firefox\Extensions: [{01856272-60D2-48c0-8F8F-852C369B15A1}] - C:\Program Files\Slotomania Coin Expansion Pack\Firefox FF HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\extensions\cliqz@cliqz.com Chrome: ======= CHR HomePage: Default -> hxxp://istart.webssearches.com/?type=hppp&ts=1402753960&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062 CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hppp&ts=1402753960&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062" CHR DefaultSearchKeyword: Default -> webssearches CHR DefaultSearchURL: Default -> hxxp://istart.webssearches.com/web/?type=dspp&ts=1402826947&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062&q={searchTerms} CHR DefaultSuggestURL: Default -> CHR Profile: C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-16] CHR Extension: (Google Drive) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-16] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27] CHR Extension: (YouTube) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-16] CHR Extension: (Slotomania Coin Expansion Pack) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmonpfhhpdjphhlanhockbccaakgahgh [2014-05-28] CHR Extension: (Google-Suche) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-16] CHR Extension: (Mediaa_Play_AIR_1.4) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek [2014-06-14] CHR Extension: (Google Wallet) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-16] CHR Extension: (MapsGalaxy) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhjnggbngfbgghjfkmpcnihbgnehgeo [2014-11-08] CHR Extension: (Google Mail) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) R2 rqpbhevlkc64; C:\Program Files\004\rqpbhevlkc64.exe [709120 2014-05-06] () [File not signed] S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-05-09] (Avira Operations GmbH & Co. KG) R3 igddim64; C:\Windows\System32\DRIVERS\igddim64.sys [1703936 2011-08-30] (Intel Corporation) R3 imgkmd64; C:\Windows\System32\DRIVERS\imgkmd64.sys [479232 2011-08-30] (Imagination Technologies) S3 s1029bus; C:\Windows\System32\DRIVERS\s1029bus.sys [116264 2009-05-25] (MCCI Corporation) S3 s1029mdfl; C:\Windows\System32\DRIVERS\s1029mdfl.sys [19496 2009-05-25] (MCCI Corporation) S3 s1029mdm; C:\Windows\System32\DRIVERS\s1029mdm.sys [158760 2009-05-25] (MCCI Corporation) S3 s1029mgmt; C:\Windows\System32\DRIVERS\s1029mgmt.sys [139304 2009-05-25] (MCCI Corporation) S3 s1029nd5; C:\Windows\System32\DRIVERS\s1029nd5.sys [34856 2009-05-25] (MCCI Corporation) S3 s1029obex; C:\Windows\System32\DRIVERS\s1029obex.sys [135208 2009-05-25] (MCCI Corporation) S3 s1029unic; C:\Windows\System32\DRIVERS\s1029unic.sys [151592 2009-05-25] (MCCI Corporation) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 massfilter_hs; \??\C:\Windows\system32\drivers\massfilter_hs.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X] S3 zghsmdm; system32\DRIVERS\zghsmdm.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-14 22:08 - 2015-02-14 22:10 - 00021991 _____ () C:\Users\Kerstin\Downloads\FRST.txt 2015-02-14 22:08 - 2015-02-14 22:08 - 00000000 ____D () C:\FRST 2015-02-14 22:06 - 2015-02-14 22:06 - 02134528 _____ (Farbar) C:\Users\Kerstin\Downloads\FRST64.exe 2015-02-14 22:01 - 2015-02-14 22:01 - 00000476 _____ () C:\Users\Kerstin\Desktop\defogger_disable.log 2015-02-14 22:01 - 2015-02-14 22:01 - 00000000 _____ () C:\Users\Kerstin\defogger_reenable 2015-02-14 21:58 - 2015-02-14 21:58 - 00050477 _____ () C:\Users\Kerstin\Desktop\Defogger.exe 2015-02-14 01:41 - 2015-02-14 01:41 - 00000000 ____D () C:\ProgramData\Samsung 2015-02-14 00:50 - 2015-02-14 01:42 - 00000000 ____D () C:\Users\Kerstin\Documents\samsung 2015-02-14 00:50 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log 2015-02-14 00:50 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Kerstin\Documents\SelfMV 2015-02-14 00:49 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Samsung 2015-02-14 00:49 - 2015-02-14 00:49 - 00001973 _____ () C:\Users\Public\Desktop\Samsung Kies 3.lnk 2015-02-14 00:49 - 2015-02-14 00:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2015-02-14 00:49 - 2015-02-14 00:49 - 00000000 ____D () C:\Program Files (x86)\Samsung 2015-02-14 00:49 - 2014-05-07 17:42 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\SysWOW64\secman.dll 2015-02-14 00:39 - 2015-02-14 00:40 - 42498888 _____ (Samsung Electronics Co., Ltd.) C:\Users\Kerstin\Downloads\Kies3Setup.exe 2015-02-14 00:00 - 2015-02-14 00:00 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\MyPhoneExplorer 2015-02-13 23:59 - 2015-02-13 23:59 - 00002061 _____ () C:\Users\Public\Desktop\MyPhoneExplorer.lnk 2015-02-13 23:59 - 2015-02-13 23:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer 2015-02-13 23:58 - 2015-02-13 23:59 - 00000000 ____D () C:\Program Files (x86)\MyPhoneExplorer 2015-02-13 23:40 - 2015-02-13 23:40 - 00659464 _____ () C:\Users\Kerstin\Downloads\myphoneexplorer.exe 2015-02-12 18:28 - 2014-12-05 11:32 - 139196615 _____ () C:\Users\Kerstin\20141205_113135.mp4 2015-02-12 18:28 - 2014-12-01 11:24 - 232466986 _____ () C:\Users\Kerstin\20141201_112247.mp4 2015-02-12 18:28 - 2014-11-30 11:30 - 275072892 _____ () C:\Users\Kerstin\20141130_112831.mp4 2015-02-12 18:27 - 2014-11-23 22:31 - 208943022 _____ () C:\Users\Kerstin\20141123_222952.mp4 2015-02-12 18:27 - 2014-11-14 19:52 - 136757681 _____ () C:\Users\Kerstin\20141114_195143.mp4 2015-02-12 18:27 - 2014-11-14 13:46 - 311908025 _____ () C:\Users\Kerstin\20141114_134342.mp4 2015-02-12 18:26 - 2015-01-26 08:34 - 143517436 _____ () C:\Users\Kerstin\20150126_083313.mp4 2015-02-12 18:26 - 2015-01-12 22:21 - 346180627 _____ () C:\Users\Kerstin\20150112_221907.mp4 2015-02-12 18:26 - 2015-01-01 00:11 - 00351735 _____ () C:\Users\Kerstin\20150101_001052.mp4 2015-02-12 18:26 - 2014-12-27 15:34 - 74917974 _____ () C:\Users\Kerstin\20141227_153416.mp4 2015-02-12 18:26 - 2014-12-27 15:32 - 41031175 _____ () C:\Users\Kerstin\20141227_153210.mp4 2015-02-12 18:26 - 2014-12-25 21:13 - 157444083 _____ () C:\Users\Kerstin\20141225_211203.mp4 2015-02-12 18:26 - 2014-11-09 18:32 - 356998952 _____ () C:\Users\Kerstin\20141109_182926.mp4 2015-02-12 18:25 - 2014-12-25 21:11 - 180618452 _____ () C:\Users\Kerstin\20141225_211021.mp4 2015-02-12 18:25 - 2014-12-25 14:36 - 207078718 _____ () C:\Users\Kerstin\20141225_143453.mp4 2015-02-12 18:25 - 2014-12-24 18:41 - 06138834 _____ () C:\Users\Kerstin\20141224_184113.mp4 2015-02-12 18:25 - 2014-12-20 14:14 - 239835541 _____ () C:\Users\Kerstin\20141220_141233.mp4 2015-02-12 18:25 - 2014-12-19 19:42 - 101770616 _____ () C:\Users\Kerstin\20141219_194114.mp4 2015-02-12 18:24 - 2014-12-15 19:04 - 244473975 _____ () C:\Users\Kerstin\20141215_190217.mp4 2015-02-12 18:24 - 2014-12-14 19:26 - 211934675 _____ () C:\Users\Kerstin\20141214_192449.mp4 2015-02-12 17:00 - 2015-02-12 17:00 - 00001753 _____ () C:\Users\Public\Desktop\iTunes.lnk 2015-02-12 17:00 - 2015-02-12 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-02-12 16:57 - 2015-02-12 16:59 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-02-12 16:57 - 2015-02-12 16:59 - 00000000 ____D () C:\Program Files\iTunes 2015-02-12 16:57 - 2015-02-12 16:57 - 00000000 ____D () C:\Program Files\iPod 2015-02-12 16:57 - 2015-02-12 16:57 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-02-11 20:51 - 2015-02-11 20:51 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\{B4A2C882-B21E-4B65-B513-4C4DDE94450C} 2015-02-11 14:47 - 2015-02-11 14:47 - 00000000 _____ () C:\Windows\SysWOW64\sho8A0A.tmp 2015-02-10 19:38 - 2015-02-10 19:54 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Genymobile 2015-02-10 19:38 - 2015-02-10 19:50 - 00000000 ____D () C:\Users\Kerstin\.VirtualBox 2015-02-10 19:36 - 2013-04-12 11:41 - 00237840 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys 2015-02-10 19:33 - 2013-04-12 11:40 - 00120080 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys 2015-02-10 19:31 - 2015-02-10 19:31 - 00000000 ____D () C:\Program Files\Genymobile 2015-02-10 19:29 - 2015-02-10 19:29 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Temp515a80549b13c62719b8b0be014862d3 2015-02-10 19:28 - 2015-02-10 19:28 - 01045496 _____ () C:\Users\Kerstin\Downloads\Genymotion-lnstall.exe 2015-02-10 16:37 - 2015-02-10 17:55 - 00002004 _____ () C:\Users\Kerstin\Desktop\WhatsApp.lnk 2015-02-10 16:14 - 2015-02-10 16:14 - 01198368 _____ () C:\Users\Kerstin\Downloads\BlueStacks App Player - CHIP-Installer(1).exe 2015-01-31 22:17 - 2015-01-31 22:17 - 00000000 _____ () C:\Windows\SysWOW64\sho83D.tmp 2015-01-31 11:58 - 2015-02-11 11:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-25 00:12 - 2015-01-25 00:12 - 00000000 _____ () C:\Windows\SysWOW64\sho29F1.tmp 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe 2015-01-21 19:55 - 2015-01-21 19:55 - 00386448 _____ () C:\Windows\Minidump\012115-17035-01.dmp ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-14 22:01 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin 2015-02-14 21:51 - 2014-06-14 14:51 - 00002272 _____ () C:\Windows\Tasks\0f35c805-0126-47dc-bc26-393cdbd9833d-4.job 2015-02-14 21:27 - 2009-07-14 05:45 - 00028896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-14 21:27 - 2009-07-14 05:45 - 00028896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-14 21:16 - 2014-05-16 19:46 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-14 20:04 - 2014-06-16 19:24 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Spotify 2015-02-14 20:03 - 2014-06-16 19:25 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Spotify 2015-02-14 20:02 - 2009-07-14 05:51 - 00049684 _____ () C:\Windows\setupact.log 2015-02-14 19:23 - 2014-05-04 19:26 - 01723057 _____ () C:\Windows\WindowsUpdate.log 2015-02-14 19:19 - 2014-05-04 20:18 - 01096056 _____ () C:\Users\Kerstin\Documents\ESET-installation-phase2.log 2015-02-14 19:19 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-14 19:18 - 2010-11-21 04:47 - 00199286 _____ () C:\Windows\PFRO.log 2015-02-14 19:14 - 2015-01-14 18:25 - 00000112 _____ () C:\ProgramData\5uKMmosV2.dat 2015-02-14 18:37 - 2015-01-14 18:19 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Compatibility Verifier 2015-02-14 18:29 - 2014-05-04 20:14 - 00000000 ____D () C:\ProgramData\ESET 2015-02-14 01:55 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries 2015-02-14 00:49 - 2014-05-04 19:55 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-02-12 18:29 - 2014-06-14 23:45 - 00792576 ___SH () C:\Users\Kerstin\Thumbs.db 2015-02-12 17:46 - 2010-11-21 07:50 - 00699386 _____ () C:\Windows\system32\perfh007.dat 2015-02-12 17:46 - 2010-11-21 07:50 - 00149268 _____ () C:\Windows\system32\perfc007.dat 2015-02-12 17:46 - 2009-07-14 06:13 - 01620248 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-12 16:57 - 2014-08-24 18:38 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-02-12 16:55 - 2014-08-24 18:40 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2015-02-11 21:17 - 2014-05-04 19:33 - 00001659 _____ () C:\Users\Kerstin\Desktop\Internet Explorer.lnk 2015-02-11 21:05 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Windows Live 2015-02-10 16:41 - 2014-05-21 09:54 - 00000000 ____D () C:\ProgramData\BlueStacksSetup 2015-02-09 14:19 - 2014-05-16 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-09 14:19 - 2014-05-16 10:01 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-09 14:19 - 2014-05-13 22:59 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-07 21:11 - 2014-05-16 19:46 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-07 21:11 - 2014-05-16 19:46 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-07 21:11 - 2014-05-16 19:46 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-07 19:29 - 2014-08-22 07:58 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Adobe 2015-02-07 19:29 - 2014-05-04 21:42 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-07 19:29 - 2014-05-04 21:42 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-02-07 00:15 - 2014-05-16 19:47 - 00002403 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-01-31 22:17 - 2014-05-04 22:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-24 20:10 - 2014-05-16 19:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-01-24 20:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2015-01-21 19:55 - 2014-06-20 16:18 - 00000000 ____D () C:\Windows\Minidump 2015-01-21 19:55 - 2014-05-14 21:26 - 196421006 _____ () C:\Windows\MEMORY.DMP 2015-01-19 12:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2015-01-15 23:09 - 2014-05-29 20:56 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\SoftGrid Client 2015-01-15 14:14 - 2015-01-14 23:09 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Facebook ==================== Files in the root of some directories ======= 2014-05-06 10:38 - 2014-05-06 11:10 - 0000312 _____ () C:\Users\Kerstin\AppData\Roaming\aps.uninstall.scan.results 2014-05-06 21:56 - 2014-05-06 21:56 - 0000046 _____ () C:\Users\Kerstin\AppData\Roaming\WB.CFG 2014-05-06 11:06 - 2014-05-06 14:02 - 1727775 _____ (AnyProtect.com) C:\Users\Kerstin\AppData\Local\AnyProtectScannerSetup.exe 2014-05-06 10:37 - 2014-05-06 10:37 - 1745608 _____ (AnyProtect.com) C:\Users\Kerstin\AppData\Local\nso4FB.tmp 2015-01-14 18:25 - 2015-02-14 19:14 - 0000112 _____ () C:\ProgramData\5uKMmosV2.dat 2014-05-13 21:56 - 2014-05-13 21:56 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Files to move or delete: ==================== C:\ProgramData\5uKMmosV2.dat Some content of TEMP: ==================== C:\Users\Kerstin\AppData\Local\Temp\avgnt.exe C:\Users\Kerstin\AppData\Local\Temp\genymotion-2.3.0-vbox.exe C:\Users\Kerstin\AppData\Local\Temp\mailcheck_ff_2014_12_02.exe C:\Users\Kerstin\AppData\Local\Temp\sdan.exe C:\Users\Kerstin\AppData\Local\Temp\sdapk.exe C:\Users\Kerstin\AppData\Local\Temp\sdaspwn.exe C:\Users\Kerstin\AppData\Local\Temp\_is7BE3.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-05 11:43 ==================== End Of Log =========================== --- --- --- --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-02-2015 Ran by Kerstin at 2015-02-14 22:12:30 Running from C:\Users\Kerstin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Apple Application Support (32-Bit) (HKLM-x32\...\{2FE00055-C4F3-4F7A-AEDD-E198D54CF12F}) (Version: 3.1.1 - Apple Inc.) Apple Application Support (64-Bit) (HKLM\...\{28791292-D18D-42FA-AE66-3D3D20AA8618}) (Version: 3.1.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{5ED7462B-EF58-4757-B609-53755021EC34}) (Version: 8.1.0.18 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG) Avira (x32 Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.3.8.2523 - CDBurnerXP) Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.31 - Cliqz.com) CouponDownloader (Version: 1.0.0.0 - CouponDownloader) Hidden <==== ATTENTION D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.111 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Intel(R) AppUp (HKLM-x32\...\{0A7596DE-9737-44D2-AAFA-58FA9BBCA0AC}) (Version: 1.0.0 - Intel Corporation) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.8.1050 - Intel Corporation) Intel(R) Integrator Assistant (HKLM-x32\...\{D1A35687-AEA9-422C-B237-FC4F8136B6F6}) (Version: 1.0.0 - Intel Corporation) Intel(R) Network Connections 18.4.59.0 (HKLM\...\PROSetDX) (Version: 18.4.59.0 - Intel) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (x32 Version: 10.0.13 - Intel(R) Corporation) Hidden iTunes (HKLM\...\{7B8D4E8A-EA2B-4A71-BFEB-A4AAAB87C5D0}) (Version: 12.1.0.71 - Apple Inc.) Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.670 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.6 - F.J. Wechselberger) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) PCmover OEM Express (HKLM-x32\...\{1EE14CC2-ED85-4EEA-8714-A31C86AF3769}) (Version: 5.00.617 - Laplink Software, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6526 - Realtek Semiconductor Corp.) Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.) Hidden Screen+ version Screen+ 1.0.4 (HKLM-x32\...\{5B7AF05A-1962-489C-B00A-F12D49889FC9}_is1) (Version: Screen+ 1.0.4 - AOC) Snap.Do (HKLM-x32\...\{F97A8857-2A38-4CE9-A53A-F07E491F2DA8}) (Version: 11.77.1.17697 - ReSoft Ltd.) <==== ATTENTION Sony Ericsson PC Suite (HKLM-x32\...\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}) (Version: - ) Spotify (HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Spotify) (Version: 0.9.10.14.g578d350b - Spotify AB) System Requirements Lab for Intel (HKLM-x32\...\{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}) (Version: 4.5.22.0 - Husdawg, LLC) Unity Web Player (HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\UnityWebPlayer) (Version: 4.5.2f1 - Unity Technologies ApS) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 11-02-2015 11:00:12 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 12-02-2015 11:02:57 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 12-02-2015 17:22:25 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 12-02-2015 20:10:08 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 12-02-2015 20:57:16 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 13-02-2015 09:53:53 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 13-02-2015 09:55:28 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 13-02-2015 18:38:40 Removed BlueStacks Notification Center 14-02-2015 00:46:10 Installed Samsung Kies3 14-02-2015 01:27:54 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 14-02-2015 01:47:44 Removed BlueStacks Notification Center 14-02-2015 10:18:44 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 14-02-2015 18:34:11 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 14-02-2015 18:34:11 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {00563FF1-94B2-4ACF-9C5B-C74614DBEB35} - System32\Tasks\{787E8A7B-C4E2-48E0-ACF9-3461BABB54B6} => pcalua.exe -a C:\Users\Kerstin\Downloads\uninstall(3).exe -d C:\Users\Kerstin\Downloads Task: {08857CFB-1827-4BC8-AE12-B859848CE7D0} - System32\Tasks\{F737814D-3683-47E5-AF0C-4E1D320A9951} => pcalua.exe -a C:\Users\Kerstin\Downloads\Player_Setup.exe -d C:\Users\Kerstin\Downloads Task: {08D094D6-0BBD-4B04-9CF4-8DBA255610ED} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {10CBE9BC-8EFE-4053-A7DC-8644AF78EB41} - System32\Tasks\FoxTab => C:\Users\Kerstin\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {25D8C43E-6604-4F17-8EE7-9FEBD69EE07D} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {2B1D12A8-48EB-41F9-95C7-12000B4CE960} - System32\Tasks\{67881B7B-FF02-4B3C-9821-7909B874027B} => pcalua.exe -a C:\Users\Kerstin\Downloads\uninstall.exe -d C:\Users\Kerstin\Downloads Task: {3187A450-53D4-4CCD-A8FF-2D5366B0CAE2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-16] (Google Inc.) Task: {3B7260BD-1C98-42DA-98F7-6297611EBF41} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {4553E21B-6E77-4D64-BF94-B5B28819CC49} - System32\Tasks\Driver Booster SkipUAC (Kerstin) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {5916A9E4-39AF-43E3-942A-A24BAF65DBF1} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {5BDEFC53-C2D7-4389-BFFB-D1D157331367} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {5BF6E004-22A9-4C7A-87E2-C78452737D12} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-16] (Google Inc.) Task: {606150B2-4484-4DEA-BEDD-A1D0283FDEED} - System32\Tasks\{E37A25D8-8838-41A3-BC93-DCE5FECBEFB5} => C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe Task: {95700BD4-E422-4E57-8939-53CAA09C99FF} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {96424FAA-C6E4-466F-9128-3F0E137581E2} - System32\Tasks\FF Watcher {702CC857-65AF-49A7-833D-5615C60C637D} => C:\Program Files\V-bates\PrefHelper.exe <==== ATTENTION Task: {A42B3360-11B3-4D6F-B56E-91078D0A055F} - System32\Tasks\{5DA50788-7ECC-4844-B7B1-A78E3EFBAFCA} => pcalua.exe -a C:\Users\Kerstin\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=tugs <==== ATTENTION Task: {A4E92CE6-2AB9-423E-B8B8-B74FB98C7932} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {A53C14D2-FE20-4182-9B0D-0B268780F4C4} - System32\Tasks\{74687C69-1F44-40E3-AF30-79BED7BB4D94} => C:\Users\Kerstin\Downloads\Takania2-Revolution1.3\metin2client_normal.exe Task: {A784D041-1160-4F06-A792-D939E6FCDE03} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {C5D81029-EB29-4F25-8889-B846207F16A8} - System32\Tasks\{CAD0AD2B-781C-4CFF-B7F2-42D9DC4C3AB4} => C:\Users\Kerstin\Downloads\Takania2-Revolution1.3\metin2client_normal.exe Task: {CC04BE37-473F-42B7-9334-71F9FC4BF5BD} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {CCAB2C81-7B17-49A3-88B8-531CB8D975B9} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {D502C482-67D8-4EDC-A288-3AA008B3729B} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {DB88C28E-7CF1-47A7-A440-C9B0EE3C51F4} - System32\Tasks\0f35c805-0126-47dc-bc26-393cdbd9833d-4 => C:\Program Files (x86)\Mediaa_Play_AIR_1.4\0f35c805-0126-47dc-bc26-393cdbd9833d-4.exe <==== ATTENTION Task: {ECCE2458-3451-47D7-836C-F668C20E8D89} - System32\Tasks\FF Watcher {900BD071-9C0E-4A65-A289-3F4BDE1F81B6} => C:\Program Files\Slotomania Coin Expansion Pack\g56yreg.exe <==== ATTENTION Task: C:\Windows\Tasks\0f35c805-0126-47dc-bc26-393cdbd9833d-4.job => C:\Program Files (x86)\Mediaa_Play_AIR_1.4\0f35c805-0126-47dc-bc26-393cdbd9833d-4.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\FF Watcher {702CC857-65AF-49A7-833D-5615C60C637D}.job => C:\Program Files\V-bates\PrefHelper.exe <==== ATTENTION Task: C:\Windows\Tasks\FF Watcher {900BD071-9C0E-4A65-A289-3F4BDE1F81B6}.job => C:\Program Files\Slotomania Coin Expansion Pack\g56yreg.exe <==== ATTENTION Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Kerstin\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2015-01-20 22:35 - 2015-01-20 22:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-01-20 22:35 - 2015-01-20 22:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-05-06 21:31 - 2014-05-06 21:31 - 00709120 _____ () C:\Program Files\004\rqpbhevlkc64.exe 2015-02-14 21:58 - 2015-02-14 21:58 - 00050477 _____ () C:\Users\Kerstin\Desktop\Defogger.exe 2014-10-18 10:12 - 2014-10-18 10:12 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\93182e9779b8be0f688fd0784df6d7fb\IsdiInterop.ni.dll 2014-05-13 23:42 - 2010-11-05 23:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2015-01-31 11:58 - 2015-01-31 11:58 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2015-02-07 19:29 - 2015-02-07 19:29 - 16852144 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:373E1720 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== Accounts: ============================= Administrator (S-1-5-21-2890383179-3499982190-3409672644-500 - Administrator - Disabled) Gast (S-1-5-21-2890383179-3499982190-3409672644-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2890383179-3499982190-3409672644-1002 - Limited - Enabled) Kerstin (S-1-5-21-2890383179-3499982190-3409672644-1001 - Administrator - Enabled) => C:\Users\Kerstin ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (02/14/2015 07:20:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2015 06:30:14 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2015 11:40:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: compatibilitycheck.exe, Version: 0.0.0.0, Zeitstempel: 0x54da5ad7 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000222d2 ID des fehlerhaften Prozesses: 0xfa4 Startzeit der fehlerhaften Anwendung: 0xcompatibilitycheck.exe0 Pfad der fehlerhaften Anwendung: compatibilitycheck.exe1 Pfad des fehlerhaften Moduls: compatibilitycheck.exe2 Berichtskennung: compatibilitycheck.exe3 Error: (02/14/2015 10:03:08 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2015 01:12:33 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2015 00:55:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: compatibilitycheck.exe, Version: 0.0.0.0, Zeitstempel: 0x54da5ad7 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000222d2 ID des fehlerhaften Prozesses: 0x94 Startzeit der fehlerhaften Anwendung: 0xcompatibilitycheck.exe0 Pfad der fehlerhaften Anwendung: compatibilitycheck.exe1 Pfad des fehlerhaften Moduls: compatibilitycheck.exe2 Berichtskennung: compatibilitycheck.exe3 Error: (02/13/2015 09:35:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: compatibilitycheck.exe, Version: 0.0.0.0, Zeitstempel: 0x54da5ad7 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000222d2 ID des fehlerhaften Prozesses: 0xad0 Startzeit der fehlerhaften Anwendung: 0xcompatibilitycheck.exe0 Pfad der fehlerhaften Anwendung: compatibilitycheck.exe1 Pfad des fehlerhaften Moduls: compatibilitycheck.exe2 Berichtskennung: compatibilitycheck.exe3 Error: (02/13/2015 06:25:47 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/13/2015 09:38:08 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/12/2015 09:28:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: compatibilitycheck.exe, Version: 0.0.0.0, Zeitstempel: 0x54da5ad7 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000222d2 ID des fehlerhaften Prozesses: 0xa84 Startzeit der fehlerhaften Anwendung: 0xcompatibilitycheck.exe0 Pfad der fehlerhaften Anwendung: compatibilitycheck.exe1 Pfad des fehlerhaften Moduls: compatibilitycheck.exe2 Berichtskennung: compatibilitycheck.exe3 System errors: ============= Error: (02/14/2015 01:55:15 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "BlueStacks Updater Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (02/12/2015 08:46:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Microsoft-Softwareschattenkopie-Anbieter" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (02/12/2015 08:46:50 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft-Softwareschattenkopie-Anbieter erreicht. Error: (02/12/2015 08:46:51 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1053swprv{65EE1DBA-8FF4-4A58-AC1C-3470EE2F376A} Error: (02/12/2015 05:44:22 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2. Error: (02/12/2015 05:44:10 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2. Error: (02/12/2015 05:44:10 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2. Error: (02/12/2015 05:44:10 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2. Error: (02/12/2015 05:41:36 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (02/12/2015 05:41:35 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Microsoft Office Sessions: ========================= Error: (02/14/2015 07:20:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2015 06:30:14 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2015 11:40:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: compatibilitycheck.exe0.0.0.054da5ad7ntdll.dll6.1.7601.18247521ea8e7c0000005000222d2fa401d04842a591c30aC:\Users\Kerstin\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exeC:\Windows\SysWOW64\ntdll.dllec17769d-b435-11e4-b7e1-00224d7b4b93 Error: (02/14/2015 10:03:08 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2015 01:12:33 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2015 00:55:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: compatibilitycheck.exe0.0.0.054da5ad7ntdll.dll6.1.7601.18247521ea8e7c0000005000222d29401d047e878f1eaebC:\Users\Kerstin\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exeC:\Windows\SysWOW64\ntdll.dllc00f31a6-b3db-11e4-a9bf-00224d7b4b93 Error: (02/13/2015 09:35:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: compatibilitycheck.exe0.0.0.054da5ad7ntdll.dll6.1.7601.18247521ea8e7c0000005000222d2ad001d047cc7ec2f3daC:\Users\Kerstin\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exeC:\Windows\SysWOW64\ntdll.dllc7515c2d-b3bf-11e4-a9bf-00224d7b4b93 Error: (02/13/2015 06:25:47 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/13/2015 09:38:08 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/12/2015 09:28:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: compatibilitycheck.exe0.0.0.054da5ad7ntdll.dll6.1.7601.18247521ea8e7c0000005000222d2a8401d047025e8cf1b1C:\Users\Kerstin\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exeC:\Windows\SysWOW64\ntdll.dlla9a828f3-b2f5-11e4-9f0b-00224d7b4b93 ==================== Memory info =========================== Processor: Intel(R) Atom(TM) CPU D2500 @ 1.86GHz Percentage of memory in use: 67% Total physical RAM: 2036.66 MB Available physical RAM: 658.86 MB Total Pagefile: 4073.31 MB Available Pagefile: 2079.84 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.99 GB) (Free:163.12 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 909528BB) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
15.02.2015, 15:32 | #4 |
/// the machine /// TB-Ausbilder | db29.exe. kommt immer wieder trotz virenscan und quarantäne Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.02.2015, 20:07 | #5 |
| db29.exe. kommt immer wieder trotz virenscan und quarantäneCode:
ATTFilter ComboFix 15-02-13.02 - Kerstin 15.02.2015 16:58:38.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.2037.574 [GMT 1:00] ausgeführt von:: c:\users\Kerstin\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\CFLog C:\install.exe C:\LIL7654.tmp C:\LIL7663.tmp C:\LIL7664.tmp C:\LIL7692.tmp c:\programdata\374311380 c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_mfhkgfigejkhikbkfkkglinnkfojkdek_0 c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_mfhkgfigejkhikbkfkkglinnkfojkdek_0\3 c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\background.html c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\chromeCoreFilesIndex.txt c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\crossriderManifest.json c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\manifest.xml c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins.json c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\1.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\102.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\104.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\13.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\14.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\155.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\17.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\177.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\182.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\183.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\184.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\19.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\191.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\193.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\195.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\207.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\21.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\211.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\22.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\220.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\221.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\242.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\246.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\257.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\262.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\263.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\267.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\28.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\4.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\47.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\64.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\7.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\72.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\78.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\80.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\9.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\91.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\93.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\97.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\userCode\background.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\userCode\extension.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\icons\actions\1.png c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\icons\icon128.png c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\icons\icon16.png c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\icons\icon48.png c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\api\chrome.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\api\cookie.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\api\message.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\api\monitor.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\api\pageAction.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\api\pageActionBG.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\background.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\app_api.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\bg_app_api.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\consts.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\cookie_store.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\crossriderAPI.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\delegate.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\events.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\extensionDataStore.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\installer.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\logFile.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\logging.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\onBGDocumentLoad.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\popupResource\newPopup.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\popupResource\popup.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\reports.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\storageWrapper.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\updateManager.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\util.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\lib\xhr.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\main.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\js\platformVersion.js c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\manifest.json c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\popup.html c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek\000202.ldb c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek\000204.ldb c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek\000207.ldb c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek\000210.ldb c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek\000211.log c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek\CURRENT c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek\LOCK c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek\LOG c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek\LOG.old c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mfhkgfigejkhikbkfkkglinnkfojkdek\MANIFEST-000209 c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mfhkgfigejkhikbkfkkglinnkfojkdek_0.localstorage-journal c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mfhkgfigejkhikbkfkkglinnkfojkdek_0.localstorage c:\users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Preferences c:\users\Kerstin\AppData\Local\nso4FB.tmp c:\users\Kerstin\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll c:\windows\msdownld.tmp c:\windows\Tasks\FF Watcher {702CC857-65AF-49A7-833D-5615C60C637D}.job c:\windows\Tasks\FF Watcher {900BD071-9C0E-4A65-A289-3F4BDE1F81B6}.job . . ((((((((((((((((((((((( Dateien erstellt von 2015-01-15 bis 2015-02-15 )))))))))))))))))))))))))))))) . . 2015-02-15 16:17 . 2015-02-15 16:17 0 ----a-w- c:\windows\SysWow64\shoA06B.tmp 2015-02-15 16:16 . 2015-02-15 16:16 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-02-15 14:52 . 2015-02-15 14:52 -------- d-----w- c:\program files (x86)\VS Revo Group 2015-02-14 23:37 . 2015-02-14 23:37 0 ----a-w- c:\windows\SysWow64\sho50B4.tmp 2015-02-14 23:25 . 2014-10-13 05:57 206080 ----a-w- c:\windows\system32\drivers\ssudmdm.sys 2015-02-14 23:25 . 2014-10-13 05:57 110336 ----a-w- c:\windows\system32\drivers\ssudbus.sys 2015-02-14 23:25 . 2015-02-14 23:25 -------- d-----w- c:\program files\SAMSUNG 2015-02-14 21:08 . 2015-02-14 21:14 -------- d-----w- C:\FRST 2015-02-14 00:41 . 2015-02-14 23:25 -------- d-----w- c:\programdata\Samsung 2015-02-13 23:49 . 2015-02-13 23:50 -------- d-----w- c:\users\Kerstin\AppData\Roaming\Samsung 2015-02-13 23:49 . 2014-05-07 16:42 144664 ----a-w- c:\windows\SysWow64\secman.dll 2015-02-13 23:49 . 2015-02-13 23:49 -------- d-----w- c:\program files (x86)\Samsung 2015-02-13 23:00 . 2015-02-13 23:00 -------- d-----w- c:\users\Kerstin\AppData\Roaming\MyPhoneExplorer 2015-02-13 22:58 . 2015-02-13 22:59 -------- d-----w- c:\program files (x86)\MyPhoneExplorer 2015-02-12 15:57 . 2015-02-12 15:57 -------- d-----w- c:\program files (x86)\iTunes 2015-02-12 15:57 . 2015-02-12 15:57 -------- d-----w- c:\program files\iPod 2015-02-12 15:57 . 2015-02-12 15:59 -------- d-----w- c:\programdata\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-02-12 15:57 . 2015-02-12 15:59 -------- d-----w- c:\program files\iTunes 2015-02-11 13:47 . 2015-02-11 13:47 0 ----a-w- c:\windows\SysWow64\sho8A0A.tmp 2015-02-10 18:38 . 2015-02-10 18:50 -------- d-----w- c:\users\Kerstin\.VirtualBox 2015-02-10 18:38 . 2015-02-10 18:54 -------- d-----w- c:\users\Kerstin\AppData\Local\Genymobile 2015-02-10 18:36 . 2013-04-12 10:41 237840 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys 2015-02-10 18:33 . 2013-04-12 10:40 120080 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys 2015-02-10 18:31 . 2015-02-10 18:31 -------- d-----w- c:\program files\Genymobile 2015-02-10 18:29 . 2015-02-10 18:29 -------- d-----w- c:\users\Kerstin\AppData\Local\Temp515a80549b13c62719b8b0be014862d3 2015-01-31 21:17 . 2015-01-31 21:17 0 ----a-w- c:\windows\SysWow64\sho83D.tmp 2015-01-24 23:12 . 2015-01-24 23:12 0 ----a-w- c:\windows\SysWow64\sho29F1.tmp . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-02-07 18:29 . 2014-05-04 20:42 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2015-02-07 18:29 . 2014-05-04 20:42 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2015-01-01 01:23 . 2015-01-01 01:23 0 ----a-w- c:\windows\SysWow64\shoF0A.tmp 2014-12-30 01:17 . 2014-12-30 01:17 0 ----a-w- c:\windows\SysWow64\shoA701.tmp 2014-12-28 01:20 . 2014-12-28 01:20 0 ----a-w- c:\windows\SysWow64\shoDA71.tmp 2014-12-13 21:21 . 2014-12-13 21:21 0 ----a-w- c:\windows\SysWow64\shoE8F2.tmp 2014-12-13 05:09 . 2014-12-18 08:43 144384 ----a-w- c:\windows\system32\ieUnatt.exe 2014-12-13 03:33 . 2014-12-18 08:43 115712 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-12-10 22:53 . 2014-12-10 22:53 0 ----a-w- c:\windows\SysWow64\sho7C29.tmp 2014-12-10 22:38 . 2014-05-06 18:00 112710672 ----a-w- c:\windows\system32\MRT.exe 2014-12-04 02:50 . 2014-12-10 15:59 413184 ----a-w- c:\windows\system32\generaltel.dll 2014-12-04 02:50 . 2014-12-10 15:59 741376 ----a-w- c:\windows\system32\invagent.dll 2014-12-04 02:50 . 2014-12-10 15:59 396800 ----a-w- c:\windows\system32\devinv.dll 2014-12-04 02:50 . 2014-12-10 15:59 830976 ----a-w- c:\windows\system32\appraiser.dll 2014-12-04 02:50 . 2014-12-10 15:59 192000 ----a-w- c:\windows\system32\aepic.dll 2014-12-04 02:50 . 2014-12-10 15:59 227328 ----a-w- c:\windows\system32\aepdu.dll 2014-12-04 02:44 . 2014-12-10 15:59 1083392 ----a-w- c:\windows\system32\aeinv.dll 2014-12-01 23:28 . 2014-12-10 15:59 1232040 ----a-w- c:\windows\system32\aitstatic.exe 2014-11-29 16:02 . 2014-11-29 16:02 0 ----a-w- c:\windows\SysWow64\shoD22.tmp 2014-11-27 01:43 . 2014-12-10 16:00 389296 ----a-w- c:\windows\system32\iedkcs32.dll 2014-11-22 03:13 . 2014-12-10 15:59 25059840 ----a-w- c:\windows\system32\mshtml.dll 2014-11-22 03:06 . 2014-12-10 16:00 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-11-22 03:06 . 2014-12-10 16:00 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-11-22 02:50 . 2014-12-10 16:00 66560 ----a-w- c:\windows\system32\iesetup.dll 2014-11-22 02:50 . 2014-12-10 15:59 580096 ----a-w- c:\windows\system32\vbscript.dll 2014-11-22 02:49 . 2014-12-10 16:00 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-11-22 02:49 . 2014-12-10 16:00 2885120 ----a-w- c:\windows\system32\iertutil.dll 2014-11-22 02:48 . 2014-12-10 15:59 88064 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-11-22 02:41 . 2014-12-10 16:00 54784 ----a-w- c:\windows\system32\jsproxy.dll 2014-11-22 02:40 . 2014-12-10 16:00 34304 ----a-w- c:\windows\system32\iernonce.dll 2014-11-22 02:37 . 2014-12-10 16:00 633856 ----a-w- c:\windows\system32\ieui.dll 2014-11-22 02:35 . 2014-12-10 16:00 114688 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-11-22 02:34 . 2014-12-10 15:59 814080 ----a-w- c:\windows\system32\jscript9diag.dll 2014-11-22 02:34 . 2014-12-10 15:59 6039552 ----a-w- c:\windows\system32\jscript9.dll 2014-11-22 02:26 . 2014-12-10 16:00 968704 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-11-22 02:22 . 2014-12-10 16:00 490496 ----a-w- c:\windows\system32\dxtmsft.dll 2014-11-22 02:20 . 2014-12-10 16:00 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-11-22 02:14 . 2014-12-10 16:00 77824 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2014-11-22 02:09 . 2014-12-10 15:59 199680 ----a-w- c:\windows\system32\msrating.dll 2014-11-22 02:08 . 2014-12-10 15:59 92160 ----a-w- c:\windows\system32\mshtmled.dll 2014-11-22 02:07 . 2014-12-10 16:00 501248 ----a-w- c:\windows\SysWow64\vbscript.dll 2014-11-22 02:07 . 2014-12-10 16:00 62464 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-11-22 02:06 . 2014-12-10 16:00 47616 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-11-22 02:05 . 2014-12-10 16:00 64000 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2014-11-22 02:05 . 2014-12-10 16:00 316928 ----a-w- c:\windows\system32\dxtrans.dll 2014-11-22 01:54 . 2014-12-10 16:00 620032 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-11-22 01:49 . 2014-12-10 16:00 718848 ----a-w- c:\windows\system32\ie4uinit.exe 2014-11-22 01:49 . 2014-12-10 16:00 800768 ----a-w- c:\windows\system32\msfeeds.dll 2014-11-22 01:47 . 2014-12-10 15:59 1359360 ----a-w- c:\windows\system32\mshtmlmedia.dll 2014-11-22 01:46 . 2014-12-10 16:00 2125312 ----a-w- c:\windows\system32\inetcpl.cpl 2014-11-22 01:43 . 2014-12-10 15:59 14412800 ----a-w- c:\windows\system32\ieframe.dll 2014-11-22 01:40 . 2014-12-10 16:00 60416 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2014-11-22 01:29 . 2014-12-10 16:00 4299264 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-11-22 01:28 . 2014-12-10 15:59 2358272 ----a-w- c:\windows\system32\wininet.dll 2014-11-22 01:22 . 2014-12-10 16:00 2052096 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-11-22 01:21 . 2014-12-10 16:00 1155072 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2014-11-22 01:15 . 2014-12-10 16:00 1548288 ----a-w- c:\windows\system32\urlmon.dll 2014-11-22 01:03 . 2014-12-10 16:00 800768 ----a-w- c:\windows\system32\ieapfltr.dll 2014-11-22 01:00 . 2014-12-10 16:00 1888256 ----a-w- c:\windows\SysWow64\wininet.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3}] 2014-05-12 15:49 90416 ----a-w- c:\program files (x86)\Coupon Downloader\Coupon Downloader.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="c:\users\Kerstin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2015-02-15 1676344] "Spotify"="c:\users\Kerstin\AppData\Roaming\Spotify\spotify.exe" [2015-02-15 6737976] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-12-11 702768] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-07-25 256896] "Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2015-01-19 126712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x] R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 massfilter_hs;HS HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys;c:\windows\SYSNATIVE\drivers\massfilter_hs.sys [x] R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x] R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 s1029bus;Sony Ericsson Device 1029 driver (WDM);c:\windows\system32\DRIVERS\s1029bus.sys;c:\windows\SYSNATIVE\DRIVERS\s1029bus.sys [x] R3 s1029mdfl;Sony Ericsson Device 1029 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1029mdfl.sys;c:\windows\SYSNATIVE\DRIVERS\s1029mdfl.sys [x] R3 s1029mdm;Sony Ericsson Device 1029 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1029mdm.sys;c:\windows\SYSNATIVE\DRIVERS\s1029mdm.sys [x] R3 s1029mgmt;Sony Ericsson Device 1029 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1029mgmt.sys;c:\windows\SYSNATIVE\DRIVERS\s1029mgmt.sys [x] R3 s1029nd5;Sony Ericsson Device 1029 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1029nd5.sys;c:\windows\SYSNATIVE\DRIVERS\s1029nd5.sys [x] R3 s1029obex;Sony Ericsson Device 1029 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1029obex.sys;c:\windows\SYSNATIVE\DRIVERS\s1029obex.sys [x] R3 s1029unic;Sony Ericsson Device 1029 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1029unic.sys;c:\windows\SYSNATIVE\DRIVERS\s1029unic.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x] R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x] R3 X6va015;X6va015;c:\windows\SysWOW64\Drivers\X6va015;c:\windows\SysWOW64\Drivers\X6va015 [x] R3 zghsmdm;ZTE General Handset USB Modem Proprietary;c:\windows\system32\DRIVERS\zghsmdm.sys;c:\windows\SYSNATIVE\DRIVERS\zghsmdm.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x] S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x] S2 rqpbhevlkc64;rqpbhevlkc64;c:\program files\004\rqpbhevlkc64.exe run options=01100010040000000000000000000000 sourceguid=A6ADCE5D-859A-4E7E-B0B2-D07F8AB9237E;c:\program files\004\rqpbhevlkc64.exe run options=01100010040000000000000000000000 sourceguid=A6ADCE5D-859A-4E7E-B0B2-D07F8AB9237E [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 ss_conn_service;SAMSUNG Mobile Connectivity Service;c:\program files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe;c:\program files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [x] S3 igddim64;igddim64;c:\windows\system32\DRIVERS\igddim64.sys;c:\windows\SYSNATIVE\DRIVERS\igddim64.sys [x] S3 imgkmd64;imgkmd64;c:\windows\system32\DRIVERS\imgkmd64.sys;c:\windows\SYSNATIVE\DRIVERS\imgkmd64.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-02-06 23:12 1086280 ----a-w- c:\program files (x86)\Google\Chrome\Application\40.0.2214.111\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2015-02-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-05-16 18:46] . 2015-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-05-16 18:46] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-13 13374568] "ESET-Phase2"="c:\programdata\ESET\ESET-phase2.exe" [2010-11-10 1100656] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-30 159744] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-30 384512] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-30 403456] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2015-01-27 169768] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_howCorPPPyzMfc8qrgBOhqWBn7kuAVVgEJVs0L86QrR_l8h9uutX0rgf97u6zEC5OFGSB1d7wjH6OaZdwls4zeoclA06b6XaurradvW_LAZ0Ol06w1pYLst07Gbu_WQb5M1f_IsS2Miy mDefault_Search_URL = about:blank mDefault_Page_URL = about:blank mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = about:blank uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_howCorPPPyzMfc8qrgBOhqWBn7kuAVVgEJVs0L86QrR_l8h9uutX0rgf97u6zEC5OFGSB1d7wjH6Oarpbx1exyiHUnMhhXy_o6EJJs4zfSUIz50GIpXGRBEJ1UbqhJFPvkmIaXdKWcFi&q={searchTerms} TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\ FF - prefs.js: browser.startup.homepage - hxxp://go.1und1.de/tb/mff_startpage|hxxp://www.giga.de/androidnews/ FF - user.js: extensions.autoDisableScopes - 0 FF - user.js: extensions.shownSelectionUI - true . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - (no file) Toolbar-Locked - (no file) Toolbar-10 - (no file) Wow6432Node-HKCU-Run-Browser Infrastructure Helper - c:\users\Kerstin\AppData\Local\Smartbar\Application\SnapDo.exe Wow6432Node-HKLM-Run-fst_de_7 - (no file) Wow6432Node-HKLM-Run-Registry Helper - c:\program files (x86)\Registry Helper\RegistryHelper.Exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) Toolbar-10 - (no file) AddRemove-Activeris AntiMalware_is1 - c:\program files (x86)\Activeris AntiMalware\unins000.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va015] "ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va015" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_246_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_246_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.15" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\windows\temp\db29.exe . ************************************************************************** . Zeit der Fertigstellung: 2015-02-15 17:27:10 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2015-02-15 16:27 . Vor Suchlauf: 23 Verzeichnis(se), 174.718.869.504 Bytes frei Nach Suchlauf: 28 Verzeichnis(se), 179.362.250.752 Bytes frei . - - End Of File - - 92AA4B1DEFF0AAD5B5016FEB47AF39FB |
16.02.2015, 10:31 | #6 |
/// the machine /// TB-Ausbilder | db29.exe. kommt immer wieder trotz virenscan und quarantäne Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> db29.exe. kommt immer wieder trotz virenscan und quarantäne |
16.02.2015, 22:26 | #7 |
| db29.exe. kommt immer wieder trotz virenscan und quarantäneCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Protection, 16.02.2015 20:34:09, SYSTEM, KERSTIN-PC, Protection, Malware Protection, Starting, Protection, 16.02.2015 20:34:09, SYSTEM, KERSTIN-PC, Protection, Malware Protection, Started, Protection, 16.02.2015 20:34:09, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Starting, Update, 16.02.2015 20:34:10, SYSTEM, KERSTIN-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1, Update, 16.02.2015 20:34:10, SYSTEM, KERSTIN-PC, Manual, Rootkit Database, 2014.11.18.1, 2015.2.3.1, Update, 16.02.2015 20:34:32, SYSTEM, KERSTIN-PC, Manual, Malware Database, 2014.11.20.6, 2015.2.16.7, Protection, 16.02.2015 20:34:32, SYSTEM, KERSTIN-PC, Protection, Refresh, Starting, Protection, 16.02.2015 20:34:49, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Started, Protection, 16.02.2015 20:34:50, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Stopping, Protection, 16.02.2015 20:34:50, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Stopped, Protection, 16.02.2015 20:35:05, SYSTEM, KERSTIN-PC, Protection, Refresh, Success, Protection, 16.02.2015 20:35:05, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Starting, Protection, 16.02.2015 20:35:06, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Started, Update, 16.02.2015 20:53:38, SYSTEM, KERSTIN-PC, Scheduler, Malware Database, 2015.2.16.7, 2015.2.16.8, Protection, 16.02.2015 20:53:38, SYSTEM, KERSTIN-PC, Protection, Refresh, Starting, Protection, 16.02.2015 20:53:38, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Stopping, Protection, 16.02.2015 20:53:38, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Stopped, Protection, 16.02.2015 20:54:29, SYSTEM, KERSTIN-PC, Protection, Refresh, Success, Protection, 16.02.2015 20:54:29, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Starting, Protection, 16.02.2015 20:54:36, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Started, (end) Code:
ATTFilter # AdwCleaner v4.110 - Bericht erstellt 16/02/2015 um 21:36:21 # Aktualisiert 05/02/2015 von Xplode # Datenbank : 2015-02-14.2 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : Kerstin - KERSTIN-PC # Gestarted von : C:\Users\Kerstin\Downloads\AdwCleaner_4.110.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\ProgramData\Registry Helper Ordner Gelöscht : C:\ProgramData\drivergenius Ordner Gelöscht : C:\Program Files (x86)\predm Ordner Gelöscht : C:\Users\Kerstin\AppData\Local\Genesis Ordner Gelöscht : C:\Users\Kerstin\AppData\Local\globalUpdate Ordner Gelöscht : C:\Users\Kerstin\AppData\Roaming\Activeris Ordner Gelöscht : C:\Users\Kerstin\AppData\Roaming\Systweak Ordner Gelöscht : C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\sparpilot@sparpilot.com Datei Gelöscht : C:\END Datei Gelöscht : C:\Windows\SysWOW64\RegistryHelperLM.ocx Datei Gelöscht : C:\Windows\System32\drivers\netfilter64.sys Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Kerstin\AppData\Local\AnyProtectScannerSetup.exe Datei Gelöscht : C:\Users\Kerstin\AppData\Roaming\aps.uninstall.scan.results Datei Gelöscht : C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\ask-search.xml Datei Gelöscht : C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\user.js Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_api.ciuvo.com_0.localstorage Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_api.ciuvo.com_0.localstorage-journal Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\Desktop\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\Desktop\Search.lnk Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (3).lnk Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6EC77D09-02CB-4E1F-E3C4-FB141B2610B3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522842288} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555845588} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566846688} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544844488} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555845588} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566846688} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} Schlüssel Gelöscht : HKCU\Software\AnyProtect Schlüssel Gelöscht : HKCU\Software\APN PIP Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\genesis Schlüssel Gelöscht : HKCU\Software\GlobalUpdate Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\simplytech Schlüssel Gelöscht : HKCU\Software\systweak Schlüssel Gelöscht : HKCU\Software\Tune Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit Schlüssel Gelöscht : HKLM\SOFTWARE\Driver-Soft Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate Schlüssel Gelöscht : HKLM\SOFTWARE\Registry Helper Schlüssel Gelöscht : HKLM\SOFTWARE\systweak Schlüssel Gelöscht : HKLM\SOFTWARE\Tune Schlüssel Gelöscht : HKLM\SOFTWARE\Taronja Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Activeris AntiMalware_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\32DA746012E6D4F488AAD113D6FA4A44 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF767AE36C8829547ACD71A4249A42B9 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\526AB318AF0B8D84B9579557C9882C91 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4 Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\default-search.net Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\portaldosites.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\trovi.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\webssearches.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.portaldosites.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.trovi.com Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17496 -\\ Mozilla Firefox v35.0.1 (x86 de) [vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.order.1", "default-search.net"); [vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.afaf73efed6aa46eb8014e0b47ac07eada90d6ab4be694e96a9791fd9c1ae6f92com58488.58488.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...] [vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false); [vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false); [vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false); [vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.Visibility", false); [vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.keepAliveLastevent", "1402754098"); [vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("{01856272-60D2-48c0-8F8F-852C369B15A1}.ScriptData_whiteListSearch", "{\"search.babylon.com\":\"q\",\"search.yahoo.com\":\"p\",\"www.bing.com\":\"q\",\"www.google.com\":\"q\",\"www.google.co[...] [vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}.ScriptData_VBATES_partn_time_mmotraffic.com", "not set"); [vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}.ScriptData_whiteListSearch", "{\"isearch.babylon.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"home.mywebsearch.com\":\"se[...] -\\ Google Chrome v40.0.2214.111 [C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1407066410&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062&q={searchTerms} [C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1407066410&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062&q={searchTerms} [C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1402826947&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062&q={searchTerms} [C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1402826947&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062&q={searchTerms} ************************* AdwCleaner[R0].txt - [11363 Bytes] - [16/02/2015 21:31:57] AdwCleaner[S0].txt - [12428 Bytes] - [16/02/2015 21:36:21] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12488 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.2 (02.02.2015:1) OS: Windows 7 Home Premium x64 Ran by Kerstin on 16.02.2015 at 22:02:11,45 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{25919770-5BAD-48FC-8AD0-ABE381933FBC} Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{2AD651C0-A973-4ED6-8DA9-3DFD46C17179} Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{32EBC90B-3383-4647-A7E4-83042D61BBAA} Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{60232E7F-D4DA-4E82-A1A4-6BB2BDE70F81} Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{81A78961-263A-47A6-8B38-0B90A567867E} Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{B4A2C882-B21E-4B65-B513-4C4DDE94450C} Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{C161DA7A-77D8-48F8-A5F3-96607D6A7080} Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{CDC2E683-777F-40DC-97EB-EC4D56C5948F} Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{D6B18C6B-E2AB-4773-BEEF-758EFDCEABF9} Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{DC94419E-9C42-48A7-A70D-DD48E3331F9C} Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{E54590EC-BE83-449F-8AE5-6F3812ACD647} ~~~ FireFox Successfully deleted: [Folder] C:\Users\Kerstin\AppData\Roaming\mozilla\firefox\profiles\vokiukc3.default\extensions\toolbar@web.de Successfully deleted the following from C:\Users\Kerstin\AppData\Roaming\mozilla\firefox\profiles\vokiukc3.default\prefs.js user_pref("ZooToolbar_25361.global.DisplayRecentSearches", "true"); user_pref("{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}.ScriptData_VBATES_executeCode", "var VBATES_IsValidUrl=function(currentUrl,currentBrowser,queryParam){try{var urlParts=curren user_pref("{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}.ScriptData_VBATES_partners", "{\"www.brandalley.co.uk\":\"www.awin1.com/awclick.php?mid=3676&id=178119\",\"www.currys.co.uk\" Emptied folder: C:\Users\Kerstin\AppData\Roaming\mozilla\firefox\profiles\vokiukc3.default\minidumps [143 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 16.02.2015 at 22:11:59,50 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-02-2015 Ran by Kerstin (administrator) on KERSTIN-PC on 16-02-2015 22:18:46 Running from C:\Users\Kerstin\Downloads Loaded Profiles: Kerstin (Available profiles: Kerstin) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Spotify Ltd) C:\Users\Kerstin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Farbar) C:\Users\Kerstin\Downloads\FRST64(1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [ESET-Phase2] => C:\ProgramData\ESET\ESET-phase2.exe [1100656 2010-11-10] () HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-01-27] (Apple Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [Spotify Web Helper] => C:\Users\Kerstin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-02-15] (Spotify Ltd) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [Spotify] => C:\Users\Kerstin\AppData\Roaming\Spotify\spotify.exe [6737976 2015-02-15] (Spotify Ltd) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [AirDroid 3] => C:\Program Files (x86)\AirDroid\AirDroid.exe [11662848 2015-02-05] (Sand Studio) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://syb.msn.com SearchScopes: HKLM -> {05B62290-31C8-45EC-99C6-F05963923521} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSBTDF&pc=MASB&src=IE-SearchBox SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default FF Homepage: hxxp://go.1und1.de/tb/mff_startpage|hxxp://www.giga.de/androidnews/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2890383179-3499982190-3409672644-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kerstin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-2890383179-3499982190-3409672644-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\google-maps.xml FF Extension: anonymoX - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\client@anonymox.net.xpi [2014-05-08] FF Extension: Trusted Shops Add-On für Firefox - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\jid1-PBNne26X1Kn6hQ@jetpack.xpi [2014-08-05] FF Extension: {0db9152f-2c09-4a6a-b006-6852e1787975} - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\{0db9152f-2c09-4a6a-b006-6852e1787975}.xpi [2015-02-10] FF HKLM\...\Firefox\Extensions: [{01856272-60D2-48c0-8F8F-852C369B15A1}] - C:\Program Files\Slotomania Coin Expansion Pack\Firefox FF HKLM-x32\...\Firefox\Extensions: [{01856272-60D2-48c0-8F8F-852C369B15A1}] - C:\Program Files\Slotomania Coin Expansion Pack\Firefox FF HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\extensions\cliqz@cliqz.com Chrome: ======= CHR Profile: C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-16] CHR Extension: (Google Drive) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-16] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27] CHR Extension: (YouTube) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-16] CHR Extension: (Slotomania Coin Expansion Pack) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmonpfhhpdjphhlanhockbccaakgahgh [2014-05-28] CHR Extension: (Google-Suche) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-16] CHR Extension: (Google Wallet) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-16] CHR Extension: (Google Mail) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-05-09] (Avira Operations GmbH & Co. KG) R3 igddim64; C:\Windows\System32\DRIVERS\igddim64.sys [1703936 2011-08-30] (Intel Corporation) R3 imgkmd64; C:\Windows\System32\DRIVERS\imgkmd64.sys [479232 2011-08-30] (Imagination Technologies) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) S3 s1029bus; C:\Windows\System32\DRIVERS\s1029bus.sys [116264 2009-05-25] (MCCI Corporation) S3 s1029mdfl; C:\Windows\System32\DRIVERS\s1029mdfl.sys [19496 2009-05-25] (MCCI Corporation) S3 s1029mdm; C:\Windows\System32\DRIVERS\s1029mdm.sys [158760 2009-05-25] (MCCI Corporation) S3 s1029mgmt; C:\Windows\System32\DRIVERS\s1029mgmt.sys [139304 2009-05-25] (MCCI Corporation) S3 s1029nd5; C:\Windows\System32\DRIVERS\s1029nd5.sys [34856 2009-05-25] (MCCI Corporation) S3 s1029obex; C:\Windows\System32\DRIVERS\s1029obex.sys [135208 2009-05-25] (MCCI Corporation) S3 s1029unic; C:\Windows\System32\DRIVERS\s1029unic.sys [151592 2009-05-25] (MCCI Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 massfilter_hs; \??\C:\Windows\system32\drivers\massfilter_hs.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X] S3 zghsmdm; system32\DRIVERS\zghsmdm.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-16 22:18 - 2015-02-16 22:18 - 02085888 _____ (Farbar) C:\Users\Kerstin\Downloads\FRST64(1).exe 2015-02-16 22:11 - 2015-02-16 22:11 - 00002703 _____ () C:\Users\Kerstin\Desktop\JRT.txt 2015-02-16 22:01 - 2015-02-16 22:01 - 01388274 _____ (Thisisu) C:\Users\Kerstin\Downloads\JRT.exe 2015-02-16 21:58 - 2015-02-16 21:58 - 00012617 _____ () C:\Users\Kerstin\Desktop\AdwCleaner[S0].txt 2015-02-16 21:50 - 2015-02-16 21:50 - 00316536 _____ () C:\Windows\Minidump\021615-14913-01.dmp 2015-02-16 21:31 - 2015-02-16 21:36 - 00000000 ____D () C:\AdwCleaner 2015-02-16 21:30 - 2015-02-16 21:30 - 02112512 _____ () C:\Users\Kerstin\Downloads\AdwCleaner_4.110.exe 2015-02-16 21:08 - 2015-02-16 21:08 - 00002081 _____ () C:\Users\Kerstin\Desktop\mbam.txt 2015-02-16 20:33 - 2015-02-16 21:52 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-16 20:33 - 2015-02-16 20:33 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-02-16 20:33 - 2015-02-16 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-02-16 20:33 - 2015-02-16 20:33 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-02-16 20:33 - 2015-02-16 20:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-02-16 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-02-16 20:33 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-02-16 20:33 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-02-16 20:31 - 2015-02-16 20:32 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Kerstin\Downloads\mbam-setup-2.0.4.1028.exe 2015-02-16 00:57 - 2015-02-16 00:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2015-02-16 00:57 - 2015-02-16 00:57 - 00000000 ____D () C:\Program Files\7-Zip 2015-02-16 00:54 - 2015-02-16 00:54 - 01513472 _____ () C:\Users\Kerstin\Downloads\7z938-x64.msi 2015-02-15 23:16 - 2015-02-15 23:23 - 00000000 ____D () C:\Users\Kerstin\Documents\AirDroid 2015-02-15 23:08 - 2015-02-15 23:22 - 00000000 ____D () C:\Program Files (x86)\AirDroid 2015-02-15 23:08 - 2015-02-15 23:16 - 00001889 _____ () C:\Users\Public\Desktop\AirDroid.lnk 2015-02-15 23:08 - 2015-02-15 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirDroid 2015-02-15 22:57 - 2015-02-15 22:58 - 09146874 _____ () C:\Users\Kerstin\Downloads\AirDroid_Desktop_Client_3.0.4.exe 2015-02-15 18:49 - 2015-02-15 18:49 - 00040320 _____ () C:\Users\Kerstin\Desktop\combofix.txt 2015-02-15 17:27 - 2015-02-15 17:27 - 00040320 _____ () C:\ComboFix.txt 2015-02-15 17:17 - 2015-02-15 17:17 - 00000000 _____ () C:\Windows\SysWOW64\shoA06B.tmp 2015-02-15 16:54 - 2015-02-15 16:54 - 00001485 _____ () C:\Users\Kerstin\Desktop\ComboFix - Verknüpfung.lnk 2015-02-15 16:54 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-02-15 16:54 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-02-15 16:54 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-02-15 16:54 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-02-15 16:54 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-02-15 16:54 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-02-15 16:54 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-02-15 16:54 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2015-02-15 16:53 - 2015-02-15 17:27 - 00000000 ____D () C:\Qoobox 2015-02-15 16:52 - 2015-02-15 17:23 - 00000000 ____D () C:\Windows\erdnt 2015-02-15 16:51 - 2015-02-15 16:51 - 05611771 ____R (Swearware) C:\Users\Kerstin\Downloads\ComboFix.exe 2015-02-15 15:53 - 2015-02-15 15:53 - 00001268 _____ () C:\Users\Kerstin\Desktop\Revo Uninstaller.lnk 2015-02-15 15:52 - 2015-02-15 15:52 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-02-15 15:37 - 2015-02-15 15:51 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Kerstin\Downloads\revosetup95.exe 2015-02-15 00:37 - 2015-02-15 00:37 - 00000000 _____ () C:\Windows\SysWOW64\sho50B4.tmp 2015-02-15 00:25 - 2015-02-15 00:25 - 00000000 ____D () C:\Program Files\SAMSUNG 2015-02-15 00:25 - 2014-10-13 06:57 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2015-02-15 00:25 - 2014-10-13 06:57 - 00110336 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2015-02-14 22:22 - 2015-02-14 22:22 - 00380416 _____ () C:\Users\Kerstin\Downloads\Gmer-19357(1).exe 2015-02-14 22:18 - 2015-02-14 22:18 - 00380416 _____ () C:\Users\Kerstin\Downloads\Gmer-19357.exe 2015-02-14 22:18 - 2015-02-14 22:18 - 00000859 _____ () C:\Users\Kerstin\Desktop\trojaner-board.txt 2015-02-14 22:16 - 2015-02-14 22:47 - 00000000 ____D () C:\Users\Kerstin\Desktop\logdateien 2015-02-14 22:12 - 2015-02-14 22:14 - 00029291 _____ () C:\Users\Kerstin\Downloads\Addition.txt 2015-02-14 22:08 - 2015-02-16 22:18 - 00016140 _____ () C:\Users\Kerstin\Downloads\FRST.txt 2015-02-14 22:08 - 2015-02-16 22:18 - 00000000 ____D () C:\FRST 2015-02-14 22:06 - 2015-02-14 22:06 - 02134528 _____ (Farbar) C:\Users\Kerstin\Downloads\FRST64.exe 2015-02-14 22:01 - 2015-02-14 22:01 - 00000000 _____ () C:\Users\Kerstin\defogger_reenable 2015-02-14 21:58 - 2015-02-14 21:58 - 00050477 _____ () C:\Users\Kerstin\Desktop\Defogger.exe 2015-02-14 01:41 - 2015-02-15 00:25 - 00000000 ____D () C:\ProgramData\Samsung 2015-02-14 00:50 - 2015-02-14 01:42 - 00000000 ____D () C:\Users\Kerstin\Documents\samsung 2015-02-14 00:50 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log 2015-02-14 00:50 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Kerstin\Documents\SelfMV 2015-02-14 00:49 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Samsung 2015-02-14 00:49 - 2015-02-14 00:49 - 00001973 _____ () C:\Users\Public\Desktop\Samsung Kies 3.lnk 2015-02-14 00:49 - 2015-02-14 00:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2015-02-14 00:49 - 2015-02-14 00:49 - 00000000 ____D () C:\Program Files (x86)\Samsung 2015-02-14 00:49 - 2014-05-07 17:42 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\SysWOW64\secman.dll 2015-02-14 00:39 - 2015-02-14 00:40 - 42498888 _____ (Samsung Electronics Co., Ltd.) C:\Users\Kerstin\Downloads\Kies3Setup.exe 2015-02-14 00:00 - 2015-02-14 00:00 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\MyPhoneExplorer 2015-02-13 23:59 - 2015-02-13 23:59 - 00002061 _____ () C:\Users\Public\Desktop\MyPhoneExplorer.lnk 2015-02-13 23:59 - 2015-02-13 23:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer 2015-02-13 23:58 - 2015-02-13 23:59 - 00000000 ____D () C:\Program Files (x86)\MyPhoneExplorer 2015-02-13 23:40 - 2015-02-13 23:40 - 00659464 _____ () C:\Users\Kerstin\Downloads\myphoneexplorer.exe 2015-02-12 18:28 - 2014-12-05 11:32 - 139196615 _____ () C:\Users\Kerstin\20141205_113135.mp4 2015-02-12 18:28 - 2014-12-01 11:24 - 232466986 _____ () C:\Users\Kerstin\20141201_112247.mp4 2015-02-12 18:28 - 2014-11-30 11:30 - 275072892 _____ () C:\Users\Kerstin\20141130_112831.mp4 2015-02-12 18:27 - 2014-11-23 22:31 - 208943022 _____ () C:\Users\Kerstin\20141123_222952.mp4 2015-02-12 18:27 - 2014-11-14 19:52 - 136757681 _____ () C:\Users\Kerstin\20141114_195143.mp4 2015-02-12 18:27 - 2014-11-14 13:46 - 311908025 _____ () C:\Users\Kerstin\20141114_134342.mp4 2015-02-12 18:26 - 2015-01-26 08:34 - 143517436 _____ () C:\Users\Kerstin\20150126_083313.mp4 2015-02-12 18:26 - 2015-01-12 22:21 - 346180627 _____ () C:\Users\Kerstin\20150112_221907.mp4 2015-02-12 18:26 - 2015-01-01 00:11 - 00351735 _____ () C:\Users\Kerstin\20150101_001052.mp4 2015-02-12 18:26 - 2014-12-27 15:34 - 74917974 _____ () C:\Users\Kerstin\20141227_153416.mp4 2015-02-12 18:26 - 2014-12-27 15:32 - 41031175 _____ () C:\Users\Kerstin\20141227_153210.mp4 2015-02-12 18:26 - 2014-12-25 21:13 - 157444083 _____ () C:\Users\Kerstin\20141225_211203.mp4 2015-02-12 18:26 - 2014-11-09 18:32 - 356998952 _____ () C:\Users\Kerstin\20141109_182926.mp4 2015-02-12 18:25 - 2014-12-25 21:11 - 180618452 _____ () C:\Users\Kerstin\20141225_211021.mp4 2015-02-12 18:25 - 2014-12-25 14:36 - 207078718 _____ () C:\Users\Kerstin\20141225_143453.mp4 2015-02-12 18:25 - 2014-12-24 18:41 - 06138834 _____ () C:\Users\Kerstin\20141224_184113.mp4 2015-02-12 18:25 - 2014-12-20 14:14 - 239835541 _____ () C:\Users\Kerstin\20141220_141233.mp4 2015-02-12 18:25 - 2014-12-19 19:42 - 101770616 _____ () C:\Users\Kerstin\20141219_194114.mp4 2015-02-12 18:24 - 2014-12-15 19:04 - 244473975 _____ () C:\Users\Kerstin\20141215_190217.mp4 2015-02-12 18:24 - 2014-12-14 19:26 - 211934675 _____ () C:\Users\Kerstin\20141214_192449.mp4 2015-02-12 17:00 - 2015-02-12 17:00 - 00001753 _____ () C:\Users\Public\Desktop\iTunes.lnk 2015-02-12 17:00 - 2015-02-12 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-02-12 16:57 - 2015-02-12 16:59 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-02-12 16:57 - 2015-02-12 16:59 - 00000000 ____D () C:\Program Files\iTunes 2015-02-12 16:57 - 2015-02-12 16:57 - 00000000 ____D () C:\Program Files\iPod 2015-02-12 16:57 - 2015-02-12 16:57 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-02-11 14:47 - 2015-02-11 14:47 - 00000000 _____ () C:\Windows\SysWOW64\sho8A0A.tmp 2015-02-10 19:38 - 2015-02-10 19:54 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Genymobile 2015-02-10 19:38 - 2015-02-10 19:50 - 00000000 ____D () C:\Users\Kerstin\.VirtualBox 2015-02-10 19:36 - 2013-04-12 11:41 - 00237840 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys 2015-02-10 19:33 - 2013-04-12 11:40 - 00120080 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys 2015-02-10 19:31 - 2015-02-10 19:31 - 00000000 ____D () C:\Program Files\Genymobile 2015-02-10 19:29 - 2015-02-10 19:29 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Temp515a80549b13c62719b8b0be014862d3 2015-02-10 16:37 - 2015-02-10 17:55 - 00002004 _____ () C:\Users\Kerstin\Desktop\WhatsApp.lnk 2015-01-31 22:17 - 2015-01-31 22:17 - 00000000 _____ () C:\Windows\SysWOW64\sho83D.tmp 2015-01-31 11:58 - 2015-02-11 11:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-25 00:12 - 2015-01-25 00:12 - 00000000 _____ () C:\Windows\SysWOW64\sho29F1.tmp 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe 2015-01-21 19:55 - 2015-01-21 19:55 - 00386448 _____ () C:\Windows\Minidump\012115-17035-01.dmp ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-16 22:00 - 2009-07-14 05:45 - 00028896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-16 22:00 - 2009-07-14 05:45 - 00028896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-16 21:54 - 2014-06-16 19:25 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Spotify 2015-02-16 21:54 - 2014-06-16 19:24 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Spotify 2015-02-16 21:53 - 2014-05-04 20:18 - 01109174 _____ () C:\Users\Kerstin\Documents\ESET-installation-phase2.log 2015-02-16 21:50 - 2014-06-20 16:18 - 00000000 ____D () C:\Windows\Minidump 2015-02-16 21:50 - 2014-05-16 19:46 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-16 21:50 - 2014-05-14 21:26 - 294253685 _____ () C:\Windows\MEMORY.DMP 2015-02-16 21:50 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-16 21:50 - 2009-07-14 05:51 - 00051389 _____ () C:\Windows\setupact.log 2015-02-16 21:43 - 2014-05-04 19:26 - 01764462 _____ () C:\Windows\WindowsUpdate.log 2015-02-16 21:37 - 2010-11-21 04:47 - 00690896 _____ () C:\Windows\PFRO.log 2015-02-16 21:36 - 2014-06-14 14:53 - 00001083 _____ () C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2015-02-16 21:36 - 2014-06-14 14:53 - 00001053 _____ () C:\Users\Kerstin\Desktop\Search.lnk 2015-02-16 21:36 - 2014-05-16 19:47 - 00001282 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-02-16 21:36 - 2014-05-16 19:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-02-16 21:36 - 2014-05-04 22:58 - 00001065 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-02-16 21:36 - 2014-05-04 22:58 - 00001053 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-02-16 21:36 - 2014-05-04 19:34 - 00000999 _____ () C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-02-16 21:36 - 2014-05-04 19:33 - 00001156 _____ () C:\Users\Kerstin\Desktop\Internet Explorer.lnk 2015-02-16 21:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\L2Schemas 2015-02-16 21:08 - 2014-05-15 22:36 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\com 2015-02-16 21:07 - 2014-05-06 21:32 - 00000000 ____D () C:\temp 2015-02-16 17:06 - 2014-05-04 20:14 - 00000000 ____D () C:\ProgramData\ESET 2015-02-16 16:46 - 2015-01-14 18:25 - 00000112 _____ () C:\ProgramData\5uKMmosV2.dat 2015-02-16 16:35 - 2015-01-10 00:53 - 00000000 ____D () C:\Users\Kerstin\Desktop\Neuer Ordner (2) 2015-02-15 23:25 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\VirtualStore 2015-02-15 17:27 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2015-02-15 17:19 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2015-02-14 22:01 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin 2015-02-14 01:55 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries 2015-02-14 00:49 - 2014-05-04 19:55 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-02-12 18:29 - 2014-06-14 23:45 - 00792576 ___SH () C:\Users\Kerstin\Thumbs.db 2015-02-12 17:46 - 2010-11-21 07:50 - 00699386 _____ () C:\Windows\system32\perfh007.dat 2015-02-12 17:46 - 2010-11-21 07:50 - 00149268 _____ () C:\Windows\system32\perfc007.dat 2015-02-12 17:46 - 2009-07-14 06:13 - 01620248 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-12 16:57 - 2014-08-24 18:38 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-02-12 16:55 - 2014-08-24 18:40 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2015-02-11 21:05 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Windows Live 2015-02-10 16:41 - 2014-05-21 09:54 - 00000000 ____D () C:\ProgramData\BlueStacksSetup 2015-02-09 14:19 - 2014-05-16 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-09 14:19 - 2014-05-16 10:01 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-09 14:19 - 2014-05-13 22:59 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-07 21:11 - 2014-05-16 19:46 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-07 21:11 - 2014-05-16 19:46 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-07 21:11 - 2014-05-16 19:46 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-07 19:29 - 2014-08-22 07:58 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Adobe 2015-02-07 19:29 - 2014-05-04 21:42 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-07 19:29 - 2014-05-04 21:42 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-31 22:17 - 2014-05-04 22:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-24 20:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2015-01-19 12:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF ==================== Files in the root of some directories ======= 2014-05-06 21:56 - 2014-05-06 21:56 - 0000046 _____ () C:\Users\Kerstin\AppData\Roaming\WB.CFG 2015-01-14 18:25 - 2015-02-16 16:46 - 0000112 _____ () C:\ProgramData\5uKMmosV2.dat 2014-05-13 21:56 - 2014-05-13 21:56 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Files to move or delete: ==================== C:\ProgramData\5uKMmosV2.dat Some content of TEMP: ==================== C:\Users\Kerstin\AppData\Local\Temp\avgnt.exe C:\Users\Kerstin\AppData\Local\Temp\Quarantine.exe C:\Users\Kerstin\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-15 17:44 ==================== End Of Log ============================ --- --- --- |
17.02.2015, 13:16 | #8 |
/// the machine /// TB-Ausbilder | db29.exe. kommt immer wieder trotz virenscan und quarantäneESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.02.2015, 00:08 | #9 |
| db29.exe. kommt immer wieder trotz virenscan und quarantäneCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=ef1d69f084a6364091d400a4837d7282 # engine=22515 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-02-17 11:32:44 # local_time=2015-02-18 12:32:44 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 27079 24588961 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 24884049 175845813 0 0 # scanned=252183 # found=133 # cleaned=0 # scan_time=21781 sh=63D66E5B87669B96D4B71475F4BF7BFF846EDAB5 ft=1 fh=43b0540ae1061eed vn="Win32/AnyProtect.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Kerstin\AppData\Local\AnyProtectScannerSetup.exe.vir" sh=2970AFDADDD6B8E8648D34221C6CB63C61B48AEA ft=1 fh=2b6f00e4925acdc0 vn="Variante von Win64/Systweak.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Windows\System32\roboot64.exe.vir" sh=8B67C4946B050285FE89EFE36AB6DC2F7B3E2D2F ft=1 fh=d91722da20002316 vn="Variante von Win64/Riskware.NetFilter.F Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Windows\System32\drivers\netfilter64.sys.vir" sh=1E35D63EBF3D1214A53E718DCAE84EC2A63AFB39 ft=1 fh=abbd31e3c3dab272 vn="Win32/AnyProtect.E evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Kerstin\AppData\Local\nso4FB.tmp.vir" sh=898ABFBE2BE495D7D9E173654696AB94C8B3343D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\91.js.vir" sh=50A844EC797C7B349568096C0673E00290A7498C ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\temp\InstallFilter64.msi" sh=5E9239D0AEB78AC6A3403A3E97797F5B1433873D ft=0 fh=0000000000000000 vn="Win32/Toolbar.Perion.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmonpfhhpdjphhlanhockbccaakgahgh\2.0.0.431_0\main.js" sh=2A33556EF0180841763790BE2A45C16CBBAA0B26 ft=1 fh=42ae3a538a4d3e9c vn="Win32/InstallMonetizer.BD evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8Y7J3MY8\20150213175185[1].exe" sh=A358BA98C004FBD0A9FA058FAECD25E414384460 ft=1 fh=6d514046f6c726f1 vn="Win32/Wajam.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RGX43U7P\WIE_2.25.2.15[1].exe" sh=CEBA426AA9430FE584CEFB88D42F0D58CE206F08 ft=1 fh=aba10e6901c1f68c vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\Users\Kerstin\AppData\Local\Temp\UpdateCV\installer.exe" sh=982FC10B17EE723E4FCE584BC68C801CA1A22911 ft=0 fh=0000000000000000 vn="MSIL/Hoax.FakeHack.EO Anwendung" ac=I fn="C:\Users\Kerstin\Downloads\Hacks_v10.2.rar" sh=A6722AD9466D59F97DFA9B7C45F935A62DB7813E ft=1 fh=b1424d485b15ecfe vn="Variante von Win32/DownloadGuide.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\Downloads\myphoneexplorer.exe" sh=6082BF68BBD8F08ABA9EE861709E4F613CBD7839 ft=1 fh=f09c391b24fe90d9 vn="Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\Downloads\setup(1).exe" sh=AAC8D90DCED7899D6F2BC2401B64C34E696E5145 ft=1 fh=30f84787d1b61df8 vn="Variante von Win32/Bundlore.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\Downloads\setup.exe" sh=A72EF64EEDE200EF388FE098B824A43F6657F5D4 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.ABD Trojaner" ac=I fn="C:\Users\Kerstin\My Downloads\Cabal.WS.FULL.27.10.13.rar" sh=50A844EC797C7B349568096C0673E00290A7498C ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Windows\Installer\c9320f.msi" sh=5CC94AE4A690844793C698C4B268E509305FCCD8 ft=1 fh=e337c06c40156b71 vn="Variante von MSIL/Toolbar.Linkury.M.gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll" sh=82CC500F0A463FD435989A4E8D0E5B140518A9C7 ft=1 fh=f8845120cf5263ea vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=571F38A34D64CCCBD914734C8BC01056A78BB5B5 ft=1 fh=d5332291ff13d174 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" sh=1E3950B5433B2EA0375A7B119E5ED2AE35655F35 ft=1 fh=ae6b8f6eb36659a8 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\spbe.dll" sh=FB6FF772C026ADC3BAA1A9FD0E9981177A953F58 ft=1 fh=19a87532ff09fe43 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\spbl.dll" sh=B547F49188B8B4FD14FD8AFED2D8DC390D760CA1 ft=1 fh=c0d2b431bd875300 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\sppsm.dll" sh=09CCC83AE946B1A2F9D123E5BCC160F0B1322E66 ft=1 fh=7225e695ddb52254 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\spusm.dll" sh=4FF4461EFC14F2B9EE8E54AD459DB3D3C0305017 ft=1 fh=72733531b3b70c5a vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\srbs.dll" sh=CD6429346DBB54DD36D81145F9D901B8741A3367 ft=1 fh=8a47f1e2252ef3f8 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\srbu.dll" sh=052E64A824CD325E5D6448F09F5943BCF231A978 ft=1 fh=9e58a417d67982a0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\srptc.dll" sh=63859BE0DDB7ACEC6AE7F0D36E638FC5B694C431 ft=1 fh=2a6e9f657a46ccad vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\srpu.dll" sh=5CC94AE4A690844793C698C4B268E509305FCCD8 ft=1 fh=e337c06c40156b71 vn="Variante von MSIL/Toolbar.Linkury.M.gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll" sh=82CC500F0A463FD435989A4E8D0E5B140518A9C7 ft=1 fh=f8845120cf5263ea vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=571F38A34D64CCCBD914734C8BC01056A78BB5B5 ft=1 fh=d5332291ff13d174 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" sh=1E3950B5433B2EA0375A7B119E5ED2AE35655F35 ft=1 fh=ae6b8f6eb36659a8 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\spbe.dll" sh=FB6FF772C026ADC3BAA1A9FD0E9981177A953F58 ft=1 fh=19a87532ff09fe43 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\spbl.dll" sh=B547F49188B8B4FD14FD8AFED2D8DC390D760CA1 ft=1 fh=c0d2b431bd875300 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\sppsm.dll" sh=09CCC83AE946B1A2F9D123E5BCC160F0B1322E66 ft=1 fh=7225e695ddb52254 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\spusm.dll" sh=4FF4461EFC14F2B9EE8E54AD459DB3D3C0305017 ft=1 fh=72733531b3b70c5a vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\srbs.dll" sh=CD6429346DBB54DD36D81145F9D901B8741A3367 ft=1 fh=8a47f1e2252ef3f8 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\srbu.dll" sh=052E64A824CD325E5D6448F09F5943BCF231A978 ft=1 fh=9e58a417d67982a0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\srptc.dll" sh=63859BE0DDB7ACEC6AE7F0D36E638FC5B694C431 ft=1 fh=2a6e9f657a46ccad vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\srpu.dll" sh=5CC94AE4A690844793C698C4B268E509305FCCD8 ft=1 fh=e337c06c40156b71 vn="Variante von MSIL/Toolbar.Linkury.M.gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll" sh=82CC500F0A463FD435989A4E8D0E5B140518A9C7 ft=1 fh=f8845120cf5263ea vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=571F38A34D64CCCBD914734C8BC01056A78BB5B5 ft=1 fh=d5332291ff13d174 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" sh=1E3950B5433B2EA0375A7B119E5ED2AE35655F35 ft=1 fh=ae6b8f6eb36659a8 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\spbe.dll" sh=FB6FF772C026ADC3BAA1A9FD0E9981177A953F58 ft=1 fh=19a87532ff09fe43 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\spbl.dll" sh=B547F49188B8B4FD14FD8AFED2D8DC390D760CA1 ft=1 fh=c0d2b431bd875300 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\sppsm.dll" sh=09CCC83AE946B1A2F9D123E5BCC160F0B1322E66 ft=1 fh=7225e695ddb52254 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\spusm.dll" sh=4FF4461EFC14F2B9EE8E54AD459DB3D3C0305017 ft=1 fh=72733531b3b70c5a vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\srbs.dll" sh=CD6429346DBB54DD36D81145F9D901B8741A3367 ft=1 fh=8a47f1e2252ef3f8 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\srbu.dll" sh=052E64A824CD325E5D6448F09F5943BCF231A978 ft=1 fh=9e58a417d67982a0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\srptc.dll" sh=63859BE0DDB7ACEC6AE7F0D36E638FC5B694C431 ft=1 fh=2a6e9f657a46ccad vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\srpu.dll" sh=5CC94AE4A690844793C698C4B268E509305FCCD8 ft=1 fh=e337c06c40156b71 vn="Variante von MSIL/Toolbar.Linkury.M.gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll" sh=82CC500F0A463FD435989A4E8D0E5B140518A9C7 ft=1 fh=f8845120cf5263ea vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=571F38A34D64CCCBD914734C8BC01056A78BB5B5 ft=1 fh=d5332291ff13d174 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" sh=1E3950B5433B2EA0375A7B119E5ED2AE35655F35 ft=1 fh=ae6b8f6eb36659a8 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\spbe.dll" sh=FB6FF772C026ADC3BAA1A9FD0E9981177A953F58 ft=1 fh=19a87532ff09fe43 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\spbl.dll" sh=B547F49188B8B4FD14FD8AFED2D8DC390D760CA1 ft=1 fh=c0d2b431bd875300 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\sppsm.dll" sh=09CCC83AE946B1A2F9D123E5BCC160F0B1322E66 ft=1 fh=7225e695ddb52254 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\spusm.dll" sh=4FF4461EFC14F2B9EE8E54AD459DB3D3C0305017 ft=1 fh=72733531b3b70c5a vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\srbs.dll" sh=CD6429346DBB54DD36D81145F9D901B8741A3367 ft=1 fh=8a47f1e2252ef3f8 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\srbu.dll" sh=052E64A824CD325E5D6448F09F5943BCF231A978 ft=1 fh=9e58a417d67982a0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\srptc.dll" sh=63859BE0DDB7ACEC6AE7F0D36E638FC5B694C431 ft=1 fh=2a6e9f657a46ccad vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\srpu.dll" sh=5CC94AE4A690844793C698C4B268E509305FCCD8 ft=1 fh=e337c06c40156b71 vn="Variante von MSIL/Toolbar.Linkury.M.gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll" sh=82CC500F0A463FD435989A4E8D0E5B140518A9C7 ft=1 fh=f8845120cf5263ea vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=571F38A34D64CCCBD914734C8BC01056A78BB5B5 ft=1 fh=d5332291ff13d174 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" sh=1E3950B5433B2EA0375A7B119E5ED2AE35655F35 ft=1 fh=ae6b8f6eb36659a8 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\spbe.dll" sh=FB6FF772C026ADC3BAA1A9FD0E9981177A953F58 ft=1 fh=19a87532ff09fe43 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\spbl.dll" sh=B547F49188B8B4FD14FD8AFED2D8DC390D760CA1 ft=1 fh=c0d2b431bd875300 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\sppsm.dll" sh=09CCC83AE946B1A2F9D123E5BCC160F0B1322E66 ft=1 fh=7225e695ddb52254 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\spusm.dll" sh=4FF4461EFC14F2B9EE8E54AD459DB3D3C0305017 ft=1 fh=72733531b3b70c5a vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\srbs.dll" sh=CD6429346DBB54DD36D81145F9D901B8741A3367 ft=1 fh=8a47f1e2252ef3f8 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\srbu.dll" sh=052E64A824CD325E5D6448F09F5943BCF231A978 ft=1 fh=9e58a417d67982a0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\srptc.dll" sh=63859BE0DDB7ACEC6AE7F0D36E638FC5B694C431 ft=1 fh=2a6e9f657a46ccad vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\srpu.dll" sh=8840DBC7533FB78B1E6D0C7D86EC7360E82D040A ft=1 fh=ae02be1ad5609f0d vn="Win32/TrojanDownloader.Agent.BCI Trojaner" ac=I fn="C:\Windows\temp\db29.exe" sh=143A7E5014919715069D5F500062A31031902F51 ft=1 fh=a38179722af15ce8 vn="Variante von Win32/AnyProtect.D evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\AnyProtectEx\AnyProtectTrayIcon.exe" sh=04D91F5EBEA96FA39B1DE6858B8FA88FE1ED41A0 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\53172.crx" sh=5A17A4CCC3E0C9612E8B8EE1C7B030C227F95973 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\53172.xpi" sh=725D0FFABC1D89C25B4CC8332719A0B5023AE9E0 ft=1 fh=3adcabf81dd26b41 vn="Variante von Win32/Toolbar.CrossRider.BP evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\Uninstall.exe" sh=D2C0F8C92CB89312B3D92E8731633C53D1871076 ft=1 fh=05fcdb39b07f92d1 vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\utils.exe" sh=20633973DCDD04727DF512944CFC4E14BA07073C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\MediaPlayerplus\54246.crx" sh=51DDA5F8363F86F856292F8107327FADEB1985CE ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\MediaPlayerplus\54246.xpi" sh=27FED6761C7629F59F73637F9E58FBD02CFAAF2D ft=1 fh=82840ad3150eeb22 vn="Variante von Win32/Toolbar.CrossRider.BP evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\MediaPlayerplus\Uninstall.exe" sh=0BC5D06253D2B7567052C62BCB32981EF2603522 ft=1 fh=697ee69403579d59 vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\MediaPlayerplus\utils.exe" sh=A8A65FB4279DF98DD572C1ABA570AD3512070C27 ft=1 fh=1f862fe9efb74ac9 vn="Variante von Win32/AdWare.AddLyrics.BA Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQL158.dll" sh=66F1BE2B0246490E8C00DEB464D8E8D225016CE4 ft=1 fh=9893a5deb0eb68f5 vn="Variante von Win32/AdWare.AddLyrics.AK Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe" sh=770C4B96450DBB3CAEA94B831119A5A45F3FEBCB ft=1 fh=ec8cb327aedd3495 vn="Variante von Win32/AdWare.AddLyrics.AJ Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQLOWw.exe" sh=732ABCFD86D73579BB270EB9EFA91DE6B22B39FC ft=1 fh=3a2d6583ece91c8d vn="Variante von Win32/AdWare.AddLyrics.AS Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\Re-markit-soft\Uninstall.exe" sh=AAEA2D2C15813161F9E114E6E1708CE545D5C8CA ft=1 fh=0022d452663e533e vn="Variante von Win32/DealPly.M evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSense\SaveSenseUpdateVer.exe" sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe" sh=10903598F769E2AC5F1E2372E90F6722A3A860B7 ft=1 fh=89560075533c3d40 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll" sh=88482528CE4F67A1004B50BA93282CEACCEDE534 ft=1 fh=e40b702402e604d5 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psmachine.dll" sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe" sh=70D49B9ABA391E6976DAB5C4BEA63733459B3F1C ft=1 fh=0b76a05977e7722a vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe" sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe" sh=F09B9B9B1D16D1539D23CC6ACDE0DC7BC983DF59 ft=1 fh=2dbadf99ca2df2d7 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe" sh=4E475FD620FBCCBB37453AF2BD0427BDA73109FF ft=1 fh=70875884387ffbdb vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\DpInterface32.dll" sh=524ED1264811258D64BA2BE8B48005C6D1935713 ft=1 fh=19b60c262a337e59 vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\DpInterface64.dll" sh=72971E4B87542575A876B36FB87879B416F4EC88 ft=1 fh=eb8c71c588367618 vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\DpInterfacef32.dll" sh=01C9B3D0E073B824021B29F1FD957A8643DF6931 ft=1 fh=9d9cb38b273b86fe vn="Variante von Win32/ELEX.AR evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\RSHP.exe" sh=F34BB16FA7EEF85B106A7C3A3FDEEE95ECF18001 ft=1 fh=7bd5299d4d87abc5 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\SearchProtect32.dll" sh=FB15CD6ADCD9BDFBF68D5DF5EAEA02BF329F8D4F ft=1 fh=dfa2b1c2f56e7303 vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\SearchProtect64.dll" sh=B733C40B96BCA6CC139230D0F7C4E51CEC12CF35 ft=1 fh=08ea3c71e6c55c1b vn="Win32/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\SpAPPSv32.dll" sh=D6F9F256C03B81C01D6CFF28D2D966F59F786AC3 ft=1 fh=3a3e287aa52ff7e5 vn="Variante von Win64/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\SpAPPSv64.dll" sh=EC7EC5D60C5A578BC9953115D368BECD05BA14B2 ft=1 fh=ecbff00cc7dcc0fd vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\SupTab.dll" sh=95D8C7F2851240F836D46EBD0DCB0BBAE3C9C3C8 ft=1 fh=c39b2415a29978f2 vn="Variante von Win32/ELEX.AV evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\ProgramData\IePluginService\PluginService.exe" sh=9A189D6EAB28C6F9C20AEEFA3E7134916E38C65B ft=1 fh=c71c0011b919b825 vn="Variante von Win32/ELEX.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\ProgramData\WPM\wprotectmanager.exe" sh=8E06E50B0CBFA8E4CA1C53E149AF51D6CB70B048 ft=1 fh=abbd31e3610824c6 vn="Win32/VOPackage.BC evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\nsg636B.tmp" sh=8E06E50B0CBFA8E4CA1C53E149AF51D6CB70B048 ft=1 fh=abbd31e3610824c6 vn="Win32/VOPackage.BC evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\13IZS1EV\Setup[1].exe" sh=CEFE0A678B49D72BDCC996F79CF2DB0B95FEF6B1 ft=1 fh=9d7011981dcd65ae vn="Win32/SpeedUpMyPC evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DVJK7S2\SpeedUpMyPC-standalone-setup[1].exe" sh=0412092F54E42A01109B16456315ACF18FCFE64B ft=1 fh=cd059c019f892a66 vn="Win32/Conduit.SearchProtect.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DVJK7S2\SPSetup[1].exe" sh=24FEC569E88DBBD7E60B93F47036302D7ECD4AA7 ft=1 fh=275222c212f2a6ff vn="Win32/AdWare.PricePeep.B Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7EGMH37D\pricepeep_190001_0102[1].exe" sh=D4E1E10EF1DB5CF927AF158CDF7D25C231BCC0E9 ft=1 fh=9c13b6a5f88b5be6 vn="Win32/OutBrowse.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I9KG89KF\RegCleanSetup10[1].exe" sh=815CE918A2CF57F5E0A3A9346FD9A6F6B3D03D30 ft=1 fh=028c167410bf2336 vn="Win32/InstallCore.GI evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\PMB Files\Upgrade41270\PMB_updater.exe" sh=7B890323ABFE8F3BD33BE0BC439076B5525D03B0 ft=1 fh=790f07a45776117f vn="MSIL/MyPCBackup.D evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\BackupSetup.exe" sh=2A97153C16443DB59BB9887AC982293250EBDB1B ft=1 fh=a5170c70675b29c9 vn="Variante von Win32/DomaIQ.AF evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\bhs64D6.tmp" sh=8E06E50B0CBFA8E4CA1C53E149AF51D6CB70B048 ft=1 fh=abbd31e3610824c6 vn="Win32/VOPackage.BC evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\nsg636B.tmp" sh=7D3C13ACA4D8F0F26AD9A458CF86DA235A58CDCE ft=1 fh=413c2d7f5aa203f9 vn="MSIL/Tuguu.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\android.exe" sh=AF57ECA3F314CD7A615212A03823D5BC0BE30AF7 ft=1 fh=bee73e22821baec6 vn="Mehrere Bedrohungen" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\2040-2082_Re-markit.exe" sh=7D3C13ACA4D8F0F26AD9A458CF86DA235A58CDCE ft=1 fh=413c2d7f5aa203f9 vn="MSIL/Tuguu.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\AndroidSetup.exe" sh=1A9C2CE8C1F539AC8546D67C9F924AEA8D2A84C2 ft=1 fh=d348c3328e970e39 vn="Win32/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\Cloud_Backup_Setup.exe" sh=537C8FAD67F52AF763BF552C0039EA5F2381BA45 ft=1 fh=10217ca882c74d14 vn="Variante von Win32/ELEX.AF evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\lly_webssearches.exe" sh=FDC9F0E6F9720F0D46259D82D9D3F0AB11768E9A ft=1 fh=511192951e276f12 vn="Win32/Packed.ScrambleWrapper.M evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\mediaplayerpluus.exe" sh=8740194542D8B48437766D831883CFA6A0B94414 ft=1 fh=836ad3b9ae02d8c2 vn="Win32/Packed.ScrambleWrapper.M evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\setup.exe" sh=D297E17514FDF53B0A58B9ED686A2B5573BFC4DF ft=1 fh=3eb7aee6a2534744 vn="Win32/SpeedUpMyPC.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\speedupmypc.exe" sh=31178B28FECEFA25D755FDA60EE7D4CD19BB62F8 ft=1 fh=df247d35c433dd44 vn="Win32/VOPackage.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\VOPackage.exe" sh=DCB97CC5B1977BB49DF05C165C63BF54550916E9 ft=1 fh=61ca867c73ed6be8 vn="MSIL/Tuguu.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\android\android.exe" sh=282501AA2FA177D942282F8E2EB5E1D25CA17AED ft=1 fh=170a29edd91c8b10 vn="Variante von Win32/ELEX.AV evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\fullpackage_temp1397857199\tmp\SupTab.exe" sh=9A189D6EAB28C6F9C20AEEFA3E7134916E38C65B ft=1 fh=c71c0011b919b825 vn="Variante von Win32/ELEX.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\fullpackage_temp1397857199\tmp\wpm.exe" sh=CEFE0A678B49D72BDCC996F79CF2DB0B95FEF6B1 ft=1 fh=9d7011981dcd65ae vn="Win32/SpeedUpMyPC evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\is-UD1IQ.tmp\SpeedUpMyPC-standalone-setup.exe" sh=89DC63472DE94DF3F12DBAE15B7EBE6C04263369 ft=1 fh=7fb9e45e0079471d vn="Variante von Win32/Toolbar.Escort.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\is39994101\mysearchdial.dll" sh=8563F21B965879AE572840082BB2E9E5990F8A45 ft=1 fh=0aef99ed940fde6b vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Roaming\OpenCandy\9E9C4CA67A8C4D4893F190CD91CB51EB\sas.exe" sh=7B722A85CE6450E5D2B061C6D55BD6C7C82B3838 ft=1 fh=4b4dd648bb3da366 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Roaming\OpenCandy\9E9C4CA67A8C4D4893F190CD91CB51EB\SaveSense_p1v2.exe" sh=D383A7A87AB3076147EA6C1EF4A98EE979670AC2 ft=1 fh=cea6bc5b1fc91d53 vn="Variante von Win32/DealPly.S evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe" sh=EC7EC5D60C5A578BC9953115D368BECD05BA14B2 ft=1 fh=ecbff00cc7dcc0fd vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Roaming\SupTab\SupTab.dll" sh=8A72F448F17C026A1B2A59686DE720079CCBA08F ft=1 fh=4d4a711952b3453e vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\Downloads\DTLite4481-0347.exe" ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=ef1d69f084a6364091d400a4837d7282 # engine=22533 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-02-18 10:29:17 # local_time=2015-02-18 11:29:17 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 26826 24671555 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 24966643 175928407 0 0 # scanned=350894 # found=135 # cleaned=0 # scan_time=22485 sh=63D66E5B87669B96D4B71475F4BF7BFF846EDAB5 ft=1 fh=43b0540ae1061eed vn="Win32/AnyProtect.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Kerstin\AppData\Local\AnyProtectScannerSetup.exe.vir" sh=2970AFDADDD6B8E8648D34221C6CB63C61B48AEA ft=1 fh=2b6f00e4925acdc0 vn="Variante von Win64/Systweak.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Windows\System32\roboot64.exe.vir" sh=8B67C4946B050285FE89EFE36AB6DC2F7B3E2D2F ft=1 fh=d91722da20002316 vn="Variante von Win64/Riskware.NetFilter.F Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Windows\System32\drivers\netfilter64.sys.vir" sh=1E35D63EBF3D1214A53E718DCAE84EC2A63AFB39 ft=1 fh=abbd31e3c3dab272 vn="Win32/AnyProtect.E evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Kerstin\AppData\Local\nso4FB.tmp.vir" sh=898ABFBE2BE495D7D9E173654696AB94C8B3343D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhkgfigejkhikbkfkkglinnkfojkdek\1.26.13_0\extensionData\plugins\91.js.vir" sh=50A844EC797C7B349568096C0673E00290A7498C ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\temp\InstallFilter64.msi" sh=5E9239D0AEB78AC6A3403A3E97797F5B1433873D ft=0 fh=0000000000000000 vn="Win32/Toolbar.Perion.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmonpfhhpdjphhlanhockbccaakgahgh\2.0.0.431_0\main.js" sh=2A33556EF0180841763790BE2A45C16CBBAA0B26 ft=1 fh=42ae3a538a4d3e9c vn="Win32/InstallMonetizer.BD evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8Y7J3MY8\20150213175185[1].exe" sh=A358BA98C004FBD0A9FA058FAECD25E414384460 ft=1 fh=6d514046f6c726f1 vn="Win32/Wajam.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RGX43U7P\WIE_2.25.2.15[1].exe" sh=CEBA426AA9430FE584CEFB88D42F0D58CE206F08 ft=1 fh=aba10e6901c1f68c vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\Users\Kerstin\AppData\Local\Temp\UpdateCV\installer.exe" sh=982FC10B17EE723E4FCE584BC68C801CA1A22911 ft=0 fh=0000000000000000 vn="MSIL/Hoax.FakeHack.EO Anwendung" ac=I fn="C:\Users\Kerstin\Downloads\Hacks_v10.2.rar" sh=A6722AD9466D59F97DFA9B7C45F935A62DB7813E ft=1 fh=b1424d485b15ecfe vn="Variante von Win32/DownloadGuide.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\Downloads\myphoneexplorer.exe" sh=6082BF68BBD8F08ABA9EE861709E4F613CBD7839 ft=1 fh=f09c391b24fe90d9 vn="Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\Downloads\setup(1).exe" sh=AAC8D90DCED7899D6F2BC2401B64C34E696E5145 ft=1 fh=30f84787d1b61df8 vn="Variante von Win32/Bundlore.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Kerstin\Downloads\setup.exe" sh=A72EF64EEDE200EF388FE098B824A43F6657F5D4 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.ABD Trojaner" ac=I fn="C:\Users\Kerstin\My Downloads\Cabal.WS.FULL.27.10.13.rar" sh=50A844EC797C7B349568096C0673E00290A7498C ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Windows\Installer\c9320f.msi" sh=5CC94AE4A690844793C698C4B268E509305FCCD8 ft=1 fh=e337c06c40156b71 vn="Variante von MSIL/Toolbar.Linkury.M.gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll" sh=82CC500F0A463FD435989A4E8D0E5B140518A9C7 ft=1 fh=f8845120cf5263ea vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=571F38A34D64CCCBD914734C8BC01056A78BB5B5 ft=1 fh=d5332291ff13d174 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" sh=1E3950B5433B2EA0375A7B119E5ED2AE35655F35 ft=1 fh=ae6b8f6eb36659a8 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\spbe.dll" sh=FB6FF772C026ADC3BAA1A9FD0E9981177A953F58 ft=1 fh=19a87532ff09fe43 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\spbl.dll" sh=B547F49188B8B4FD14FD8AFED2D8DC390D760CA1 ft=1 fh=c0d2b431bd875300 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\sppsm.dll" sh=09CCC83AE946B1A2F9D123E5BCC160F0B1322E66 ft=1 fh=7225e695ddb52254 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\spusm.dll" sh=4FF4461EFC14F2B9EE8E54AD459DB3D3C0305017 ft=1 fh=72733531b3b70c5a vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\srbs.dll" sh=CD6429346DBB54DD36D81145F9D901B8741A3367 ft=1 fh=8a47f1e2252ef3f8 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\srbu.dll" sh=052E64A824CD325E5D6448F09F5943BCF231A978 ft=1 fh=9e58a417d67982a0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\srptc.dll" sh=63859BE0DDB7ACEC6AE7F0D36E638FC5B694C431 ft=1 fh=2a6e9f657a46ccad vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI30C9.tmp-\srpu.dll" sh=5CC94AE4A690844793C698C4B268E509305FCCD8 ft=1 fh=e337c06c40156b71 vn="Variante von MSIL/Toolbar.Linkury.M.gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll" sh=82CC500F0A463FD435989A4E8D0E5B140518A9C7 ft=1 fh=f8845120cf5263ea vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=571F38A34D64CCCBD914734C8BC01056A78BB5B5 ft=1 fh=d5332291ff13d174 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" sh=1E3950B5433B2EA0375A7B119E5ED2AE35655F35 ft=1 fh=ae6b8f6eb36659a8 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\spbe.dll" sh=FB6FF772C026ADC3BAA1A9FD0E9981177A953F58 ft=1 fh=19a87532ff09fe43 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\spbl.dll" sh=B547F49188B8B4FD14FD8AFED2D8DC390D760CA1 ft=1 fh=c0d2b431bd875300 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\sppsm.dll" sh=09CCC83AE946B1A2F9D123E5BCC160F0B1322E66 ft=1 fh=7225e695ddb52254 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\spusm.dll" sh=4FF4461EFC14F2B9EE8E54AD459DB3D3C0305017 ft=1 fh=72733531b3b70c5a vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\srbs.dll" sh=CD6429346DBB54DD36D81145F9D901B8741A3367 ft=1 fh=8a47f1e2252ef3f8 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\srbu.dll" sh=052E64A824CD325E5D6448F09F5943BCF231A978 ft=1 fh=9e58a417d67982a0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\srptc.dll" sh=63859BE0DDB7ACEC6AE7F0D36E638FC5B694C431 ft=1 fh=2a6e9f657a46ccad vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI3941.tmp-\srpu.dll" sh=5CC94AE4A690844793C698C4B268E509305FCCD8 ft=1 fh=e337c06c40156b71 vn="Variante von MSIL/Toolbar.Linkury.M.gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll" sh=82CC500F0A463FD435989A4E8D0E5B140518A9C7 ft=1 fh=f8845120cf5263ea vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=571F38A34D64CCCBD914734C8BC01056A78BB5B5 ft=1 fh=d5332291ff13d174 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" sh=1E3950B5433B2EA0375A7B119E5ED2AE35655F35 ft=1 fh=ae6b8f6eb36659a8 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\spbe.dll" sh=FB6FF772C026ADC3BAA1A9FD0E9981177A953F58 ft=1 fh=19a87532ff09fe43 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\spbl.dll" sh=B547F49188B8B4FD14FD8AFED2D8DC390D760CA1 ft=1 fh=c0d2b431bd875300 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\sppsm.dll" sh=09CCC83AE946B1A2F9D123E5BCC160F0B1322E66 ft=1 fh=7225e695ddb52254 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\spusm.dll" sh=4FF4461EFC14F2B9EE8E54AD459DB3D3C0305017 ft=1 fh=72733531b3b70c5a vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\srbs.dll" sh=CD6429346DBB54DD36D81145F9D901B8741A3367 ft=1 fh=8a47f1e2252ef3f8 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\srbu.dll" sh=052E64A824CD325E5D6448F09F5943BCF231A978 ft=1 fh=9e58a417d67982a0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\srptc.dll" sh=63859BE0DDB7ACEC6AE7F0D36E638FC5B694C431 ft=1 fh=2a6e9f657a46ccad vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI4FA0.tmp-\srpu.dll" sh=5CC94AE4A690844793C698C4B268E509305FCCD8 ft=1 fh=e337c06c40156b71 vn="Variante von MSIL/Toolbar.Linkury.M.gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll" sh=82CC500F0A463FD435989A4E8D0E5B140518A9C7 ft=1 fh=f8845120cf5263ea vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=571F38A34D64CCCBD914734C8BC01056A78BB5B5 ft=1 fh=d5332291ff13d174 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" sh=1E3950B5433B2EA0375A7B119E5ED2AE35655F35 ft=1 fh=ae6b8f6eb36659a8 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\spbe.dll" sh=FB6FF772C026ADC3BAA1A9FD0E9981177A953F58 ft=1 fh=19a87532ff09fe43 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\spbl.dll" sh=B547F49188B8B4FD14FD8AFED2D8DC390D760CA1 ft=1 fh=c0d2b431bd875300 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\sppsm.dll" sh=09CCC83AE946B1A2F9D123E5BCC160F0B1322E66 ft=1 fh=7225e695ddb52254 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\spusm.dll" sh=4FF4461EFC14F2B9EE8E54AD459DB3D3C0305017 ft=1 fh=72733531b3b70c5a vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\srbs.dll" sh=CD6429346DBB54DD36D81145F9D901B8741A3367 ft=1 fh=8a47f1e2252ef3f8 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\srbu.dll" sh=052E64A824CD325E5D6448F09F5943BCF231A978 ft=1 fh=9e58a417d67982a0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\srptc.dll" sh=63859BE0DDB7ACEC6AE7F0D36E638FC5B694C431 ft=1 fh=2a6e9f657a46ccad vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI9AFD.tmp-\srpu.dll" sh=5CC94AE4A690844793C698C4B268E509305FCCD8 ft=1 fh=e337c06c40156b71 vn="Variante von MSIL/Toolbar.Linkury.M.gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll" sh=82CC500F0A463FD435989A4E8D0E5B140518A9C7 ft=1 fh=f8845120cf5263ea vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=571F38A34D64CCCBD914734C8BC01056A78BB5B5 ft=1 fh=d5332291ff13d174 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" sh=1E3950B5433B2EA0375A7B119E5ED2AE35655F35 ft=1 fh=ae6b8f6eb36659a8 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\spbe.dll" sh=FB6FF772C026ADC3BAA1A9FD0E9981177A953F58 ft=1 fh=19a87532ff09fe43 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\spbl.dll" sh=B547F49188B8B4FD14FD8AFED2D8DC390D760CA1 ft=1 fh=c0d2b431bd875300 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\sppsm.dll" sh=09CCC83AE946B1A2F9D123E5BCC160F0B1322E66 ft=1 fh=7225e695ddb52254 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\spusm.dll" sh=4FF4461EFC14F2B9EE8E54AD459DB3D3C0305017 ft=1 fh=72733531b3b70c5a vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\srbs.dll" sh=CD6429346DBB54DD36D81145F9D901B8741A3367 ft=1 fh=8a47f1e2252ef3f8 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\srbu.dll" sh=052E64A824CD325E5D6448F09F5943BCF231A978 ft=1 fh=9e58a417d67982a0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\srptc.dll" sh=63859BE0DDB7ACEC6AE7F0D36E638FC5B694C431 ft=1 fh=2a6e9f657a46ccad vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSIDDF3.tmp-\srpu.dll" sh=8840DBC7533FB78B1E6D0C7D86EC7360E82D040A ft=1 fh=ae02be1ad5609f0d vn="Win32/TrojanDownloader.Agent.BCI Trojaner" ac=I fn="C:\Windows\temp\db29.exe" sh=143A7E5014919715069D5F500062A31031902F51 ft=1 fh=a38179722af15ce8 vn="Variante von Win32/AnyProtect.D evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\AnyProtectEx\AnyProtectTrayIcon.exe" sh=04D91F5EBEA96FA39B1DE6858B8FA88FE1ED41A0 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\53172.crx" sh=5A17A4CCC3E0C9612E8B8EE1C7B030C227F95973 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\53172.xpi" sh=725D0FFABC1D89C25B4CC8332719A0B5023AE9E0 ft=1 fh=3adcabf81dd26b41 vn="Variante von Win32/Toolbar.CrossRider.BP evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\Uninstall.exe" sh=D2C0F8C92CB89312B3D92E8731633C53D1871076 ft=1 fh=05fcdb39b07f92d1 vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\utils.exe" sh=20633973DCDD04727DF512944CFC4E14BA07073C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\MediaPlayerplus\54246.crx" sh=51DDA5F8363F86F856292F8107327FADEB1985CE ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\MediaPlayerplus\54246.xpi" sh=27FED6761C7629F59F73637F9E58FBD02CFAAF2D ft=1 fh=82840ad3150eeb22 vn="Variante von Win32/Toolbar.CrossRider.BP evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\MediaPlayerplus\Uninstall.exe" sh=0BC5D06253D2B7567052C62BCB32981EF2603522 ft=1 fh=697ee69403579d59 vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\MediaPlayerplus\utils.exe" sh=A8A65FB4279DF98DD572C1ABA570AD3512070C27 ft=1 fh=1f862fe9efb74ac9 vn="Variante von Win32/AdWare.AddLyrics.BA Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQL158.dll" sh=66F1BE2B0246490E8C00DEB464D8E8D225016CE4 ft=1 fh=9893a5deb0eb68f5 vn="Variante von Win32/AdWare.AddLyrics.AK Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe" sh=770C4B96450DBB3CAEA94B831119A5A45F3FEBCB ft=1 fh=ec8cb327aedd3495 vn="Variante von Win32/AdWare.AddLyrics.AJ Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQLOWw.exe" sh=732ABCFD86D73579BB270EB9EFA91DE6B22B39FC ft=1 fh=3a2d6583ece91c8d vn="Variante von Win32/AdWare.AddLyrics.AS Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\Re-markit-soft\Uninstall.exe" sh=AAEA2D2C15813161F9E114E6E1708CE545D5C8CA ft=1 fh=0022d452663e533e vn="Variante von Win32/DealPly.M evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSense\SaveSenseUpdateVer.exe" sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe" sh=10903598F769E2AC5F1E2372E90F6722A3A860B7 ft=1 fh=89560075533c3d40 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll" sh=88482528CE4F67A1004B50BA93282CEACCEDE534 ft=1 fh=e40b702402e604d5 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psmachine.dll" sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe" sh=70D49B9ABA391E6976DAB5C4BEA63733459B3F1C ft=1 fh=0b76a05977e7722a vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe" sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe" sh=F09B9B9B1D16D1539D23CC6ACDE0DC7BC983DF59 ft=1 fh=2dbadf99ca2df2d7 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe" sh=4E475FD620FBCCBB37453AF2BD0427BDA73109FF ft=1 fh=70875884387ffbdb vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\DpInterface32.dll" sh=524ED1264811258D64BA2BE8B48005C6D1935713 ft=1 fh=19b60c262a337e59 vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\DpInterface64.dll" sh=72971E4B87542575A876B36FB87879B416F4EC88 ft=1 fh=eb8c71c588367618 vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\DpInterfacef32.dll" sh=01C9B3D0E073B824021B29F1FD957A8643DF6931 ft=1 fh=9d9cb38b273b86fe vn="Variante von Win32/ELEX.AR evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\RSHP.exe" sh=F34BB16FA7EEF85B106A7C3A3FDEEE95ECF18001 ft=1 fh=7bd5299d4d87abc5 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\SearchProtect32.dll" sh=FB15CD6ADCD9BDFBF68D5DF5EAEA02BF329F8D4F ft=1 fh=dfa2b1c2f56e7303 vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\SearchProtect64.dll" sh=B733C40B96BCA6CC139230D0F7C4E51CEC12CF35 ft=1 fh=08ea3c71e6c55c1b vn="Win32/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\SpAPPSv32.dll" sh=D6F9F256C03B81C01D6CFF28D2D966F59F786AC3 ft=1 fh=3a3e287aa52ff7e5 vn="Variante von Win64/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\SpAPPSv64.dll" sh=EC7EC5D60C5A578BC9953115D368BECD05BA14B2 ft=1 fh=ecbff00cc7dcc0fd vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Program Files (x86)\SupTab\SupTab.dll" sh=95D8C7F2851240F836D46EBD0DCB0BBAE3C9C3C8 ft=1 fh=c39b2415a29978f2 vn="Variante von Win32/ELEX.AV evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\ProgramData\IePluginService\PluginService.exe" sh=9A189D6EAB28C6F9C20AEEFA3E7134916E38C65B ft=1 fh=c71c0011b919b825 vn="Variante von Win32/ELEX.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\ProgramData\WPM\wprotectmanager.exe" sh=8E06E50B0CBFA8E4CA1C53E149AF51D6CB70B048 ft=1 fh=abbd31e3610824c6 vn="Win32/VOPackage.BC evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\nsg636B.tmp" sh=8E06E50B0CBFA8E4CA1C53E149AF51D6CB70B048 ft=1 fh=abbd31e3610824c6 vn="Win32/VOPackage.BC evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\13IZS1EV\Setup[1].exe" sh=CEFE0A678B49D72BDCC996F79CF2DB0B95FEF6B1 ft=1 fh=9d7011981dcd65ae vn="Win32/SpeedUpMyPC evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DVJK7S2\SpeedUpMyPC-standalone-setup[1].exe" sh=0412092F54E42A01109B16456315ACF18FCFE64B ft=1 fh=cd059c019f892a66 vn="Win32/Conduit.SearchProtect.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DVJK7S2\SPSetup[1].exe" sh=24FEC569E88DBBD7E60B93F47036302D7ECD4AA7 ft=1 fh=275222c212f2a6ff vn="Win32/AdWare.PricePeep.B Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7EGMH37D\pricepeep_190001_0102[1].exe" sh=D4E1E10EF1DB5CF927AF158CDF7D25C231BCC0E9 ft=1 fh=9c13b6a5f88b5be6 vn="Win32/OutBrowse.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I9KG89KF\RegCleanSetup10[1].exe" sh=815CE918A2CF57F5E0A3A9346FD9A6F6B3D03D30 ft=1 fh=028c167410bf2336 vn="Win32/InstallCore.GI evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\PMB Files\Upgrade41270\PMB_updater.exe" sh=7B890323ABFE8F3BD33BE0BC439076B5525D03B0 ft=1 fh=790f07a45776117f vn="MSIL/MyPCBackup.D evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\BackupSetup.exe" sh=2A97153C16443DB59BB9887AC982293250EBDB1B ft=1 fh=a5170c70675b29c9 vn="Variante von Win32/DomaIQ.AF evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\bhs64D6.tmp" sh=8E06E50B0CBFA8E4CA1C53E149AF51D6CB70B048 ft=1 fh=abbd31e3610824c6 vn="Win32/VOPackage.BC evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\nsg636B.tmp" sh=7D3C13ACA4D8F0F26AD9A458CF86DA235A58CDCE ft=1 fh=413c2d7f5aa203f9 vn="MSIL/Tuguu.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\android.exe" sh=AF57ECA3F314CD7A615212A03823D5BC0BE30AF7 ft=1 fh=bee73e22821baec6 vn="Mehrere Bedrohungen" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\2040-2082_Re-markit.exe" sh=7D3C13ACA4D8F0F26AD9A458CF86DA235A58CDCE ft=1 fh=413c2d7f5aa203f9 vn="MSIL/Tuguu.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\AndroidSetup.exe" sh=1A9C2CE8C1F539AC8546D67C9F924AEA8D2A84C2 ft=1 fh=d348c3328e970e39 vn="Win32/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\Cloud_Backup_Setup.exe" sh=537C8FAD67F52AF763BF552C0039EA5F2381BA45 ft=1 fh=10217ca882c74d14 vn="Variante von Win32/ELEX.AF evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\lly_webssearches.exe" sh=FDC9F0E6F9720F0D46259D82D9D3F0AB11768E9A ft=1 fh=511192951e276f12 vn="Win32/Packed.ScrambleWrapper.M evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\mediaplayerpluus.exe" sh=8740194542D8B48437766D831883CFA6A0B94414 ft=1 fh=836ad3b9ae02d8c2 vn="Win32/Packed.ScrambleWrapper.M evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\setup.exe" sh=D297E17514FDF53B0A58B9ED686A2B5573BFC4DF ft=1 fh=3eb7aee6a2534744 vn="Win32/SpeedUpMyPC.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\speedupmypc.exe" sh=31178B28FECEFA25D755FDA60EE7D4CD19BB62F8 ft=1 fh=df247d35c433dd44 vn="Win32/VOPackage.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\VOPackage.exe" sh=DCB97CC5B1977BB49DF05C165C63BF54550916E9 ft=1 fh=61ca867c73ed6be8 vn="MSIL/Tuguu.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\android\android.exe" sh=282501AA2FA177D942282F8E2EB5E1D25CA17AED ft=1 fh=170a29edd91c8b10 vn="Variante von Win32/ELEX.AV evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\fullpackage_temp1397857199\tmp\SupTab.exe" sh=9A189D6EAB28C6F9C20AEEFA3E7134916E38C65B ft=1 fh=c71c0011b919b825 vn="Variante von Win32/ELEX.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\fullpackage_temp1397857199\tmp\wpm.exe" sh=CEFE0A678B49D72BDCC996F79CF2DB0B95FEF6B1 ft=1 fh=9d7011981dcd65ae vn="Win32/SpeedUpMyPC evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\is-UD1IQ.tmp\SpeedUpMyPC-standalone-setup.exe" sh=89DC63472DE94DF3F12DBAE15B7EBE6C04263369 ft=1 fh=7fb9e45e0079471d vn="Variante von Win32/Toolbar.Escort.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Local\Temp\is39994101\mysearchdial.dll" sh=8563F21B965879AE572840082BB2E9E5990F8A45 ft=1 fh=0aef99ed940fde6b vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Roaming\OpenCandy\9E9C4CA67A8C4D4893F190CD91CB51EB\sas.exe" sh=7B722A85CE6450E5D2B061C6D55BD6C7C82B3838 ft=1 fh=4b4dd648bb3da366 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Roaming\OpenCandy\9E9C4CA67A8C4D4893F190CD91CB51EB\SaveSense_p1v2.exe" sh=D383A7A87AB3076147EA6C1EF4A98EE979670AC2 ft=1 fh=cea6bc5b1fc91d53 vn="Variante von Win32/DealPly.S evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe" sh=EC7EC5D60C5A578BC9953115D368BECD05BA14B2 ft=1 fh=ecbff00cc7dcc0fd vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\AppData\Roaming\SupTab\SupTab.dll" sh=8A72F448F17C026A1B2A59686DE720079CCBA08F ft=1 fh=4d4a711952b3453e vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\Downloads\DTLite4481-0347.exe" sh=AED302F289133C696DC7B8CB5176DF8CA2997F86 ft=1 fh=1ac604f9fee00e4d vn="Win32/OutBrowse.P evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\Downloads\setup.exe" sh=A2CCC5D721A94540E6276D965CB3045357F5AA52 ft=1 fh=c71c001190e6f348 vn="Variante von Win32/InstallCore.IK evtl. unerwünschte Anwendung" ac=I fn="C:\Windows.old\Users\kerstin\Downloads\UltimateCodec.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.96 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 67 Java version 32-bit out of Date! Java 64-bit 8 Update 31 Adobe Flash Player 16.0.0.305 Adobe Reader XI Mozilla Firefox (35.0.1) Google Chrome (40.0.2214.111) Google Chrome (40.0.2214.94) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2015 01 Ran by Kerstin (administrator) on KERSTIN-PC on 19-02-2015 00:03:30 Running from C:\Users\Kerstin\Desktop Loaded Profiles: Kerstin (Available profiles: Kerstin) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Spotify Ltd) C:\Users\Kerstin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [ESET-Phase2] => C:\ProgramData\ESET\ESET-phase2.exe [1100656 2010-11-10] () HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-01-27] (Apple Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [Spotify Web Helper] => C:\Users\Kerstin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-02-15] (Spotify Ltd) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [Spotify] => C:\Users\Kerstin\AppData\Roaming\Spotify\spotify.exe [6737976 2015-02-15] (Spotify Ltd) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [AirDroid 3] => C:\Program Files (x86)\AirDroid\AirDroid.exe /start GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://syb.msn.com SearchScopes: HKLM -> {05B62290-31C8-45EC-99C6-F05963923521} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSBTDF&pc=MASB&src=IE-SearchBox SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default FF Homepage: hxxp://go.1und1.de/tb/mff_startpage|hxxp://www.giga.de/androidnews/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2890383179-3499982190-3409672644-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kerstin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-2890383179-3499982190-3409672644-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\google-maps.xml FF Extension: anonymoX - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\client@anonymox.net.xpi [2014-05-08] FF Extension: Trusted Shops Add-On für Firefox - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\jid1-PBNne26X1Kn6hQ@jetpack.xpi [2014-08-05] FF Extension: {0db9152f-2c09-4a6a-b006-6852e1787975} - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\{0db9152f-2c09-4a6a-b006-6852e1787975}.xpi [2015-02-10] FF HKLM\...\Firefox\Extensions: [{01856272-60D2-48c0-8F8F-852C369B15A1}] - C:\Program Files\Slotomania Coin Expansion Pack\Firefox FF HKLM-x32\...\Firefox\Extensions: [{01856272-60D2-48c0-8F8F-852C369B15A1}] - C:\Program Files\Slotomania Coin Expansion Pack\Firefox Chrome: ======= CHR HomePage: Default -> hxxp://istart.webssearches.com/?type=hppp&ts=1402753960&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062 CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hppp&ts=1402753960&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062" CHR DefaultSearchKeyword: Default -> webssearches CHR DefaultSearchURL: Default -> hxxp://istart.webssearches.com/web/?type=dspp&ts=1402826947&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062&q={searchTerms} CHR DefaultSuggestURL: Default -> CHR Profile: C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-16] CHR Extension: (Google Drive) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-16] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27] CHR Extension: (YouTube) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-16] CHR Extension: (Slotomania Coin Expansion Pack) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmonpfhhpdjphhlanhockbccaakgahgh [2014-05-28] CHR Extension: (Google Search) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-16] CHR Extension: (Google Wallet) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-16] CHR Extension: (Gmail) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-05-09] (Avira Operations GmbH & Co. KG) R3 igddim64; C:\Windows\System32\DRIVERS\igddim64.sys [1703936 2011-08-30] (Intel Corporation) R3 imgkmd64; C:\Windows\System32\DRIVERS\imgkmd64.sys [479232 2011-08-30] (Imagination Technologies) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) S3 s1029bus; C:\Windows\System32\DRIVERS\s1029bus.sys [116264 2009-05-25] (MCCI Corporation) S3 s1029mdfl; C:\Windows\System32\DRIVERS\s1029mdfl.sys [19496 2009-05-25] (MCCI Corporation) S3 s1029mdm; C:\Windows\System32\DRIVERS\s1029mdm.sys [158760 2009-05-25] (MCCI Corporation) S3 s1029mgmt; C:\Windows\System32\DRIVERS\s1029mgmt.sys [139304 2009-05-25] (MCCI Corporation) S3 s1029nd5; C:\Windows\System32\DRIVERS\s1029nd5.sys [34856 2009-05-25] (MCCI Corporation) S3 s1029obex; C:\Windows\System32\DRIVERS\s1029obex.sys [135208 2009-05-25] (MCCI Corporation) S3 s1029unic; C:\Windows\System32\DRIVERS\s1029unic.sys [151592 2009-05-25] (MCCI Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 massfilter_hs; \??\C:\Windows\system32\drivers\massfilter_hs.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X] S3 zghsmdm; system32\DRIVERS\zghsmdm.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-19 00:03 - 2015-02-19 00:04 - 00016452 _____ () C:\Users\Kerstin\Desktop\FRST.txt 2015-02-19 00:03 - 2015-02-19 00:03 - 00000000 ____D () C:\Users\Kerstin\Desktop\FRST-OlderVersion 2015-02-18 23:44 - 2015-02-18 23:44 - 00852594 _____ () C:\Users\Kerstin\Downloads\SecurityCheck.exe 2015-02-18 21:42 - 2015-02-18 21:43 - 00000000 ____D () C:\Users\Kerstin\Desktop\Keiner Kommt Klar Mit Mir 2015-02-18 17:12 - 2015-02-18 17:12 - 02347384 _____ (ESET) C:\Users\Kerstin\Downloads\esetsmartinstaller_deu(1).exe 2015-02-17 18:25 - 2015-02-17 18:25 - 02347384 _____ (ESET) C:\Users\Kerstin\Downloads\esetsmartinstaller_deu.exe 2015-02-16 22:18 - 2015-02-16 22:18 - 02085888 _____ (Farbar) C:\Users\Kerstin\Downloads\FRST64(1).exe 2015-02-16 22:01 - 2015-02-16 22:01 - 01388274 _____ (Thisisu) C:\Users\Kerstin\Desktop\JRT.exe 2015-02-16 21:50 - 2015-02-16 21:50 - 00316536 _____ () C:\Windows\Minidump\021615-14913-01.dmp 2015-02-16 21:31 - 2015-02-16 21:36 - 00000000 ____D () C:\AdwCleaner 2015-02-16 21:30 - 2015-02-16 21:30 - 02112512 _____ () C:\Users\Kerstin\Desktop\AdwCleaner_4.110.exe 2015-02-16 20:33 - 2015-02-18 16:08 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-16 20:33 - 2015-02-16 20:33 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-02-16 20:33 - 2015-02-16 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-02-16 20:33 - 2015-02-16 20:33 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-02-16 20:33 - 2015-02-16 20:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-02-16 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-02-16 20:33 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-02-16 20:33 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-02-16 20:31 - 2015-02-16 20:32 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Kerstin\Downloads\mbam-setup-2.0.4.1028.exe 2015-02-16 00:57 - 2015-02-16 00:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2015-02-16 00:57 - 2015-02-16 00:57 - 00000000 ____D () C:\Program Files\7-Zip 2015-02-16 00:54 - 2015-02-16 00:54 - 01513472 _____ () C:\Users\Kerstin\Downloads\7z938-x64.msi 2015-02-15 23:16 - 2015-02-15 23:23 - 00000000 ____D () C:\Users\Kerstin\Documents\AirDroid 2015-02-15 22:57 - 2015-02-15 22:58 - 09146874 _____ () C:\Users\Kerstin\Downloads\AirDroid_Desktop_Client_3.0.4.exe 2015-02-15 17:27 - 2015-02-15 17:27 - 00040320 _____ () C:\ComboFix.txt 2015-02-15 17:17 - 2015-02-15 17:17 - 00000000 _____ () C:\Windows\SysWOW64\shoA06B.tmp 2015-02-15 16:54 - 2015-02-15 16:54 - 00001485 _____ () C:\Users\Kerstin\Desktop\ComboFix - Verknüpfung.lnk 2015-02-15 16:54 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-02-15 16:54 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-02-15 16:54 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-02-15 16:54 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-02-15 16:54 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-02-15 16:54 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-02-15 16:54 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-02-15 16:54 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2015-02-15 16:53 - 2015-02-15 17:27 - 00000000 ____D () C:\Qoobox 2015-02-15 16:52 - 2015-02-15 17:23 - 00000000 ____D () C:\Windows\erdnt 2015-02-15 16:51 - 2015-02-15 16:51 - 05611771 ____R (Swearware) C:\Users\Kerstin\Downloads\ComboFix.exe 2015-02-15 15:53 - 2015-02-15 15:53 - 00001268 _____ () C:\Users\Kerstin\Desktop\Revo Uninstaller.lnk 2015-02-15 15:52 - 2015-02-15 15:52 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-02-15 15:37 - 2015-02-15 15:51 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Kerstin\Downloads\revosetup95.exe 2015-02-15 00:37 - 2015-02-15 00:37 - 00000000 _____ () C:\Windows\SysWOW64\sho50B4.tmp 2015-02-15 00:25 - 2015-02-15 00:25 - 00000000 ____D () C:\Program Files\SAMSUNG 2015-02-15 00:25 - 2014-10-13 06:57 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2015-02-15 00:25 - 2014-10-13 06:57 - 00110336 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2015-02-14 22:22 - 2015-02-14 22:22 - 00380416 _____ () C:\Users\Kerstin\Downloads\Gmer-19357(1).exe 2015-02-14 22:18 - 2015-02-14 22:18 - 00380416 _____ () C:\Users\Kerstin\Downloads\Gmer-19357.exe 2015-02-14 22:16 - 2015-02-16 22:29 - 00000000 ____D () C:\Users\Kerstin\Desktop\logdateien 2015-02-14 22:12 - 2015-02-14 22:14 - 00029291 _____ () C:\Users\Kerstin\Downloads\Addition.txt 2015-02-14 22:08 - 2015-02-19 00:03 - 00000000 ____D () C:\FRST 2015-02-14 22:08 - 2015-02-16 22:20 - 00034458 _____ () C:\Users\Kerstin\Downloads\FRST.txt 2015-02-14 22:06 - 2015-02-19 00:03 - 02086912 _____ (Farbar) C:\Users\Kerstin\Desktop\FRST64.exe 2015-02-14 22:01 - 2015-02-14 22:01 - 00000000 _____ () C:\Users\Kerstin\defogger_reenable 2015-02-14 21:58 - 2015-02-14 21:58 - 00050477 _____ () C:\Users\Kerstin\Desktop\Defogger.exe 2015-02-14 01:41 - 2015-02-15 00:25 - 00000000 ____D () C:\ProgramData\Samsung 2015-02-14 00:50 - 2015-02-14 01:42 - 00000000 ____D () C:\Users\Kerstin\Documents\samsung 2015-02-14 00:50 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log 2015-02-14 00:50 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Kerstin\Documents\SelfMV 2015-02-14 00:49 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Samsung 2015-02-14 00:49 - 2015-02-14 00:49 - 00001973 _____ () C:\Users\Public\Desktop\Samsung Kies 3.lnk 2015-02-14 00:49 - 2015-02-14 00:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2015-02-14 00:49 - 2015-02-14 00:49 - 00000000 ____D () C:\Program Files (x86)\Samsung 2015-02-14 00:49 - 2014-05-07 17:42 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\SysWOW64\secman.dll 2015-02-14 00:39 - 2015-02-14 00:40 - 42498888 _____ (Samsung Electronics Co., Ltd.) C:\Users\Kerstin\Downloads\Kies3Setup.exe 2015-02-14 00:00 - 2015-02-14 00:00 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\MyPhoneExplorer 2015-02-13 23:59 - 2015-02-13 23:59 - 00002061 _____ () C:\Users\Public\Desktop\MyPhoneExplorer.lnk 2015-02-13 23:59 - 2015-02-13 23:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer 2015-02-13 23:58 - 2015-02-13 23:59 - 00000000 ____D () C:\Program Files (x86)\MyPhoneExplorer 2015-02-13 23:40 - 2015-02-13 23:40 - 00659464 _____ () C:\Users\Kerstin\Downloads\myphoneexplorer.exe 2015-02-12 18:28 - 2014-12-05 11:32 - 139196615 _____ () C:\Users\Kerstin\20141205_113135.mp4 2015-02-12 18:28 - 2014-12-01 11:24 - 232466986 _____ () C:\Users\Kerstin\20141201_112247.mp4 2015-02-12 18:28 - 2014-11-30 11:30 - 275072892 _____ () C:\Users\Kerstin\20141130_112831.mp4 2015-02-12 18:27 - 2014-11-23 22:31 - 208943022 _____ () C:\Users\Kerstin\20141123_222952.mp4 2015-02-12 18:27 - 2014-11-14 19:52 - 136757681 _____ () C:\Users\Kerstin\20141114_195143.mp4 2015-02-12 18:27 - 2014-11-14 13:46 - 311908025 _____ () C:\Users\Kerstin\20141114_134342.mp4 2015-02-12 18:26 - 2015-01-26 08:34 - 143517436 _____ () C:\Users\Kerstin\20150126_083313.mp4 2015-02-12 18:26 - 2015-01-12 22:21 - 346180627 _____ () C:\Users\Kerstin\20150112_221907.mp4 2015-02-12 18:26 - 2015-01-01 00:11 - 00351735 _____ () C:\Users\Kerstin\20150101_001052.mp4 2015-02-12 18:26 - 2014-12-27 15:34 - 74917974 _____ () C:\Users\Kerstin\20141227_153416.mp4 2015-02-12 18:26 - 2014-12-27 15:32 - 41031175 _____ () C:\Users\Kerstin\20141227_153210.mp4 2015-02-12 18:26 - 2014-12-25 21:13 - 157444083 _____ () C:\Users\Kerstin\20141225_211203.mp4 2015-02-12 18:26 - 2014-11-09 18:32 - 356998952 _____ () C:\Users\Kerstin\20141109_182926.mp4 2015-02-12 18:25 - 2014-12-25 21:11 - 180618452 _____ () C:\Users\Kerstin\20141225_211021.mp4 2015-02-12 18:25 - 2014-12-25 14:36 - 207078718 _____ () C:\Users\Kerstin\20141225_143453.mp4 2015-02-12 18:25 - 2014-12-24 18:41 - 06138834 _____ () C:\Users\Kerstin\20141224_184113.mp4 2015-02-12 18:25 - 2014-12-20 14:14 - 239835541 _____ () C:\Users\Kerstin\20141220_141233.mp4 2015-02-12 18:25 - 2014-12-19 19:42 - 101770616 _____ () C:\Users\Kerstin\20141219_194114.mp4 2015-02-12 18:24 - 2014-12-15 19:04 - 244473975 _____ () C:\Users\Kerstin\20141215_190217.mp4 2015-02-12 18:24 - 2014-12-14 19:26 - 211934675 _____ () C:\Users\Kerstin\20141214_192449.mp4 2015-02-12 17:00 - 2015-02-12 17:00 - 00001753 _____ () C:\Users\Public\Desktop\iTunes.lnk 2015-02-12 17:00 - 2015-02-12 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-02-12 16:57 - 2015-02-12 16:59 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-02-12 16:57 - 2015-02-12 16:59 - 00000000 ____D () C:\Program Files\iTunes 2015-02-12 16:57 - 2015-02-12 16:57 - 00000000 ____D () C:\Program Files\iPod 2015-02-12 16:57 - 2015-02-12 16:57 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-02-11 14:47 - 2015-02-11 14:47 - 00000000 _____ () C:\Windows\SysWOW64\sho8A0A.tmp 2015-02-10 19:38 - 2015-02-10 19:54 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Genymobile 2015-02-10 19:38 - 2015-02-10 19:50 - 00000000 ____D () C:\Users\Kerstin\.VirtualBox 2015-02-10 19:36 - 2013-04-12 11:41 - 00237840 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys 2015-02-10 19:33 - 2013-04-12 11:40 - 00120080 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys 2015-02-10 19:31 - 2015-02-10 19:31 - 00000000 ____D () C:\Program Files\Genymobile 2015-02-10 19:29 - 2015-02-10 19:29 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Temp515a80549b13c62719b8b0be014862d3 2015-01-31 22:17 - 2015-01-31 22:17 - 00000000 _____ () C:\Windows\SysWOW64\sho83D.tmp 2015-01-31 11:58 - 2015-02-11 11:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-25 00:12 - 2015-01-25 00:12 - 00000000 _____ () C:\Windows\SysWOW64\sho29F1.tmp 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia 2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe 2015-01-21 19:55 - 2015-01-21 19:55 - 00386448 _____ () C:\Windows\Minidump\012115-17035-01.dmp ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-18 21:47 - 2014-05-04 19:26 - 01777251 _____ () C:\Windows\WindowsUpdate.log 2015-02-18 21:35 - 2009-07-14 05:51 - 00054336 _____ () C:\Windows\setupact.log 2015-02-18 21:16 - 2014-05-16 19:46 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-18 21:12 - 2010-11-21 07:50 - 00699386 _____ () C:\Windows\system32\perfh007.dat 2015-02-18 21:12 - 2010-11-21 07:50 - 00149268 _____ () C:\Windows\system32\perfc007.dat 2015-02-18 21:12 - 2009-07-14 06:13 - 01620248 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-18 16:48 - 2014-06-16 19:24 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Spotify 2015-02-18 16:02 - 2009-07-14 05:45 - 00028896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-18 16:02 - 2009-07-14 05:45 - 00028896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-18 15:56 - 2014-06-16 19:25 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Spotify 2015-02-18 15:53 - 2014-05-04 20:18 - 01114783 _____ () C:\Users\Kerstin\Documents\ESET-installation-phase2.log 2015-02-18 15:52 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-17 17:54 - 2014-05-04 20:14 - 00000000 ____D () C:\ProgramData\ESET 2015-02-16 22:33 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin 2015-02-16 21:50 - 2014-06-20 16:18 - 00000000 ____D () C:\Windows\Minidump 2015-02-16 21:50 - 2014-05-14 21:26 - 294253685 _____ () C:\Windows\MEMORY.DMP 2015-02-16 21:37 - 2010-11-21 04:47 - 00690896 _____ () C:\Windows\PFRO.log 2015-02-16 21:36 - 2014-06-14 14:53 - 00001083 _____ () C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2015-02-16 21:36 - 2014-05-16 19:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-02-16 21:36 - 2014-05-04 22:58 - 00001065 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-02-16 21:36 - 2014-05-04 19:34 - 00000999 _____ () C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-02-16 21:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\L2Schemas 2015-02-16 21:08 - 2014-05-15 22:36 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\com 2015-02-16 21:07 - 2014-05-06 21:32 - 00000000 ____D () C:\temp 2015-02-16 16:46 - 2015-01-14 18:25 - 00000112 _____ () C:\ProgramData\5uKMmosV2.dat 2015-02-16 16:35 - 2015-01-10 00:53 - 00000000 ____D () C:\Users\Kerstin\Desktop\Neuer Ordner (2) 2015-02-15 23:25 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\VirtualStore 2015-02-15 17:27 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2015-02-15 17:19 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2015-02-14 01:55 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries 2015-02-14 00:49 - 2014-05-04 19:55 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-02-12 18:29 - 2014-06-14 23:45 - 00792576 ___SH () C:\Users\Kerstin\Thumbs.db 2015-02-12 16:57 - 2014-08-24 18:38 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-02-12 16:55 - 2014-08-24 18:40 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2015-02-11 21:05 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Windows Live 2015-02-10 16:41 - 2014-05-21 09:54 - 00000000 ____D () C:\ProgramData\BlueStacksSetup 2015-02-09 14:19 - 2014-05-16 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-09 14:19 - 2014-05-16 10:01 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-09 14:19 - 2014-05-13 22:59 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-07 21:11 - 2014-05-16 19:46 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-07 21:11 - 2014-05-16 19:46 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-07 21:11 - 2014-05-16 19:46 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-07 19:29 - 2014-08-22 07:58 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Adobe 2015-02-07 19:29 - 2014-05-04 21:42 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-07 19:29 - 2014-05-04 21:42 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-31 22:17 - 2014-05-04 22:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-24 20:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration ==================== Files in the root of some directories ======= 2014-05-06 21:56 - 2014-05-06 21:56 - 0000046 _____ () C:\Users\Kerstin\AppData\Roaming\WB.CFG 2015-01-14 18:25 - 2015-02-16 16:46 - 0000112 _____ () C:\ProgramData\5uKMmosV2.dat 2014-05-13 21:56 - 2014-05-13 21:56 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Files to move or delete: ==================== C:\ProgramData\5uKMmosV2.dat Some content of TEMP: ==================== C:\Users\Kerstin\AppData\Local\Temp\avgnt.exe C:\Users\Kerstin\AppData\Local\Temp\Quarantine.exe C:\Users\Kerstin\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-15 17:44 ==================== End Of Log ============================ --- --- --- |
19.02.2015, 00:09 | #10 |
| db29.exe. kommt immer wieder trotz virenscan und quarantäneCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-02-2015 01 Ran by Kerstin at 2015-02-19 00:06:35 Running from C:\Users\Kerstin\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.38 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0938-000001000000}) (Version: 9.38.00.0 - Igor Pavlov) Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Apple Application Support (32-Bit) (HKLM-x32\...\{2FE00055-C4F3-4F7A-AEDD-E198D54CF12F}) (Version: 3.1.1 - Apple Inc.) Apple Application Support (64-Bit) (HKLM\...\{28791292-D18D-42FA-AE66-3D3D20AA8618}) (Version: 3.1.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{5ED7462B-EF58-4757-B609-53755021EC34}) (Version: 8.1.0.18 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG) Avira (x32 Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.3.8.2523 - CDBurnerXP) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.111 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Intel(R) AppUp (HKLM-x32\...\{0A7596DE-9737-44D2-AAFA-58FA9BBCA0AC}) (Version: 1.0.0 - Intel Corporation) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.8.1050 - Intel Corporation) Intel(R) Integrator Assistant (HKLM-x32\...\{D1A35687-AEA9-422C-B237-FC4F8136B6F6}) (Version: 1.0.0 - Intel Corporation) Intel(R) Network Connections 18.4.59.0 (HKLM\...\PROSetDX) (Version: 18.4.59.0 - Intel) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (x32 Version: 10.0.13 - Intel(R) Corporation) Hidden iTunes (HKLM\...\{7B8D4E8A-EA2B-4A71-BFEB-A4AAAB87C5D0}) (Version: 12.1.0.71 - Apple Inc.) Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.670 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.6 - F.J. Wechselberger) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) PCmover OEM Express (HKLM-x32\...\{1EE14CC2-ED85-4EEA-8714-A31C86AF3769}) (Version: 5.00.617 - Laplink Software, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6526 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.) Screen+ version Screen+ 1.0.4 (HKLM-x32\...\{5B7AF05A-1962-489C-B00A-F12D49889FC9}_is1) (Version: Screen+ 1.0.4 - AOC) Sony Ericsson PC Suite (HKLM-x32\...\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}) (Version: - ) Spotify (HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) System Requirements Lab for Intel (HKLM-x32\...\{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}) (Version: 4.5.22.0 - Husdawg, LLC) Unity Web Player (HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\UnityWebPlayer) (Version: 4.5.2f1 - Unity Technologies ApS) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 15-02-2015 10:00:51 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-02-2015 10:01:26 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-02-2015 10:01:26 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-02-2015 10:40:18 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-02-2015 11:10:07 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-02-2015 12:41:58 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-02-2015 12:43:45 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-02-2015 12:43:48 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-02-2015 13:05:11 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-02-2015 14:45:57 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-02-2015 15:58:22 Revo Uninstaller's restore point - Snap.Do 15-02-2015 16:45:49 Revo Uninstaller's restore point - Snap.Do 15-02-2015 19:08:27 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 16-02-2015 00:55:07 Installed 7-Zip 9.38 (x64 edition) 16-02-2015 09:10:20 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2015-02-15 17:17 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {00563FF1-94B2-4ACF-9C5B-C74614DBEB35} - System32\Tasks\{787E8A7B-C4E2-48E0-ACF9-3461BABB54B6} => pcalua.exe -a C:\Users\Kerstin\Downloads\uninstall(3).exe -d C:\Users\Kerstin\Downloads Task: {08857CFB-1827-4BC8-AE12-B859848CE7D0} - System32\Tasks\{F737814D-3683-47E5-AF0C-4E1D320A9951} => pcalua.exe -a C:\Users\Kerstin\Downloads\Player_Setup.exe -d C:\Users\Kerstin\Downloads Task: {08D094D6-0BBD-4B04-9CF4-8DBA255610ED} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {2B1D12A8-48EB-41F9-95C7-12000B4CE960} - System32\Tasks\{67881B7B-FF02-4B3C-9821-7909B874027B} => pcalua.exe -a C:\Users\Kerstin\Downloads\uninstall.exe -d C:\Users\Kerstin\Downloads Task: {3187A450-53D4-4CCD-A8FF-2D5366B0CAE2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-16] (Google Inc.) Task: {3B7260BD-1C98-42DA-98F7-6297611EBF41} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {4553E21B-6E77-4D64-BF94-B5B28819CC49} - System32\Tasks\Driver Booster SkipUAC (Kerstin) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {5916A9E4-39AF-43E3-942A-A24BAF65DBF1} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {5BF6E004-22A9-4C7A-87E2-C78452737D12} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-16] (Google Inc.) Task: {606150B2-4484-4DEA-BEDD-A1D0283FDEED} - System32\Tasks\{E37A25D8-8838-41A3-BC93-DCE5FECBEFB5} => C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe Task: {96424FAA-C6E4-466F-9128-3F0E137581E2} - \FF Watcher {702CC857-65AF-49A7-833D-5615C60C637D} No Task File <==== ATTENTION Task: {A42B3360-11B3-4D6F-B56E-91078D0A055F} - System32\Tasks\{5DA50788-7ECC-4844-B7B1-A78E3EFBAFCA} => pcalua.exe -a C:\Users\Kerstin\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=tugs <==== ATTENTION Task: {A4E92CE6-2AB9-423E-B8B8-B74FB98C7932} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {A53C14D2-FE20-4182-9B0D-0B268780F4C4} - System32\Tasks\{74687C69-1F44-40E3-AF30-79BED7BB4D94} => C:\Users\Kerstin\Downloads\Takania2-Revolution1.3\metin2client_normal.exe Task: {A784D041-1160-4F06-A792-D939E6FCDE03} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {C5D81029-EB29-4F25-8889-B846207F16A8} - System32\Tasks\{CAD0AD2B-781C-4CFF-B7F2-42D9DC4C3AB4} => C:\Users\Kerstin\Downloads\Takania2-Revolution1.3\metin2client_normal.exe Task: {CC04BE37-473F-42B7-9334-71F9FC4BF5BD} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {CCAB2C81-7B17-49A3-88B8-531CB8D975B9} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {D502C482-67D8-4EDC-A288-3AA008B3729B} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {ECCE2458-3451-47D7-836C-F668C20E8D89} - \FF Watcher {900BD071-9C0E-4A65-A289-3F4BDE1F81B6} No Task File <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2015-01-20 22:35 - 2015-01-20 22:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-01-20 22:35 - 2015-01-20 22:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-10-18 10:12 - 2014-10-18 10:12 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\93182e9779b8be0f688fd0784df6d7fb\IsdiInterop.ni.dll 2014-05-13 23:42 - 2010-11-05 23:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2015-01-31 11:58 - 2015-01-31 11:58 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2015-02-07 19:29 - 2015-02-07 19:29 - 16852144 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:373E1720 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== Accounts: ============================= Administrator (S-1-5-21-2890383179-3499982190-3409672644-500 - Administrator - Disabled) Gast (S-1-5-21-2890383179-3499982190-3409672644-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2890383179-3499982190-3409672644-1002 - Limited - Enabled) Kerstin (S-1-5-21-2890383179-3499982190-3409672644-1001 - Administrator - Enabled) => C:\Users\Kerstin ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (02/18/2015 11:37:08 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/18/2015 10:58:54 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 35.0.1.5500, Zeitstempel: 0x54c1f9f3 Name des fehlerhaften Moduls: mozalloc.dll, Version: 35.0.1.5500, Zeitstempel: 0x54c1f224 Ausnahmecode: 0x80000003 Fehleroffset: 0x00001425 ID des fehlerhaften Prozesses: 0x13b0 Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (02/18/2015 05:13:04 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/18/2015 05:12:59 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/18/2015 03:54:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/17/2015 06:26:17 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/17/2015 06:26:10 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/17/2015 05:55:42 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/16/2015 11:53:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (02/18/2015 09:36:05 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR8 gefunden. Error: (02/18/2015 09:36:04 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR8 gefunden. Error: (02/18/2015 09:36:04 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR8 gefunden. Error: (02/18/2015 09:31:37 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (02/18/2015 09:31:07 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (02/18/2015 09:30:35 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (02/18/2015 09:30:05 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (02/18/2015 09:29:03 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (02/18/2015 09:28:33 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst LanmanServer erreicht. Error: (02/18/2015 09:19:52 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR5 gefunden. Microsoft Office Sessions: ========================= Error: (02/18/2015 11:37:08 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (02/18/2015 10:58:54 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe35.0.1.550054c1f9f3mozalloc.dll35.0.1.550054c1f224800000030000142513b001d04bb745e44679C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll540b9b49-b7b9-11e4-9578-00224d7b4b93 Error: (02/18/2015 05:13:04 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Kerstin\Downloads\esetsmartinstaller_deu(1).exe Error: (02/18/2015 05:12:59 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Kerstin\Downloads\esetsmartinstaller_deu(1).exe Error: (02/18/2015 03:54:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/17/2015 06:26:17 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Kerstin\Downloads\esetsmartinstaller_deu.exe Error: (02/17/2015 06:26:10 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Kerstin\Downloads\esetsmartinstaller_deu.exe Error: (02/17/2015 05:55:42 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/16/2015 11:53:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2015-02-15 17:14:35.124 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-15 17:14:34.437 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: Intel(R) Atom(TM) CPU D2500 @ 1.86GHz Percentage of memory in use: 79% Total physical RAM: 2036.66 MB Available physical RAM: 422.21 MB Total Pagefile: 4073.31 MB Available Pagefile: 1844.22 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.99 GB) (Free:158.61 GB) NTFS Drive e: (PHONE CARD) (Removable) (Total:1.87 GB) (Free:1.87 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 909528BB) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 1.8 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ |
19.02.2015, 11:54 | #11 |
/// the machine /// TB-Ausbilder | db29.exe. kommt immer wieder trotz virenscan und quarantäne Java udpaten. WIndows.old löschen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\temp\InstallFilter64.msi C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmonpfhhpdjphhlanhockbccaakgahgh\2.0.0.431_0\main.js C:\Users\Kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8Y7J3MY8\20150213175185[1].exe C:\Users\Kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RGX43U7P\WIE_2.25.2.15[1].exe C:\Users\Kerstin\AppData\Local\Temp\UpdateCV\installer.exe C:\Users\Kerstin\Downloads\Hacks_v10.2.rar C:\Users\Kerstin\Downloads\myphoneexplorer.exe C:\Users\Kerstin\Downloads\setup(1).exe C:\Users\Kerstin\Downloads\setup.exe C:\Users\Kerstin\My Downloads\Cabal.WS.FULL.27.10.13.rar C:\Windows\Installer\c9320f.msi C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSI30C9.tmp-\spbe.dll C:\Windows\Installer\MSI30C9.tmp-\spbl.dll C:\Windows\Installer\MSI30C9.tmp-\sppsm.dll C:\Windows\Installer\MSI30C9.tmp-\spusm.dll C:\Windows\Installer\MSI30C9.tmp-\srbs.dll C:\Windows\Installer\MSI30C9.tmp-\srbu.dll C:\Windows\Installer\MSI30C9.tmp-\srptc.dll C:\Windows\Installer\MSI30C9.tmp-\srpu.dll C:\Windows\Installer\MSI3941.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll C:\Windows\Installer\MSI3941.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSI3941.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSI3941.tmp-\spbe.dll C:\Windows\Installer\MSI3941.tmp-\spbl.dll C:\Windows\Installer\MSI3941.tmp-\sppsm.dll C:\Windows\Installer\MSI3941.tmp-\spusm.dll C:\Windows\Installer\MSI3941.tmp-\srbs.dll C:\Windows\Installer\MSI3941.tmp-\srbu.dll C:\Windows\Installer\MSI3941.tmp-\srptc.dll C:\Windows\Installer\MSI3941.tmp-\srpu.dll C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSI4FA0.tmp-\spbe.dll C:\Windows\Installer\MSI4FA0.tmp-\spbl.dll C:\Windows\Installer\MSI4FA0.tmp-\sppsm.dll C:\Windows\Installer\MSI4FA0.tmp-\spusm.dll C:\Windows\Installer\MSI4FA0.tmp-\srbs.dll C:\Windows\Installer\MSI4FA0.tmp-\srbu.dll C:\Windows\Installer\MSI4FA0.tmp-\srptc.dll C:\Windows\Installer\MSI4FA0.tmp-\srpu.dll C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSI9AFD.tmp-\spbe.dll C:\Windows\Installer\MSI9AFD.tmp-\spbl.dll C:\Windows\Installer\MSI9AFD.tmp-\sppsm.dll C:\Windows\Installer\MSI9AFD.tmp-\spusm.dll C:\Windows\Installer\MSI9AFD.tmp-\srbs.dll C:\Windows\Installer\MSI9AFD.tmp-\srbu.dll C:\Windows\Installer\MSI9AFD.tmp-\srptc.dll C:\Windows\Installer\MSI9AFD.tmp-\srpu.dll C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSIDDF3.tmp-\spbe.dll C:\Windows\Installer\MSIDDF3.tmp-\spbl.dll C:\Windows\Installer\MSIDDF3.tmp-\sppsm.dll C:\Windows\Installer\MSIDDF3.tmp-\spusm.dll C:\Windows\Installer\MSIDDF3.tmp-\srbs.dll C:\Windows\Installer\MSIDDF3.tmp-\srbu.dll C:\Windows\Installer\MSIDDF3.tmp-\srptc.dll C:\Windows\Installer\MSIDDF3.tmp-\srpu.dll C:\Windows\temp\db29.exe C:\Windows.old\Program Files (x86)\AnyProtectEx\AnyProtectTrayIcon.exe C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\53172.crx C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\53172.xpi C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\Uninstall.exe C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\utils.exe C:\Windows.old\Program Files (x86)\MediaPlayerplus\54246.crx C:\Windows.old\Program Files (x86)\MediaPlayerplus\54246.xpi C:\Windows.old\Program Files (x86)\MediaPlayerplus\Uninstall.exe C:\Windows.old\Program Files (x86)\MediaPlayerplus\utils.exe C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQL158.dll C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQLOWw.exe C:\Windows.old\Program Files (x86)\Re-markit-soft\Uninstall.exe C:\Windows.old\Program Files (x86)\SaveSense\SaveSenseUpdateVer.exe C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psmachine.dll C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe C:\Windows.old\Program Files (x86)\SupTab\DpInterface32.dll C:\Windows.old\Program Files (x86)\SupTab\DpInterface64.dll C:\Windows.old\Program Files (x86)\SupTab\DpInterfacef32.dll C:\Windows.old\Program Files (x86)\SupTab\RSHP.exe C:\Windows.old\Program Files (x86)\SupTab\SearchProtect32.dll C:\Windows.old\Program Files (x86)\SupTab\SearchProtect64.dll C:\Windows.old\Program Files (x86)\SupTab\SpAPPSv32.dll C:\Windows.old\Program Files (x86)\SupTab\SpAPPSv64.dll C:\Windows.old\Program Files (x86)\SupTab\SupTab.dll C:\Windows.old\ProgramData\IePluginService\PluginService.exe C:\Windows.old\ProgramData\WPM\wprotectmanager.exe C:\Windows.old\Users\kerstin\AppData\Local\nsg636B.tmp C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\13IZS1EV\Setup[1].exe C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DVJK7S2\SpeedUpMyPC-standalone-setup[1].exe C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DVJK7S2\SPSetup[1].exe C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7EGMH37D\pricepeep_190001_0102[1].exe C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I9KG89KF\RegCleanSetup10[1].exe C:\Windows.old\Users\kerstin\AppData\Local\PMB Files\Upgrade41270\PMB_updater.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\BackupSetup.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\bhs64D6.tmp C:\Windows.old\Users\kerstin\AppData\Local\Temp\nsg636B.tmp C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\android.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\2040-2082_Re-markit.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\AndroidSetup.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\Cloud_Backup_Setup.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\lly_webssearches.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\mediaplayerpluus.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\setup.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\speedupmypc.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\VOPackage.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\android\android.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\fullpackage_temp1397857199\tmp\SupTab.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\fullpackage_temp1397857199\tmp\wpm.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\is-UD1IQ.tmp\SpeedUpMyPC-standalone-setup.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\is39994101\mysearchdial.dll C:\Windows.old\Users\kerstin\AppData\Roaming\OpenCandy\9E9C4CA67A8C4D4893F190CD91CB51EB\sas.exe C:\Windows.old\Users\kerstin\AppData\Roaming\OpenCandy\9E9C4CA67A8C4D4893F190CD91CB51EB\SaveSense_p1v2.exe C:\Windows.old\Users\kerstin\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe C:\Windows.old\Users\kerstin\AppData\Roaming\SupTab\SupTab.dll C:\Windows.old\Users\kerstin\Downloads\DTLite4481-0347.exe C:\Windows.old\Users\kerstin\Downloads\setup.exe C:\Windows.old\Users\kerstin\Downloads\UltimateCodec.exe Task: {96424FAA-C6E4-466F-9128-3F0E137581E2} - \FF Watcher {702CC857-65AF-49A7-833D-5615C60C637D} No Task File <==== ATTENTION Task: {A42B3360-11B3-4D6F-B56E-91078D0A055F} - System32\Tasks\{5DA50788-7ECC-4844-B7B1-A78E3EFBAFCA} => pcalua.exe -a C:\Users\Kerstin\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=tugs <==== ATTENTION Task: {ECCE2458-3451-47D7-836C-F668C20E8D89} - \FF Watcher {900BD071-9C0E-4A65-A289-3F4BDE1F81B6} No Task File <==== ATTENTION C:\Users\Kerstin\AppData\Roaming\webssearches S3 zghsmdm; system32\DRIVERS\zghsmdm.sys [X] Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.02.2015, 21:10 | #12 |
| db29.exe. kommt immer wieder trotz virenscan und quarantäne windows.old löschen? passiert da auch nix mit dem rechner? der ordner hat 17 GB....LG |
20.02.2015, 10:42 | #13 |
/// the machine /// TB-Ausbilder | db29.exe. kommt immer wieder trotz virenscan und quarantäne
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.02.2015, 21:25 | #14 |
| db29.exe. kommt immer wieder trotz virenscan und quarantäneCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-02-2015 01 Ran by Kerstin at 2015-02-20 20:59:13 Run:1 Running from C:\Users\Kerstin\Desktop Loaded Profiles: Kerstin (Available profiles: Kerstin) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\temp\InstallFilter64.msi C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmonpfhhpdjphhlanhockbccaakgahgh\2.0.0.431_0\main.js C:\Users\Kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8Y7J3MY8\20150213175185[1].exe C:\Users\Kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RGX43U7P\WIE_2.25.2.15[1].exe C:\Users\Kerstin\AppData\Local\Temp\UpdateCV\installer.exe C:\Users\Kerstin\Downloads\Hacks_v10.2.rar C:\Users\Kerstin\Downloads\myphoneexplorer.exe C:\Users\Kerstin\Downloads\setup(1).exe C:\Users\Kerstin\Downloads\setup.exe C:\Users\Kerstin\My Downloads\Cabal.WS.FULL.27.10.13.rar C:\Windows\Installer\c9320f.msi C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSI30C9.tmp-\spbe.dll C:\Windows\Installer\MSI30C9.tmp-\spbl.dll C:\Windows\Installer\MSI30C9.tmp-\sppsm.dll C:\Windows\Installer\MSI30C9.tmp-\spusm.dll C:\Windows\Installer\MSI30C9.tmp-\srbs.dll C:\Windows\Installer\MSI30C9.tmp-\srbu.dll C:\Windows\Installer\MSI30C9.tmp-\srptc.dll C:\Windows\Installer\MSI30C9.tmp-\srpu.dll C:\Windows\Installer\MSI3941.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll C:\Windows\Installer\MSI3941.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSI3941.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSI3941.tmp-\spbe.dll C:\Windows\Installer\MSI3941.tmp-\spbl.dll C:\Windows\Installer\MSI3941.tmp-\sppsm.dll C:\Windows\Installer\MSI3941.tmp-\spusm.dll C:\Windows\Installer\MSI3941.tmp-\srbs.dll C:\Windows\Installer\MSI3941.tmp-\srbu.dll C:\Windows\Installer\MSI3941.tmp-\srptc.dll C:\Windows\Installer\MSI3941.tmp-\srpu.dll C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSI4FA0.tmp-\spbe.dll C:\Windows\Installer\MSI4FA0.tmp-\spbl.dll C:\Windows\Installer\MSI4FA0.tmp-\sppsm.dll C:\Windows\Installer\MSI4FA0.tmp-\spusm.dll C:\Windows\Installer\MSI4FA0.tmp-\srbs.dll C:\Windows\Installer\MSI4FA0.tmp-\srbu.dll C:\Windows\Installer\MSI4FA0.tmp-\srptc.dll C:\Windows\Installer\MSI4FA0.tmp-\srpu.dll C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSI9AFD.tmp-\spbe.dll C:\Windows\Installer\MSI9AFD.tmp-\spbl.dll C:\Windows\Installer\MSI9AFD.tmp-\sppsm.dll C:\Windows\Installer\MSI9AFD.tmp-\spusm.dll C:\Windows\Installer\MSI9AFD.tmp-\srbs.dll C:\Windows\Installer\MSI9AFD.tmp-\srbu.dll C:\Windows\Installer\MSI9AFD.tmp-\srptc.dll C:\Windows\Installer\MSI9AFD.tmp-\srpu.dll C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSIDDF3.tmp-\spbe.dll C:\Windows\Installer\MSIDDF3.tmp-\spbl.dll C:\Windows\Installer\MSIDDF3.tmp-\sppsm.dll C:\Windows\Installer\MSIDDF3.tmp-\spusm.dll C:\Windows\Installer\MSIDDF3.tmp-\srbs.dll C:\Windows\Installer\MSIDDF3.tmp-\srbu.dll C:\Windows\Installer\MSIDDF3.tmp-\srptc.dll C:\Windows\Installer\MSIDDF3.tmp-\srpu.dll C:\Windows\temp\db29.exe C:\Windows.old\Program Files (x86)\AnyProtectEx\AnyProtectTrayIcon.exe C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\53172.crx C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\53172.xpi C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\Uninstall.exe C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\utils.exe C:\Windows.old\Program Files (x86)\MediaPlayerplus\54246.crx C:\Windows.old\Program Files (x86)\MediaPlayerplus\54246.xpi C:\Windows.old\Program Files (x86)\MediaPlayerplus\Uninstall.exe C:\Windows.old\Program Files (x86)\MediaPlayerplus\utils.exe C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQL158.dll C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQLOWw.exe C:\Windows.old\Program Files (x86)\Re-markit-soft\Uninstall.exe C:\Windows.old\Program Files (x86)\SaveSense\SaveSenseUpdateVer.exe C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psmachine.dll C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe C:\Windows.old\Program Files (x86)\SupTab\DpInterface32.dll C:\Windows.old\Program Files (x86)\SupTab\DpInterface64.dll C:\Windows.old\Program Files (x86)\SupTab\DpInterfacef32.dll C:\Windows.old\Program Files (x86)\SupTab\RSHP.exe C:\Windows.old\Program Files (x86)\SupTab\SearchProtect32.dll C:\Windows.old\Program Files (x86)\SupTab\SearchProtect64.dll C:\Windows.old\Program Files (x86)\SupTab\SpAPPSv32.dll C:\Windows.old\Program Files (x86)\SupTab\SpAPPSv64.dll C:\Windows.old\Program Files (x86)\SupTab\SupTab.dll C:\Windows.old\ProgramData\IePluginService\PluginService.exe C:\Windows.old\ProgramData\WPM\wprotectmanager.exe C:\Windows.old\Users\kerstin\AppData\Local\nsg636B.tmp C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\13IZS1EV\Setup[1].exe C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DVJK7S2\SpeedUpMyPC-standalone-setup[1].exe C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DVJK7S2\SPSetup[1].exe C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7EGMH37D\pricepeep_190001_0102[1].exe C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I9KG89KF\RegCleanSetup10[1].exe C:\Windows.old\Users\kerstin\AppData\Local\PMB Files\Upgrade41270\PMB_updater.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\BackupSetup.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\bhs64D6.tmp C:\Windows.old\Users\kerstin\AppData\Local\Temp\nsg636B.tmp C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\android.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\2040-2082_Re-markit.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\AndroidSetup.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\Cloud_Backup_Setup.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\lly_webssearches.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\mediaplayerpluus.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\setup.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\speedupmypc.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\VOPackage.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\android\android.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\fullpackage_temp1397857199\tmp\SupTab.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\fullpackage_temp1397857199\tmp\wpm.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\is-UD1IQ.tmp\SpeedUpMyPC-standalone-setup.exe C:\Windows.old\Users\kerstin\AppData\Local\Temp\is39994101\mysearchdial.dll C:\Windows.old\Users\kerstin\AppData\Roaming\OpenCandy\9E9C4CA67A8C4D4893F190CD91CB51EB\sas.exe C:\Windows.old\Users\kerstin\AppData\Roaming\OpenCandy\9E9C4CA67A8C4D4893F190CD91CB51EB\SaveSense_p1v2.exe C:\Windows.old\Users\kerstin\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe C:\Windows.old\Users\kerstin\AppData\Roaming\SupTab\SupTab.dll C:\Windows.old\Users\kerstin\Downloads\DTLite4481-0347.exe C:\Windows.old\Users\kerstin\Downloads\setup.exe C:\Windows.old\Users\kerstin\Downloads\UltimateCodec.exe Task: {96424FAA-C6E4-466F-9128-3F0E137581E2} - \FF Watcher {702CC857-65AF-49A7-833D-5615C60C637D} No Task File <==== ATTENTION Task: {A42B3360-11B3-4D6F-B56E-91078D0A055F} - System32\Tasks\{5DA50788-7ECC-4844-B7B1-A78E3EFBAFCA} => pcalua.exe -a C:\Users\Kerstin\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=tugs <==== ATTENTION Task: {ECCE2458-3451-47D7-836C-F668C20E8D89} - \FF Watcher {900BD071-9C0E-4A65-A289-3F4BDE1F81B6} No Task File <==== ATTENTION C:\Users\Kerstin\AppData\Roaming\webssearches S3 zghsmdm; system32\DRIVERS\zghsmdm.sys [X] Emptytemp: ***************** C:\temp\InstallFilter64.msi => Moved successfully. C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmonpfhhpdjphhlanhockbccaakgahgh\2.0.0.431_0\main.js => Moved successfully. "C:\Users\Kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8Y7J3MY8\20150213175185[1].exe" => File/Directory not found. "C:\Users\Kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RGX43U7P\WIE_2.25.2.15[1].exe" => File/Directory not found. C:\Users\Kerstin\AppData\Local\Temp\UpdateCV\installer.exe => Moved successfully. C:\Users\Kerstin\Downloads\Hacks_v10.2.rar => Moved successfully. C:\Users\Kerstin\Downloads\myphoneexplorer.exe => Moved successfully. "C:\Users\Kerstin\Downloads\setup(1).exe" => File/Directory not found. "C:\Users\Kerstin\Downloads\setup.exe" => File/Directory not found. C:\Users\Kerstin\My Downloads\Cabal.WS.FULL.27.10.13.rar => Moved successfully. C:\Windows\Installer\c9320f.msi => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\Smartbar.Resources.LanguageSettings.resources.dll => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\spbe.dll => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\spbl.dll => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\sppsm.dll => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\spusm.dll => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\srbs.dll => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\srbu.dll => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\srptc.dll => Moved successfully. C:\Windows\Installer\MSI30C9.tmp-\srpu.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\Smartbar.Resources.LanguageSettings.resources.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\spbe.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\spbl.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\sppsm.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\spusm.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\srbs.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\srbu.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\srptc.dll => Moved successfully. C:\Windows\Installer\MSI3941.tmp-\srpu.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\Smartbar.Resources.LanguageSettings.resources.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\spbe.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\spbl.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\sppsm.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\spusm.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\srbs.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\srbu.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\srptc.dll => Moved successfully. C:\Windows\Installer\MSI4FA0.tmp-\srpu.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\Smartbar.Resources.LanguageSettings.resources.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\spbe.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\spbl.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\sppsm.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\spusm.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\srbs.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\srbu.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\srptc.dll => Moved successfully. C:\Windows\Installer\MSI9AFD.tmp-\srpu.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Monetization.Proxy.ProxyService.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\Smartbar.Resources.LanguageSettings.resources.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\spbe.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\spbl.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\sppsm.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\spusm.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\srbs.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\srbu.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\srptc.dll => Moved successfully. C:\Windows\Installer\MSIDDF3.tmp-\srpu.dll => Moved successfully. C:\Windows\temp\db29.exe => Moved successfully. "C:\Windows.old\Program Files (x86)\AnyProtectEx\AnyProtectTrayIcon.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\53172.crx" => File/Directory not found. "C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\53172.xpi" => File/Directory not found. "C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\Uninstall.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\HQ-Video-Pro-1.9\utils.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\MediaPlayerplus\54246.crx" => File/Directory not found. "C:\Windows.old\Program Files (x86)\MediaPlayerplus\54246.xpi" => File/Directory not found. "C:\Windows.old\Program Files (x86)\MediaPlayerplus\Uninstall.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\MediaPlayerplus\utils.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQL158.dll" => File/Directory not found. "C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\Re-markit-soft\Re-markitfQLOWw.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\Re-markit-soft\Uninstall.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SaveSense\SaveSenseUpdateVer.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psmachine.dll" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SupTab\DpInterface32.dll" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SupTab\DpInterface64.dll" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SupTab\DpInterfacef32.dll" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SupTab\RSHP.exe" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SupTab\SearchProtect32.dll" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SupTab\SearchProtect64.dll" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SupTab\SpAPPSv32.dll" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SupTab\SpAPPSv64.dll" => File/Directory not found. "C:\Windows.old\Program Files (x86)\SupTab\SupTab.dll" => File/Directory not found. "C:\Windows.old\ProgramData\IePluginService\PluginService.exe" => File/Directory not found. "C:\Windows.old\ProgramData\WPM\wprotectmanager.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\nsg636B.tmp" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\13IZS1EV\Setup[1].exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DVJK7S2\SpeedUpMyPC-standalone-setup[1].exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DVJK7S2\SPSetup[1].exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7EGMH37D\pricepeep_190001_0102[1].exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I9KG89KF\RegCleanSetup10[1].exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\PMB Files\Upgrade41270\PMB_updater.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\BackupSetup.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\bhs64D6.tmp" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\nsg636B.tmp" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\android.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\2040-2082_Re-markit.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\AndroidSetup.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\Cloud_Backup_Setup.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\lly_webssearches.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\mediaplayerpluus.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\setup.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\speedupmypc.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\2b55b279-be93-4381-82ea-0f83a1d5622d\software\VOPackage.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\android\android.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\fullpackage_temp1397857199\tmp\SupTab.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\fullpackage_temp1397857199\tmp\wpm.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\is-UD1IQ.tmp\SpeedUpMyPC-standalone-setup.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Local\Temp\is39994101\mysearchdial.dll" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Roaming\OpenCandy\9E9C4CA67A8C4D4893F190CD91CB51EB\sas.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Roaming\OpenCandy\9E9C4CA67A8C4D4893F190CD91CB51EB\SaveSense_p1v2.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\AppData\Roaming\SupTab\SupTab.dll" => File/Directory not found. "C:\Windows.old\Users\kerstin\Downloads\DTLite4481-0347.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\Downloads\setup.exe" => File/Directory not found. "C:\Windows.old\Users\kerstin\Downloads\UltimateCodec.exe" => File/Directory not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{96424FAA-C6E4-466F-9128-3F0E137581E2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{96424FAA-C6E4-466F-9128-3F0E137581E2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FF Watcher {702CC857-65AF-49A7-833D-5615C60C637D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A42B3360-11B3-4D6F-B56E-91078D0A055F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A42B3360-11B3-4D6F-B56E-91078D0A055F}" => Key deleted successfully. C:\Windows\System32\Tasks\{5DA50788-7ECC-4844-B7B1-A78E3EFBAFCA} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5DA50788-7ECC-4844-B7B1-A78E3EFBAFCA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{ECCE2458-3451-47D7-836C-F668C20E8D89}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ECCE2458-3451-47D7-836C-F668C20E8D89}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FF Watcher {900BD071-9C0E-4A65-A289-3F4BDE1F81B6}" => Key deleted successfully. "C:\Users\Kerstin\AppData\Roaming\webssearches" => File/Directory not found. zghsmdm => Service deleted successfully. EmptyTemp: => Removed 1.7 GB temporary data. The system needed a reboot. ==== End of Fixlog 21:03:57 ==== |
21.02.2015, 14:10 | #15 |
/// the machine /// TB-Ausbilder | db29.exe. kommt immer wieder trotz virenscan und quarantäne fertig
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu db29.exe. kommt immer wieder trotz virenscan und quarantäne |
.exe, adware, adware/adsuproot.99496, avira, db29.exe, immer wieder, inter, interne, internet, kommt immer wieder, langsam, meldung, quara, quarantäne, sache, sachen, scan, taucht, tr/fakeav.1169920.6, trojaner, trotz, verschieben, virenscan, virus, warnung |