|
Plagegeister aller Art und deren Bekämpfung: Malware bei FacebookWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.07.2015, 01:11 | #1 |
| Malware bei Facebook Hallo, ich habe das gleiche Problem wie der User Susi16. Ich gebe mal folgende Infos, vielleicht helfen sie weiter. Ich vermute, dass es sich um eine Facebook-Pishingseite handelt. Ich wollte mich über den Firefox in Facebook einloggen und es erscheint folgender Seitenname: https:// www.facebook.com/?_rdr ?_rdr macht mich sehr stutzig, normal klickt man dann drauf und dann kommt das mit dem Checkpoint, dass eine Malware auf dem PC gefunden wurde! Man wird dann aufgefordert, entweder von Kaspersky oder F Secure ein Malwareprogramm runterzuladen. Es sind natürlich exe Dateien unter gleicher Adresse. Ich lade da natürlich nichts runter. Ich habe einen Screenshot gemacht, da kann man genau die Adresse sehen, wo es runtergeladen werden soll. Ich kann mich übrigens über Opera und Google Chrome ganz normal in Facebook einloggen, dass Problem ist nur mit Firefox, denn ich schon neu installiert habe und das Problem mit Facebook bleibt bestehen. Das Problem ist an einem anderen Pc auch nicht, nur bei mir über Firefox. Was ist denn da los? Handelt es sich defintiv um eine Pishingseite? Wie bekomme ich Firefox wieder sauber, ich vermute, da stimmt etwas nicht. Ich habe mal danach gesucht: AKAMAIHD Das ist doch ein Virus! Adwc Cleaner hat ihn nicht gefunden, Kaspersky und Malwarebytes ebenfalls nicht! Viele Grüße Michelle Das ist der Screenshot: Geändert von michelle80 (09.07.2015 um 02:08 Uhr) |
09.07.2015, 07:05 | #2 |
/// the machine /// TB-Ausbilder | Malware bei Facebook hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
09.07.2015, 09:57 | #3 |
| Malware bei Facebook Hallo Schrauber,
__________________vielen lieben Dank für deine schnelle Hilfe. Ich habe den Scan soeben gemacht. FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015 Ran by lxxxxx (administrator) on Lxxxxx-PC on 09-07-2015 10:50:46 Running from C:\Users\lxxxxx\Downloads Loaded Profiles: lxxxxx & (Available Profiles: laxxxxx & _supereasy_1cbackup_) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe () C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation) HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] () HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd) HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] () Startup: C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-06-03] ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) BootExecute: autocheck autochk * ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-09] (IObit) BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-15] (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-15] (Oracle Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{95A34309-0424-4A48-8ACC-627CE7D0719F}: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default FF DefaultSearchEngine: Ecosia FF SelectedSearchEngine: Ecosia FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_203.dll [2015-07-09] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_203.dll [2015-07-09] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-15] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-15] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( ) FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP) FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( ) FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP) FF SearchPlugin: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\searchplugins\ecosia.xml [2015-05-29] FF Extension: PAYBACK Toolbar - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\toolbar-ff@payback.de.xpi [2014-12-10] FF Extension: Ecosia — The search engine that plants trees! - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2014-06-27] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-03] Chrome: ======= CHR Profile: C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-03] CHR Extension: (Google Drive) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-03] CHR Extension: (YouTube) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-03] CHR Extension: (Google Search) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-03] CHR Extension: (Kaspersky URL Advisor) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-03] CHR Extension: (Safe Money) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-06-03] CHR Extension: (Dangerous Websites Blocker) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-06-03] CHR Extension: (Virtual Keyboard) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-06-03] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12] CHR Extension: (Google Wallet) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-03] CHR Extension: (Gmail) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-03] CHR Extension: (Anti-Banner) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-03] CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-06-03] (Adobe Systems) [File not signed] R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed] R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-07-09] (IObit) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 supereasy_1cbackup; No ImagePath ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices) R0 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20672 2014-06-03] (Glarysoft Ltd) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2014-06-22] (REALiX(tm)) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-03] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-03] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-03] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-03] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-03] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-09] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation) S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] () R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation) S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-09 10:49 - 2015-07-09 10:49 - 02112512 _____ (Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe 2015-07-09 04:41 - 2015-07-09 04:41 - 02953707 _____ (Malwarebytes Corporation) C:\Users\lxxxxx\Downloads\JRT.exe 2015-07-09 04:22 - 2015-07-09 04:22 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-07-09 04:22 - 2015-07-09 04:22 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-07-09 04:22 - 2015-07-09 04:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-07-09 04:19 - 2015-07-09 04:19 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (2).exe 2015-07-09 03:22 - 2015-07-09 04:16 - 00002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_lazzyy 2015-07-09 03:22 - 2015-07-09 03:22 - 00001252 _____ C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2015-07-09 03:22 - 2015-07-09 03:22 - 00001228 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\ProductData 2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\ProductData 2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\IObit 2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IObit 2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\IObit 2015-07-09 03:19 - 2015-07-09 03:20 - 15889184 _____ (IObit) C:\Users\lxxxxx\Downloads\iobituninstaller4.3.0.122.exe 2015-07-09 03:10 - 2015-07-09 03:10 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\lxxxxx\Downloads\rkill.exe 2015-07-09 02:55 - 2015-07-09 02:55 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\172C3BAE.sys 2015-07-09 02:50 - 2015-07-09 02:50 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (1).exe 2015-07-09 01:31 - 2015-07-09 01:31 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0.exe 2015-07-09 01:25 - 2015-07-09 01:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxxx\Downloads\revosetup95 (1).exe 2015-07-09 01:23 - 2015-07-09 01:23 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207 (1).exe 2015-07-09 01:22 - 2015-07-09 01:22 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207.exe 2015-07-09 00:27 - 2015-07-09 00:39 - 00000000 ____D C:\ProgramData\F-Secure 2015-07-09 00:27 - 2015-07-09 00:27 - 00572456 _____ (F-Secure Corporation) C:\Users\lxxxxx\Desktop\F-SecureOnlineScanner.exe 2015-07-09 00:27 - 2015-07-09 00:27 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\F-Secure 2015-07-08 16:07 - 2015-07-08 16:07 - 00416576 _____ (Kaspersky Lab) C:\Users\lxxxxx\Desktop\de-de.setup.exe 2015-07-06 23:41 - 2015-07-06 23:41 - 00003584 _____ C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-07-06 21:29 - 2015-07-06 21:29 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\55ED2575.sys 2015-07-03 15:32 - 2015-07-03 15:32 - 00003288 ____N C:\bootsqm.dat 2015-07-01 23:15 - 2015-07-01 23:15 - 00207349 _____ C:\Users\lxxxxx\Desktop\IMG-20150701-WA0000.jpeg 2015-07-01 23:15 - 2015-07-01 23:15 - 00000256 _____ C:\Users\lxxxxx\Desktop\smil.xml 2015-07-01 18:01 - 2015-07-01 23:09 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\10940049.sys 2015-07-01 18:01 - 2015-07-01 18:01 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6AAD0032.sys 2015-06-30 23:59 - 2015-07-01 14:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\767943A1.sys 2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\54A74377.sys 2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C7C439E.sys 2015-06-30 00:42 - 2015-06-30 00:42 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\550E1672.sys 2015-06-27 21:55 - 2015-06-27 21:55 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\mresreg 2015-06-27 21:54 - 2015-06-27 21:56 - 39346840 _____ (IN MEDIA KG ) C:\Users\lxxxxx\Desktop\diasetup.exe 2015-06-27 21:53 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\FotoWorksXL_2 2015-06-27 21:53 - 2015-06-27 21:53 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IN-MEDIAKG-TI 2015-06-27 21:52 - 2015-06-27 21:52 - 00000000 ____D C:\Program Files (x86)\mresreg 2015-06-27 21:50 - 2015-06-27 21:51 - 36964664 _____ (IN MEDIAKG TI ) C:\Users\lxxxxx\Desktop\fotoworks_setup.exe 2015-06-27 02:25 - 2015-06-27 02:25 - 00942709 _____ C:\Users\lxxxxx\Desktop\bilder-27062015-0224.zip 2015-06-27 02:14 - 2015-06-27 02:26 - 00000000 ____D C:\Users\lxxxxx\Bilder von Jxxxx xxxxx 2015-06-27 00:41 - 2015-06-27 01:20 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\220D2BA0.sys 2015-06-23 00:12 - 2015-06-23 00:12 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\28755C5A.sys 2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6C8C43E3.sys 2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\428F43E0.sys 2015-06-15 16:36 - 2015-06-15 16:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-06-15 16:36 - 2015-06-15 16:36 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2015-06-14 00:47 - 2015-06-14 18:46 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\76213859.sys 2015-06-14 00:47 - 2015-06-14 00:47 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C253856.sys 2015-06-13 01:23 - 2015-06-13 01:23 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2015-06-12 15:41 - 2015-06-12 15:41 - 00017174 _____ C:\Users\lxxxxx\Documents\coolpad.odt 2015-06-11 14:42 - 2015-06-11 15:52 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1D534D16.sys 2015-06-10 15:53 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-06-10 15:53 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-06-10 15:53 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-06-10 15:53 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-06-10 15:53 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-06-10 15:53 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-06-10 15:53 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-06-10 15:53 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe 2015-06-10 15:53 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-06-10 15:53 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-06-10 15:53 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-06-10 15:53 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-06-10 15:53 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe 2015-06-10 15:53 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-06-10 15:53 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-06-10 15:53 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-06-10 15:53 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-06-10 15:53 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-06-10 15:53 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2015-06-10 15:53 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-06-10 15:53 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-06-10 15:53 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-06-10 15:53 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-06-10 15:53 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-06-10 15:53 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-06-10 15:53 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-06-10 15:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-06-10 15:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-06-10 15:53 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-06-10 15:53 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2015-06-10 15:53 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2015-06-10 15:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2015-06-10 15:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2015-06-10 15:53 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2015-06-10 15:52 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-06-10 15:52 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-06-10 15:52 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2015-06-10 15:52 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-06-10 15:51 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-06-10 15:51 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-06-10 15:51 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-06-10 15:51 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-06-10 15:51 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-06-10 15:51 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-06-10 15:51 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-06-10 15:51 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-06-10 15:51 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-06-10 15:51 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-06-10 15:51 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-06-10 15:51 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-06-10 15:51 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-06-10 15:51 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-06-10 15:51 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-06-10 15:51 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-06-10 15:51 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-06-10 15:51 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-06-10 15:51 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-06-10 15:51 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-06-10 15:51 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-06-10 15:51 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-06-10 15:51 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-06-10 15:51 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-06-10 15:51 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-06-10 15:51 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-06-10 15:51 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-06-10 15:51 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-06-10 15:51 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-06-10 15:51 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-06-10 15:51 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-06-10 15:51 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-06-10 15:51 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-06-10 15:51 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-06-10 15:51 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-06-10 15:51 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-06-10 15:51 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-06-10 15:51 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-06-10 15:51 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-06-10 15:51 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-06-10 15:51 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-06-10 15:51 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-06-10 15:51 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-06-10 15:51 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-06-10 15:51 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-06-10 15:51 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-06-10 15:51 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-06-10 15:51 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-06-10 15:51 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-06-10 15:51 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-06-10 15:51 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-06-10 15:51 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-06-10 15:51 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-06-10 15:51 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-06-10 15:51 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-06-10 15:51 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-06-10 15:51 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-06-10 15:51 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-06-10 15:51 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-06-10 15:51 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-06-10 00:39 - 2015-06-10 00:39 - 00013412 _____ C:\Users\lxxxxxx\Documents\michaxxxxxxxxxxxx.odt ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-09 10:50 - 2014-06-12 09:00 - 00022046 _____ C:\Users\lxxxxx\Downloads\FRST.txt 2015-07-09 10:50 - 2014-06-12 08:59 - 00000000 ____D C:\FRST 2015-07-09 10:45 - 2014-06-05 23:04 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-07-09 10:45 - 2014-06-03 17:43 - 00000336 _____ C:\Windows\Tasks\GlaryInitialize 5.job 2015-07-09 10:45 - 2014-06-03 15:47 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-09 10:45 - 2014-06-03 15:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-07-09 10:44 - 2014-06-05 15:51 - 00056806 _____ C:\Windows\setupact.log 2015-07-09 10:44 - 2014-06-05 05:04 - 00000234 _____ C:\BackupLoader.ini 2015-07-09 10:44 - 2014-06-03 15:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-07-09 10:44 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-09 05:07 - 2014-06-02 10:56 - 01900281 _____ C:\Windows\WindowsUpdate.log 2015-07-09 04:26 - 2014-06-03 17:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-07-09 04:25 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-09 04:25 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-09 04:20 - 2014-06-03 15:47 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-09 04:18 - 2011-04-12 09:43 - 00699090 _____ C:\Windows\system32\perfh007.dat 2015-07-09 04:18 - 2011-04-12 09:43 - 00149230 _____ C:\Windows\system32\perfc007.dat 2015-07-09 04:18 - 2009-07-14 07:13 - 01619272 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-09 04:11 - 2015-02-10 02:06 - 00000000 ____D C:\Program Files (x86)\Secunia 2015-07-09 04:11 - 2014-06-06 03:18 - 00019030 _____ C:\Windows\PFRO.log 2015-07-09 03:02 - 2014-06-12 05:32 - 00000000 ____D C:\AdwCleaner 2015-07-09 02:46 - 2014-06-06 18:02 - 00000000 ____D C:\Users\_supereasy_1cbackup_ 2015-07-09 01:27 - 2014-06-03 17:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-07-09 01:26 - 2014-06-03 17:10 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-09 01:26 - 2014-06-03 17:10 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-09 01:25 - 2014-06-03 17:38 - 00001264 _____ C:\Users\lxxxxx\Desktop\Revo Uninstaller.lnk 2015-07-09 01:25 - 2014-06-03 17:38 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2015-07-08 15:48 - 2015-04-21 01:08 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxxxxxab April 2015 2015-07-08 15:21 - 2015-05-18 17:00 - 00000000 ____D C:\Users\lxxxx\Bxxxxx ab Mai 2015 unbearbeitet 2015-07-07 23:22 - 2014-06-03 15:50 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-07-07 22:32 - 2014-06-10 03:33 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0 2015-07-06 23:59 - 2015-01-13 01:36 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieBrowserModeList 2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieUserList 2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieSiteList 2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-07-03 03:41 - 2015-03-23 23:16 - 00000000 ____D C:\Users\lxxxxxBilder xxxxxxxxxxx 2015-07-02 16:28 - 2014-06-10 15:01 - 00000000 ____D C:\Users\lxxxxx\Bildervonxxxxxxxxx 2015-07-01 02:03 - 2014-09-09 01:22 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kontoxxxxx 2015-07-01 02:02 - 2015-01-05 01:38 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kontoxxxxx 2015-06-30 04:10 - 2015-04-16 04:01 - 00000000 ____D C:\Users\lxxxxx\Bilder xxxxxxxxx 2015-06-30 00:40 - 2015-05-18 01:42 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxxx von xxxxxxx 2015-06-27 21:55 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\VirtualStore 2015-06-27 02:14 - 2014-06-03 15:17 - 00000000 ____D C:\Users\lxxxxx 2015-06-27 01:18 - 2014-06-05 23:04 - 00001102 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-06-27 01:18 - 2014-06-05 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-06-27 01:18 - 2014-06-05 23:04 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-06-26 01:47 - 2014-06-06 03:27 - 00000000 ____D C:\xxxxxxxxx 2015-06-25 13:50 - 2014-06-03 16:42 - 00003854 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401804726 2015-06-25 13:50 - 2014-06-03 16:12 - 00000000 ____D C:\Program Files (x86)\Opera 2015-06-24 02:32 - 2014-12-27 01:04 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-06-22 17:22 - 2014-06-14 02:36 - 00000000 ____D C:\Users\lxxxxx\Formular für xxxxxxxxx 2015-06-22 02:21 - 2015-06-08 21:32 - 00012990 _____ C:\Users\lxxxxx\Documents xxxxxxx.odt 2015-06-18 12:19 - 2015-01-10 01:24 - 00000000 ____D C:\Users\lxxxxx\Bilder xxxxxxx2015 2015-06-18 08:41 - 2014-06-05 23:04 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-06-18 08:41 - 2014-06-05 23:04 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-06-18 08:41 - 2014-06-05 23:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-06-17 11:34 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2015-06-15 23:08 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\Adobe 2015-06-15 23:07 - 2014-08-21 05:14 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\Adobe 2015-06-15 16:36 - 2014-06-03 17:29 - 00000000 ____D C:\ProgramData\Adobe 2015-06-15 16:36 - 2014-06-03 17:28 - 00000000 ____D C:\Program Files (x86)\Adobe 2015-06-15 16:33 - 2014-09-10 16:10 - 00000000 ____D C:\ProgramData\Oracle 2015-06-15 16:32 - 2015-02-10 02:13 - 00000000 ____D C:\Program Files (x86)\Java 2015-06-15 16:29 - 2015-02-10 02:13 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-06-15 16:28 - 2015-04-02 03:26 - 00561248 _____ (Oracle Corporation) C:\Users\lxxxxx\Desktop\jxpiinstall.exe 2015-06-13 01:23 - 2014-06-03 15:47 - 00000000 ____D C:\Program Files (x86)\Google 2015-06-10 22:29 - 2009-07-14 06:45 - 00296104 _____ C:\Windows\system32\FNTCACHE.DAT 2015-06-10 22:27 - 2014-12-10 06:09 - 00000000 ____D C:\Windows\system32\appraiser 2015-06-10 22:27 - 2014-06-05 03:10 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-06-10 22:27 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2015-06-10 16:06 - 2014-03-13 13:01 - 00000000 ____D C:\Windows\system32\MRT 2015-06-10 16:02 - 2014-03-13 13:01 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-06-10 15:30 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT ==================== Files in the root of some directories ======= 2015-05-15 03:15 - 2015-05-17 00:13 - 0001062 _____ () C:\Users\lxxxxx\AppData\Local\998087a8e589f390f0b710fed8b8c1bf 2015-07-06 23:41 - 2015-07-06 23:41 - 0003584 _____ () C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-03 17:05 - 2014-06-03 17:05 - 0000057 _____ () C:\ProgramData\Ament.ini 2014-06-02 11:08 - 2014-06-02 11:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Files to move or delete: ==================== C:\Users\lxxxxx\cc_20140606_180858.reg Some files in TEMP: ==================== C:\Users\lxxxxx\AppData\Local\Temp\Quarantine.exe C:\Users\lxxxxx\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-04 15:15 ==================== End of log ============================ FRST Additions Logfile: [CODE]Additional FRST Logfile: Code:
ATTFilter scan result of Farbar Recovery Scan Tool (x64) Version:05-07-2015 Ran by lxxxxx at 2015-07-09 11:01:44 Running from C:\Users\lxxxxx\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-479257388-3634607433-1617756106-500 - Administrator - Disabled) Gast (S-1-5-21-479257388-3634607433-1617756106-501 - Limited - Enabled) lxxxxx (S-1-5-21-479257388-3634607433-1617756106-1001 - Administrator - Enabled) => C:\Users\lxxxxx _supereasy_1cbackup_ (S-1-5-21-479257388-3634607433-1617756106-1002 - Administrator - Enabled) => C:\Users\_supereasy_1cbackup_ ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A} AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) A1-Faktura 1.429 (HKLM-x32\...\A1-Faktura_is1) (Version: - A1-Faktura) AAVUpdateManager (HKLM-x32\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated) Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.191 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.203 - Adobe Systems Incorporated) Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0407-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.) Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.) AMD Catalyst Install Manager (HKLM\...\{82DEBC0B-5BAD-5918-2EDB-7C78BE01BA59}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) Ashampoo Music Studio 4 v.4.1.2 (HKLM-x32\...\{91B33C97-7650-0EB0-B6C7-DDBA2932B7B4}_is1) (Version: 4.1.2 - Ashampoo GmbH & Co. KG) Ashampoo Photo Converter 2 v.2.0.0 (HKLM-x32\...\{C92AB6F1-5566-A904-B32C-720C3BA1A819}_is1) (Version: 2.0.0 - Ashampoo GmbH & Co. KG) CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.4852 - CDBurnerXP) COLOR projects premium (64-Bit) (HKLM\...\COLOR_PROJECTS_1_2_C935FDA1_is1) (Version: 1.14 - Franzis Verlag GmbH) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DriverEasy 4.9.0 (HKLM\...\DriverEasy_is1) (Version: 4.9.0.0 - Easeware) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Glary Utilities 5.1 (HKLM-x32\...\Glary Utilities 5) (Version: 5.1.0.4 - Glarysoft Ltd) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.132 - Google Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard) HP Officejet 6700 - Grundlegende Software für das Gerät (HKLM\...\{9086D601-50B7-491D-A143-28193DADE36B}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet 6700 Hilfe (HKLM-x32\...\{E1AE0CB7-1333-4728-8520-CB3F88A252B4}) (Version: 140.0.2.2 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP) HP Photo Creations (HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\HP Photo Creations) (Version: 1.0.0.18332 - HP) HP Photo Creations (HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\HP Photo Creations) (Version: 1.0.0.18332 - HP) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden HPOJ6700FWUpdateAlert (x32 Version: 1.00.0000 - HP) Hidden HWiNFO64 Version 4.40 (HKLM\...\HWiNFO64_is1) (Version: 4.40 - Martin Malík - REALiX) I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 4.3.0.122 - IObit) Java 7 Update 75 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217075FF}) (Version: 7.0.750 - Oracle) Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden K-Lite Codec Pack 6.0.4 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 6.0.4 - ) Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft_VC100_CRT_x86 (HKLM-x32\...\{6FDDB201-2CA0-42BD-973F-7B2C4A61EA3F}) (Version: 1.0.0 - Microsoft) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 39.0 - Mozilla) Mozilla Thunderbird 31.7.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.7.0 (x86 de)) (Version: 31.7.0 - Mozilla) OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) Opera Stable 30.0.1835.88 (HKLM-x32\...\Opera 30.0.1835.88) (Version: 30.0.1835.88 - Opera Software) phonostar-Player Version 3.03.6 (HKLM-x32\...\phonostar3RadioPlayer_is1) (Version: - ) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) PicPick (HKLM-x32\...\PicPick) (Version: 3.3.3 - NTeWORKS) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.75.827.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7071 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) SIW version 2011.10.29 (HKLM-x32\...\{AB67580-257C-45FF-B8F4-C8C30682091A}_is1) (Version: 2011.10.29 - Topala Software Solutions) StarMoney (x32 Version: 4.0.4.16 - StarFinanz) Hidden StarMoney 9.0 (HKLM-x32\...\{5ACFB561-1610-47FC-8560-3476A99436A1}) (Version: 9.0 - Star Finanz GmbH) Studie zur Verbesserung von HP Officejet 6700 Produkten (HKLM\...\{4EE2A4CB-47B0-4412-808C-D556E3940598}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinRAR 5.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) WinSysClean X5 (HKLM-x32\...\WinSysClean X5) (Version: 15.01 - Ultimate Systems, Inc.) WinSysClean X5 (Version: 15.01 - Ultimate Systems, Inc.) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\lazzyy\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\lazzyy\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\lazzyy\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 30-06-2015 00:04:48 Windows-Sicherung 30-06-2015 00:10:03 Windows Update 03-07-2015 15:50:03 Windows Update 06-07-2015 21:39:14 Windows-Sicherung 07-07-2015 22:46:31 Windows Update 09-07-2015 01:26:29 Revo Uninstaller's restore point - Mozilla Firefox 39.0 (x86 de) 09-07-2015 02:48:04 Revo Uninstaller's restore point - Mozilla Firefox 39.0 (x86 de) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0D15FB05-DDE2-4F40-A56F-CB41A45A35F5} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [2014-06-03] (Glarysoft Ltd) Task: {13EB2625-D6C1-4FBD-A551-122F008041FF} - System32\Tasks\HP AR Program Upload - f1968a237e824f1aac56549d8184b39ff8a9e9ea862440da8e76c91d923d9a8e => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>) Task: {239DC78C-78E0-4712-B88F-9613AD91E785} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-09] (Adobe Systems Incorporated) Task: {2B590E4A-912A-499F-B212-7BE5D8885942} - System32\Tasks\Opera scheduled Autoupdate 1401804726 => C:\Program Files (x86)\Opera\launcher.exe [2015-06-19] (Opera Software) Task: {331EE7CF-85AC-4461-B67A-3641F9816F74} - System32\Tasks\{CAFA87E7-5B0E-4D6A-93D9-41C8A04C3F8E} => pcalua.exe -a C:\Users\lxxxxx\Downloads\wlsetup-web.exe -d C:\Users\lxxxxx\Downloads Task: {48A209B5-AA2D-45CE-ACE7-B1CA2F979172} - System32\Tasks\HPCustParticipation HP Officejet 6700 => C:\Program Files\HP\HP Officejet 6700\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) Task: {4AF9CFD7-9A0E-4A20-AFF7-77595F97912A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-03] (Google Inc.) Task: {4BF0598C-36F1-4E04-97FB-966EA800733B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-03] (Google Inc.) Task: {6D92F43E-CA02-48D1-806B-F9645C42C55F} - System32\Tasks\Uninstaller_SkipUac_lazzyy => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-07-09] (IObit) Task: {77C78D64-44CA-4F07-B984-C7E75DE09E47} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated) Task: {85E0CFE5-ED27-461E-B0B5-64C639234CD0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd) Task: {8C463591-B8BC-4012-8BB9-D82CE68E9612} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [2014-06-03] (Glarysoft Ltd) Task: {A3CE22B5-4185-40F0-A185-93B07931397D} - System32\Tasks\HP AR Program Upload - 8dc37cfbbe5c4f059cab48437ef87ad787a7744ea3d2478eb8cf20e9dd897e9f => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>) Task: {B7087859-6698-4B73-B54D-4A59475B6BD1} - System32\Tasks\HP AR Program Upload - 7ff5e0a1a5934275be8c8d37eb8932441c42c281b9c74d9e89ef987ddd215ffc => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>) Task: {CEF591EC-E41D-4FED-9E30-980843C425C5} - System32\Tasks\HP AR Program Upload - ffe403e0ab8f4198b9fa1da2f8f6350582569d660e024e99a86b80da37b9acf6 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GlaryInitialize 5.job => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2008-10-24 16:35 - 2008-10-24 16:35 - 00128296 _____ () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe 2013-11-01 11:46 - 2013-11-01 11:46 - 00214528 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll 2013-07-26 05:59 - 2013-07-26 05:59 - 00814592 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll 2013-07-26 05:59 - 2013-07-26 05:59 - 03650560 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll 2014-06-04 00:56 - 2014-12-04 11:38 - 00042496 _____ () C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe 2013-11-01 11:46 - 2013-11-01 11:46 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll 2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll 2014-08-04 00:39 - 2011-01-13 11:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney 9.0\ouservice\PATCHW32.dll 2015-05-20 13:47 - 2015-05-20 13:47 - 03350640 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll 2015-05-20 13:47 - 2015-05-20 13:47 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2015-05-20 13:47 - 2015-05-20 13:47 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll 2015-06-25 13:50 - 2015-06-25 13:49 - 01649272 _____ () C:\Program Files (x86)\Opera\30.0.1835.88\libglesv2.dll 2015-06-25 13:50 - 2015-06-25 13:49 - 00081016 _____ () C:\Program Files (x86)\Opera\30.0.1835.88\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{09FF651C-67A9-468E-81C2-5DF8D6DD4CE1}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\FaxApplications.exe FirewallRules: [{9B4E79DA-DCA3-4E0C-9F2B-E8CA186B24B6}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\DigitalWizards.exe FirewallRules: [{A369D5B9-1D02-4E17-AD34-533ECA8486C6}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\SendAFax.exe FirewallRules: [{3E47F44E-8609-44D6-ABC4-2658288C431C}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\DeviceSetup.exe FirewallRules: [{9E111A7C-E2F7-41B4-B504-A4ADD4751613}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe FirewallRules: [{DB00A7DB-A842-4B42-AC53-523114D1F317}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{CA4D1AC4-837F-41C8-A941-34719BF26A6D}] => (Allow) C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{6CCD0811-4563-425C-BFD8-9A2ADB1A55B2}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{129ABF9A-C4E6-4E5D-B4D0-FBAE990C51BB}] => (Allow) LPort=2869 FirewallRules: [{8BF8FCCD-5B06-4343-83E0-2244EB3B46AD}] => (Allow) LPort=1900 FirewallRules: [{325A9DF6-4BE7-4928-BAD7-C176956D5194}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{52659777-06C9-4773-BF70-869C9CA9AB2B}] => (Allow) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe FirewallRules: [{186659B8-57D8-4D9D-8C8D-7644F6BE7BEE}] => (Allow) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe FirewallRules: [{DEE1F2D5-24E5-4FAC-97C9-29B251ABE36B}] => (Allow) C:\Program Files (x86)\StarMoney 9.0\app\StarMoney.exe FirewallRules: [{AC3840B2-B76A-44A9-BCB0-73F3A297A21B}] => (Allow) C:\Program Files (x86)\StarMoney 9.0\app\StarMoney.exe FirewallRules: [{636AB5DB-43B7-4859-B01B-8CAE4CE1DE4C}] => (Allow) LPort=80 FirewallRules: [{F9FA9DAF-623E-4C3B-BE53-41F7F6FCB867}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{FB96EF5E-AE06-4512-8BE6-EDAEF64EE243}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{35C873E8-79BE-4A5A-9448-E0C87AC127B0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Faulty Device Manager Devices ============= Name: Microsoft-Teredo-Tunneling-Adapter Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/09/2015 10:46:17 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2015 04:13:16 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2015 02:47:42 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2015 00:17:30 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2015 02:05:07 PM) (Source: Adobe Reader) (EventID: 16) (User: ) Description: Error: (07/08/2015 01:36:46 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/07/2015 10:34:08 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/07/2015 02:10:46 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/06/2015 09:30:14 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/06/2015 04:09:16 PM) (Source: Adobe Reader) (EventID: 16) (User: ) Description: System errors: ============= Error: (07/09/2015 10:44:39 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SuperEasy 1-Click Backup" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error: (07/09/2015 04:16:34 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Error: (07/09/2015 04:11:53 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SuperEasy 1-Click Backup" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/09/2015 04:11:32 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 09.07.2015 um 04:04:47 unerwartet heruntergefahren. Error: (07/09/2015 02:46:45 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SuperEasy 1-Click Backup" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/09/2015 02:45:08 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (07/09/2015 02:45:08 AM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "WSearch" konnte sich nicht als "NT AUTHORITY\SYSTEM" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%50 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (07/09/2015 02:44:48 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/09/2015 02:44:38 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/09/2015 02:44:38 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office: ========================= Error: (07/09/2015 10:46:17 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2015 04:13:16 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2015 02:47:42 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2015 00:17:30 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2015 02:05:07 PM) (Source: Adobe Reader) (EventID: 16) (User: ) Description: Error: (07/08/2015 01:36:46 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/07/2015 10:34:08 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/07/2015 02:10:46 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/06/2015 09:30:14 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/06/2015 04:09:16 PM) (Source: Adobe Reader) (EventID: 16) (User: ) Description: CodeIntegrity Errors: =================================== Date: 2015-02-12 03:40:11.947 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-02-12 03:40:11.897 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-02-12 03:40:11.896 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-02-12 03:40:11.895 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-02-12 03:40:11.867 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: AMD A8-6600K APU with Radeon(tm) HD Graphics Percentage of memory in use: 34% Total physical RAM: 7364.8 MB Available physical RAM: 4799.22 MB Total Virtual: 14727.82 MB Available Virtual: 11574.88 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.17 GB) (Free:745.49 GB) NTFS Drive g: () (Removable) (Total:1.89 GB) (Free:0.99 GB) FAT Drive j: () (Fixed) (Total:931.51 GB) (Free:541.55 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 18565D10) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.2 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: 00DA6471) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ======================================================== Disk: 5 (Size: 1.9 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End of log ============================ --- --- --- Geändert von michelle80 (09.07.2015 um 10:37 Uhr) |
09.07.2015, 13:19 | #4 |
/// the machine /// TB-Ausbilder | Malware bei Facebook Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2015, 16:08 | #5 |
| Malware bei Facebook Hallo Schrauber, Mbam habe ich schonmal fertig :-) Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 09.07.2015 Suchlaufzeit: 15:56 Protokolldatei: mbam.txt Administrator: Ja Version: 2.1.8.1057 Malware-Datenbank: v2015.07.09.03 Rootkit-Datenbank: v2015.07.09.01 Lizenz: Premium-Version Malware-Schutz: Aktiviert Schutz vor bösartigen Websites: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: lxxxxx Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 400698 Abgelaufene Zeit: 16 Min., 42 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 0 (keine bösartigen Elemente erkannt) Registrierungswerte: 0 (keine bösartigen Elemente erkannt) Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Dateien: 0 (keine bösartigen Elemente erkannt) Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) AdwCleaner ist fertig Ich habe diese Datei in Verdacht! [ Datei : C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\prefs.js ] AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.212 - Bericht erstellt am 13/06/2014 um 15:08:11 # Aktualisiert 05/06/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : lxxxxx - Lxxxxx-PC # Gestartet von : C:\Users\lxxxxx\Downloads\adwcleaner_3.212(1).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 -\\ Mozilla Firefox v29.0.1 (de) [ Datei : C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\prefs.js ] -\\ Google Chrome v35.0.1916.153 [ Datei : C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [6912 octets] - [12/06/2014 05:32:36] AdwCleaner[R1].txt - [1067 octets] - [13/06/2014 14:55:33] AdwCleaner[S0].txt - [6360 octets] - [12/06/2014 05:41:51] AdwCleaner[S1].txt - [990 octets] - [13/06/2014 15:08:11] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1049 octets] ########## AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v4.207 - Bericht erstellt 09/07/2015 um 16:21:27 # Aktualisiert 21/06/2015 von Xplode # Datenbank : 2015-07-05.2 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : lxxxxx - Lxxxxx-PC # Gestarted von : C:\Users\lxxxxx\Downloads\adwcleaner_4.207 (1).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17840 -\\ Mozilla Firefox v39.0 (x86 de) -\\ Google Chrome v43.0.2357.132 -\\ Opera v30.0.1835.88 ************************* AdwCleaner[R0].txt - [9130 Bytes] - [12/06/2014 05:32:36] AdwCleaner[R1].txt - [3285 Bytes] - [13/06/2014 14:55:33] AdwCleaner[R2].txt - [2277 Bytes] - [09/07/2015 02:43:29] AdwCleaner[R3].txt - [1158 Bytes] - [09/07/2015 02:57:25] AdwCleaner[R4].txt - [1217 Bytes] - [09/07/2015 03:02:27] AdwCleaner[R5].txt - [1281 Bytes] - [09/07/2015 16:20:03] AdwCleaner[S0].txt - [8591 Bytes] - [12/06/2014 05:41:51] AdwCleaner[S1].txt - [2271 Bytes] - [13/06/2014 15:08:11] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2330 Bytes] ########## JRT ist auch fertigJRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 7.3.8 (07.09.2015:1) OS: Windows 7 Home Premium x64 Ran by lxxxxx on 09.07.2015 at 16:31:21,40 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks Successfully deleted: [Task] C:\Windows\system32\tasks\Uninstaller_SkipUac_lxxxxx ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update webporpoise Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util webporpoise ~~~ Files Successfully deleted: [File] C:\Users\lxxxxx\appdata\local\998087a8e589f390f0b710fed8b8c1bf Successfully deleted: [File] C:\users\public\desktop\drivereasy.lnk ~~~ Folders Successfully deleted: [Folder] C:\ProgramData\microsoft\windows\start menu\programs\drivereasy Successfully deleted: [Folder] C:\ProgramData\productdata Successfully deleted: [Folder] C:\Users\lxxxxx\AppData\Roaming\productdata ~~~ FireFox Emptied folder: C:\Users\lxxxxx\AppData\Roaming\mozilla\firefox\profiles\y9uvrwqa.default\minidumps [228 files] ~~~ Chrome [C:\Users\lxxxxx\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset [C:\Users\lxxxxx\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted: [C:\Users\lxxxxx\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset [C:\Users\lxxxxx\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted: [] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 09.07.2015 at 16:35:29,75 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Ganz neues FRST FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015 Ran by lxxxxx (administrator) on Lxxxxx-PC on 09-07-2015 16:42:13 Running from C:\Users\lxxxxx\Downloads Loaded Profiles: lxxxxx (Available Profiles: lxxxxx & _supereasy_1cbackup_) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Farbar) C:\Users\lxxxxxx\Downloads\FRST64 (1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation) HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] () Startup: C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-06-03] ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) BootExecute: autocheck autochk * ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-09] (IObit) BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-15] (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-15] (Oracle Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{95A34309-0424-4A48-8ACC-627CE7D0719F}: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default FF DefaultSearchEngine: Ecosia FF SelectedSearchEngine: Ecosia FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_203.dll [2015-07-09] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_203.dll [2015-07-09] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-15] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-15] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( ) FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP) FF SearchPlugin: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\searchplugins\ecosia.xml [2015-05-29] FF Extension: PAYBACK Toolbar - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\toolbar-ff@payback.de.xpi [2014-12-10] FF Extension: Ecosia — The search engine that plants trees! - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2014-06-27] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-03] Chrome: ======= CHR Profile: C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-03] CHR Extension: (Google Drive) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-03] CHR Extension: (YouTube) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-03] CHR Extension: (Google Search) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-03] CHR Extension: (Kaspersky URL Advisor) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-03] CHR Extension: (Safe Money) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-06-03] CHR Extension: (Dangerous Websites Blocker) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-06-03] CHR Extension: (Virtual Keyboard) - C:\Users\lxxxxxAppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-06-03] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12] CHR Extension: (Google Wallet) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-03] CHR Extension: (Gmail) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-03] CHR Extension: (Anti-Banner) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-03] CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-06-03] (Adobe Systems) [File not signed] S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed] R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-07-09] (IObit) S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation) S2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 supereasy_1cbackup; No ImagePath ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices) R0 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20672 2014-06-03] (Glarysoft Ltd) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2014-06-22] (REALiX(tm)) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-03] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-03] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-03] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-03] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-03] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-09] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation) S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] () R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation) S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-09 16:35 - 2015-07-09 16:38 - 00001946 _____ C:\Users\lxxxxx\Desktop\JRT.txt 2015-07-09 16:31 - 2015-07-09 16:31 - 00000207 _____ C:\Windows\tweaking.com-regbackup-Lxxxxx-PC-Windows-7-Home-Premium-(64-bit).dat 2015-07-09 16:31 - 2015-07-09 16:31 - 00000000 ____D C:\RegBackup 2015-07-09 16:29 - 2015-07-09 16:29 - 02953724 _____ (Malwarebytes Corporation) C:\Users\lxxxxx\Downloads\JRT (1).exe 2015-07-09 16:16 - 2015-07-09 16:16 - 00001202 _____ C:\Users\lxxxxx\Desktop\mbam.txt 2015-07-09 16:04 - 2015-07-09 16:05 - 01981655 _____ C:\Users\lxxxxx\Downloads\u1501.zip 2015-07-09 16:04 - 2015-07-09 16:05 - 00000600 _____ C:\Users\lxxxxx\PUTTY.RND 2015-07-09 16:04 - 2015-07-09 16:04 - 01961239 _____ C:\Users\lxxxxx\Downloads\u__1304.zip 2015-07-09 15:52 - 2015-07-09 15:53 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\lxxxxx\Downloads\mbam-setup-2.1.6.1022.exe 2015-07-09 11:41 - 2015-07-09 11:41 - 00033300 _____ C:\Users\lxxxxx\Desktop\Addition.txt 2015-07-09 11:00 - 2015-07-09 11:00 - 00062490 _____ C:\Users\lxxxxx\Desktop\FRST.txt 2015-07-09 10:49 - 2015-07-09 10:49 - 02112512 _____ (Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe 2015-07-09 04:41 - 2015-07-09 04:41 - 02953707 _____ (Malwarebytes Corporation) C:\Users\lxxxxx\Downloads\JRT.exe 2015-07-09 04:22 - 2015-07-09 04:22 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-07-09 04:22 - 2015-07-09 04:22 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-07-09 04:22 - 2015-07-09 04:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-07-09 04:19 - 2015-07-09 04:19 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (2).exe 2015-07-09 03:22 - 2015-07-09 03:22 - 00001252 _____ C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2015-07-09 03:22 - 2015-07-09 03:22 - 00001228 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\IObit 2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IObit 2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\IObit 2015-07-09 03:19 - 2015-07-09 03:20 - 15889184 _____ (IObit) C:\Users\lxxxxx\Downloads\iobituninstaller4.3.0.122.exe 2015-07-09 03:10 - 2015-07-09 03:10 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\lxxxxx\Downloads\rkill.exe 2015-07-09 02:55 - 2015-07-09 02:55 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\172C3BAE.sys 2015-07-09 02:50 - 2015-07-09 02:50 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (1).exe 2015-07-09 01:31 - 2015-07-09 01:31 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0.exe 2015-07-09 01:25 - 2015-07-09 01:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxxx\Downloads\revosetup95 (1).exe 2015-07-09 01:23 - 2015-07-09 01:23 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207 (1).exe 2015-07-09 01:22 - 2015-07-09 01:22 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207.exe 2015-07-09 00:27 - 2015-07-09 00:39 - 00000000 ____D C:\ProgramData\F-Secure 2015-07-09 00:27 - 2015-07-09 00:27 - 00572456 _____ (F-Secure Corporation) C:\Users\lxxxxx\Desktop\F-SecureOnlineScanner.exe 2015-07-09 00:27 - 2015-07-09 00:27 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\F-Secure 2015-07-08 16:07 - 2015-07-08 16:07 - 00416576 _____ (Kaspersky Lab) C:\Users\lxxxxx\Desktop\de-de.setup.exe 2015-07-06 23:41 - 2015-07-06 23:41 - 00003584 _____ C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-07-06 21:29 - 2015-07-06 21:29 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\55ED2575.sys 2015-07-03 15:32 - 2015-07-03 15:32 - 00003288 ____N C:\bootsqm.dat 2015-07-01 23:15 - 2015-07-01 23:15 - 00207349 _____ C:\Users\lxxxxx\Desktop\IMG-20150701-WA0000.jpeg 2015-07-01 23:15 - 2015-07-01 23:15 - 00000256 _____ C:\Users\lxxxxx\Desktop\smil.xml 2015-07-01 18:01 - 2015-07-01 23:09 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\10940049.sys 2015-07-01 18:01 - 2015-07-01 18:01 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6AAD0032.sys 2015-06-30 23:59 - 2015-07-01 14:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\767943A1.sys 2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\54A74377.sys 2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C7C439E.sys 2015-06-30 00:42 - 2015-06-30 00:42 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\550E1672.sys 2015-06-27 21:55 - 2015-06-27 21:55 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\mresreg 2015-06-27 21:54 - 2015-06-27 21:56 - 39346840 _____ (IN MEDIA KG ) C:\Users\lxxxxx\Desktop\diasetup.exe 2015-06-27 21:53 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\FotoWorksXL_2 2015-06-27 21:53 - 2015-06-27 21:53 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IN-MEDIAKG-TI 2015-06-27 21:52 - 2015-06-27 21:52 - 00000000 ____D C:\Program Files (x86)\mresreg 2015-06-27 21:50 - 2015-06-27 21:51 - 36964664 _____ (IN MEDIAKG TI ) C:\Users\lxxxxx\Desktop\fotoworks_setup.exe 2015-06-27 02:25 - 2015-06-27 02:25 - 00942709 _____ C:\Users\lxxxxx\Desktop\bilder-27062015-0224.zip 2015-06-27 02:14 - 2015-06-27 02:26 - 00000000 ____D C:\Users\lxxxxx\Bilder von xxxxx xxxxx 2015-06-27 00:41 - 2015-06-27 01:20 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\220D2BA0.sys 2015-06-23 00:12 - 2015-06-23 00:12 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\28755C5A.sys 2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6C8C43E3.sys 2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\428F43E0.sys 2015-06-15 16:36 - 2015-06-15 16:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-06-15 16:36 - 2015-06-15 16:36 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2015-06-14 00:47 - 2015-06-14 18:46 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\76213859.sys 2015-06-14 00:47 - 2015-06-14 00:47 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C253856.sys 2015-06-13 01:23 - 2015-06-13 01:23 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2015-06-12 15:41 - 2015-06-12 15:41 - 00017174 _____ C:\Users\lxxxxx\Documents\coolpad.odt 2015-06-11 14:42 - 2015-06-11 15:52 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1D534D16.sys 2015-06-10 15:53 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-06-10 15:53 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-06-10 15:53 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-06-10 15:53 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-06-10 15:53 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-06-10 15:53 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-06-10 15:53 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-06-10 15:53 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-06-10 15:53 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-06-10 15:53 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe 2015-06-10 15:53 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-06-10 15:53 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-06-10 15:53 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-06-10 15:53 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-06-10 15:53 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-06-10 15:53 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-06-10 15:53 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe 2015-06-10 15:53 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-06-10 15:53 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-06-10 15:53 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-06-10 15:53 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-06-10 15:53 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-06-10 15:53 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2015-06-10 15:53 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-06-10 15:53 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-06-10 15:53 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-06-10 15:53 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-06-10 15:53 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-06-10 15:53 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-06-10 15:53 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-06-10 15:53 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-06-10 15:53 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-06-10 15:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-06-10 15:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-06-10 15:53 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-06-10 15:53 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2015-06-10 15:53 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2015-06-10 15:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2015-06-10 15:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2015-06-10 15:53 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2015-06-10 15:52 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-06-10 15:52 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-06-10 15:52 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2015-06-10 15:52 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-06-10 15:51 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-06-10 15:51 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-06-10 15:51 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-06-10 15:51 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-06-10 15:51 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-06-10 15:51 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-06-10 15:51 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-06-10 15:51 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-06-10 15:51 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-06-10 15:51 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-06-10 15:51 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-06-10 15:51 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-06-10 15:51 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-06-10 15:51 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-06-10 15:51 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-06-10 15:51 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-06-10 15:51 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-06-10 15:51 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-06-10 15:51 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-06-10 15:51 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-06-10 15:51 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-06-10 15:51 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-06-10 15:51 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-06-10 15:51 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-06-10 15:51 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-06-10 15:51 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-06-10 15:51 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-06-10 15:51 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-06-10 15:51 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-06-10 15:51 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-06-10 15:51 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-06-10 15:51 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-06-10 15:51 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-06-10 15:51 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-06-10 15:51 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-06-10 15:51 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-06-10 15:51 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-06-10 15:51 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-06-10 15:51 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-06-10 15:51 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-06-10 15:51 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-06-10 15:51 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-06-10 15:51 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-06-10 15:51 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-06-10 15:51 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-06-10 15:51 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-06-10 15:51 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-06-10 15:51 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-06-10 15:51 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-06-10 15:51 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-06-10 15:51 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-06-10 15:51 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-06-10 15:51 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-06-10 15:51 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-06-10 15:51 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-06-10 15:51 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-06-10 15:51 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-06-10 15:51 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-06-10 15:51 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-06-10 15:51 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-06-10 00:39 - 2015-06-10 00:39 - 00013412 _____ C:\Users\lxxxxx\Documents\mxxxxxxxxx.odt ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-09 16:42 - 2014-06-12 09:00 - 00018964 _____ C:\Users\lxxxxx\Downloads\FRST.txt 2015-07-09 16:42 - 2014-06-12 08:59 - 00000000 ____D C:\FRST 2015-07-09 16:30 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-09 16:30 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-09 16:28 - 2011-04-12 09:43 - 00699090 _____ C:\Windows\system32\perfh007.dat 2015-07-09 16:28 - 2011-04-12 09:43 - 00149230 _____ C:\Windows\system32\perfc007.dat 2015-07-09 16:28 - 2009-07-14 07:13 - 01619272 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-09 16:26 - 2014-06-03 17:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-07-09 16:25 - 2014-06-02 10:56 - 01922482 _____ C:\Windows\WindowsUpdate.log 2015-07-09 16:23 - 2014-06-03 17:43 - 00000336 _____ C:\Windows\Tasks\GlaryInitialize 5.job 2015-07-09 16:23 - 2014-06-03 15:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-07-09 16:22 - 2014-06-05 23:04 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-07-09 16:22 - 2014-06-05 15:51 - 00056918 _____ C:\Windows\setupact.log 2015-07-09 16:22 - 2014-06-05 05:04 - 00000234 _____ C:\BackupLoader.ini 2015-07-09 16:22 - 2014-06-03 15:47 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-09 16:22 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-09 16:21 - 2014-06-12 05:32 - 00000000 ____D C:\AdwCleaner 2015-07-09 16:20 - 2014-06-03 15:47 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-09 16:04 - 2014-06-03 15:17 - 00000000 ____D C:\Users\lxxxxx 2015-07-09 15:55 - 2014-06-05 23:04 - 00001102 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-07-09 11:41 - 2014-06-12 09:01 - 00033300 _____ C:\Users\lxxxxx\Downloads\Addition.txt 2015-07-09 10:44 - 2014-06-03 15:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-07-09 04:11 - 2015-02-10 02:06 - 00000000 ____D C:\Program Files (x86)\Secunia 2015-07-09 04:11 - 2014-06-06 03:18 - 00019030 _____ C:\Windows\PFRO.log 2015-07-09 02:46 - 2014-06-06 18:02 - 00000000 ____D C:\Users\_supereasy_1cbackup_ 2015-07-09 01:27 - 2014-06-03 17:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-07-09 01:26 - 2014-06-03 17:10 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-09 01:26 - 2014-06-03 17:10 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-09 01:25 - 2014-06-03 17:38 - 00001264 _____ C:\Users\lxxxxx\Desktop\Revo Uninstaller.lnk 2015-07-09 01:25 - 2014-06-03 17:38 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2015-07-08 15:48 - 2015-04-21 01:08 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxx 2015-07-08 15:21 - 2015-05-18 17:00 - 00000000 ____D C:\Users\lxxxxx\Bilder xxxx 2015-07-07 23:22 - 2014-06-03 15:50 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-07-07 22:32 - 2014-06-10 03:33 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0 2015-07-06 23:59 - 2015-01-13 01:36 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieBrowserModeList 2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieUserList 2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieSiteList 2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-07-03 03:41 - 2015-03-23 23:16 - 00000000 ____D C:\Users\lxxxxx\Bilder vonxxxx 2015-07-02 16:28 - 2014-06-10 15:01 - 00000000 ____D C:\Users\lxxxxx\Bilderxxxxxx 2015-07-01 02:03 - 2014-09-09 01:22 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kontxxxxxx Mxxxx 2015-07-01 02:02 - 2015-01-05 01:38 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kontxxxxxx Mxxxx 2015-06-30 04:10 - 2015-04-16 04:01 - 00000000 ____D C:\Users\lxxxxx\Bilder mit xxxx 2015-06-30 00:40 - 2015-05-18 01:42 - 00000000 ____D C:\Users\lxxxxx\Neue xxxx xxxxx 2015-06-27 21:55 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\VirtualStore 2015-06-26 01:47 - 2014-06-06 03:27 - 00000000 ____D C:\A1-Faktura 2015-06-25 13:50 - 2014-06-03 16:42 - 00003854 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401804726 2015-06-25 13:50 - 2014-06-03 16:12 - 00000000 ____D C:\Program Files (x86)\Opera 2015-06-24 02:32 - 2014-12-27 01:04 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-06-22 17:22 - 2014-06-14 02:36 - 00000000 ____D C:\Users\lxxxxx\Fxxxxxx 2015-06-22 02:21 - 2015-06-08 21:32 - 00012990 _____ C:\Users\lxxxxx\Documents\Dxxxxxx.odt 2015-06-18 12:19 - 2015-01-10 01:24 - 00000000 ____D C:\Users\lxxxxx\Bildxxxxxxxx 2015-06-18 08:41 - 2014-06-05 23:04 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-06-18 08:41 - 2014-06-05 23:04 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-06-18 08:41 - 2014-06-05 23:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-06-17 11:34 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2015-06-15 23:08 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\Adobe 2015-06-15 23:07 - 2014-08-21 05:14 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\Adobe 2015-06-15 16:36 - 2014-06-03 17:29 - 00000000 ____D C:\ProgramData\Adobe 2015-06-15 16:36 - 2014-06-03 17:28 - 00000000 ____D C:\Program Files (x86)\Adobe 2015-06-15 16:33 - 2014-09-10 16:10 - 00000000 ____D C:\ProgramData\Oracle 2015-06-15 16:32 - 2015-02-10 02:13 - 00000000 ____D C:\Program Files (x86)\Java 2015-06-15 16:29 - 2015-02-10 02:13 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-06-15 16:28 - 2015-04-02 03:26 - 00561248 _____ (Oracle Corporation) C:\Users\lxxxxx\Desktop\jxpiinstall.exe 2015-06-13 01:23 - 2014-06-03 15:47 - 00000000 ____D C:\Program Files (x86)\Google 2015-06-10 22:29 - 2009-07-14 06:45 - 00296104 _____ C:\Windows\system32\FNTCACHE.DAT 2015-06-10 22:27 - 2014-12-10 06:09 - 00000000 ____D C:\Windows\system32\appraiser 2015-06-10 22:27 - 2014-06-05 03:10 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-06-10 22:27 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2015-06-10 16:06 - 2014-03-13 13:01 - 00000000 ____D C:\Windows\system32\MRT 2015-06-10 16:02 - 2014-03-13 13:01 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-06-10 15:30 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT ==================== Files in the root of some directories ======= 2015-07-06 23:41 - 2015-07-06 23:41 - 0003584 _____ () C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-03 17:05 - 2014-06-03 17:05 - 0000057 _____ () C:\ProgramData\Ament.ini 2014-06-02 11:08 - 2014-06-02 11:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Files to move or delete: ==================== C:\Users\lxxxxx\cc_20140606_180858.reg Some files in TEMP: ==================== C:\Users\lxxxxx\AppData\Local\Temp\Quarantine.exe C:\Users\lxxxxx\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-04 15:15 ==================== End of log ============================ |
10.07.2015, 08:07 | #6 |
/// the machine /// TB-Ausbilder | Malware bei FacebookESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Malware bei Facebook |
11.07.2015, 01:34 | #7 |
| Malware bei Facebook Hallo Schrauber, Eset hat so einiges gefunden ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # end=init # utc_time=2015-07-10 02:51:42 # local_time=2015-07-10 04:51:42 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 24740 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # end=updated # utc_time=2015-07-10 02:58:04 # local_time=2015-07-10 04:58:04 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # engine=24740 # end=stopped # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-07-10 03:01:25 # local_time=2015-07-10 05:01:25 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Kaspersky Internet Security' # compatibility_mode=1292 16777213 100 100 2819 68018507 0 0 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 4225759 59524479 0 0 # scanned=5036 # found=2 # cleaned=0 # scan_time=200 sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxx\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=0ABC8ADF9D9E13D3D9BC26A52E01E51147905548 ft=1 fh=c48ce4d4114f6e4f vn="Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\785a6d7308790902373cc6e150959891\picpick _333inst.exe.vir" ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # end=init # utc_time=2015-07-10 03:03:49 # local_time=2015-07-10 05:03:49 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download esets_scanner_update returned -1 esets_gle=53251 Update Finalize Updated modules version: 24740 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # end=updated # utc_time=2015-07-10 03:04:32 # local_time=2015-07-10 05:04:32 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # engine=24740 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-07-10 03:10:24 # local_time=2015-07-10 05:10:24 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Kaspersky Internet Security' # compatibility_mode=1292 16777213 100 100 3358 68019046 0 0 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 4226298 59525018 0 0 # scanned=17924 # found=2 # cleaned=0 # scan_time=351 sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=0ABC8ADF9D9E13D3D9BC26A52E01E51147905548 ft=1 fh=c48ce4d4114f6e4f vn="Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\785a6d7308790902373cc6e150959891\picpick _333inst.exe.vir" ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # end=init # utc_time=2015-07-10 09:10:15 # local_time=2015-07-10 11:10:15 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 24743 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # end=updated # utc_time=2015-07-10 09:10:43 # local_time=2015-07-10 11:10:43 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # end=init # utc_time=2015-07-10 10:25:31 # local_time=2015-07-11 12:25:31 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 24746 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # end=updated # utc_time=2015-07-10 10:25:58 # local_time=2015-07-11 12:25:58 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=c5e21436d427434a9e80b871edbb09f2 # engine=24746 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-07-10 11:57:32 # local_time=2015-07-11 01:57:32 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Kaspersky Internet Security' # compatibility_mode=1292 16777213 100 100 5673 68050674 0 0 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 4257926 59556646 0 0 # scanned=115552 # found=38 # cleaned=0 # scan_time=5493 sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxxx\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=0ABC8ADF9D9E13D3D9BC26A52E01E51147905548 ft=1 fh=c48ce4d4114f6e4f vn="Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\785a6d7308790902373cc6e150959891\picpick _333inst.exe.vir" sh=91738DC254FDC7041A3D934ED35F478BD7050C2A ft=1 fh=4f8f7046f2fcfbeb vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Desktop\TestDisk PhotoRec - CHIP-Installer.exe" sh=80B86F2B7E604FC94778C110DD25641204D8209D ft=1 fh=88381e48320a06f7 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0\mgHelperGCFB.dll" sh=95ADC7925C2BB20FACE637E7031972F8E208FA33 ft=0 fh=0000000000000000 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx" sh=4F1EC034FA273DF15EBEF1E3FA66F819DB8A1943 ft=1 fh=752909aa377c6468 vn="Variante von Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\AppData\Roaming\OpenCandy\OpenCandy_D883580E954D4BFBA1C169803F66DE1D\registrybooster(9).exe" sh=D60F6EBE31E049C5236DBCE204F82B3CC16AE311 ft=1 fh=f1eedba83c490651 vn="Variante von Win32/SweetIM.N evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Desktop\Programme\bundlesweetimsetup.exe" sh=5B499F87EE8B3BF2E981BBA51F4C2732EC32599C ft=1 fh=d086c7dc76977fbd vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Desktop\Programme\rcpsetup_softonic_sd.exe" sh=457335C7D7CF3B76BDA5156BDFC9D2E55F5EB26E ft=1 fh=733834ea60493ef0 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Documents\Downloads\Integrated_CT2325506.exe" sh=08E5233775142E9C220C190CAD3E27A549652193 ft=1 fh=1f207ee3eb72f580 vn="Variante von Win32/Systweak.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Downloads\adusetup_ashampoo.exe" sh=D5D8C00EA49AA0455C4507AB8FAA0B7CFF3C6FA4 ft=1 fh=ba487aeb357dec5c vn="Variante von Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\asc-setup(2).exe" sh=38D920413DA6977CEC22A54F59C537D61FB5E3A7 ft=1 fh=1552aabc3c379211 vn="Win32/ELEX.AH evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\asc-setup.exe" sh=5010BDDBEDDF9DF52905ECE13A54AD1831760CFC ft=1 fh=ae0f36ec463e8583 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Downloads\ashampoo_photo_commander_8_8.4.0_8416.exe" sh=31048732171730E332CF83C59A1E9C8F87FE9D9B ft=1 fh=69d728c96126b483 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\ashampoo_photo_optimizer_4_4.0.3_12123.exe" sh=A286C0831A97F92D5B02D4B93E86530036A8699D ft=1 fh=541a6d15877510a0 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\ashampoo_winoptimizer_6_6.60_7259.exe" sh=DFDAF3E7ED920730B123DA30F0B1F79837B28ABE ft=1 fh=14851b481a89f9f9 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Downloads\FreeYouTubeDownload.exe" sh=2898AC44F5B280E0A16E3ECEAED861EA6C1B122F ft=1 fh=90c5cb6befc06df7 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxx vom alten Pc\lxxxx\Downloads\FreeYouTubetoMP3Converter (1).exe" sh=8547D1E5EACE099ECFE5EDBF6958FA077650894B ft=1 fh=61435738673b6524 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\FreeYouTubeToMP3Converter.exe" sh=CA4465FED8127902C233876084962BE515219103 ft=1 fh=2aae4c570c2e1699 vn="Variante von Win32/ELEX.AG evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\gusetup(1).exe" sh=22DD19DAE5F13FC01E8768E0AF7A6916D4B56AD8 ft=1 fh=d64b1c57ab7859c7 vn="Variante von Win32/Vittalia.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\installer_abc_amber_text_converter_5_07_Deutsch.exe" sh=FD2E7E52315B75CF5A4CC9F58891A8392C0E3F36 ft=1 fh=d53cd0c16606807f vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\installer_paint_shop_pro_x4_ultimate_14_0_0_332_Deutsch (1).exe" sh=FD2E7E52315B75CF5A4CC9F58891A8392C0E3F36 ft=1 fh=d53cd0c16606807f vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\installer_paint_shop_pro_x4_ultimate_14_0_0_332_Deutsch (2).exe" sh=FD2E7E52315B75CF5A4CC9F58891A8392C0E3F36 ft=1 fh=d53cd0c16606807f vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\installer_paint_shop_pro_x4_ultimate_14_0_0_332_Deutsch.exe" sh=6341D91DE330954BB8D497FCF8D7D50043B7F38C ft=1 fh=5fb1c7e382475525 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\Magix-Foto-Designer-Setup.exe" sh=6381C969CBF840D71B6DC7073563BE074C44BD94 ft=1 fh=4baa470ede468fd4 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Paint NET - CHIP-Downloader(1).exe" sh=0BD5AB3AC384C83014B59DF19100D07B209C1DD8 ft=1 fh=57cb94fce1dea516 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\Paint NET - CHIP-Downloader.exe" sh=05C4561F9C8843B923104E8D275364898C53B357 ft=1 fh=77b670143b46f13b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\ranktracker643-jre-Downloader.exe" sh=6BA3AD49D76DFB397D0FC14F0555A38353D2E662 ft=1 fh=0d40b11a59bb767f vn="Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\registryboosterplc.exe" sh=F78E1730B2A61817987EB987CE9C7629B05F1F13 ft=1 fh=250619b73124c19c vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Setup_FreeVideoConverter (1).exe" sh=6DF41BE2115F17EF773045825B7AD168C46FD71E ft=1 fh=250619b710cddeb8 vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Setup_FreeVideoConverter.exe" sh=9C1B9244769611DFAA18E0ADE669C1BC275848F8 ft=1 fh=250619b75fad7c7c vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxxvom alten Pc\lxxxx\Downloads\Setup_FreeVideoConverter26.exe" sh=47935A3CA85ADB764E1B2D1260FD7152B158369E ft=1 fh=ecaa409289e7c4b9 vn="Win32/SoftonicDownloader evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_bannershop-gif-animator(1).exe" sh=47935A3CA85ADB764E1B2D1260FD7152B158369E ft=1 fh=ecaa409289e7c4b9 vn="Win32/SoftonicDownloader evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_bannershop-gif-animator(2).exe" sh=47935A3CA85ADB764E1B2D1260FD7152B158369E ft=1 fh=ecaa409289e7c4b9 vn="Win32/SoftonicDownloader evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_bannershop-gif-animator.exe" sh=BD5D8E1A532DC977499E96056023F9922A5213A1 ft=1 fh=ac2eabd5779085bf vn="Win32/SoftonicDownloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_koyote-free-video-converter.exe" sh=CCD667FE196B0E1FAD991130AE214EF32169BE97 ft=1 fh=65ad072f5b9444d7 vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\SoftonicDownloader_fuer_photoscape.exe" sh=846D95D63EDE9508EFC7CEEE1D145D7CE62988C3 ft=1 fh=ec23a4ae3310ce50 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\Software Downloads\FreeYouTubeToMP3Converter31132918 (1).exe" sh=846D95D63EDE9508EFC7CEEE1D145D7CE62988C3 ft=1 fh=ec23a4ae3310ce50 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Software Downloads\FreeYouTubeToMP3Converter31132918.exe" Security Check ist auch fertig Results of screen317's Security Check version 1.004 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Kaspersky Internet Security Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 75 Java 8 Update 45 Adobe Flash Player 18.0.0.203 Mozilla Firefox (39.0) Mozilla Thunderbird (31.7.0) Google Chrome (43.0.2357.130) Google Chrome (43.0.2357.132) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe StarMoney 9.0 ouservice StarMoneyOnlineUpdate.exe Kaspersky Lab Kaspersky Internet Security 14.0.0 avp.exe Kaspersky Lab Kaspersky Internet Security 14.0.0 avpui.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Ganz frisches FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015 Ran by lxxxxx (administrator) on Lxxxx-PC on 11-07-2015 02:21:04 Running from C:\Users\lxxxxx\Downloads Loaded Profiles: lxxxx (Available Profiles: lxxxx & _supereasy_1cbackup_) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe () C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (phonostar GmbH) C:\Program Files (x86)\phonostar-Player\phonostar.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation) HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] () Startup: C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-06-03] ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) BootExecute: autocheck autochk * ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-09] (IObit) BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-15] (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-15] (Oracle Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{95A34309-0424-4A48-8ACC-627CE7D0719F}: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default FF DefaultSearchEngine: Ecosia FF SelectedSearchEngine: Ecosia FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_203.dll [2015-07-09] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_203.dll [2015-07-09] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-15] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-15] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( ) FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP) FF SearchPlugin: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\searchplugins\ecosia.xml [2015-05-29] FF Extension: PAYBACK Toolbar - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\toolbar-ff@payback.de.xpi [2014-12-10] FF Extension: Ecosia — The search engine that plants trees! - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2014-06-27] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-03] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-03] Chrome: ======= CHR Profile: C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-03] CHR Extension: (Google Drive) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-03] CHR Extension: (YouTube) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-03] CHR Extension: (Google Search) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-03] CHR Extension: (Kaspersky URL Advisor) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-03] CHR Extension: (Safe Money) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-06-03] CHR Extension: (Dangerous Websites Blocker) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-06-03] CHR Extension: (Virtual Keyboard) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-06-03] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12] CHR Extension: (Google Wallet) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-03] CHR Extension: (Gmail) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-03] CHR Extension: (Anti-Banner) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-03] CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-06-03] (Adobe Systems) [File not signed] R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed] R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-07-09] (IObit) S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 supereasy_1cbackup; No ImagePath ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices) R0 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20672 2014-06-03] (Glarysoft Ltd) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2014-06-22] (REALiX(tm)) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-03] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-03] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-03] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-03] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-03] (Kaspersky Lab ZAO) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation) S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] () R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation) S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-11 02:16 - 2015-07-11 02:16 - 00852662 _____ C:\Users\lxxxxx\Downloads\SecurityCheck.exe 2015-07-11 02:14 - 2015-07-11 02:14 - 00002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_lxxxxx 2015-07-11 02:14 - 2015-07-11 02:14 - 00000000 ____D C:\ProgramData\ProductData 2015-07-10 17:02 - 2015-07-10 17:03 - 02870984 _____ (ESET) C:\Users\lxxxxx\Downloads\esetsmartinstaller_deu (1).exe 2015-07-10 16:48 - 2015-07-10 16:49 - 02870984 _____ (ESET) C:\Users\lxxxxx\Downloads\esetsmartinstaller_deu.exe 2015-07-09 19:43 - 2015-07-09 19:43 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\ProductData 2015-07-09 16:35 - 2015-07-09 16:38 - 00001946 _____ C:\Users\lxxxxx\Desktop\JRT.txt 2015-07-09 16:31 - 2015-07-09 16:31 - 00000207 _____ C:\Windows\tweaking.com-regbackup-Lxxxxx-PC-Windows-7-Home-Premium-(64-bit).dat 2015-07-09 16:31 - 2015-07-09 16:31 - 00000000 ____D C:\RegBackup 2015-07-09 16:29 - 2015-07-09 16:29 - 02953724 _____ (Malwarebytes Corporation) C:\Users\lxxxx\Downloads\JRT (1).exe 2015-07-09 16:16 - 2015-07-09 16:16 - 00001202 _____ C:\Users\lxxxx\Desktop\mbam.txt 2015-07-09 16:04 - 2015-07-09 16:05 - 01981655 _____ C:\Users\lxxxxx\Downloads\u1501.zip 2015-07-09 16:04 - 2015-07-09 16:05 - 00000600 _____ C:\Users\lxxxxx\PUTTY.RND 2015-07-09 16:04 - 2015-07-09 16:04 - 01961239 _____ C:\Users\lxxxxx\Downloads\u__1304.zip 2015-07-09 15:52 - 2015-07-09 15:53 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\lxxxxx\Downloads\mbam-setup-2.1.6.1022.exe 2015-07-09 11:41 - 2015-07-09 11:41 - 00033300 _____ C:\Users\lxxxxx\Desktop\Addition.txt 2015-07-09 11:00 - 2015-07-09 11:00 - 00062490 _____ C:\Users\lxxxxx\Desktop\FRST.txt 2015-07-09 10:49 - 2015-07-09 10:49 - 02112512 _____ (Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe 2015-07-09 04:41 - 2015-07-09 04:41 - 02953707 _____ (Malwarebytes Corporation) C:\Users\lxxxxx\Downloads\JRT.exe 2015-07-09 04:22 - 2015-07-09 04:22 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-07-09 04:22 - 2015-07-09 04:22 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-07-09 04:22 - 2015-07-09 04:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-07-09 04:19 - 2015-07-09 04:19 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (2).exe 2015-07-09 03:22 - 2015-07-09 03:22 - 00001252 _____ C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2015-07-09 03:22 - 2015-07-09 03:22 - 00001228 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\IObit 2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IObit 2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\IObit 2015-07-09 03:19 - 2015-07-09 03:20 - 15889184 _____ (IObit) C:\Users\lxxxxx\Downloads\iobituninstaller4.3.0.122.exe 2015-07-09 03:10 - 2015-07-09 03:10 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\lxxxxx\Downloads\rkill.exe 2015-07-09 02:55 - 2015-07-09 02:55 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\172C3BAE.sys 2015-07-09 02:50 - 2015-07-09 02:50 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (1).exe 2015-07-09 01:31 - 2015-07-09 01:31 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0.exe 2015-07-09 01:25 - 2015-07-09 01:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxxx\Downloads\revosetup95 (1).exe 2015-07-09 01:23 - 2015-07-09 01:23 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207 (1).exe 2015-07-09 01:22 - 2015-07-09 01:22 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207.exe 2015-07-09 00:27 - 2015-07-09 00:39 - 00000000 ____D C:\ProgramData\F-Secure 2015-07-09 00:27 - 2015-07-09 00:27 - 00572456 _____ (F-Secure Corporation) C:\Users\lxxxxx\Desktop\F-SecureOnlineScanner.exe 2015-07-09 00:27 - 2015-07-09 00:27 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\F-Secure 2015-07-08 16:07 - 2015-07-08 16:07 - 00416576 _____ (Kaspersky Lab) C:\Users\lxxxxx\Desktop\de-de.setup.exe 2015-07-06 23:41 - 2015-07-06 23:41 - 00003584 _____ C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-07-06 21:29 - 2015-07-06 21:29 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\55ED2575.sys 2015-07-03 15:32 - 2015-07-03 15:32 - 00003288 ____N C:\bootsqm.dat 2015-07-01 23:15 - 2015-07-01 23:15 - 00207349 _____ C:\Users\lxxxxx\Desktop\IMG-20150701-WA0000.jpeg 2015-07-01 23:15 - 2015-07-01 23:15 - 00000256 _____ C:\Users\lxxxxx\Desktop\smil.xml 2015-07-01 18:01 - 2015-07-01 23:09 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\10940049.sys 2015-07-01 18:01 - 2015-07-01 18:01 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6AAD0032.sys 2015-06-30 23:59 - 2015-07-01 14:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\767943A1.sys 2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\54A74377.sys 2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C7C439E.sys 2015-06-30 00:42 - 2015-06-30 00:42 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\550E1672.sys 2015-06-27 21:55 - 2015-06-27 21:55 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\mresreg 2015-06-27 21:54 - 2015-06-27 21:56 - 39346840 _____ (IN MEDIA KG ) C:\Users\lxxxxx\Desktop\diasetup.exe 2015-06-27 21:53 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\FotoWorksXL_2 2015-06-27 21:53 - 2015-06-27 21:53 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IN-MEDIAKG-TI 2015-06-27 21:52 - 2015-06-27 21:52 - 00000000 ____D C:\Program Files (x86)\mresreg 2015-06-27 21:50 - 2015-06-27 21:51 - 36964664 _____ (IN MEDIAKG TI ) C:\Users\Lxxxxx\Desktop\fotoworks_setup.exe 2015-06-27 02:25 - 2015-06-27 02:25 - 00942709 _____ C:\Users\lxxxx\Desktop\bilder-27062015-0224.zip 2015-06-27 02:14 - 2015-06-27 02:26 - 00000000 ____D C:\Users\lxxxxx\Bilder von xxxxx 2015-06-27 00:41 - 2015-06-27 01:20 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\220D2BA0.sys 2015-06-23 00:12 - 2015-06-23 00:12 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\28755C5A.sys 2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6C8C43E3.sys 2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\428F43E0.sys 2015-06-15 16:36 - 2015-06-15 16:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-06-15 16:36 - 2015-06-15 16:36 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2015-06-14 00:47 - 2015-06-14 18:46 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\76213859.sys 2015-06-14 00:47 - 2015-06-14 00:47 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C253856.sys 2015-06-13 01:23 - 2015-06-13 01:23 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2015-06-12 15:41 - 2015-06-12 15:41 - 00017174 _____ C:\Users\lxxxxx\Documents\cxxxxx.odt 2015-06-11 14:42 - 2015-06-11 15:52 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1D534D16.sys ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-11 02:21 - 2014-06-12 09:00 - 00020410 _____ C:\Users\lxxxx\Downloads\FRST.txt 2015-07-11 02:21 - 2014-06-12 08:59 - 00000000 ____D C:\FRST 2015-07-11 02:20 - 2014-06-03 15:47 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-11 02:12 - 2014-06-02 10:56 - 02043516 _____ C:\Windows\WindowsUpdate.log 2015-07-11 01:26 - 2014-06-03 17:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-07-11 01:12 - 2014-06-03 15:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-07-11 00:51 - 2014-06-05 23:04 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-07-11 00:31 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-11 00:31 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-11 00:29 - 2011-04-12 09:43 - 00699090 _____ C:\Windows\system32\perfh007.dat 2015-07-11 00:29 - 2011-04-12 09:43 - 00149230 _____ C:\Windows\system32\perfc007.dat 2015-07-11 00:29 - 2009-07-14 07:13 - 01619272 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-11 00:23 - 2014-06-03 17:43 - 00000336 _____ C:\Windows\Tasks\GlaryInitialize 5.job 2015-07-11 00:22 - 2014-06-05 15:51 - 00057198 _____ C:\Windows\setupact.log 2015-07-11 00:22 - 2014-06-05 05:04 - 00000234 _____ C:\BackupLoader.ini 2015-07-11 00:22 - 2014-06-03 15:47 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-11 00:22 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-09 16:21 - 2014-06-12 05:32 - 00000000 ____D C:\AdwCleaner 2015-07-09 16:04 - 2014-06-03 15:17 - 00000000 ____D C:\Users\lxxxxx 2015-07-09 15:55 - 2014-06-05 23:04 - 00001102 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-07-09 11:41 - 2014-06-12 09:01 - 00033300 _____ C:\Users\lxxxxx\Downloads\Addition.txt 2015-07-09 10:44 - 2014-06-03 15:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-07-09 04:11 - 2015-02-10 02:06 - 00000000 ____D C:\Program Files (x86)\Secunia 2015-07-09 04:11 - 2014-06-06 03:18 - 00019030 _____ C:\Windows\PFRO.log 2015-07-09 02:46 - 2014-06-06 18:02 - 00000000 ____D C:\Users\_supereasy_1cbackup_ 2015-07-09 01:27 - 2014-06-03 17:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-07-09 01:26 - 2014-06-03 17:10 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-09 01:26 - 2014-06-03 17:10 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-09 01:25 - 2014-06-03 17:38 - 00001264 _____ C:\Users\lxxxxx\Desktop\Revo Uninstaller.lnk 2015-07-09 01:25 - 2014-06-03 17:38 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2015-07-08 15:48 - 2015-04-21 01:08 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxxxx 2015-07-08 15:21 - 2015-05-18 17:00 - 00000000 ____D C:\Users\lxxxxx\Bilder vonxxxxxx 2015-07-07 23:22 - 2014-06-03 15:50 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-07-07 22:32 - 2014-06-10 03:33 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0 2015-07-06 23:59 - 2015-01-13 01:36 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieBrowserModeList 2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieUserList 2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieSiteList 2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-07-03 03:41 - 2015-03-23 23:16 - 00000000 ____D C:\Users\lxxxx\Bilder vonxxxxxx 2015-07-02 16:28 - 2014-06-10 15:01 - 00000000 ____D C:\Users\lxxxx\Bilderxxxxxx 2015-07-01 02:03 - 2014-09-09 01:22 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kxxxxxxxx 2015-07-01 02:02 - 2015-01-05 01:38 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kxxxxxxxx 2015-06-30 04:10 - 2015-04-16 04:01 - 00000000 ____D C:\Users\lxxxxx\Bilder xxxxxx 2015-06-30 00:40 - 2015-05-18 01:42 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxxxx 2015-06-27 21:55 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\VirtualStore 2015-06-26 01:47 - 2014-06-06 03:27 - 00000000 ____D C:\A1-Faktura 2015-06-25 13:50 - 2014-06-03 16:42 - 00003854 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401804726 2015-06-25 13:50 - 2014-06-03 16:12 - 00000000 ____D C:\Program Files (x86)\Opera 2015-06-24 02:32 - 2014-12-27 01:04 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-06-22 17:22 - 2014-06-14 02:36 - 00000000 ____D C:\Users\lxxxxx\Formular xxxxx 2015-06-22 02:21 - 2015-06-08 21:32 - 00012990 _____ C:\Users\lxxxxx\Documents\xxxxxxxxxxxxxxxx.odt 2015-06-18 12:19 - 2015-01-10 01:24 - 00000000 ____D C:\Users\lxxxxx\Bilderxxxxxxx 2015-06-18 08:41 - 2014-06-05 23:04 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-06-18 08:41 - 2014-06-05 23:04 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-06-18 08:41 - 2014-06-05 23:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-06-17 11:34 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2015-06-15 23:08 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxxx\AppData\Roaming\Adobe 2015-06-15 23:07 - 2014-08-21 05:14 - 00000000 ____D C:\Users\lxxxxxx\AppData\Local\Adobe 2015-06-15 16:36 - 2014-06-03 17:29 - 00000000 ____D C:\ProgramData\Adobe 2015-06-15 16:36 - 2014-06-03 17:28 - 00000000 ____D C:\Program Files (x86)\Adobe 2015-06-15 16:33 - 2014-09-10 16:10 - 00000000 ____D C:\ProgramData\Oracle 2015-06-15 16:32 - 2015-02-10 02:13 - 00000000 ____D C:\Program Files (x86)\Java 2015-06-15 16:29 - 2015-02-10 02:13 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-06-15 16:28 - 2015-04-02 03:26 - 00561248 _____ (Oracle Corporation) C:\Users\lxxxxxx\Desktop\jxpiinstall.exe 2015-06-13 01:23 - 2014-06-03 15:47 - 00000000 ____D C:\Program Files (x86)\Google ==================== Files in the root of some directories ======= 2015-07-06 23:41 - 2015-07-06 23:41 - 0003584 _____ () C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-03 17:05 - 2014-06-03 17:05 - 0000057 _____ () C:\ProgramData\Ament.ini 2014-06-02 11:08 - 2014-06-02 11:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Files to move or delete: ==================== C:\Users\lxxxxx\cc_20140606_180858.reg Some files in TEMP: ==================== C:\Users\lxxxxx\AppData\Local\Temp\Quarantine.exe C:\Users\lxxxxx\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-04 15:15 ==================== End of log ============================ Das Facebookproblem in Firefox besteht weiterhin, diesmal soll wieder ein anderer Scanner runtergeladen werden. Eset hatte ja soviele Einträge gefunden, fast 40. Müssen die denn nicht alle gelöscht werden? Ich habe die Checkbox zum Löschen nicht angeklickt gehabt. Bisher war Eset der einziger Scanner, der diese Einträge gefunden hat. Geändert von michelle80 (11.07.2015 um 01:41 Uhr) |
11.07.2015, 15:01 | #8 |
/// the machine /// TB-Ausbilder | Malware bei Facebook Facebook scannt auf irgendeine Weise angeblich irgendwelche Daten und erkennt, dass der Rechner infiziert sein soll. Nach dem Zufallsprinzip wird dann irgendeiner der zig Scanner angeboten, die sich bei FB eingekauft haben. Laut Logs ist alles gut. Die ESET Funde sind Downloads von Dir, meist auch in nem alten Ordner. Siehste ja im Log selbst. Ich würde den ganzen Ordner löschen. Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.07.2015, 03:51 | #9 |
| Malware bei Facebook Hallo Schrauber, ich muss bei den alten PC Sachen erst noch schauen, was ich davon noch brauche, bevor ich das löschen kann. Ich habe jetzt zwar schonmal den Firefox mit Revo deinstalliert und neuinstalliert und dann war ich bei der Support Seite von Mozilla für die Restaurierung. Dann habe ich mich bei Facebook eingeloggt und hatte wieder die gleiche Anzeige, dass mein PC infiziert ist. |
12.07.2015, 16:06 | #10 |
/// the machine /// TB-Ausbilder | Malware bei Facebook Hast Du die nur in Firefox? Teste mal Facebook mit dem Internet Explorer.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.07.2015, 04:12 | #11 |
| Malware bei Facebook Hallo Schrauber, ich habe das Facebookproblem nur in Firefox. Opera, Google Chrome und Explorer sind nicht davon betroffen. Ich habe jetzt mal folgendes gemacht: den betroffenen Ordner mit den alten Daten auf eine externe Festplatte kopiert und dann vom Pc gelöscht und siehe da, das Facebookproblem hat sich erledigt, ich kann mich einloggen, ohne dass mir angezeigt wird, dass ich einen Virus habe. Das Problem war ja nur in Firefox, alle anderen Browser waren davon nicht betroffen. Soll ich den Pc jetzt nochmal komplett durchscannen? Eset hatte diese Dinge alle gefunden. |
13.07.2015, 15:17 | #12 |
/// the machine /// TB-Ausbilder | Malware bei Facebook nur ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.07.2015, 23:42 | #13 |
| Malware bei Facebook Hallo Schrauber, ich habe ein aktuelles FRST gemacht: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015 Ran by lxxxx (administrator) on Lxxxx-PC on 14-07-2015 00:31:31 Running from C:\Users\lxxxx\Downloads Loaded Profiles: lxxxx (Available Profiles: lxxxx & _supereasy_1cbackup_) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe () C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation) HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] () Startup: C:\Users\lxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-06-03] ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) BootExecute: autocheck autochk * ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-09] (IObit) BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-15] (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-15] (Oracle Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{95A34309-0424-4A48-8ACC-627CE7D0719F}: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\lxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\xq0dkekp.default-1436669174552 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_203.dll [2015-07-09] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_203.dll [2015-07-09] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-15] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-15] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( ) FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP) Chrome: ======= CHR Profile: C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-03] CHR Extension: (Google Drive) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-03] CHR Extension: (YouTube) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-03] CHR Extension: (Google Search) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-03] CHR Extension: (Kaspersky URL Advisor) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-03] CHR Extension: (Safe Money) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-06-03] CHR Extension: (Dangerous Websites Blocker) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-06-03] CHR Extension: (Virtual Keyboard) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-06-03] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12] CHR Extension: (Google Wallet) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-03] CHR Extension: (Gmail) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-03] CHR Extension: (Anti-Banner) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-03] CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-06-03] (Adobe Systems) [File not signed] R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed] R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-07-09] (IObit) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 supereasy_1cbackup; No ImagePath ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices) R0 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20672 2014-06-03] (Glarysoft Ltd) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2014-06-22] (REALiX(tm)) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-03] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-03] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-03] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-03] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-03] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-14] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation) S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] () R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation) S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-14 00:31 - 2015-07-14 00:31 - 00000000 ____D C:\Users\lxxxx\Downloads\FRST-OlderVersion 2015-07-13 06:12 - 2015-07-13 06:12 - 00000000 ____D C:\Program Files (x86)\ESET 2015-07-12 04:45 - 2015-07-12 04:46 - 00000000 ____D C:\Users\lxxxx\Desktop\Alte Firefox-Daten 2015-07-12 04:44 - 2015-07-12 04:44 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-07-12 04:44 - 2015-07-12 04:44 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-07-12 04:44 - 2015-07-12 04:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-07-12 04:42 - 2015-07-12 04:42 - 00242928 _____ C:\Users\lxxxx\Downloads\Firefox Setup Stub 39.0 (3).exe 2015-07-12 04:35 - 2015-07-12 04:35 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxx\Downloads\revosetup95 (3).exe 2015-07-12 04:35 - 2015-07-12 04:35 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxx\Downloads\revosetup95 (2).exe 2015-07-12 04:31 - 2015-07-12 04:31 - 00042536 _____ C:\Users\lxxxx\Desktop\ESET.txt 2015-07-12 00:34 - 2015-07-12 00:34 - 02870984 _____ (ESET) C:\Users\lxxxx\Downloads\esetsmartinstaller_deu (2).exe 2015-07-11 04:57 - 2015-07-11 04:57 - 00000000 ____D C:\Users\lxxxx\Documents\Updater 2015-07-11 02:16 - 2015-07-11 02:16 - 00852662 _____ C:\Users\lxxxx\Downloads\SecurityCheck.exe 2015-07-11 02:14 - 2015-07-12 04:31 - 00002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_lxxxx 2015-07-11 02:14 - 2015-07-11 02:14 - 00000000 ____D C:\ProgramData\ProductData 2015-07-10 17:02 - 2015-07-10 17:03 - 02870984 _____ (ESET) C:\Users\Lxxxx\Downloads\esetsmartinstaller_deu (1).exe 2015-07-10 16:48 - 2015-07-10 16:49 - 02870984 _____ (ESET) C:\Users\lxxxx\Downloads\esetsmartinstaller_deu.exe 2015-07-09 19:43 - 2015-07-09 19:43 - 00000000 ____D C:\Users\lxxxx\AppData\Roaming\ProductData 2015-07-09 16:35 - 2015-07-09 16:38 - 00001946 _____ C:\Users\lxxx\Desktop\JRT.txt 2015-07-09 16:31 - 2015-07-09 16:31 - 00000207 _____ C:\Windows\tweaking.com-regbackup-Lxxxx-PC-Windows-7-Home-Premium-(64-bit).dat 2015-07-09 16:31 - 2015-07-09 16:31 - 00000000 ____D C:\RegBackup 2015-07-09 16:29 - 2015-07-09 16:29 - 02953724 _____ (Malwarebytes Corporation) C:\Users\lxxxx\Downloads\JRT (1).exe 2015-07-09 16:16 - 2015-07-09 16:16 - 00001202 _____ C:\Users\lxxxx\Desktop\mbam.txt 2015-07-09 16:04 - 2015-07-09 16:05 - 00000600 _____ C:\Users\lxxxx\PUTTY.RND 2015-07-09 15:52 - 2015-07-09 15:53 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\lxxxx\Downloads\mbam-setup-2.1.6.1022.exe 2015-07-09 11:41 - 2015-07-09 11:41 - 00033300 _____ C:\Users\lxxxx\Desktop\Addition.txt 2015-07-09 11:00 - 2015-07-09 11:00 - 00062490 _____ C:\Users\lxxxx\Desktop\FRST.txt 2015-07-09 04:41 - 2015-07-09 04:41 - 02953707 _____ (Malwarebytes Corporation) C:\Users\lxxxx\Downloads\JRT.exe 2015-07-09 04:19 - 2015-07-09 04:19 - 00242928 _____ C:\Users\lxxxx\Downloads\Firefox Setup Stub 39.0 (2).exe 2015-07-09 03:22 - 2015-07-09 03:22 - 00001252 _____ C:\Users\lxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2015-07-09 03:22 - 2015-07-09 03:22 - 00001228 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\IObit 2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxx\AppData\Roaming\IObit 2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\IObit 2015-07-09 03:19 - 2015-07-09 03:20 - 15889184 _____ (IObit) C:\Users\lxxxx\Downloads\iobituninstaller4.3.0.122.exe 2015-07-09 03:10 - 2015-07-09 03:10 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\lxxxx\Downloads\rkill.exe 2015-07-09 02:55 - 2015-07-09 02:55 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\172C3BAE.sys 2015-07-09 02:50 - 2015-07-09 02:50 - 00242928 _____ C:\Users\lxxxx\Downloads\Firefox Setup Stub 39.0 (1).exe 2015-07-09 01:31 - 2015-07-09 01:31 - 00242928 _____ C:\Users\lxxxx\Downloads\Firefox Setup Stub 39.0.exe 2015-07-09 01:25 - 2015-07-09 01:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxx\Downloads\revosetup95 (1).exe 2015-07-09 01:23 - 2015-07-09 01:23 - 02244096 _____ C:\Users\lxxxx\Downloads\adwcleaner_4.207 (1).exe 2015-07-09 01:22 - 2015-07-09 01:22 - 02244096 _____ C:\Users\lxxxx\Downloads\adwcleaner_4.207.exe 2015-07-09 00:27 - 2015-07-09 00:39 - 00000000 ____D C:\ProgramData\F-Secure 2015-07-09 00:27 - 2015-07-09 00:27 - 00572456 _____ (F-Secure Corporation) C:\Users\lxxxx\Desktop\F-SecureOnlineScanner.exe 2015-07-09 00:27 - 2015-07-09 00:27 - 00000000 ____D C:\Users\lxxxx\AppData\Local\F-Secure 2015-07-08 16:07 - 2015-07-08 16:07 - 00416576 _____ (Kaspersky Lab) C:\Users\lxxxx\Desktop\de-de.setup.exe 2015-07-06 23:41 - 2015-07-06 23:41 - 00003584 _____ C:\Users\lxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-07-06 21:29 - 2015-07-06 21:29 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\55ED2575.sys 2015-07-03 15:32 - 2015-07-03 15:32 - 00003288 ____N C:\bootsqm.dat 2015-07-01 23:15 - 2015-07-01 23:15 - 00207349 _____ C:\Users\lxxxx\Desktop\IMG-20150701-WA0000.jpeg 2015-07-01 23:15 - 2015-07-01 23:15 - 00000256 _____ C:\Users\lxxxx\Desktop\smil.xml 2015-07-01 18:01 - 2015-07-01 23:09 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\10940049.sys 2015-07-01 18:01 - 2015-07-01 18:01 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6AAD0032.sys 2015-06-30 23:59 - 2015-07-01 14:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\767943A1.sys 2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\54A74377.sys 2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C7C439E.sys 2015-06-30 00:42 - 2015-06-30 00:42 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\550E1672.sys 2015-06-27 21:55 - 2015-06-27 21:55 - 00000000 ____D C:\Users\lxxxx\AppData\Roaming\mresreg 2015-06-27 21:54 - 2015-06-27 21:56 - 39346840 _____ (IN MEDIA KG ) C:\Users\lxxxx\Desktop\diasetup.exe 2015-06-27 21:53 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\FotoWorksXL_2 2015-06-27 21:53 - 2015-06-27 21:53 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IN-MEDIAKG-TI 2015-06-27 21:52 - 2015-06-27 21:52 - 00000000 ____D C:\Program Files (x86)\mresreg 2015-06-27 21:50 - 2015-06-27 21:51 - 36964664 _____ (IN MEDIAKG TI ) C:\Users\lxxxx\Desktop\fotoworks_setup.exe 2015-06-27 02:25 - 2015-06-27 02:25 - 00942709 _____ C:\Users\lxxxx Desktop\bilder-27062015-0224.zip 2015-06-27 02:14 - 2015-06-27 02:26 - 00000000 ____D C:\Users\lxxxx\Bilderxxxxxxx 2015-06-27 00:41 - 2015-06-27 01:20 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\220D2BA0.sys 2015-06-23 00:12 - 2015-06-23 00:12 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\28755C5A.sys 2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6C8C43E3.sys 2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\428F43E0.sys 2015-06-15 16:36 - 2015-06-15 16:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-06-15 16:36 - 2015-06-15 16:36 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2015-06-14 00:47 - 2015-06-14 18:46 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\76213859.sys 2015-06-14 00:47 - 2015-06-14 00:47 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C253856.sys ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-14 00:31 - 2014-06-12 09:00 - 00018551 _____ C:\Users\lxxxx\Downloads\FRST.txt 2015-07-14 00:31 - 2014-06-12 08:59 - 00000000 ____D C:\FRST 2015-07-14 00:31 - 2014-06-12 08:58 - 02133504 _____ (Farbar) C:\Users\lxxxx\Downloads\FRST64.exe 2015-07-14 00:26 - 2014-06-03 17:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-07-14 00:20 - 2014-06-03 15:47 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-14 00:16 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-14 00:16 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-14 00:14 - 2011-04-12 09:43 - 00699090 _____ C:\Windows\system32\perfh007.dat 2015-07-14 00:14 - 2011-04-12 09:43 - 00149230 _____ C:\Windows\system32\perfc007.dat 2015-07-14 00:14 - 2009-07-14 07:13 - 01619272 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-14 00:11 - 2014-06-02 10:56 - 01256473 _____ C:\Windows\WindowsUpdate.log 2015-07-14 00:09 - 2014-06-05 23:04 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-07-14 00:09 - 2014-06-03 17:43 - 00000336 _____ C:\Windows\Tasks\GlaryInitialize 5.job 2015-07-14 00:09 - 2014-06-03 15:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-07-14 00:07 - 2014-06-05 15:51 - 00057534 _____ C:\Windows\setupact.log 2015-07-14 00:07 - 2014-06-05 05:04 - 00000234 _____ C:\BackupLoader.ini 2015-07-14 00:07 - 2014-06-03 15:47 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-14 00:07 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-13 05:06 - 2014-07-11 15:45 - 00000000 ____D C:\Users\lxxxx\Lxxxx vom alten Pc 2015-07-13 02:40 - 2014-06-06 03:18 - 00020190 _____ C:\Windows\PFRO.log 2015-07-13 02:40 - 2014-06-03 15:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-07-12 05:06 - 2014-06-03 15:17 - 00000000 ____D C:\Users\lxxxx 2015-07-12 04:35 - 2014-06-03 17:38 - 00001264 _____ C:\Users\lxxxx\Desktop\Revo Uninstaller.lnk 2015-07-12 04:35 - 2014-06-03 17:38 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2015-07-12 04:05 - 2014-06-22 04:30 - 00000000 ____D C:\Program Files (x86)\SIW 2015-07-12 01:32 - 2014-06-06 03:27 - 00000000 ____D C:\A1-Faktura 2015-07-09 16:21 - 2014-06-12 05:32 - 00000000 ____D C:\AdwCleaner 2015-07-09 15:55 - 2014-06-05 23:04 - 00001102 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-07-09 11:41 - 2014-06-12 09:01 - 00033300 _____ C:\Users\lxxxx\Downloads\Addition.txt 2015-07-09 04:11 - 2015-02-10 02:06 - 00000000 ____D C:\Program Files (x86)\Secunia 2015-07-09 02:46 - 2014-06-06 18:02 - 00000000 ____D C:\Users\_supereasy_1cbackup_ 2015-07-09 01:27 - 2014-06-03 17:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-07-09 01:26 - 2014-06-03 17:10 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-09 01:26 - 2014-06-03 17:10 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-08 15:48 - 2015-04-21 01:08 - 00000000 ____D C:\Users\lxxxx\Neue xxxxxxx 2015-07-08 15:21 - 2015-05-18 17:00 - 00000000 ____D C:\Users\lxxxx\Bilderxxxxxxxx 2015-07-07 23:22 - 2014-06-03 15:50 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-07-07 22:32 - 2014-06-10 03:33 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0 2015-07-06 23:59 - 2015-01-13 01:36 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieBrowserModeList 2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieUserList 2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieSiteList 2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-07-03 03:41 - 2015-03-23 23:16 - 00000000 ____D C:\Users\lxxxx\Bilder xxxxxx 2015-07-02 16:28 - 2014-06-10 15:01 - 00000000 ____D C:\Users\lxxxx\Bilderxxxxxxx 2015-07-01 02:03 - 2014-09-09 01:22 - 00000000 ____D C:\Users\lxxxxxx\Downloads\Kxxxxxxxxxx 2015-07-01 02:02 - 2015-01-05 01:38 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kxxxxxxxxxx 2015-06-30 04:10 - 2015-04-16 04:01 - 00000000 ____D C:\Users\lxxxxx\Bilderxxxxxx 2015-06-30 00:40 - 2015-05-18 01:42 - 00000000 ____D C:\Users\lxxxxx\Neuexxxxxxxxx 2015-06-27 21:55 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxxx\AppData\Local\VirtualStore 2015-06-25 13:50 - 2014-06-03 16:42 - 00003854 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401804726 2015-06-25 13:50 - 2014-06-03 16:12 - 00000000 ____D C:\Program Files (x86)\Opera 2015-06-24 02:32 - 2014-12-27 01:04 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-06-22 17:22 - 2014-06-14 02:36 - 00000000 ____D C:\Users\lxxxx\xxxxxxx 2015-06-22 02:21 - 2015-06-08 21:32 - 00012990 _____ C:\Users\lxxxxxx\Documents\xxxxxxxxx.odt 2015-06-18 12:19 - 2015-01-10 01:24 - 00000000 ____D C:\Users\lxxxxx\Bildxxxxxx 2015-06-18 08:41 - 2014-06-05 23:04 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-06-18 08:41 - 2014-06-05 23:04 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-06-18 08:41 - 2014-06-05 23:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-06-17 11:34 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2015-06-15 23:08 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxx\AppData\Roaming\Adobe 2015-06-15 23:07 - 2014-08-21 05:14 - 00000000 ____D C:\Users\lxxxx\AppData\Local\Adobe 2015-06-15 16:36 - 2014-06-03 17:29 - 00000000 ____D C:\ProgramData\Adobe 2015-06-15 16:36 - 2014-06-03 17:28 - 00000000 ____D C:\Program Files (x86)\Adobe 2015-06-15 16:33 - 2014-09-10 16:10 - 00000000 ____D C:\ProgramData\Oracle 2015-06-15 16:32 - 2015-02-10 02:13 - 00000000 ____D C:\Program Files (x86)\Java 2015-06-15 16:29 - 2015-02-10 02:13 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-06-15 16:28 - 2015-04-02 03:26 - 00561248 _____ (Oracle Corporation) C:\Users\lxxxxx\Desktop\jxpiinstall.exe ==================== Files in the root of some directories ======= 2015-07-06 23:41 - 2015-07-06 23:41 - 0003584 _____ () C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-03 17:05 - 2014-06-03 17:05 - 0000057 _____ () C:\ProgramData\Ament.ini 2014-06-02 11:08 - 2014-06-02 11:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Files to move or delete: ==================== C:\Users\lxxxx\cc_20140606_180858.reg Some files in TEMP: ==================== C:\Users\lxxxx\AppData\Local\Temp\Quarantine.exe C:\Users\lxxxx\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-04 15:15 ==================== End of log ============================ |
14.07.2015, 10:21 | #14 |
/// the machine /// TB-Ausbilder | Malware bei Facebook Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Ansonsten sieht das gut aus
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.07.2015, 22:55 | #15 |
| Malware bei Facebook Hallo Schrauber, die Fixlist habe ich erstellt. Ich bekomme sie irgendwie nicht mit ins Frst. Ich probiere es später nochmal. Die Fixlist ist im Ordner von Frst mit drin, aber Frst findet die Liste nicht. Ich komme leider nicht weiter. Ich habe es nochmal probiert. Ich habe die Fixlist nochmal abgespeichert, aber, das FRST findet sie einfach nicht. |
Themen zu Malware bei Facebook |
anderen, browser, dateien, einloggen, exe, facebook, firefox, folge, folgende, geändert, google, infos, installiert, kaspersky, klick, klickt, malware, natürlich, neu, nichts, opera, passwort, pishing, problem, sauber, screenshot, secure |