Hallo,
ich hatte zwischenzeitlich Spybot laufen lassen, daher auch hiervon die Logfiles: Code:
01.01.2014 13:38:55 - ##### check started #####
01.01.2014 13:38:55 - ### Version: 1.6.2
01.01.2014 13:38:55 - ### Date: 01.01.2014 13:38:55
01.01.2014 13:38:57 - ##### checking bots #####
01.01.2014 13:40:39 - found: Win32.Downloader.gen Programm-Verzeichnis
01.01.2014 13:40:39 - found: Win32.Downloader.gen Bibliothek
01.01.2014 13:40:44 - found: JDownloader Programm-Verzeichnis
01.01.2014 13:40:45 - found: Toolbar.Facemood Interface
01.01.2014 13:40:45 - found: Toolbar.Facemood Interface
01.01.2014 13:40:45 - found: Toolbar.Facemood Interface
01.01.2014 13:40:45 - found: Toolbar.Facemood Interface
01.01.2014 13:40:45 - found: Toolbar.Facemood Einstellungen
01.01.2014 13:40:45 - found: Toolbar.Facemood Anwendungs-ID
01.01.2014 13:40:45 - found: Toolbar.Facemood Anwendungs-ID
01.01.2014 13:40:45 - found: Toolbar.Facemood Class ID
01.01.2014 13:40:45 - found: Toolbar.Facemood Class ID
01.01.2014 13:40:45 - found: Toolbar.Facemood IE Suchseite
01.01.2014 13:40:45 - found: Toolbar.Facemood Web-Seite
01.01.2014 13:45:03 - found: DoubleClick Verfolgender Cookie (Internet Explorer: Pepe)
01.01.2014 13:45:03 - ##### check finished ##### Code:
--- Report generated: 2014-01-01 13:45 ---
Win32.Downloader.gen: [SBI $E6AD2227] Programm-Verzeichnis (Verzeichnis, nothing done)
C:\Users\Pepe\AppData\Local\Conduit\
Win32.Downloader.gen: [SBI $F65FFCFA] Bibliothek (Datei, nothing done)
C:\Program Files (x86)\Conduit\Community Alerts\Alert.dll
Properties.size=634976
Properties.md5=775D1655DCEF4AA65EBF89E744E511A0
Properties.filedate=1297767850
Properties.filedatetext=2011-02-15 12:04:10
JDownloader: [SBI $01C58A36] Programm-Verzeichnis (Verzeichnis, nothing done)
C:\Program Files (x86)\JDownloader\
Toolbar.Facemood: [SBI $D3994306] Interface (Registrierungsdatenbank-Schlüssel, nothing done)
HKEY_CLASSES_ROOT\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Toolbar.Facemood: [SBI $D3994306] Interface (Registrierungsdatenbank-Schlüssel, nothing done)
HKEY_CLASSES_ROOT\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Toolbar.Facemood: [SBI $04C50E46] Interface (Registrierungsdatenbank-Schlüssel, nothing done)
HKEY_CLASSES_ROOT\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Toolbar.Facemood: [SBI $04C50E46] Interface (Registrierungsdatenbank-Schlüssel, nothing done)
HKEY_CLASSES_ROOT\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Toolbar.Facemood: [SBI $8B30B7C1] Einstellungen (Registrierungsdatenbank-Schlüssel, nothing done)
HKEY_USERS\S-1-5-21-309064147-804680091-3328322202-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}
Toolbar.Facemood: [SBI $8F44A361] Anwendungs-ID (Registrierungsdatenbank-Schlüssel, nothing done)
HKEY_CLASSES_ROOT\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}
Toolbar.Facemood: [SBI $8F44A361] Anwendungs-ID (Registrierungsdatenbank-Schlüssel, nothing done)
HKEY_CLASSES_ROOT\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}
Toolbar.Facemood: [SBI $91EA8548] Class ID (Registrierungsdatenbank-Schlüssel, nothing done)
HKEY_CLASSES_ROOT\CLSID\{64182481-4F71-486b-A045-B233BD0DA8FC}
Toolbar.Facemood: [SBI $CDB19D2C] Class ID (Registrierungsdatenbank-Schlüssel, nothing done)
HKEY_CLASSES_ROOT\CLSID\{DDE2C74F-58CC-4d71-8CE1-09DEBB8CFB78}
Toolbar.Facemood: [SBI $05FB3923] IE Suchseite (Registrierungsdatenbank-Änderung, nothing done)
HKEY_LOCAL_MACHINESoftware\Microsoft\Internet Explorer\Search\SearchAssistant=about:blank
Toolbar.Facemood: [SBI $1786BAF6] Web-Seite (Datei, nothing done)
C:\Program Files (x86)\Mozilla Firefox\searchplugins\fcmdSrch.xml
Properties.size=2048
Properties.md5=E87861BC473518FCCE677F918D555D0C
Properties.filedate=1309194705
Properties.filedatetext=2011-06-27 18:11:44
DoubleClick: Verfolgender Cookie (Internet Explorer: Pepe) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2014-01-01 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2013-11-06 Includes\Adware.sbi (*)
2013-12-23 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2012-11-14 Includes\Dialer.sbi (*)
2013-04-11 Includes\DialerC.sbi (*)
2013-04-11 Includes\HeavyDuty.sbi (*)
2012-11-14 Includes\Hijackers.sbi (*)
2013-04-11 Includes\HijackersC.sbi (*)
2013-10-16 Includes\iPhone.sbi (*)
2013-06-25 Includes\Keyloggers.sbi (*)
2013-10-30 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2013-05-29 Includes\Malware.sbi (*)
2013-12-23 Includes\MalwareC.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2013-12-23 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2012-11-14 Includes\Security.sbi (*)
2013-10-30 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2013-09-17 Includes\Spyware.sbi (*)
2013-08-06 Includes\SpywareC.sbi (*)
2012-11-19 Includes\Tracks.uti
2013-01-16 Includes\Trojans.sbi (*)
2013-12-11 Includes\TrojansC-02.sbi (*)
2013-12-10 Includes\TrojansC-03.sbi (*)
2013-12-23 Includes\TrojansC-04.sbi (*)
2013-06-13 Includes\TrojansC-05.sbi (*)
2013-08-06 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll Spybot Fixes: Code:
--- Report generated: 2014-01-01 14:18 ---
Win32.Downloader.gen: [SBI $E6AD2227] Programm-Verzeichnis (Verzeichnis, fixed)
C:\Users\Pepe\AppData\Local\Conduit\
Win32.Downloader.gen: [SBI $F65FFCFA] Bibliothek (Datei, fixed)
C:\Program Files (x86)\Conduit\Community Alerts\Alert.dll
Properties.size=0
Properties.md5=D41D8CD98F00B204E9800998ECF8427E
JDownloader: [SBI $01C58A36] Programm-Verzeichnis (Verzeichnis, fixed)
C:\Program Files (x86)\JDownloader\
Toolbar.Facemood: [SBI $D3994306] Interface (Registrierungsdatenbank-Schlüssel, fixed)
HKEY_CLASSES_ROOT\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Toolbar.Facemood: [SBI $D3994306] Interface (Registrierungsdatenbank-Schlüssel, fixed)
HKEY_CLASSES_ROOT\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Toolbar.Facemood: [SBI $04C50E46] Interface (Registrierungsdatenbank-Schlüssel, fixed)
HKEY_CLASSES_ROOT\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Toolbar.Facemood: [SBI $04C50E46] Interface (Registrierungsdatenbank-Schlüssel, fixed)
HKEY_CLASSES_ROOT\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Toolbar.Facemood: [SBI $8B30B7C1] Einstellungen (Registrierungsdatenbank-Schlüssel, fixed)
HKEY_USERS\S-1-5-21-309064147-804680091-3328322202-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}
Toolbar.Facemood: [SBI $8F44A361] Anwendungs-ID (Registrierungsdatenbank-Schlüssel, fixed)
HKEY_CLASSES_ROOT\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}
Toolbar.Facemood: [SBI $8F44A361] Anwendungs-ID (Registrierungsdatenbank-Schlüssel, fixed)
HKEY_CLASSES_ROOT\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}
Toolbar.Facemood: [SBI $91EA8548] Class ID (Registrierungsdatenbank-Schlüssel, fixed)
HKEY_CLASSES_ROOT\CLSID\{64182481-4F71-486b-A045-B233BD0DA8FC}
Toolbar.Facemood: [SBI $CDB19D2C] Class ID (Registrierungsdatenbank-Schlüssel, fixed)
HKEY_CLASSES_ROOT\CLSID\{DDE2C74F-58CC-4d71-8CE1-09DEBB8CFB78}
Toolbar.Facemood: [SBI $05FB3923] IE Suchseite (Registrierungsdatenbank-Änderung, fixed)
HKEY_LOCAL_MACHINESoftware\Microsoft\Internet Explorer\Search\SearchAssistant=about:blank
Toolbar.Facemood: [SBI $1786BAF6] Web-Seite (Datei, fixed)
C:\Program Files (x86)\Mozilla Firefox\searchplugins\fcmdSrch.xml
Properties.size=0
Properties.md5=D41D8CD98F00B204E9800998ECF8427E
DoubleClick: Verfolgender Cookie (Internet Explorer: Pepe) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2014-01-01 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2013-11-06 Includes\Adware.sbi (*)
2013-12-23 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2012-11-14 Includes\Dialer.sbi (*)
2013-04-11 Includes\DialerC.sbi (*)
2013-04-11 Includes\HeavyDuty.sbi (*)
2012-11-14 Includes\Hijackers.sbi (*)
2013-04-11 Includes\HijackersC.sbi (*)
2013-10-16 Includes\iPhone.sbi (*)
2013-06-25 Includes\Keyloggers.sbi (*)
2013-10-30 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2013-05-29 Includes\Malware.sbi (*)
2013-12-23 Includes\MalwareC.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2013-12-23 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2012-11-14 Includes\Security.sbi (*)
2013-10-30 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2013-09-17 Includes\Spyware.sbi (*)
2013-08-06 Includes\SpywareC.sbi (*)
2012-11-19 Includes\Tracks.uti
2013-01-16 Includes\Trojans.sbi (*)
2013-12-11 Includes\TrojansC-02.sbi (*)
2013-12-10 Includes\TrojansC-03.sbi (*)
2013-12-23 Includes\TrojansC-04.sbi (*)
2013-06-13 Includes\TrojansC-05.sbi (*)
2013-08-06 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll MBAM: Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.01.01.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Pepe :: HAL [Administrator]
01.01.2014 14:25:45
mbam-log-2014-01-01 (14-25-45).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 243152
Laufzeit: 3 Minute(n), 13 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) AdwCleaner[S0].txt: Code:
# AdwCleaner v3.016 - Bericht erstellt am 01/01/2014 um 14:31:01
# Aktualisiert 23/12/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Pepe - HAL
# Gestartet von : C:\Users\Pepe\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Program Files (x86)\myfree codec
Ordner Gelöscht : C:\Program Files (x86)\Vuze
Ordner Gelöscht : C:\Users\Pepe\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Pepe\AppData\LocalLow\ConduitEngine
Ordner Gelöscht : C:\Users\Pepe\AppData\LocalLow\facemoods.com
Ordner Gelöscht : C:\Users\Pepe\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Fraen\AppData\LocalLow\facemoods.com
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\conduit.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\conduitapps.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Mozilla Firefox v26.0 (de)
[ Datei : C:\Users\Pepe\AppData\Roaming\Mozilla\Firefox\Profiles\dphoewqm.default-1388496873126\prefs.js ]
[ Datei : C:\Users\Fraen\AppData\Roaming\Mozilla\Firefox\Profiles\dj7csg7z.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [4792 octets] - [01/01/2014 14:30:32]
AdwCleaner[S0].txt - [4434 octets] - [01/01/2014 14:31:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4494 octets] ########## JRT.txt: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.9 (01.01.2014:1)
OS: Windows 7 Professional x64
Ran by Pepe on 01.01.2014 at 14:36:22,27
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Pepe\AppData\Roaming\mozilla\firefox\profiles\dphoewqm.default-1388496873126\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.01.2014 at 14:40:28,53
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Aktuelles frst.log:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-12-2013 01
Ran by Pepe (administrator) on HAL on 01-01-2014 14:44:35
Running from C:\Users\Pepe\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe
() C:\Windows\SysWOW64\XSrvSetup.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe
() C:\Users\Pepe\AppData\LocalLow\WOT\IE\WOTUpdater.exe
(CANON INC.) C:\Windows\System32\CNAB4RPD.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(The Eraser Project) C:\Program Files\Eraser\Eraser.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Dropbox, Inc.) C:\Users\Pepe\AppData\Roaming\Dropbox\bin\Dropbox.exe
(NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\AlarmClock.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10135584 2010-03-26] (Realtek Semiconductor)
HKLM\...\Run: [Eraser] - C:\Program Files\Eraser\Eraser.exe [980368 2010-11-04] (The Eraser Project)
HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [43632 2010-01-19] ()
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-11-20] (NEC Electronics Corporation)
HKLM-x32\...\Run: [EasyTuneVI] - C:\Program Files (x86)\GIGABYTE\ET6\ETcall.exe [20480 2007-07-26] ()
HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-17] (InstallShield Software Corporation)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-11-06] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [KeePass 2 PreLoad] - C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2065408 2013-11-03] (Dominik Reichl)
HKCU\...\Run: [ISUSPM Startup] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-17] (InstallShield Software Corporation)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-11-06] (Samsung)
HKCU\...\Run: [KeePass Password Safe 2] - C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2065408 2013-11-03] (Dominik Reichl)
HKU\Fraen\...\Run: [AVMUSBFernanschluss] - C:\Users\Fraen\AppData\Local\Apps\2.0\7N7932WX.9O0\8JQAB865.1TM\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\AVMAutoStart.exe [147456 2012-11-01] (AVM Berlin)
Startup: C:\Users\Fraen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Pepe\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Pepe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Pepe\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8FA70AE2732ACC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO-x32: WOT - {9E571C81-21E7-496B-9E6B-127E60263022} - C:\Users\Pepe\AppData\LocalLow\WOT\IE\WOT.dll (WOT Services Oy)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Pepe\AppData\Roaming\Mozilla\Firefox\Profiles\dphoewqm.default-1388496873126
FF Homepage: hxxp://www.google.de
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=1.1.10 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-30] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-18] (Avira Operations GmbH & Co. KG)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [68136 2009-06-17] ()
R2 JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [72304 2010-01-19] ()
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.)
R2 WOTUpdater; C:\Users\Pepe\AppData\LocalLow\WOT\IE\WOTUpdater.exe [18432 2012-01-12] ()
==================== Drivers (Whitelisted) ====================
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21544 2010-04-22] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-30] (Avira Operations GmbH & Co. KG)
R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [116096 2012-10-29] (AVM Berlin)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2014-01-01] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-01 14:40 - 2014-01-01 14:40 - 00000774 _____ C:\Users\Pepe\Desktop\JRT.txt
2014-01-01 14:36 - 2014-01-01 14:36 - 00000000 ____D C:\Windows\ERUNT
2014-01-01 14:35 - 2014-01-01 14:35 - 01036305 _____ (Thisisu) C:\Users\Pepe\Downloads\JRT.exe
2014-01-01 14:30 - 2014-01-01 14:31 - 00000000 ____D C:\AdwCleaner
2014-01-01 14:27 - 2014-01-01 14:27 - 01233962 _____ C:\Users\Pepe\Downloads\adwcleaner.exe
2014-01-01 14:20 - 2014-01-01 14:20 - 00819144 _____ (Google Inc.) C:\Users\Pepe\Downloads\ChromeSetup(3).exe
2014-01-01 13:36 - 2014-01-01 14:18 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2014-01-01 13:36 - 2014-01-01 13:38 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2014-01-01 13:36 - 2014-01-01 13:36 - 00001258 _____ C:\Users\Pepe\Desktop\Spybot - Search & Destroy.lnk
2014-01-01 13:35 - 2014-01-01 13:35 - 16409960 _____ (Safer Networking Limited ) C:\Users\Pepe\Downloads\spybotsd162.exe
2014-01-01 13:26 - 2014-01-01 13:26 - 00185800 _____ (Лаборатория Касперского) C:\Users\Pepe\Downloads\kss12.0.1.117abRU_EN_DE_FR_ES_IT_JA_PT_ZH_5203.exe
2014-01-01 13:19 - 2014-01-01 13:19 - 00819144 _____ (Google Inc.) C:\Users\Pepe\Downloads\ChromeSetup(2).exe
2014-01-01 13:05 - 2014-01-01 13:05 - 00819176 _____ (Google Inc.) C:\Users\Pepe\Downloads\ChromeSetup(1).exe
2014-01-01 13:03 - 2014-01-01 13:03 - 00819176 _____ (Google Inc.) C:\Users\Pepe\Downloads\ChromeSetup.exe
2014-01-01 12:22 - 2014-01-01 12:22 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-01 12:22 - 2014-01-01 12:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-01 12:22 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-01 12:18 - 2014-01-01 14:33 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-01 12:18 - 2014-01-01 14:30 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-01 12:18 - 2014-01-01 12:25 - 00004108 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-01-01 12:18 - 2014-01-01 12:25 - 00003856 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-01-01 12:18 - 2014-01-01 12:18 - 00000000 ____D C:\Users\Pepe\AppData\Local\Google
2014-01-01 12:18 - 2014-01-01 12:18 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-31 16:18 - 2013-12-31 16:18 - 02520814 _____ (Dominik Reichl ) C:\Users\Pepe\Downloads\KeePass-2.24-Setup.exe
2013-12-31 15:35 - 2013-12-31 15:35 - 00022952 _____ C:\ComboFix.txt
2013-12-31 15:28 - 2013-12-31 15:35 - 00000000 ____D C:\Qoobox
2013-12-31 15:28 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-12-31 15:28 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-12-31 15:28 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-12-31 15:28 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-12-31 15:28 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-12-31 15:28 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-12-31 15:28 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-12-31 15:28 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-12-31 15:27 - 2013-12-31 15:34 - 00000000 ____D C:\Windows\erdnt
2013-12-31 15:26 - 2013-12-31 15:26 - 05160176 ____R (Swearware) C:\Users\Pepe\Desktop\ComboFix.exe
2013-12-31 15:26 - 2013-12-31 15:26 - 05160176 _____ (Swearware) C:\Users\Pepe\Downloads\ComboFix.exe
2013-12-31 14:34 - 2013-12-31 14:34 - 00000000 ____D C:\Users\Pepe\Desktop\Alte Firefox-Daten
2013-12-31 12:24 - 2014-01-01 14:42 - 00000000 ____D C:\Users\Pepe\Desktop\analyse
2013-12-31 12:16 - 2013-12-31 12:16 - 00001699 _____ C:\Users\Pepe\Downloads\Gmer.txt
2013-12-31 12:08 - 2013-12-31 12:08 - 00377856 _____ C:\Users\Pepe\Downloads\gmer_2.1.19163.exe
2013-12-31 12:05 - 2013-12-31 12:05 - 00015046 _____ C:\Users\Pepe\Downloads\Addition.txt
2013-12-31 12:04 - 2014-01-01 14:44 - 00010127 _____ C:\Users\Pepe\Downloads\FRST.txt
2013-12-31 12:04 - 2013-12-31 12:04 - 00000000 ____D C:\FRST
2013-12-31 12:03 - 2013-12-31 12:03 - 01931302 _____ (Farbar) C:\Users\Pepe\Downloads\FRST64.exe
2013-12-31 12:01 - 2013-12-31 12:02 - 00000476 _____ C:\Users\Pepe\Downloads\defogger_disable.log
2013-12-31 12:01 - 2013-12-31 12:01 - 00000000 _____ C:\Users\Pepe\defogger_reenable
2013-12-31 12:00 - 2013-12-31 12:00 - 00050477 _____ C:\Users\Pepe\Downloads\Defogger.exe
2013-12-31 11:54 - 2013-12-31 11:54 - 00003130 _____ C:\Windows\System32\Tasks\{39F03511-2216-47B8-A1FB-1AE223F7793A}
2013-12-31 11:49 - 2013-12-31 11:49 - 00010645 _____ C:\Users\Pepe\Downloads\hijackthis.log
2013-12-31 11:47 - 2013-12-31 11:47 - 00388608 _____ (Trend Micro Inc.) C:\Users\Pepe\Downloads\HijackThis.exe
2013-12-29 13:08 - 2014-01-01 14:32 - 00000560 _____ C:\Windows\setupact.log
2013-12-29 13:08 - 2013-12-31 15:47 - 00001118 _____ C:\Windows\PFRO.log
2013-12-29 13:08 - 2013-12-29 13:08 - 00000000 _____ C:\Windows\setuperr.log
2013-12-29 12:57 - 2013-12-29 12:57 - 00000000 ____D C:\Users\Pepe\AppData\Roaming\Malwarebytes
2013-12-29 12:56 - 2013-12-29 12:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Pepe\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-29 12:56 - 2013-12-29 12:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-27 18:41 - 2013-12-27 18:41 - 00251584 _____ C:\Users\Pepe\Downloads\FRITZ.Box Fon WLAN 7390 84.06.01_27.12.13_1841.export
2013-12-24 11:59 - 2013-12-24 11:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-22 13:29 - 2013-12-22 13:29 - 00097792 _____ (IEA Software, Inc) C:\Users\Pepe\Downloads\mtupath.exe
2013-12-22 11:47 - 2013-12-22 11:47 - 00171344 _____ C:\Users\Pepe\Desktop\kontaktlinsen.xps
2013-12-11 21:38 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 21:38 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 21:38 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-11 21:38 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-11 21:38 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-11 21:38 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-11 21:38 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 21:38 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 21:38 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-11 21:38 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-11 21:38 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 21:38 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-11 21:38 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-11 21:38 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-11 21:38 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-11 21:38 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-11 21:38 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-11 21:38 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 21:38 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-11 21:38 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-11 21:38 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-11 21:38 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-11 21:38 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 21:38 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-11 21:38 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-11 21:38 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 21:38 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 21:38 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-11 21:38 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-11 21:38 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-11 21:38 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 21:35 - 2013-12-11 21:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-12-11 20:39 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 20:39 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 20:39 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 20:39 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 20:39 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 20:39 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 20:39 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 20:38 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 20:38 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 20:38 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 20:38 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 20:38 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 20:38 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 20:38 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 20:38 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-09 22:00 - 2013-12-09 22:01 - 00000000 ____D C:\Users\Pepe\2013NY
2013-12-09 21:47 - 2013-12-09 21:47 - 00000000 ____D C:\Users\Pepe\restore
2013-12-09 21:45 - 2013-12-10 00:37 - 00000000 ____D C:\ProgramData\tmp
2013-12-09 21:45 - 2013-12-09 22:04 - 00000000 ____D C:\ProgramData\hps
2013-12-09 21:42 - 2013-12-09 21:42 - 01628432 _____ C:\Users\Pepe\Downloads\setup_Pixum_Fotobuch.exe
2013-12-09 21:42 - 2013-12-09 21:42 - 00000000 ____D C:\Program Files (x86)\Pixum
2013-12-09 20:50 - 2013-12-09 21:04 - 00000000 ____D C:\Users\Pepe\Kalender2013
2013-12-03 19:46 - 2013-12-03 19:48 - 00007680 ___SH C:\Users\Pepe\Thumbs.db
==================== One Month Modified Files and Folders =======
2014-01-01 14:45 - 2013-12-31 12:04 - 00010127 _____ C:\Users\Pepe\Downloads\FRST.txt
2014-01-01 14:42 - 2013-12-31 12:24 - 00000000 ____D C:\Users\Pepe\Desktop\analyse
2014-01-01 14:40 - 2014-01-01 14:40 - 00000774 _____ C:\Users\Pepe\Desktop\JRT.txt
2014-01-01 14:40 - 2009-07-14 05:45 - 00018960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-01 14:40 - 2009-07-14 05:45 - 00018960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-01 14:36 - 2014-01-01 14:36 - 00000000 ____D C:\Windows\ERUNT
2014-01-01 14:35 - 2014-01-01 14:35 - 01036305 _____ (Thisisu) C:\Users\Pepe\Downloads\JRT.exe
2014-01-01 14:35 - 2011-06-14 10:24 - 00030528 _____ C:\Windows\GVTDrv64.sys
2014-01-01 14:34 - 2011-06-14 13:36 - 00000000 ____D C:\Users\Pepe\AppData\Roaming\KeePass
2014-01-01 14:34 - 2011-06-14 13:31 - 00000000 ___RD C:\Users\Pepe\Dropbox
2014-01-01 14:34 - 2011-06-14 13:24 - 00000000 ____D C:\Users\Pepe\AppData\Roaming\Dropbox
2014-01-01 14:34 - 2011-06-14 10:23 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2014-01-01 14:33 - 2014-01-01 12:18 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-01 14:32 - 2013-12-29 13:08 - 00000560 _____ C:\Windows\setupact.log
2014-01-01 14:32 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-01 14:31 - 2014-01-01 14:30 - 00000000 ____D C:\AdwCleaner
2014-01-01 14:31 - 2011-06-14 15:45 - 01533138 _____ C:\Windows\WindowsUpdate.log
2014-01-01 14:30 - 2014-01-01 12:18 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-01 14:27 - 2014-01-01 14:27 - 01233962 _____ C:\Users\Pepe\Downloads\adwcleaner.exe
2014-01-01 14:20 - 2014-01-01 14:20 - 00819144 _____ (Google Inc.) C:\Users\Pepe\Downloads\ChromeSetup(3).exe
2014-01-01 14:19 - 2012-10-25 19:30 - 00000000 ____D C:\Program Files (x86)\PantsOff
2014-01-01 14:18 - 2014-01-01 13:36 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2014-01-01 14:15 - 2012-07-16 18:43 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-01 13:38 - 2014-01-01 13:36 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2014-01-01 13:36 - 2014-01-01 13:36 - 00001258 _____ C:\Users\Pepe\Desktop\Spybot - Search & Destroy.lnk
2014-01-01 13:35 - 2014-01-01 13:35 - 16409960 _____ (Safer Networking Limited ) C:\Users\Pepe\Downloads\spybotsd162.exe
2014-01-01 13:26 - 2014-01-01 13:26 - 00185800 _____ (Лаборатория Касперского) C:\Users\Pepe\Downloads\kss12.0.1.117abRU_EN_DE_FR_ES_IT_JA_PT_ZH_5203.exe
2014-01-01 13:19 - 2014-01-01 13:19 - 00819144 _____ (Google Inc.) C:\Users\Pepe\Downloads\ChromeSetup(2).exe
2014-01-01 13:05 - 2014-01-01 13:05 - 00819176 _____ (Google Inc.) C:\Users\Pepe\Downloads\ChromeSetup(1).exe
2014-01-01 13:03 - 2014-01-01 13:03 - 00819176 _____ (Google Inc.) C:\Users\Pepe\Downloads\ChromeSetup.exe
2014-01-01 12:25 - 2014-01-01 12:18 - 00004108 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-01-01 12:25 - 2014-01-01 12:18 - 00003856 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-01-01 12:22 - 2014-01-01 12:22 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-01 12:22 - 2014-01-01 12:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-01 12:18 - 2014-01-01 12:18 - 00000000 ____D C:\Users\Pepe\AppData\Local\Google
2014-01-01 12:18 - 2014-01-01 12:18 - 00000000 ____D C:\Program Files (x86)\Google
2014-01-01 12:18 - 2012-10-29 13:56 - 00000000 ____D C:\Users\Pepe\AppData\Local\Deployment
2014-01-01 11:54 - 2011-06-21 08:50 - 00003918 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{BE6DEA73-F9B3-4F89-8DAA-8C96438EC7ED}
2013-12-31 16:18 - 2013-12-31 16:18 - 02520814 _____ (Dominik Reichl ) C:\Users\Pepe\Downloads\KeePass-2.24-Setup.exe
2013-12-31 16:18 - 2011-06-14 13:34 - 00000000 ____D C:\Program Files (x86)\KeePass Password Safe 2
2013-12-31 15:47 - 2013-12-29 13:08 - 00001118 _____ C:\Windows\PFRO.log
2013-12-31 15:47 - 2012-10-29 13:56 - 00000000 ____D C:\Users\Pepe\AppData\Local\Apps\2.0
2013-12-31 15:35 - 2013-12-31 15:35 - 00022952 _____ C:\ComboFix.txt
2013-12-31 15:35 - 2013-12-31 15:28 - 00000000 ____D C:\Qoobox
2013-12-31 15:34 - 2013-12-31 15:27 - 00000000 ____D C:\Windows\erdnt
2013-12-31 15:34 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2013-12-31 15:26 - 2013-12-31 15:26 - 05160176 ____R (Swearware) C:\Users\Pepe\Desktop\ComboFix.exe
2013-12-31 15:26 - 2013-12-31 15:26 - 05160176 _____ (Swearware) C:\Users\Pepe\Downloads\ComboFix.exe
2013-12-31 14:34 - 2013-12-31 14:34 - 00000000 ____D C:\Users\Pepe\Desktop\Alte Firefox-Daten
2013-12-31 12:16 - 2013-12-31 12:16 - 00001699 _____ C:\Users\Pepe\Downloads\Gmer.txt
2013-12-31 12:08 - 2013-12-31 12:08 - 00377856 _____ C:\Users\Pepe\Downloads\gmer_2.1.19163.exe
2013-12-31 12:05 - 2013-12-31 12:05 - 00015046 _____ C:\Users\Pepe\Downloads\Addition.txt
2013-12-31 12:04 - 2013-12-31 12:04 - 00000000 ____D C:\FRST
2013-12-31 12:03 - 2013-12-31 12:03 - 01931302 _____ (Farbar) C:\Users\Pepe\Downloads\FRST64.exe
2013-12-31 12:02 - 2013-12-31 12:01 - 00000476 _____ C:\Users\Pepe\Downloads\defogger_disable.log
2013-12-31 12:01 - 2013-12-31 12:01 - 00000000 _____ C:\Users\Pepe\defogger_reenable
2013-12-31 12:01 - 2011-06-14 10:06 - 00000000 ____D C:\Users\Pepe
2013-12-31 12:00 - 2013-12-31 12:00 - 00050477 _____ C:\Users\Pepe\Downloads\Defogger.exe
2013-12-31 11:54 - 2013-12-31 11:54 - 00003130 _____ C:\Windows\System32\Tasks\{39F03511-2216-47B8-A1FB-1AE223F7793A}
2013-12-31 11:49 - 2013-12-31 11:49 - 00010645 _____ C:\Users\Pepe\Downloads\hijackthis.log
2013-12-31 11:48 - 2011-06-14 10:06 - 00000000 ____D C:\Users\Pepe\AppData\Local\VirtualStore
2013-12-31 11:47 - 2013-12-31 11:47 - 00388608 _____ (Trend Micro Inc.) C:\Users\Pepe\Downloads\HijackThis.exe
2013-12-30 18:14 - 2011-06-15 01:41 - 00643628 _____ C:\Windows\system32\perfh007.dat
2013-12-30 18:14 - 2011-06-15 01:41 - 00126188 _____ C:\Windows\system32\perfc007.dat
2013-12-30 18:14 - 2009-07-14 06:13 - 01472002 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-29 13:08 - 2013-12-29 13:08 - 00000000 _____ C:\Windows\setuperr.log
2013-12-29 12:57 - 2013-12-29 12:57 - 00000000 ____D C:\Users\Pepe\AppData\Roaming\Malwarebytes
2013-12-29 12:56 - 2013-12-29 12:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Pepe\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-29 12:56 - 2013-12-29 12:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-29 12:34 - 2011-11-30 22:29 - 00000000 ____D C:\Windows\Minidump
2013-12-29 12:34 - 2011-06-15 01:42 - 00000000 ____D C:\Windows\Panther
2013-12-29 12:13 - 2012-03-20 10:49 - 00000830 _____ C:\Windows\wiso.ini
2013-12-29 10:27 - 2011-06-14 13:25 - 00000000 ____D C:\Users\Pepe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-12-29 10:27 - 2011-06-14 10:06 - 00000000 ___RD C:\Users\Pepe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-27 18:41 - 2013-12-27 18:41 - 00251584 _____ C:\Users\Pepe\Downloads\FRITZ.Box Fon WLAN 7390 84.06.01_27.12.13_1841.export
2013-12-27 18:35 - 2012-05-06 09:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-24 11:59 - 2013-12-24 11:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-22 13:29 - 2013-12-22 13:29 - 00097792 _____ (IEA Software, Inc) C:\Users\Pepe\Downloads\mtupath.exe
2013-12-22 11:47 - 2013-12-22 11:47 - 00171344 _____ C:\Users\Pepe\Desktop\kontaktlinsen.xps
2013-12-18 19:30 - 2013-08-10 17:53 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-12-18 19:30 - 2013-08-09 07:12 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-12-18 19:30 - 2013-08-09 07:12 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-15 19:20 - 2012-11-18 12:09 - 00000000 ____D C:\Users\Pepe\.dreamstream
2013-12-15 09:49 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-14 14:16 - 2013-08-16 12:56 - 00000000 ____D C:\Windows\system32\MRT
2013-12-14 14:14 - 2011-06-14 10:36 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-13 20:27 - 2012-11-01 12:08 - 00000000 ____D C:\Users\Fraen\AppData\Local\Deployment
2013-12-13 20:23 - 2012-10-09 21:33 - 00000000 ____D C:\Users\Fraen\AppData\Roaming\Dropbox
2013-12-13 20:22 - 2012-10-11 19:41 - 00000000 ___RD C:\Users\Fraen\Dropbox
2013-12-13 20:21 - 2011-06-14 19:06 - 00001421 _____ C:\Users\Fraen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-12 19:59 - 2009-07-14 05:45 - 00413624 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-11 21:39 - 2011-06-27 17:06 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 21:35 - 2013-12-11 21:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-12-11 21:15 - 2012-07-16 18:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 21:15 - 2012-07-16 18:43 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 21:15 - 2011-06-14 11:58 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-10 00:37 - 2013-12-09 21:45 - 00000000 ____D C:\ProgramData\tmp
2013-12-09 22:04 - 2013-12-09 21:45 - 00000000 ____D C:\ProgramData\hps
2013-12-09 22:01 - 2013-12-09 22:00 - 00000000 ____D C:\Users\Pepe\2013NY
2013-12-09 21:47 - 2013-12-09 21:47 - 00000000 ____D C:\Users\Pepe\restore
2013-12-09 21:42 - 2013-12-09 21:42 - 01628432 _____ C:\Users\Pepe\Downloads\setup_Pixum_Fotobuch.exe
2013-12-09 21:42 - 2013-12-09 21:42 - 00000000 ____D C:\Program Files (x86)\Pixum
2013-12-09 21:04 - 2013-12-09 20:50 - 00000000 ____D C:\Users\Pepe\Kalender2013
2013-12-06 23:25 - 2012-03-23 10:18 - 00000000 ____D C:\Program Files (x86)\fotokasten comfort
2013-12-05 17:53 - 2012-10-03 11:58 - 00000000 ____D C:\Users\Pepe\Documents\Turbo Lister Backup
2013-12-03 19:48 - 2013-12-03 19:46 - 00007680 ___SH C:\Users\Pepe\Thumbs.db
Some content of TEMP:
====================
C:\Users\Pepe\AppData\Local\Temp\avgnt.exe
C:\Users\Pepe\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-30 18:48
==================== End Of Log ============================ --- --- ---
--- --- ---
Weitere festgestellte Symptome:
- Probleme bestehen auch im abgesicherten Modus
- Google Chrome lässt sich weder via Firefox noch per IE downloaden und installieren (bleibt hängen)
Viele Grüße
Pepe
Hallo Schrauber,
folgendes habe ich herausgefunden:
- Das Problem existiert in meinem Netzwerk auf allen Windows 7-Rechnern wenn sie per LAN-Kabel verbunden sind.
- Das Problem existiert bei Windows 7 via WLAN nicht
- Das Problem existiert bei Windows XP via LAN ebenfalls nicht
- WillyTel hat mittlerweile zugegeben, dass das Problem seit 10 Tagen bekannt ist. :schrei: Betroffen ist die Kombination WillyTel, FritzBox 7390 (WT-eigene Firmware) + LAN-Verbindung (+ Windows 7 nach meiner Erfahrung)
Wenn aus Deiner Sicht auf meine Logfiles nichts dagegen spricht würde ich drum bitten diesen Thread zu schließen. Es sei denn Du hast was entdeckt was trotzdem behoben werden sollte.
Welche Schritte muss ich weiter durchführen (ComboFix deinstallieren, Defogger erneut ausführen etc.)?
Danke und Grüße
Pepe |