Balsberg | 02.04.2014 04:52 | Hallo!
Danke für den Hinweis und sorry für die lange Funkstille, die sich u.a. durch einen Unfall inkl. Rippenfraktur ergab.
Ich dachte eigentlich, mit meinem Rechner sei wohl doch alles bestens, und wollte nichtsdestotrotz mit den nächsten Schritten (ESET, Security Check, erneut FRST) weitermachen, doch letzte Woche tauchte ein neues Problem auf, das vielleicht gar nicht so neu ist, denn das "Verhalten" des Rechners war wieder genau das gleiche wie vor ca. 1 Monat, als ich dann deswegen hier um Hilfe bat! Inzwischen habe ich nämlich Malwarebytes und es hat jedesmal reagiert, wenn Firefox selbständig eine neue Adresse öffnen wollte. Beobachtet habe ich das Ganze zuerst am 26.3., leider habe ich aber die Logs aus Versehen gelöscht. Dafür sind die Logs vom 27.3., 28.3. und 29.3. vorhanden (s. unten). Seitdem trat das Problem (versuchter Abruf einer mir unbekannten Adresse durch Firefox) vorerst nicht mehr auf. Spätere Malwarebytes-Logs dokumentieren nur das (tägliche) Datenbank-Update und zeigen keinerlei Funde, daher habe ich sie hier erstmal nicht eingefügt.
Hier besagte Malwarebytes-Logs:
27.3. Code:
2014/03/27 05:13:27 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50189, Process: firefox.exe)
2014/03/27 05:13:35 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50195, Process: firefox.exe)
2014/03/27 05:13:35 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50197, Process: firefox.exe)
2014/03/27 05:17:52 +0100 HP-HP HP IP-BLOCK 93.174.93.77 (Type: outgoing, Port: 50296, Process: firefox.exe)
2014/03/27 05:17:52 +0100 HP-HP HP IP-BLOCK 93.174.93.77 (Type: outgoing, Port: 50303, Process: firefox.exe)
2014/03/27 05:17:52 +0100 HP-HP HP IP-BLOCK 93.174.93.77 (Type: outgoing, Port: 50305, Process: firefox.exe)
2014/03/27 05:17:52 +0100 HP-HP HP IP-BLOCK 93.174.93.77 (Type: outgoing, Port: 50307, Process: firefox.exe)
2014/03/27 05:40:53 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50950, Process: firefox.exe)
2014/03/27 05:40:54 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50954, Process: firefox.exe)
2014/03/27 05:40:54 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50958, Process: firefox.exe)
2014/03/27 05:40:54 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50959, Process: firefox.exe)
2014/03/27 05:40:54 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50961, Process: firefox.exe)
2014/03/27 05:40:54 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50962, Process: firefox.exe)
2014/03/27 05:41:02 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50969, Process: firefox.exe)
2014/03/27 05:41:02 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50970, Process: firefox.exe)
2014/03/27 05:41:18 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50976, Process: firefox.exe)
2014/03/27 05:41:18 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 50977, Process: firefox.exe)
2014/03/27 05:42:46 +0100 HP-HP HP IP-BLOCK 93.174.93.77 (Type: outgoing, Port: 51046, Process: firefox.exe)
2014/03/27 12:17:35 +0100 HP-HP (null) MESSAGE Starting protection
2014/03/27 12:17:36 +0100 HP-HP (null) MESSAGE Protection started successfully
2014/03/27 12:17:36 +0100 HP-HP (null) MESSAGE Starting IP protection
2014/03/27 12:17:40 +0100 HP-HP (null) MESSAGE IP Protection started successfully
2014/03/27 12:28:52 +0100 HP-HP (null) MESSAGE Executing scheduled update: Daily
2014/03/27 12:28:53 +0100 HP-HP (null) ERROR Scheduled update failed: No address found failed with error code 0
28.3. Code:
2014/03/28 00:11:47 +0100 HP-HP HP MESSAGE Starting protection
2014/03/28 00:11:47 +0100 HP-HP HP MESSAGE Protection started successfully
2014/03/28 00:11:47 +0100 HP-HP HP MESSAGE Starting IP protection
2014/03/28 00:11:51 +0100 HP-HP HP MESSAGE IP Protection started successfully
2014/03/28 00:14:16 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 49194, Process: firefox.exe)
2014/03/28 00:14:16 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 49203, Process: firefox.exe)
2014/03/28 00:15:12 +0100 HP-HP HP MESSAGE Executing scheduled update: Daily
2014/03/28 00:15:26 +0100 HP-HP HP MESSAGE Scheduled update executed successfully: database updated from version v2014.03.22.10 to version v2014.03.27.07
2014/03/28 00:15:26 +0100 HP-HP HP MESSAGE Starting database refresh
2014/03/28 00:15:26 +0100 HP-HP HP MESSAGE Stopping IP protection
2014/03/28 00:15:26 +0100 HP-HP HP MESSAGE IP Protection stopped successfully
2014/03/28 00:15:31 +0100 HP-HP HP MESSAGE Database refreshed successfully
2014/03/28 00:15:31 +0100 HP-HP HP MESSAGE Starting IP protection
2014/03/28 00:15:36 +0100 HP-HP HP MESSAGE IP Protection started successfully
2014/03/28 00:24:53 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49500, Process: firefox.exe)
2014/03/28 00:24:53 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49501, Process: firefox.exe)
2014/03/28 00:25:01 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49502, Process: firefox.exe)
2014/03/28 00:25:01 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49503, Process: firefox.exe)
2014/03/28 00:25:01 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49504, Process: firefox.exe)
2014/03/28 00:25:01 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49505, Process: firefox.exe)
2014/03/28 00:25:01 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49506, Process: firefox.exe)
2014/03/28 00:25:01 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49507, Process: firefox.exe)
2014/03/28 00:25:09 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49508, Process: firefox.exe)
2014/03/28 00:25:09 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49509, Process: firefox.exe)
2014/03/28 00:25:17 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49512, Process: firefox.exe)
2014/03/28 00:25:17 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49513, Process: firefox.exe)
2014/03/28 00:25:25 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49514, Process: firefox.exe)
2014/03/28 00:25:25 +0100 HP-HP HP IP-BLOCK 93.115.87.171 (Type: outgoing, Port: 49515, Process: firefox.exe)
2014/03/28 00:25:35 +0100 HP-HP HP MESSAGE Stopping IP protection
2014/03/28 00:25:36 +0100 HP-HP HP MESSAGE IP Protection stopped successfully
2014/03/28 00:28:03 +0100 HP-HP HP MESSAGE Starting IP protection
2014/03/28 00:28:07 +0100 HP-HP HP MESSAGE IP Protection started successfully
2014/03/28 00:40:54 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 50332, Process: firefox.exe)
2014/03/28 00:40:54 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 50333, Process: firefox.exe)
2014/03/28 00:40:57 +0100 HP-HP HP MESSAGE Stopping IP protection
2014/03/28 00:40:57 +0100 HP-HP HP MESSAGE IP Protection stopped successfully
2014/03/28 00:41:25 +0100 HP-HP HP MESSAGE Starting IP protection
2014/03/28 00:41:29 +0100 HP-HP HP MESSAGE IP Protection started successfully
2014/03/28 00:41:33 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 50339, Process: firefox.exe)
2014/03/28 00:41:49 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 50340, Process: firefox.exe)
2014/03/28 00:47:46 +0100 HP-HP HP MESSAGE Stopping IP protection
2014/03/28 00:47:47 +0100 HP-HP HP MESSAGE IP Protection stopped successfully
2014/03/28 00:48:15 +0100 HP-HP HP MESSAGE Starting IP protection
2014/03/28 00:48:19 +0100 HP-HP HP MESSAGE IP Protection started successfully
2014/03/28 23:27:30 +0100 HP-HP (null) MESSAGE Executing scheduled update: Daily
2014/03/28 23:27:31 +0100 HP-HP (null) ERROR Scheduled update failed: No address found failed with error code 0
2014/03/28 23:27:36 +0100 HP-HP (null) MESSAGE Starting protection
2014/03/28 23:27:36 +0100 HP-HP (null) MESSAGE Protection started successfully
2014/03/28 23:27:36 +0100 HP-HP (null) MESSAGE Starting IP protection
2014/03/28 23:27:40 +0100 HP-HP (null) MESSAGE IP Protection started successfully 29.3. Code:
2014/03/29 14:11:43 +0100 HP-HP (null) MESSAGE Starting protection
2014/03/29 14:11:43 +0100 HP-HP (null) MESSAGE Protection started successfully
2014/03/29 14:11:43 +0100 HP-HP (null) MESSAGE Starting IP protection
2014/03/29 14:11:47 +0100 HP-HP (null) MESSAGE IP Protection started successfully
2014/03/29 15:32:20 +0100 HP-HP HP IP-BLOCK 81.169.145.156 (Type: outgoing, Port: 51171, Process: firefox.exe)
2014/03/29 15:32:20 +0100 HP-HP HP IP-BLOCK 81.169.145.156 (Type: outgoing, Port: 51172, Process: firefox.exe)
2014/03/29 15:32:20 +0100 HP-HP HP IP-BLOCK 81.169.145.156 (Type: outgoing, Port: 51174, Process: firefox.exe)
2014/03/29 15:32:20 +0100 HP-HP HP IP-BLOCK 81.169.145.156 (Type: outgoing, Port: 51176, Process: firefox.exe)
2014/03/29 15:32:20 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 51241, Process: firefox.exe)
2014/03/29 15:32:20 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 51242, Process: firefox.exe)
2014/03/29 15:32:20 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 51243, Process: firefox.exe)
2014/03/29 15:34:21 +0100 HP-HP HP IP-BLOCK 81.169.145.156 (Type: outgoing, Port: 51313, Process: firefox.exe)
2014/03/29 15:34:29 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 51322, Process: firefox.exe)
2014/03/29 15:34:29 +0100 HP-HP HP IP-BLOCK 81.169.145.156 (Type: outgoing, Port: 51330, Process: firefox.exe)
2014/03/29 15:34:29 +0100 HP-HP HP IP-BLOCK 98.126.43.221 (Type: outgoing, Port: 51331, Process: firefox.exe)
2014/03/29 15:34:29 +0100 HP-HP HP IP-BLOCK 81.169.145.156 (Type: outgoing, Port: 51335, Process: firefox.exe)
2014/03/29 15:36:05 +0100 HP-HP HP IP-BLOCK 81.169.145.156 (Type: outgoing, Port: 51359, Process: firefox.exe)
2014/03/29 15:36:05 +0100 HP-HP HP IP-BLOCK 81.169.145.156 (Type: outgoing, Port: 51360, Process: firefox.exe)
2014/03/29 15:36:18 +0100 HP-HP HP MESSAGE Stopping IP protection
2014/03/29 15:36:19 +0100 HP-HP HP MESSAGE IP Protection stopped successfully
2014/03/29 15:36:48 +0100 HP-HP HP MESSAGE Starting IP protection
2014/03/29 15:36:53 +0100 HP-HP HP MESSAGE IP Protection started successfully Dann habe ich nochmal von vorne angefangen und mit FRST und GMER gescannt. (Ich hoffe, das war richtig so...)
FRST:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by HP (administrator) on HP-HP on 02-04-2014 03:33:13
Running from C:\Users\HP\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe
(Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Check Point Software Technologies) C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Check Point Software Technologies) C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-01-04] (IDT, Inc.)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [644696 2007-05-14] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1840720 2007-04-03] (CANON INC.)
HKLM\...\Run: [CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805}] - "C:\Users\HP\AppData\Local\Temp\cisBC7B.exe" --PostUninstall {15198508-521A-4D69-8E5B-B94A6CCFF805} <===== ATTENTION
HKLM\...\Run: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] - "C:\Users\HP\AppData\Local\Temp\cisBC7B.exe" --PostUninstall {81EFDD93-DBBE-415B-BE6E-49B9664E3E82} <===== ATTENTION
HKLM\...\Run: [ISW] - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe [1127592 2012-11-02] (Check Point Software Technologies)
HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190472 2009-09-17] (Logitech Inc.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [630912 2012-02-10] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-09-15] (EasyBits Software AS)
HKLM-x32\...\Run: [HPOSD] - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] - C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1343904 2012-11-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SSBkgdUpdate] - C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ZoneAlarm] - C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [73392 2012-11-19] (Check Point Software Technologies LTD)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Winlogon: [Userinit] c:\windows\system32\userinit.exe,C:\Program Files\MPK\mpk.exe
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-4233285500-2345498560-950285895-1001\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-4233285500-2345498560-950285895-1001\...\Policies\system: [DisableChangePassword] 0
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms}
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms}
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2012-06-25] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\3qkit518.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Google.com/GoogleEarthPlugin - C:\Users\HP\AppData\Local\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Flash Video Downloader - Full HD Download - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\3qkit518.default\Extensions\artur.dubovoy@gmail.com [2014-03-10]
FF HKLM\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] - C:\Program Files\CheckPoint\ZAForceField\TrustChecker
FF Extension: No Name - C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2013-02-07]
FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF Extension: ZoneAlarm Security Engine - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2013-02-07]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-02-10] (Advanced Micro Devices, Inc.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-21] (Avira Operations GmbH & Co. KG)
R2 IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [827560 2012-11-02] (Check Point Software Technologies)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2447440 2012-11-19] (Check Point Software Technologies LTD)
==================== Drivers (Whitelisted) ====================
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [31872 2012-02-02] (Advanced Micro Devices, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-01] (Avira Operations GmbH & Co. KG)
R2 ISWKL; C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [33712 2012-11-02] (Check Point Software Technologies)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [258664 2011-09-22] (Realtek Semiconductor Corp.)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [450136 2012-11-01] (Check Point Software Technologies LTD)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-02 02:00 - 2014-04-02 02:00 - 03739840 _____ () C:\Users\HP\Desktop\Sprachproben_wma.wma
2014-04-02 00:25 - 2014-04-02 00:25 - 01968708 _____ () C:\Users\HP\Desktop\_20140402_003802.tif
2014-04-02 00:25 - 2014-04-02 00:25 - 00324314 _____ () C:\Users\HP\Desktop\_20140402_003508.tif
2014-03-29 16:32 - 2014-03-29 16:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 00:39 - 2014-03-29 00:41 - 00000000 ____D () C:\Users\HP\AppData\Local\Windows Live
2014-03-29 00:39 - 2014-03-29 00:39 - 00000000 ____D () C:\Users\HP\AppData\Local\{53C312A8-A158-42C7-8594-FAC41904AA75}
2014-03-29 00:38 - 2014-03-29 00:38 - 00003182 _____ () C:\Users\HP\Desktop\message-rfc822-attachment.eml
2014-03-28 03:20 - 2014-03-28 05:47 - 00000985 _____ () C:\Users\HP\Desktop\GG.txt
2014-03-28 03:08 - 2014-03-28 03:10 - 00001298 _____ () C:\Users\HP\Desktop\FG.txt
2014-03-28 02:45 - 2014-03-28 03:02 - 00000550 _____ () C:\Users\HP\Desktop\DFG.txt
2014-03-28 02:41 - 2014-03-28 02:53 - 00001570 _____ () C:\Users\HP\Desktop\BG.txt
2014-03-24 05:59 - 2014-03-24 05:59 - 00987442 _____ () C:\Users\HP\Desktop\SecurityCheck.exe
2014-03-23 15:13 - 2014-03-23 15:14 - 02347384 _____ (ESET) C:\Users\HP\Desktop\esetsmartinstaller_enu.exe
2014-03-23 07:54 - 2014-03-23 07:54 - 00001209 _____ () C:\Users\HP\Desktop\JRT.txt
2014-03-23 07:42 - 2014-03-23 07:42 - 00000000 ____D () C:\Windows\ERUNT
2014-03-23 07:38 - 2014-03-23 07:38 - 00003298 _____ () C:\Users\HP\Desktop\AdwC.txt
2014-03-23 07:25 - 2014-03-23 07:32 - 00000000 ____D () C:\AdwCleaner
2014-03-23 07:24 - 2014-03-23 07:24 - 00002168 _____ () C:\Users\HP\Desktop\MBAM.txt
2014-03-23 01:17 - 2014-03-23 01:17 - 00001119 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-23 01:17 - 2014-03-23 01:17 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Malwarebytes
2014-03-23 01:17 - 2014-03-23 01:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-23 01:17 - 2014-03-23 01:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-23 01:17 - 2013-04-04 15:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-22 02:49 - 2014-03-22 02:49 - 01037734 _____ (Thisisu) C:\Users\HP\Desktop\JRT.exe
2014-03-22 02:48 - 2014-03-22 02:48 - 01950720 _____ () C:\Users\HP\Desktop\adwcleaner.exe
2014-03-22 02:47 - 2014-03-22 02:47 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\HP\Desktop\mbam-setup-1.75.0.1300.exe
2014-03-21 04:18 - 2014-03-21 04:18 - 00018451 _____ () C:\ComboFix.txt
2014-03-21 02:31 - 2014-03-21 04:26 - 00000000 ____D () C:\Qoobox
2014-03-21 02:31 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-03-21 02:31 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-03-21 02:31 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-03-21 02:31 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-03-21 02:31 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-03-21 02:31 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-03-21 02:31 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-03-21 02:31 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-03-21 02:30 - 2014-03-21 03:57 - 00000000 ____D () C:\Windows\erdnt
2014-03-20 11:55 - 2014-03-20 11:55 - 05190052 ____R (Swearware) C:\Users\HP\Desktop\ComboFix.exe
2014-03-20 03:43 - 2014-03-20 03:43 - 00001215 _____ () C:\Users\HP\Desktop\GMER.txt
2014-03-20 03:30 - 2014-03-20 03:30 - 00033678 _____ () C:\Users\HP\Desktop\Addition.txt
2014-03-20 03:29 - 2014-04-02 03:33 - 00016706 _____ () C:\Users\HP\Desktop\FRST.txt
2014-03-20 03:28 - 2014-04-02 03:33 - 00000000 ____D () C:\FRST
2014-03-20 03:27 - 2014-03-20 03:27 - 00000466 _____ () C:\Users\HP\Desktop\defogger_disable.log
2014-03-20 03:27 - 2014-03-20 03:27 - 00000000 _____ () C:\Users\HP\defogger_reenable
2014-03-20 03:09 - 2014-03-20 03:09 - 02157056 _____ (Farbar) C:\Users\HP\Desktop\FRST64.exe
2014-03-20 03:09 - 2014-03-20 03:09 - 00380416 _____ () C:\Users\HP\Desktop\Gmer-19357.exe
2014-03-20 03:07 - 2014-03-20 03:08 - 00050477 _____ () C:\Users\HP\Desktop\Defogger.exe
2014-03-16 05:21 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-16 05:21 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-16 05:21 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-16 05:21 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-16 05:21 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-16 05:21 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-16 05:21 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-16 05:21 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-16 05:21 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-16 05:21 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-16 05:21 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-16 05:20 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-16 05:20 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-16 05:20 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-16 05:20 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-16 05:20 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-16 05:20 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-16 05:20 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-16 05:20 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-16 05:20 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-16 05:20 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-16 05:20 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-16 05:20 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-16 05:20 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-16 05:20 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-16 05:20 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-16 05:20 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-16 05:20 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-16 05:20 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-16 05:20 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-16 05:20 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-16 05:20 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-16 05:20 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-16 05:20 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-16 05:20 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-16 05:20 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-16 05:20 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-16 05:20 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-16 05:20 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-16 05:20 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-16 05:20 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-16 05:20 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-16 05:20 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-16 05:19 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-16 05:19 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-16 05:19 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-16 05:19 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-16 05:19 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-13 16:36 - 2014-03-13 16:36 - 00029373 _____ () C:\Users\HP\Desktop\Klausurergebnisse.xlsx
==================== One Month Modified Files and Folders =======
2014-04-02 03:34 - 2014-03-20 03:29 - 00016706 _____ () C:\Users\HP\Desktop\FRST.txt
2014-04-02 03:33 - 2014-03-20 03:28 - 00000000 ____D () C:\FRST
2014-04-02 02:00 - 2014-04-02 02:00 - 03739840 _____ () C:\Users\HP\Desktop\Sprachproben_wma.wma
2014-04-02 00:27 - 2013-02-01 09:47 - 00003906 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{60B686FB-5218-4ED2-938C-C2748479D3B2}
2014-04-02 00:25 - 2014-04-02 00:25 - 01968708 _____ () C:\Users\HP\Desktop\_20140402_003802.tif
2014-04-02 00:25 - 2014-04-02 00:25 - 00324314 _____ () C:\Users\HP\Desktop\_20140402_003508.tif
2014-04-02 00:25 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-02 00:25 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-02 00:24 - 2012-03-04 00:46 - 00700134 _____ () C:\Windows\system32\perfh007.dat
2014-04-02 00:24 - 2012-03-04 00:46 - 00149984 _____ () C:\Windows\system32\perfc007.dat
2014-04-02 00:24 - 2009-07-14 07:13 - 01622236 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-02 00:17 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-02 00:17 - 2009-07-14 06:51 - 00084625 _____ () C:\Windows\setupact.log
2014-04-01 13:25 - 2013-02-01 09:44 - 01989593 _____ () C:\Windows\WindowsUpdate.log
2014-03-30 04:16 - 2013-02-08 01:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-29 16:32 - 2014-03-29 16:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 00:41 - 2014-03-29 00:39 - 00000000 ____D () C:\Users\HP\AppData\Local\Windows Live
2014-03-29 00:39 - 2014-03-29 00:39 - 00000000 ____D () C:\Users\HP\AppData\Local\{53C312A8-A158-42C7-8594-FAC41904AA75}
2014-03-29 00:38 - 2014-03-29 00:38 - 00003182 _____ () C:\Users\HP\Desktop\message-rfc822-attachment.eml
2014-03-29 00:34 - 2013-02-06 20:55 - 00003168 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForHP
2014-03-29 00:34 - 2013-02-06 20:55 - 00000320 _____ () C:\Windows\Tasks\HPCeeScheduleForHP.job
2014-03-28 05:47 - 2014-03-28 03:20 - 00000985 _____ () C:\Users\HP\Desktop\GG.txt
2014-03-28 03:10 - 2014-03-28 03:08 - 00001298 _____ () C:\Users\HP\Desktop\FG.txt
2014-03-28 03:02 - 2014-03-28 02:45 - 00000550 _____ () C:\Users\HP\Desktop\DFG.txt
2014-03-28 02:53 - 2014-03-28 02:41 - 00001570 _____ () C:\Users\HP\Desktop\BG.txt
2014-03-24 05:59 - 2014-03-24 05:59 - 00987442 _____ () C:\Users\HP\Desktop\SecurityCheck.exe
2014-03-23 20:20 - 2013-02-12 04:18 - 00000000 ____D () C:\Users\HP\AppData\Roaming\SoftGrid Client
2014-03-23 15:14 - 2014-03-23 15:13 - 02347384 _____ (ESET) C:\Users\HP\Desktop\esetsmartinstaller_enu.exe
2014-03-23 07:54 - 2014-03-23 07:54 - 00001209 _____ () C:\Users\HP\Desktop\JRT.txt
2014-03-23 07:42 - 2014-03-23 07:42 - 00000000 ____D () C:\Windows\ERUNT
2014-03-23 07:38 - 2014-03-23 07:38 - 00003298 _____ () C:\Users\HP\Desktop\AdwC.txt
2014-03-23 07:35 - 2013-02-07 01:36 - 00000000 ____D () C:\Users\HP\AppData\Roaming\CheckPoint
2014-03-23 07:32 - 2014-03-23 07:25 - 00000000 ____D () C:\AdwCleaner
2014-03-23 07:24 - 2014-03-23 07:24 - 00002168 _____ () C:\Users\HP\Desktop\MBAM.txt
2014-03-23 01:17 - 2014-03-23 01:17 - 00001119 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-23 01:17 - 2014-03-23 01:17 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Malwarebytes
2014-03-23 01:17 - 2014-03-23 01:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-23 01:17 - 2014-03-23 01:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-22 02:49 - 2014-03-22 02:49 - 01037734 _____ (Thisisu) C:\Users\HP\Desktop\JRT.exe
2014-03-22 02:48 - 2014-03-22 02:48 - 01950720 _____ () C:\Users\HP\Desktop\adwcleaner.exe
2014-03-22 02:47 - 2014-03-22 02:47 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\HP\Desktop\mbam-setup-1.75.0.1300.exe
2014-03-21 21:50 - 2010-11-21 05:47 - 00838966 _____ () C:\Windows\PFRO.log
2014-03-21 05:57 - 2013-05-06 01:20 - 00000000 ____D () C:\Users\HP\AppData\Local\CrashDumps
2014-03-21 04:26 - 2014-03-21 02:31 - 00000000 ____D () C:\Qoobox
2014-03-21 04:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-03-21 04:18 - 2014-03-21 04:18 - 00018451 _____ () C:\ComboFix.txt
2014-03-21 03:57 - 2014-03-21 02:30 - 00000000 ____D () C:\Windows\erdnt
2014-03-21 02:56 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-03-20 11:55 - 2014-03-20 11:55 - 05190052 ____R (Swearware) C:\Users\HP\Desktop\ComboFix.exe
2014-03-20 03:43 - 2014-03-20 03:43 - 00001215 _____ () C:\Users\HP\Desktop\GMER.txt
2014-03-20 03:30 - 2014-03-20 03:30 - 00033678 _____ () C:\Users\HP\Desktop\Addition.txt
2014-03-20 03:27 - 2014-03-20 03:27 - 00000466 _____ () C:\Users\HP\Desktop\defogger_disable.log
2014-03-20 03:27 - 2014-03-20 03:27 - 00000000 _____ () C:\Users\HP\defogger_reenable
2014-03-20 03:27 - 2013-02-01 09:44 - 00000000 ____D () C:\Users\HP
2014-03-20 03:09 - 2014-03-20 03:09 - 02157056 _____ (Farbar) C:\Users\HP\Desktop\FRST64.exe
2014-03-20 03:09 - 2014-03-20 03:09 - 00380416 _____ () C:\Users\HP\Desktop\Gmer-19357.exe
2014-03-20 03:08 - 2014-03-20 03:07 - 00050477 _____ () C:\Users\HP\Desktop\Defogger.exe
2014-03-19 14:39 - 2012-03-03 16:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-19 14:39 - 2012-03-03 16:32 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-16 07:44 - 2009-07-14 06:45 - 00368800 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-16 07:42 - 2013-02-15 03:18 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-16 07:42 - 2013-02-15 03:18 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-16 05:27 - 2013-07-17 12:08 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-16 05:25 - 2013-02-05 23:10 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-16 05:11 - 2013-02-01 09:52 - 00087376 _____ () C:\Users\HP\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-13 16:36 - 2014-03-13 16:36 - 00029373 _____ () C:\Users\HP\Desktop\Klausurergebnisse.xlsx
2014-03-10 16:39 - 2013-02-15 06:21 - 00000000 ____D () C:\Users\HP\Total
Some content of TEMP:
====================
C:\Users\HP\AppData\Local\Temp\avgnt.exe
C:\Users\HP\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-20 14:11
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
GMER: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-04-02 03:51:23
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000060 ST640LM0 rev.2AJ1 596,17GB
Running: Gmer-19357.exe; Driver: C:\Users\HP\AppData\Local\Temp\kxddipog.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002ff9000 16 bytes [8B, E3, 41, 5F, 41, 5E, 41, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 545 fffff80002ff9011 35 bytes {LEA ECX, [RSP+0x70]; CALL 0x3d64f}
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1532] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076741465 2 bytes [74, 76]
.text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1532] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767414bb 2 bytes [74, 76]
.text ... * 2
.text C:\Windows\SysWOW64\ezSharedSvcHost.exe[2088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076741465 2 bytes [74, 76]
.text C:\Windows\SysWOW64\ezSharedSvcHost.exe[2088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767414bb 2 bytes [74, 76]
.text ... * 2
.text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076741465 2 bytes [74, 76]
.text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[2232] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767414bb 2 bytes [74, 76]
.text ... * 2
? C:\Windows\system32\mssprxy.dll [2724] entry point in ".rdata" section 00000000738171e6
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[5072] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076741465 2 bytes [74, 76]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[5072] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767414bb 2 bytes [74, 76]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\spoolsv.exe [1904:4028] 000007fef53f10c8
Thread C:\Windows\System32\spoolsv.exe [1904:3272] 000007fef5386144
Thread C:\Windows\System32\spoolsv.exe [1904:3248] 000007fef53b5fd0
Thread C:\Windows\System32\spoolsv.exe [1904:3264] 000007fef4e63438
Thread C:\Windows\System32\spoolsv.exe [1904:3316] 000007fef53b63ec
Thread C:\Windows\System32\spoolsv.exe [1904:2420] 000007fef5b85e5c
Thread C:\Windows\System32\spoolsv.exe [1904:3472] 000007fef5775074
Thread C:\Windows\System32\svchost.exe [2628:2252] 000007fef7089688
---- EOF - GMER 2.1 ----
Bin nun etwas ratlos und ahne böses...
LG
Balsberg |