So, nachdem ich erfolglos versuchte nach der Deinstallation restliche Dateien des Anti- Malware- Programmes zu entfernen, installierte ich es erneut und exportierte erst die mbam.txt- Datei und verschob anschließend die gefundenen Dateien. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 14.05.2014
Suchlauf-Zeit: 21:32:07
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.14.08
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: ********
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 257753
Verstrichene Zeit: 29 Min, 2 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 1
PUP.Optional.Conduit.A, HKU\S-1-5-21-529792085-2144148937-180937944-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?ctid=CT3314932&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP64625AB8-0A50-47DC-97B9-A8FAC97E22FB&SSPV=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.conduit.com/?ctid=CT3314932&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP64625AB8-0A50-47DC-97B9-A8FAC97E22FB&SSPV=),,[fa5675dc2e4d6cca1b7ff549bc4813ed]
Ordner: 18
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, , [4a065af767149e98ced4c2f7ca393fc1],
Dateien: 79
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe_1399914313710, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll_1399914313804, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.css, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.html, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\defaults.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\button-bg.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\SPDialogAPI.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js, , [4a065af767149e98ced4c2f7ca393fc1],
PUP.Optional.CrossRider.A, C:\Users\********\AppData\Roaming\Mozilla\Firefox\Profiles\8jtvym4t.default-1398775407563\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "145ad963b78b806a111fb38810b2f070");), ,[c7894a079edd9e982a332f4563a19070]
PUP.Optional.Conduit.A, C:\Users\********\AppData\Roaming\Mozilla\Firefox\Profiles\8jtvym4t.default-1398775407563\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3314932&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP64625AB8-0A50-47DC-97B9-A8FAC97E22FB&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&ISID=");), ,[d27e450ca3d8cc6a354d7301996b4db3]
PUP.Optional.Conduit.A, C:\Users\********\AppData\Roaming\Mozilla\Firefox\Profiles\8jtvym4t.default-1398775407563\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3314932&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SP64625AB8-0A50-47DC-97B9-A8FAC97E22FB&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&ISID=");), ,[1e32ed6494e785b166560f6560a4ea16]
Physische Sektoren: 0
(No malicious items detected)
(end)
AdwCleaner Logfile: Code:
# AdwCleaner v3.208 - Bericht erstellt am 14/05/2014 um 21:44:09
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : ******** - ANA
# Gestartet von : C:\Users\********\Downloads\adwcleaner_3.208.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : 70e6ca8c
[#] Dienst Gelöscht : BackupStack
Dienst Gelöscht : NewPlayerUpdaterService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\InternetUpdater
Ordner Gelöscht : C:\ProgramData\topdeal
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\ProgramData\TicTaCoUpon
Ordner Gelöscht : C:\ProgramData\webseaVer
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\NewPlayer
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\Windows\SysWOW64\SearchProtect
Ordner Gelöscht : C:\Users\********\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\********\AppData\LocalLow\StumbleUpon
Ordner Gelöscht : C:\Users\********\AppData\Roaming\Activeris
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\********\AppData\Roaming\aps.scan.quick.results
Datei Gelöscht : C:\Users\********\Desktop\MyPC Backup.lnk
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\********\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{8e7d6746-77a0-402a-b4ab-a6f73a41db80}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\AddonsFramework.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ButtonSite.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHost.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{19975B78-1907-4DD6-A437-4C48120F46A4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9317-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\pc speed maximizer
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DynConIE
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\Software\ImInstaller
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : HKLM\Software\SearchProtect
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\********\AppData\Roaming\Mozilla\Firefox\Profiles\8jtvym4t.default-1398775407563\prefs.js ]
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3314932&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SP64625AB8-0A50-47DC-97B9-A8FAC97E22FB&SSPV=&SSPV=&SSPV=&SSPV[...]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Conduit Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Conduit Search");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3314932&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP64625AB8-0A50-47DC-97B9-A8FAC97E22FB&SSPV=&SSPV=&SSPV=&SSPV=&SSPV[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "145ad963b78b806a111fb38810b2f070");
*************************
AdwCleaner[R0].txt - [6516 octets] - [14/05/2014 21:43:13]
AdwCleaner[S0].txt - [5749 octets] - [14/05/2014 21:44:09]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5809 octets] ########## --- --- ---
[/CODE] Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by ******** on 14.05.2014 at 21:51:17,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\im
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "\software"
~~~ FireFox
Emptied folder: C:\Users\********\AppData\Roaming\mozilla\firefox\profiles\8jtvym4t.default-1398775407563\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.05.2014 at 22:04:18,39
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-05-2014
Ran by Ana Sydow (administrator) on ANA on 14-05-2014 22:08:44
Running from C:\Users\Ana Sydow\Desktop
Platform: Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
(Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(IncrediMail, Ltd.) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(IncrediMail, Ltd.) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2874256 2012-12-07] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13519432 2000-01-01] (Realtek Semiconductor)
HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2013-04-09] (Pixart Imaging Inc)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-13] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-24] (Avira Operations GmbH & Co. KG)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-04-15] ( (Atheros Communications))
HKU\S-1-5-21-529792085-2144148937-180937944-1001\...\Run: [Amazon Cloud Player] => C:\Users\Ana Sydow\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3140608 2014-01-14] ()
HKU\S-1-5-21-529792085-2144148937-180937944-1001\...\Run: [IncrediMail] => C:\Program Files (x86)\IncrediMail\bin\IncMail.exe [444840 2014-01-29] (IncrediMail, Ltd.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {5A6CD5A0-E384-4C39-B2EA-2C4345E8590B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAPBJS
SearchScopes: HKLM-x32 - {5A6CD5A0-E384-4C39-B2EA-2C4345E8590B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAPBJS
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Ana Sydow\AppData\Roaming\Mozilla\Firefox\Profiles\8jtvym4t.default-1398775407563
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: NoScript - C:\Users\Ana Sydow\AppData\Roaming\Mozilla\Firefox\Profiles\8jtvym4t.default-1398775407563\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-29]
==================== Services (Whitelisted) =================
R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [228480 2013-04-15] (Qualcomm Atheros Commnucations)
R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [515632 2013-05-21] (REINER SCT)
S3 DeviceFastLaneService; C:\Program Files\Packard Bell\Packard Bell Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-16] (Acer Incorporated)
S3 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [662088 2013-03-15] (Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2012-12-07] (ELAN Microelectronics Corp.)
R2 LMSvc; C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe [431656 2013-03-15] (Acer Incorporate)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2412344 2014-01-28] (TuneUp Software)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [94208 2013-02-14] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131576 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-31] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-22] (Avira Operations GmbH & Co. KG)
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-04-15] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
S3 cjusb; C:\Windows\system32\DRIVERS\cjusb.sys [35192 2012-09-04] (REINER SCT)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-14] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2013-11-17] ()
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-07-19] (TuneUp Software)
S3 t_mouse.sys; C:\Windows\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-14 22:08 - 2014-05-14 22:08 - 00011474 _____ () C:\Users\Ana Sydow\Desktop\FRST.txt
2014-05-14 22:08 - 2014-05-14 22:08 - 00000000 ____D () C:\Users\Ana Sydow\Desktop\FRST-OlderVersion
2014-05-14 22:04 - 2014-05-14 22:04 - 00000949 _____ () C:\Users\Ana Sydow\Desktop\JRT.txt
2014-05-14 21:51 - 2014-05-14 21:51 - 00000000 ____D () C:\Windows\ERUNT
2014-05-14 21:50 - 2014-05-14 21:50 - 01016261 _____ (Thisisu) C:\Users\Ana Sydow\Downloads\JRT.exe
2014-05-14 21:34 - 2014-05-14 21:44 - 00000000 ____D () C:\AdwCleaner
2014-05-14 21:34 - 2014-05-14 21:34 - 01325827 _____ () C:\Users\Ana Sydow\Downloads\adwcleaner_3.208.exe
2014-05-14 21:32 - 2014-05-14 21:33 - 00015602 _____ () C:\Users\Ana Sydow\Desktop\mbam.txt
2014-05-14 21:01 - 2014-05-14 21:01 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-14 21:01 - 2014-05-14 21:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-14 21:01 - 2014-05-14 21:01 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-14 21:01 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-14 21:01 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-14 21:01 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-14 21:00 - 2014-05-14 21:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Ana Sydow\Downloads\mbam-setup-2.0.1.1004(2).exe
2014-05-12 21:14 - 2014-05-12 21:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Ana Sydow\Downloads\mbam-setup-2.0.1.1004(1).exe
2014-05-10 20:01 - 2014-05-10 20:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-10 19:58 - 2014-05-14 21:48 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-10 19:57 - 2014-05-10 19:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-10 19:55 - 2014-05-10 19:56 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Ana Sydow\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-08 18:49 - 2014-05-08 21:30 - 00001276 _____ () C:\Users\Ana Sydow\Desktop\Revo Uninstaller.lnk
2014-05-08 18:49 - 2014-05-08 21:30 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-08 18:48 - 2014-05-08 18:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Ana Sydow\Desktop\revosetup95.exe
2014-05-07 11:35 - 2014-05-07 11:35 - 00380416 _____ () C:\Users\Ana Sydow\Desktop\Gmer-19357.exe
2014-05-07 11:30 - 2014-05-14 22:08 - 00000000 ____D () C:\FRST
2014-05-07 11:29 - 2014-05-14 22:08 - 02066944 _____ (Farbar) C:\Users\Ana Sydow\Desktop\FRST64.exe
2014-05-07 11:23 - 2014-05-07 11:25 - 00000480 _____ () C:\Users\Ana Sydow\Downloads\defogger_disable.log
2014-05-07 11:23 - 2014-05-07 11:23 - 00000000 _____ () C:\Users\Ana Sydow\defogger_reenable
2014-05-07 11:21 - 2014-05-07 11:22 - 00050477 _____ () C:\Users\Ana Sydow\Desktop\Defogger.exe
2014-05-06 15:01 - 2014-04-19 11:39 - 00628024 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-05-06 15:01 - 2014-04-19 10:45 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-05-06 15:01 - 2014-04-19 10:45 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-06 15:01 - 2014-04-19 08:57 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-05-06 15:01 - 2014-04-19 08:57 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-05 06:59 - 2014-04-29 16:14 - 19275264 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-05 06:59 - 2014-04-29 14:47 - 14357504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-05 06:59 - 2014-04-29 14:36 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-05 06:59 - 2014-04-29 14:25 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-30 10:04 - 2014-04-30 10:04 - 251586632 _____ () C:\Users\Ana Sydow\Documents\regedit Sicherung.reg
==================== One Month Modified Files and Folders =======
2014-05-14 22:09 - 2014-05-14 22:08 - 00011474 _____ () C:\Users\Ana Sydow\Desktop\FRST.txt
2014-05-14 22:08 - 2014-05-14 22:08 - 00000000 ____D () C:\Users\Ana Sydow\Desktop\FRST-OlderVersion
2014-05-14 22:08 - 2014-05-07 11:30 - 00000000 ____D () C:\FRST
2014-05-14 22:08 - 2014-05-07 11:29 - 02066944 _____ (Farbar) C:\Users\Ana Sydow\Desktop\FRST64.exe
2014-05-14 22:04 - 2014-05-14 22:04 - 00000949 _____ () C:\Users\Ana Sydow\Desktop\JRT.txt
2014-05-14 22:01 - 2013-09-28 14:34 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-529792085-2144148937-180937944-1001
2014-05-14 22:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-05-14 21:51 - 2014-05-14 21:51 - 00000000 ____D () C:\Windows\ERUNT
2014-05-14 21:50 - 2014-05-14 21:50 - 01016261 _____ (Thisisu) C:\Users\Ana Sydow\Downloads\JRT.exe
2014-05-14 21:50 - 2013-11-11 14:08 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-14 21:48 - 2014-05-10 19:58 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-14 21:46 - 2013-12-18 19:15 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-14 21:46 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-14 21:45 - 2014-02-24 17:50 - 00029612 _____ () C:\Windows\PFRO.log
2014-05-14 21:44 - 2014-05-14 21:34 - 00000000 ____D () C:\AdwCleaner
2014-05-14 21:44 - 2014-02-08 12:47 - 00001073 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-14 21:42 - 2013-10-07 14:55 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{1FE1C09B-6610-4F02-922D-F5789EB168C5}
2014-05-14 21:36 - 2014-02-08 12:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-14 21:36 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-05-14 21:34 - 2014-05-14 21:34 - 01325827 _____ () C:\Users\Ana Sydow\Downloads\adwcleaner_3.208.exe
2014-05-14 21:33 - 2014-05-14 21:32 - 00015602 _____ () C:\Users\Ana Sydow\Desktop\mbam.txt
2014-05-14 21:25 - 2013-12-18 19:15 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-14 21:01 - 2014-05-14 21:01 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-14 21:01 - 2014-05-14 21:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-14 21:01 - 2014-05-14 21:01 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-14 21:00 - 2014-05-14 21:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Ana Sydow\Downloads\mbam-setup-2.0.1.1004(2).exe
2014-05-14 20:59 - 2013-06-26 18:33 - 01968808 _____ () C:\Windows\WindowsUpdate.log
2014-05-14 16:28 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-05-14 07:33 - 2013-06-26 18:49 - 00065536 _____ () C:\Windows\system32\spu_storage.bin
2014-05-13 19:55 - 2013-11-11 14:08 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-12 21:16 - 2013-11-06 19:52 - 00000000 ____D () C:\Users\Ana Sydow\AppData\Local\CrashDumps
2014-05-12 21:14 - 2014-05-12 21:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Ana Sydow\Downloads\mbam-setup-2.0.1.1004(1).exe
2014-05-11 21:59 - 2014-01-13 20:00 - 00012504 _____ () C:\Users\Ana Sydow\Documents\Stundenzettel INP.odt
2014-05-10 21:01 - 2014-02-09 12:40 - 00000000 ____D () C:\ProgramData\Updater
2014-05-10 21:01 - 2014-01-24 13:57 - 00000000 ____D () C:\ProgramData\AAppptooU
2014-05-10 20:02 - 2014-05-10 20:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-10 19:57 - 2014-05-10 19:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-10 19:56 - 2014-05-10 19:55 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Ana Sydow\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-09 13:54 - 2014-02-08 13:17 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0
2014-05-08 21:30 - 2014-05-08 18:49 - 00001276 _____ () C:\Users\Ana Sydow\Desktop\Revo Uninstaller.lnk
2014-05-08 21:30 - 2014-05-08 18:49 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-08 18:48 - 2014-05-08 18:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Ana Sydow\Desktop\revosetup95.exe
2014-05-08 13:06 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-05-07 11:35 - 2014-05-07 11:35 - 00380416 _____ () C:\Users\Ana Sydow\Desktop\Gmer-19357.exe
2014-05-07 11:25 - 2014-05-07 11:23 - 00000480 _____ () C:\Users\Ana Sydow\Downloads\defogger_disable.log
2014-05-07 11:23 - 2014-05-07 11:23 - 00000000 _____ () C:\Users\Ana Sydow\defogger_reenable
2014-05-07 11:23 - 2013-09-28 14:25 - 00000000 ____D () C:\Users\Ana Sydow
2014-05-07 11:22 - 2014-05-07 11:21 - 00050477 _____ () C:\Users\Ana Sydow\Desktop\Defogger.exe
2014-05-07 11:04 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-04-30 10:04 - 2014-04-30 10:04 - 251586632 _____ () C:\Users\Ana Sydow\Documents\regedit Sicherung.reg
2014-04-29 16:14 - 2014-05-05 06:59 - 19275264 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:08 - 2013-06-27 04:13 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-04-29 15:08 - 2013-06-27 04:13 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-04-29 15:08 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-29 14:47 - 2014-05-05 06:59 - 14357504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:43 - 2013-12-23 17:49 - 00000000 ____D () C:\Users\Ana Sydow\Desktop\Alte Firefox-Daten
2014-04-29 14:36 - 2014-05-05 06:59 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:25 - 2014-05-05 06:59 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-23 01:47 - 2013-11-17 14:38 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-23 01:47 - 2013-11-17 14:38 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-19 11:39 - 2014-05-06 15:01 - 00628024 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-04-19 10:45 - 2014-05-06 15:01 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-04-19 10:45 - 2014-05-06 15:01 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-19 08:57 - 2014-05-06 15:01 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-04-19 08:57 - 2014-05-06 15:01 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-14 14:24 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
Some content of TEMP:
====================
C:\Users\Ana Sydow\AppData\Local\Temp\avgnt.exe
C:\Users\Ana Sydow\AppData\Local\Temp\Quarantine.exe
C:\Users\Ana Sydow\AppData\Local\Temp\SPSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-07 11:04
==================== End Of Log ============================ --- --- ---
--- --- ---
[/CODE] |