musiker3107 | 23.05.2014 08:38 | Hallo!
Richtig... MBAM und AdwC fehlten noch :headbang: :stirn:
EST und Security Check werde ich jetzt erledigen. Habe ich das richtig verstanden? Ich muss sämtliche externen FP und USB-Sticks bei EST anschließen?
Websearches hat sich jetzt nicht mehr "gemeldet", aber wenn ich Firefox aktiviere, öffnet sich automatisch die letzte Internetsitzung, obwohl ich als Startseite Google hinterlegt habe.
Eine Zusatzfrage noch: Ist Dir beim Durchsehen der ganzen logfiles noch etwas Seltsames/Unnötiges an meinem Läppi aufgefallen? Der Kasten wird langsam etwas behäbig, aber er hat immerhin schon 5 Jahre auf dem Buckel und ich nutze ihn sehr intensiv. Besonders die Arbeit mit "Video DeLuxe" (Urlaubsfilme, Hochzeitsfilme usw.) fordert ihn :zzwhip:
Vielen Dank & Grüßle,
Musiker Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 21.05.2014
Suchlauf-Zeit: 09:51:51
Logdatei: Malwarebytes - Report 02 ( 21.05.2014).txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.21.03
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: b
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 269899
Verstrichene Zeit: 27 Min, 24 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, 372, Löschen bei Neustart, [43c497bd5a213ff7d97adc7a837e4eb2]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 11
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, In Quarantäne, [43c497bd5a213ff7d97adc7a837e4eb2],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, In Quarantäne, [ab5c01533e3db6801ebf200bbd45ab55],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [ab5c01533e3db6801ebf200bbd45ab55],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [ab5c01533e3db6801ebf200bbd45ab55],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, In Quarantäne, [ab5c01533e3db6801ebf200bbd45ab55],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [a36469ebe398c175f978bd6e9a688f71],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [5cabca8a6417d1650bd97b464fb4f50b],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [ad5a6fe51c5fba7c174f0093d72bec14],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [e22596be512a9d990ada972ab2517f81],
PUP.Optional.Qone8, HKU\S-1-5-21-2895535926-268550826-4121004969-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [dd2a79db3348b3836083d3ee40c37090],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2895535926-268550826-4121004969-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Löschen bei Neustart, [21e69bb9d9a2310509a46e207f83d729],
Registrierungswerte: 1
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\49igy6fe.default\extensions\quick_start@gmail.com, In Quarantäne, [46c1d3815f1c5bdb8a992074e12122de]
Registrierungsdaten: 13
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://istart.webssearches.com/?type=sc&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197, Gut: (firefox.exe), Schlecht: (C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://istart.webssearches.com/?type=sc&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197),Ersetzt,[ab5cc68e7308ff3749f38db942c2df21]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197, Gut: (iexplore.exe), Schlecht: (C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197),Ersetzt,[fb0cc391d7a43ff7d865192d07fda65a]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197&q={searchTerms}),Ersetzt,[56b11a3a106bb5811a1afe489173d729]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197),Ersetzt,[0bfc55fff388b28444ee65e10ff527d9]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197),Ersetzt,[7f884e062655cf677db9a4a205ff956b]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[60a7193bb9c240f63e27c09028dc36ca]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://istart.webssearches.com/?type=sc&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197, Gut: (firefox.exe), Schlecht: (C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://istart.webssearches.com/?type=sc&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197),Ersetzt,[ac5b193bfc7f4fe7bf7d85c142c2659b]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197, Gut: (iexplore.exe), Schlecht: (C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197),Ersetzt,[e522480c4e2d94a21a231a2c9b694eb2]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197&q={searchTerms}),Ersetzt,[24e3074de09b52e4b183024425dffb05]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197),Ersetzt,[d7304311334856e0a78bed59b64e53ad]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197),Ersetzt,[49be1d373d3e4de9f73f163033d145bb]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[18ef8dc7a1dab482b2b3113fbf457a86]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-2895535926-268550826-4121004969-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1400486403&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197),Löschen bei Neustart,[3ccbaba92853ec4a2b08242206febc44]
Ordner: 3
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, Löschen bei Neustart, [f017094b1c5f122468b3f48261a15fa1],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, In Quarantäne, [f017094b1c5f122468b3f48261a15fa1],
PUP.Optional.WebsSearches.A, C:\Users\b\AppData\Roaming\webssearches, In Quarantäne, [45c23b196b1054e201205723956d36ca],
Dateien: 22
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, Löschen bei Neustart, [43c497bd5a213ff7d97adc7a837e4eb2],
PUP.Optional.OutBrowse, C:\Users\b\AppData\Local\Temp\DownloadManager.exe, In Quarantäne, [ab5c01533e3db6801ebf200bbd45ab55],
PUP.Optional.SupTab.A, C:\Users\b\AppData\Roaming\SupTab\SupTab.dll, In Quarantäne, [36d17fd536456cca12390431e020d32d],
PUP.Optional.SkyTech.A, C:\Users\b\AppData\Local\Temp\toolbar4969259.exe, In Quarantäne, [7c8b153f7dfed066fc37ada932cfc838],
PUP.Optional.RegCleanerPro, C:\Users\b\AppData\Local\Temp\toolbar4996507.exe, In Quarantäne, [31d6aea6cfac0d295e86f8120bf68c74],
PUP.Optional.Spigot.A, C:\Users\b\AppData\Local\Temp\AskPIP_FF_.exe, In Quarantäne, [6e9959fb710a80b6ad07c361f908e917],
PUP.Optional.SearchProtect.A, C:\Users\b\AppData\Local\Temp\nse64B0.exe, In Quarantäne, [93744113314a2a0c71e5a980a35e1fe1],
PUP.Optional.SearchProtect.A, C:\Users\b\AppData\Local\Temp\nsj5FBF.exe, In Quarantäne, [3fc87adae398171fcf87fb2efc059070],
PUP.Optional.RegCleanerPro, C:\Users\b\AppData\Local\Temp\RegClean2.exe, In Quarantäne, [887f70e4dba05cda865e9476d130817f],
PUP.Optional.SearchProtect.A, C:\Users\b\AppData\Local\Temp\nsp633A.exe, In Quarantäne, [a85f6aea85f677bf421464c5e12035cb],
PUP.Optional.SearchProtect.A, C:\Users\b\AppData\Local\Temp\nsp808A.exe, In Quarantäne, [44c3d97bcfac8bab1442aa7fe819aa56],
PUP.Optional.SearchProtect.A, C:\Users\b\AppData\Local\Temp\nsp83D6.exe, In Quarantäne, [08ff2e26106b87af4b0b36f37f8235cb],
PUP.Optional.GoForFiles.A, C:\Users\b\AppData\Local\Temp\uninstall-updater275032.exe, In Quarantäne, [cb3ceb69c2b962d429ef57c4d13046ba],
PUP.Optional.GoForFiles.A, C:\Users\b\AppData\Local\Temp\uninstall290632.exe, In Quarantäne, [30d70f45d2a9c5718b8dd04b9071c838],
PUP.Optional.GoForFiles.A, C:\Users\b\AppData\Local\Temp\uninstall322580.exe, In Quarantäne, [6e99c88cd0ab43f324f4eb30e918e51b],
PUP.Optional.Conduit.A, C:\Users\b\AppData\Local\Temp\is-HH6G2.tmp\sp-downloader.exe, In Quarantäne, [986fef6592e996a0cdb5e13bfc05bb45],
PUP.Optional.SkyTech.A, C:\Users\b\AppData\Local\Temp\fullpackage_temp1400486385\alilog.dll, In Quarantäne, [83844d07780306309d78a88a1fe144bc],
PUP.Optional.IePluginService.A, C:\Users\b\AppData\Local\Temp\fullpackage_temp1400486385\tmp\SupTab.exe, In Quarantäne, [6f98c1931b6069cd381b91c59c6517e9],
PUP.Optional.WpManager, C:\Users\b\AppData\Local\Temp\fullpackage_temp1400486385\tmp\wpm_v18.8.0.304.exe, In Quarantäne, [2cdba4b02556c175466e2b359c65a35d],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [1dea57fddba084b256aba1f9986ab64a],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, In Quarantäne, [f017094b1c5f122468b3f48261a15fa1],
PUP.Optional.WebsSearches.A, C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\49igy6fe.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hppp&ts=1400487716&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197");), Ersetzt,[c443d381ea9103338cf57ffda95b9b65]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.210 - Bericht erstellt am 21/05/2014 um 09:58:50
# Aktualisiert 19/05/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : b - B-PC
# Gestartet von : C:\Users\b\Desktop\Trojaner\adwcleaner_3.210.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : IePluginService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\IePluginService
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\b\AppData\Local\lollipop
Ordner Gelöscht : C:\Users\b\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\b\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\b\AppData\Roaming\goforfiles
Ordner Gelöscht : C:\Users\b\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\b\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\49igy6fe.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
Ordner Gelöscht : C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\49igy6fe.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\webssearches.xml
Datei Gelöscht : C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\49igy6fe.default\user.js
Datei Gelöscht : C:\Windows\Tasks\GoforFilesUpdate.job
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox (Safe-Mode).lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\b\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
Verknüpfung Desinfiziert : C:\Users\b\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\b\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\b\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\b\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\b\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskPIP_FF__RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskPIP_FF__RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Lollipop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Lollipop_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SupTab_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SupTab_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_guitar-pro_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_guitar-pro_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKCU\Software\GoforFiles
Schlüssel Gelöscht : HKCU\Software\lollipop
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\Software\GoforFiles
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FLV Player
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16450
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v9.0 (de)
[ Datei : C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\49igy6fe.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "webssearches");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hppp&ts=1400487716&from=exp&uid=WDCXWD3200BEVT-60ZCT1_WD-WX50A892519725197");
*************************
AdwCleaner[R0].txt - [7586 octets] - [21/05/2014 09:55:26]
AdwCleaner[S0].txt - [5755 octets] - [21/05/2014 09:58:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5815 octets] ########## Guten Abend Schrauber,
hier die neuen logfiles.
=> ESET
Leider konnte ich Avira nicht ausschalten. Ich war zwar der Meinung, ich hätte ihn korrekt deaktiviert, aber während ESET lief, hat er sich doch zweimal gemeldet.
Zuerst "Zugriff auf die Datei C:\AdwCleaner....\PluginService.exe.vir mit dem Virus TR/Drop.Softomat.AN wurde blockiert" und später die Meldung "Zugriff auf die Datei C:\Users\...\Temp\toolbar4968122.exe mit dem Virus ADWARE/AgentCV.A.6793 wurde blockiert. Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=95bcfc4155032347a9fa07048a5647e9
# engine=18363
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-05-22 08:29:38
# local_time=2014-05-22 10:29:38 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=771 16777214 16 1 45263369 45263369 0 0
# compatibility_mode=5893 16776574 100 94 49166040 152377228 0 0
# scanned=498
# found=2
# cleaned=0
# scan_time=62
sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir"
sh=34BCDE11A22683EC42F88CF11A55DF978A1CA53B ft=1 fh=902e7624f4009a9d vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\b\AppData\Local\Temp\OCS\ocs_v7d.exe.vir"
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=95bcfc4155032347a9fa07048a5647e9
# engine=18363
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-05-22 02:34:02
# local_time=2014-05-22 04:34:02 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=771 16777214 16 1 45288833 45288833 0 0
# compatibility_mode=5893 16776574 100 94 49191504 152399092 0 0
# scanned=355681
# found=17
# cleaned=0
# scan_time=21658
sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir"
sh=34BCDE11A22683EC42F88CF11A55DF978A1CA53B ft=1 fh=902e7624f4009a9d vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\b\AppData\Local\Temp\OCS\ocs_v7d.exe.vir"
sh=B39D37C05F4EB887826A77D81E7FCF5E80CA98F0 ft=1 fh=3695aadb21ee2e87 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\PPAG\WIN 7 - Installationen\iPhone - FreeVideoToiPhoneConverter.exe"
sh=780B558BAFED2423FB54F8D9B05599018E80AF87 ft=1 fh=845e21fd0df02840 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5KN7S0IC\SPIdentifierImpl[1].exe"
sh=F61C6750D1032B04DFBEA218AE579B30A1DD1F45 ft=1 fh=e0df02dd5fbc1171 vn="Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5KN7S0IC\SPSetup[1].exe"
sh=1EB0E7F1BC33C6D92D4B091D38C47AF5897130BB ft=1 fh=5f2aa65e353e77b1 vn="Variante von Win32/Skintrim.MK Trojaner" ac=I fn="C:\Users\b\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BXS95IZ9\download[1].php"
sh=1744D17BA33A5B8B30641DBBD3B3661D6E0A8FAE ft=1 fh=5ffe66a92c5de1ab vn="Variante von Win32/BrowseFox.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WMMCEMPH\Setup[1].exe"
sh=067D40AEFA9A224C7B18EAE8E06FE0CF611F6D4E ft=1 fh=79164116608e27d7 vn="Win32/OutBrowse.G evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Temp\toolbar5235267.exe"
sh=EF414742749B388D4F6A3FD2BCF089125B23FA2C ft=1 fh=bcbf14a4a15fe222 vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Temp\is1070216317\MyBabylonTB.exe"
sh=BEE96291323D129CF104D0FA8ECBE8AAB5E4BCA5 ft=1 fh=c71c001156299171 vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Temp\NERO14180\Toolbar.exe"
sh=B39D37C05F4EB887826A77D81E7FCF5E80CA98F0 ft=1 fh=3695aadb21ee2e87 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\BACKUP (USB-Sticks)\BACKUP - ****-Stick (22.04.2014)\WIN 7 - Installationen\iPhone - FreeVideoToiPhoneConverter.exe"
sh=33AC2D349B26B8E75F76D9B2528133CBB7979F45 ft=1 fh=092b8237ed127bb7 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\APE_FLAC - SpesoftAudioConverterSetup.exe"
sh=C318C520B070146647C507B109917F4B957608FC ft=1 fh=f64f4ef2667e41f3 vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\Flv_Converter_Setup674_.exe"
sh=59BDAC2F36577DD073E5321F81DCA1D88F736B60 ft=1 fh=8a8ff7b6d3308d85 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\FreeVideoToiPod325Converter.exe"
sh=59BDAC2F36577DD073E5321F81DCA1D88F736B60 ft=1 fh=8a8ff7b6d3308d85 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\iPhone - FreeVideoToiPod325Converter.exe"
sh=E535ECD0508367568242C2308C2BFC192E668D30 ft=1 fh=1683bc139d84c090 vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\Nero Essentials-9.4.12.3d_free.exe"
sh=DA3A28D142C1F19B2FB5A3097271D52446CE6167 ft=1 fh=917b716edfb5e5cf vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\Nero - Version 8.1.1.4\Nero-8.1.1.4.exe" => Security : Code:
Results of screen317's Security Check version 0.99.83
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````
xp-AntiSpy 3.98-2
TuneUp Utilities 2003
Java 7 Update 11
Java version out of Date!
Adobe Flash Player 12.0.0.43 Flash Player out of Date!
Adobe Reader 10.1.2 Adobe Reader out of Date!
Mozilla Firefox 9.0 Firefox out of Date! ````````Process Check: objlist.exe by Laurent````````
Avira Antivir avgnt.exe
Avira Antivir avguard.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST :-)
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014
Ran by b (administrator) on B-PC on 22-05-2014 21:04:00
Running from C:\Users\b\Desktop\Trojaner (webssearches.com, 19.05.2014)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe
() C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(WinZip Computing, Inc.) C:\Program Files (x86)\WinZip\WZQKPICK.EXE
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [134416 2007-04-11] (Logitech Inc.)
HKLM\...\Run: [NvCplDaemon] => C:\Windows\system32\NvCpl.dll [16334368 2009-07-23] (NVIDIA Corporation)
HKLM\...\Run: [Zune Launcher] => C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NBKeyScan] => C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [1836328 2007-09-20] (Nero AG)
HKLM-x32\...\Run: [TrayServer] => C:\Program Files (x86)\MAGIX\Video_deluxe_17_Premium\TrayServer.exe [90112 2008-08-07] (MAGIX AG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-15] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [TkBellExe] => c:\program files (x86)\real\realplayer\Update\realsched.exe [295512 2013-09-05] (RealNetworks, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [OPSE reminder] => "C:\Program Files (x86)\ScanSoft\OmniPageSE2.0\EregGer\Ereg.exe" -r "C:\Program Files (x86)\ScanSoft\OmniPageSE2.0\EregGer\ereg.ini"
HKLM\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\Run: [Update Service] => C:\Program Files (x86)\Common Files\Teknum Systems\update.exe [19456 2011-12-28] (Teknum Systems AS)
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe [202024 2007-10-23] (Nero AG)
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\Run: [Wisdom-soft AutoScreenRecorder 3.1 Pro] => 0
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2013-04-25] ()
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_43_Plugin.exe [840072 2014-01-15] (Adobe Systems Incorporated)
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\MountPoints2: {e588cac3-234b-11e2-b8e0-00269e25f89d} - E:\LaunchU3.exe -a
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office Outlook 2007.lnk
ShortcutTarget: Microsoft Office Outlook 2007.lnk -> C:\Windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\outicon.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files (x86)\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\49igy6fe.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.11.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @phonostar.de/phonostar - C:\Program Files (x86)\dradio-Recorder\npphonostarDetectNP.dll No File
FF Plugin HKCU: @phonostar.de/phonostar-Player - C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll ( )
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-05]
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
==================== Services (Whitelisted) =================
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [801872 2014-05-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-05-15] (Avira Operations GmbH & Co. KG)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [853288 2007-09-20] (Nero AG)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-10-23] (Nero AG)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
==================== Drivers (Whitelisted) ====================
S2 Asapi; C:\Windows\SysWow64\Drivers\Asapi.sys [8768 2000-05-12] (VOB Computersysteme GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-04-29] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-04-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG)
S3 L6UX1; C:\Windows\System32\Drivers\L6UX164.sys [830720 2009-01-29] (Line 6)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-22 21:03 - 2014-05-22 21:03 - 00000980 _____ () C:\Users\b\Desktop\Security Check checkup.txt
2014-05-22 10:23 - 2014-05-22 10:23 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-22 09:52 - 2014-05-22 09:52 - 00854367 _____ () C:\Users\b\Desktop\SecurityCheck.exe
2014-05-22 09:51 - 2014-05-22 09:51 - 02347384 _____ (ESET) C:\Users\b\Desktop\esetsmartinstaller_deu.exe
2014-05-21 20:45 - 2014-05-21 20:45 - 00000000 ____D () C:\********
2014-05-21 19:48 - 2014-05-21 19:48 - 00000000 _____ () C:\Users\b\Sti_Trace.log
2014-05-21 18:01 - 2014-05-21 18:01 - 00012241 _____ () C:\Users\b\Desktop\Zoom - Mouse Over Zoom.zip
2014-05-21 17:54 - 2014-05-21 17:55 - 00071762 _____ () C:\Users\b\Desktop\Zoom In - j2.5_j3.0_v1.2.zip
2014-05-21 10:05 - 2014-05-21 10:05 - 00000000 ____D () C:\Windows\ERUNT
2014-05-21 09:55 - 2014-05-21 09:58 - 00000000 ____D () C:\AdwCleaner
2014-05-21 09:21 - 2014-05-21 09:22 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-21 09:21 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-21 09:21 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-21 09:21 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-19 14:05 - 2014-05-22 21:04 - 00000000 ____D () C:\Users\b\Desktop\Trojaner (webssearches.com, 19.05.2014)
2014-05-19 11:01 - 2014-05-22 21:04 - 00000000 ____D () C:\FRST
2014-05-19 10:25 - 2014-05-19 10:25 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-13 13:48 - 2014-05-13 13:48 - 00290864 _____ () C:\Windows\Minidump\051314-17206-01.dmp
2014-05-05 11:22 - 2014-05-05 11:22 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - c72b5f17d0534e369e06a396cfbc328bc4705dba9acb485db5796e12f0d468e2.job
2014-04-30 11:00 - 2014-04-30 11:00 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - 4af5a92c095c4169aadccfff10027f7d1d5a9ad1f6f74b228508eefeff21f10e.job
2014-04-22 10:27 - 2014-04-22 10:27 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - ef178c02cb934ff2be89baa6065a57346be2a15d187d44619db4c3f78f59263e.job
==================== One Month Modified Files and Folders =======
2014-05-22 21:04 - 2014-05-19 14:05 - 00000000 ____D () C:\Users\b\Desktop\********
2014-05-22 21:04 - 2014-05-19 11:01 - 00000000 ____D () C:\FRST
2014-05-22 21:03 - 2014-05-22 21:03 - 00000980 _____ () C:\Users\b\Desktop\Security Check checkup.txt
2014-05-22 11:58 - 2014-03-17 10:45 - 00000000 ____D () C:\Users\b\Desktop\********
2014-05-22 10:24 - 2011-04-12 09:43 - 40540932 _____ () C:\Windows\system32\perfh007.dat
2014-05-22 10:24 - 2011-04-12 09:43 - 13161384 _____ () C:\Windows\system32\perfc007.dat
2014-05-22 10:24 - 2009-07-14 07:13 - 00004760 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-22 10:23 - 2014-05-22 10:23 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-22 09:52 - 2014-05-22 09:52 - 00854367 _____ () C:\Users\b\Desktop\SecurityCheck.exe
2014-05-22 09:51 - 2014-05-22 09:51 - 02347384 _____ (ESET) C:\Users\b\Desktop\esetsmartinstaller_deu.exe
2014-05-22 08:56 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-22 08:56 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-22 08:47 - 2009-07-14 06:51 - 00146447 _____ () C:\Windows\setupact.log
2014-05-21 20:45 - 2014-05-21 20:45 - 00000000 ____D () C:\wech damit
2014-05-21 20:40 - 2011-12-22 13:41 - 00000000 ____D () C:\Users\b\AppData\Local\VirtualStore
2014-05-21 19:48 - 2014-05-21 19:48 - 00000000 _____ () C:\Users\b\Sti_Trace.log
2014-05-21 19:48 - 2011-12-22 13:41 - 00000000 ____D () C:\Users\b
2014-05-21 19:27 - 2011-12-22 14:50 - 00000000 ____D () C:\PPAG
2014-05-21 19:07 - 2014-04-13 07:23 - 00000000 ____D () C:\Users\b\Desktop\********
2014-05-21 18:01 - 2014-05-21 18:01 - 00012241 _____ () C:\Users\b\Desktop\Zoom - Mouse Over Zoom.zip
2014-05-21 17:55 - 2014-05-21 17:54 - 00071762 _____ () C:\Users\b\Desktop\Zoom In - j2.5_j3.0_v1.2.zip
2014-05-21 12:48 - 2013-09-05 12:14 - 00000290 _____ () C:\Windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2895535926-268550826-4121004969-1000.job
2014-05-21 10:07 - 2011-12-22 14:46 - 00000000 ___RD () C:\Users\b\Desktop\Programme
2014-05-21 10:05 - 2014-05-21 10:05 - 00000000 ____D () C:\Windows\ERUNT
2014-05-21 09:59 - 2011-12-30 10:15 - 00000000 ____D () C:\Windows\uninstall
2014-05-21 09:59 - 2010-11-21 05:47 - 00290654 _____ () C:\Windows\PFRO.log
2014-05-21 09:58 - 2014-05-21 09:55 - 00000000 ____D () C:\AdwCleaner
2014-05-21 09:58 - 2011-12-27 13:27 - 00001061 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-21 09:58 - 2011-12-23 11:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
2014-05-21 09:58 - 2011-12-22 13:42 - 00001158 _____ () C:\Users\b\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-21 09:58 - 2011-12-22 13:42 - 00000975 _____ () C:\Users\b\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-05-21 09:34 - 2011-12-27 12:34 - 00000000 ____D () C:\Users\b\AppData\Roaming\Mp3tag
2014-05-21 09:22 - 2014-05-21 09:21 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-20 17:39 - 2014-04-20 06:56 - 00000000 ____D () C:\Users\b\Desktop\********
2014-05-19 10:25 - 2014-05-19 10:25 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-19 10:13 - 2011-12-22 13:42 - 00000000 ___RD () C:\Users\b\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-19 10:01 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-05-16 10:44 - 2013-01-24 11:10 - 00000000 ____D () C:\Users\b\AppData\Roaming\FileZilla
2014-05-13 13:48 - 2014-05-13 13:48 - 00290864 _____ () C:\Windows\Minidump\051314-17206-01.dmp
2014-05-13 13:48 - 2012-02-07 13:05 - 00000000 ____D () C:\Windows\Minidump
2014-05-05 11:22 - 2014-05-05 11:22 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - c72b5f17d0534e369e06a396cfbc328bc4705dba9acb485db5796e12f0d468e2.job
2014-04-30 11:00 - 2014-04-30 11:00 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - 4af5a92c095c4169aadccfff10027f7d1d5a9ad1f6f74b228508eefeff21f10e.job
2014-04-29 12:03 - 2013-03-27 14:00 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-04-29 12:03 - 2013-03-27 14:00 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-04-26 18:32 - 2011-12-23 10:45 - 00000000 ____D () C:\********
2014-04-22 10:27 - 2014-04-22 10:27 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - ef178c02cb934ff2be89baa6065a57346be2a15d187d44619db4c3f78f59263e.job
Files to move or delete:
====================
C:\Users\b\AppData\Roaming\swk.ini
Some content of TEMP:
====================
C:\Users\b\AppData\Local\Temp\AskSLib.dll
C:\Users\b\AppData\Local\Temp\atl.exe
C:\Users\b\AppData\Local\Temp\avgnt.exe
C:\Users\b\AppData\Local\Temp\BackupSetup.exe
C:\Users\b\AppData\Local\Temp\firefoxjre_exe-1.exe
C:\Users\b\AppData\Local\Temp\firefoxjre_exe.exe
C:\Users\b\AppData\Local\Temp\htmlayout.dll
C:\Users\b\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Users\b\AppData\Local\Temp\L6GPInst.dll
C:\Users\b\AppData\Local\Temp\MSN6A65.exe
C:\Users\b\AppData\Local\Temp\MSND78C.exe
C:\Users\b\AppData\Local\Temp\MSNDEAE.exe
C:\Users\b\AppData\Local\Temp\Nv3DVStreaming.dll
C:\Users\b\AppData\Local\Temp\nvStInst.exe
C:\Users\b\AppData\Local\Temp\ose00000.exe
C:\Users\b\AppData\Local\Temp\Quarantine.exe
C:\Users\b\AppData\Local\Temp\SBLCopyF.EXE
C:\Users\b\AppData\Local\Temp\stubhelper.dll
C:\Users\b\AppData\Local\Temp\toolbar4968122.exe
C:\Users\b\AppData\Local\Temp\toolbar4970210.exe
C:\Users\b\AppData\Local\Temp\toolbar4970371.exe
C:\Users\b\AppData\Local\Temp\toolbar5235267.exe
C:\Users\b\AppData\Local\Temp\UNINST.EXE
C:\Users\b\AppData\Local\Temp\uninstall290570.exe
C:\Users\b\AppData\Local\Temp\uninstall328629.exe
C:\Users\b\AppData\Local\Temp\unwise.exe
C:\Users\b\AppData\Local\Temp\Update1.EXE
C:\Users\b\AppData\Local\Temp\vcredist_x64.exe
C:\Users\b\AppData\Local\Temp\wmaudio.exe
C:\Users\b\AppData\Local\Temp\wmf9.exe
C:\Users\b\AppData\Local\Temp\wmpcdcs8.exe
C:\Users\b\AppData\Local\Temp\_isAD10.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2012-10-17 12:28
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Schöne Grüße,
Musiker
Hallo,
ich bin mir nicht ganz sicher, ob das mit meiner Antwort von gestern abend geklappt hat, daher hier noch einmal die neuen logfiles.
=> ESET
Leider konnte ich Avira nicht ausschalten. Ich war zwar der Meinung, ich hätte ihn korrekt deaktiviert, aber während ESET lief, hat er sich doch zweimal gemeldet.
Zuerst "Zugriff auf die Datei C:\AdwCleaner....\PluginService.exe.vir mit dem Virus TR/Drop.Softomat.AN wurde blockiert" und später die Meldung "Zugriff auf die Datei C:\Users\...\Temp\toolbar4968122.exe mit dem Virus ADWARE/AgentCV.A.6793 wurde blockiert. Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=95bcfc4155032347a9fa07048a5647e9
# engine=18363
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-05-22 08:29:38
# local_time=2014-05-22 10:29:38 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=771 16777214 16 1 45263369 45263369 0 0
# compatibility_mode=5893 16776574 100 94 49166040 152377228 0 0
# scanned=498
# found=2
# cleaned=0
# scan_time=62
sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir"
sh=34BCDE11A22683EC42F88CF11A55DF978A1CA53B ft=1 fh=902e7624f4009a9d vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\b\AppData\Local\Temp\OCS\ocs_v7d.exe.vir"
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=95bcfc4155032347a9fa07048a5647e9
# engine=18363
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-05-22 02:34:02
# local_time=2014-05-22 04:34:02 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=771 16777214 16 1 45288833 45288833 0 0
# compatibility_mode=5893 16776574 100 94 49191504 152399092 0 0
# scanned=355681
# found=17
# cleaned=0
# scan_time=21658
sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir"
sh=34BCDE11A22683EC42F88CF11A55DF978A1CA53B ft=1 fh=902e7624f4009a9d vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\b\AppData\Local\Temp\OCS\ocs_v7d.exe.vir"
sh=B39D37C05F4EB887826A77D81E7FCF5E80CA98F0 ft=1 fh=3695aadb21ee2e87 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\PPAG\WIN 7 - Installationen\iPhone - FreeVideoToiPhoneConverter.exe"
sh=780B558BAFED2423FB54F8D9B05599018E80AF87 ft=1 fh=845e21fd0df02840 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5KN7S0IC\SPIdentifierImpl[1].exe"
sh=F61C6750D1032B04DFBEA218AE579B30A1DD1F45 ft=1 fh=e0df02dd5fbc1171 vn="Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5KN7S0IC\SPSetup[1].exe"
sh=1EB0E7F1BC33C6D92D4B091D38C47AF5897130BB ft=1 fh=5f2aa65e353e77b1 vn="Variante von Win32/Skintrim.MK Trojaner" ac=I fn="C:\Users\b\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BXS95IZ9\download[1].php"
sh=1744D17BA33A5B8B30641DBBD3B3661D6E0A8FAE ft=1 fh=5ffe66a92c5de1ab vn="Variante von Win32/BrowseFox.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WMMCEMPH\Setup[1].exe"
sh=067D40AEFA9A224C7B18EAE8E06FE0CF611F6D4E ft=1 fh=79164116608e27d7 vn="Win32/OutBrowse.G evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Temp\toolbar5235267.exe"
sh=EF414742749B388D4F6A3FD2BCF089125B23FA2C ft=1 fh=bcbf14a4a15fe222 vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Temp\is1070216317\MyBabylonTB.exe"
sh=BEE96291323D129CF104D0FA8ECBE8AAB5E4BCA5 ft=1 fh=c71c001156299171 vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="C:\Users\b\AppData\Local\Temp\NERO14180\Toolbar.exe"
sh=B39D37C05F4EB887826A77D81E7FCF5E80CA98F0 ft=1 fh=3695aadb21ee2e87 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\BACKUP (USB-Sticks)\BACKUP - ****-Stick (22.04.2014)\WIN 7 - Installationen\iPhone - FreeVideoToiPhoneConverter.exe"
sh=33AC2D349B26B8E75F76D9B2528133CBB7979F45 ft=1 fh=092b8237ed127bb7 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\APE_FLAC - SpesoftAudioConverterSetup.exe"
sh=C318C520B070146647C507B109917F4B957608FC ft=1 fh=f64f4ef2667e41f3 vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\Flv_Converter_Setup674_.exe"
sh=59BDAC2F36577DD073E5321F81DCA1D88F736B60 ft=1 fh=8a8ff7b6d3308d85 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\FreeVideoToiPod325Converter.exe"
sh=59BDAC2F36577DD073E5321F81DCA1D88F736B60 ft=1 fh=8a8ff7b6d3308d85 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\iPhone - FreeVideoToiPod325Converter.exe"
sh=E535ECD0508367568242C2308C2BFC192E668D30 ft=1 fh=1683bc139d84c090 vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\Nero Essentials-9.4.12.3d_free.exe"
sh=DA3A28D142C1F19B2FB5A3097271D52446CE6167 ft=1 fh=917b716edfb5e5cf vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="E:\BÜRO\Setup-Dateien\Audio + Video\Nero - Version 8.1.1.4\Nero-8.1.1.4.exe" Code:
Results of screen317's Security Check version 0.99.83
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````
xp-AntiSpy 3.98-2
TuneUp Utilities 2003
Java 7 Update 11
Java version out of Date!
Adobe Flash Player 12.0.0.43 Flash Player out of Date!
Adobe Reader 10.1.2 Adobe Reader out of Date!
Mozilla Firefox 9.0 Firefox out of Date! ````````Process Check: objlist.exe by Laurent````````
Avira Antivir avgnt.exe
Avira Antivir avguard.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014
Ran by b (administrator) on B-PC on 22-05-2014 21:04:00
Running from C:\Users\b\Desktop\Trojaner (webssearches.com, 19.05.2014)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe
() C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(WinZip Computing, Inc.) C:\Program Files (x86)\WinZip\WZQKPICK.EXE
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [134416 2007-04-11] (Logitech Inc.)
HKLM\...\Run: [NvCplDaemon] => C:\Windows\system32\NvCpl.dll [16334368 2009-07-23] (NVIDIA Corporation)
HKLM\...\Run: [Zune Launcher] => C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NBKeyScan] => C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [1836328 2007-09-20] (Nero AG)
HKLM-x32\...\Run: [TrayServer] => C:\Program Files (x86)\MAGIX\Video_deluxe_17_Premium\TrayServer.exe [90112 2008-08-07] (MAGIX AG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-15] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [TkBellExe] => c:\program files (x86)\real\realplayer\Update\realsched.exe [295512 2013-09-05] (RealNetworks, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [OPSE reminder] => "C:\Program Files (x86)\ScanSoft\OmniPageSE2.0\EregGer\Ereg.exe" -r "C:\Program Files (x86)\ScanSoft\OmniPageSE2.0\EregGer\ereg.ini"
HKLM\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\Run: [Update Service] => C:\Program Files (x86)\Common Files\Teknum Systems\update.exe [19456 2011-12-28] (Teknum Systems AS)
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe [202024 2007-10-23] (Nero AG)
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\Run: [Wisdom-soft AutoScreenRecorder 3.1 Pro] => 0
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2013-04-25] ()
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_43_Plugin.exe [840072 2014-01-15] (Adobe Systems Incorporated)
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-2895535926-268550826-4121004969-1000\...\MountPoints2: {e588cac3-234b-11e2-b8e0-00269e25f89d} - E:\LaunchU3.exe -a
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office Outlook 2007.lnk
ShortcutTarget: Microsoft Office Outlook 2007.lnk -> C:\Windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\outicon.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files (x86)\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\49igy6fe.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.11.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @phonostar.de/phonostar - C:\Program Files (x86)\dradio-Recorder\npphonostarDetectNP.dll No File
FF Plugin HKCU: @phonostar.de/phonostar-Player - C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll ( )
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-05]
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
==================== Services (Whitelisted) =================
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [801872 2014-05-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-05-15] (Avira Operations GmbH & Co. KG)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [853288 2007-09-20] (Nero AG)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-10-23] (Nero AG)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
==================== Drivers (Whitelisted) ====================
S2 Asapi; C:\Windows\SysWow64\Drivers\Asapi.sys [8768 2000-05-12] (VOB Computersysteme GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-04-29] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-04-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG)
S3 L6UX1; C:\Windows\System32\Drivers\L6UX164.sys [830720 2009-01-29] (Line 6)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-22 21:03 - 2014-05-22 21:03 - 00000980 _____ () C:\Users\b\Desktop\Security Check checkup.txt
2014-05-22 10:23 - 2014-05-22 10:23 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-22 09:52 - 2014-05-22 09:52 - 00854367 _____ () C:\Users\b\Desktop\SecurityCheck.exe
2014-05-22 09:51 - 2014-05-22 09:51 - 02347384 _____ (ESET) C:\Users\b\Desktop\esetsmartinstaller_deu.exe
2014-05-21 20:45 - 2014-05-21 20:45 - 00000000 ____D () C:\********
2014-05-21 19:48 - 2014-05-21 19:48 - 00000000 _____ () C:\Users\b\Sti_Trace.log
2014-05-21 18:01 - 2014-05-21 18:01 - 00012241 _____ () C:\Users\b\Desktop\Zoom - Mouse Over Zoom.zip
2014-05-21 17:54 - 2014-05-21 17:55 - 00071762 _____ () C:\Users\b\Desktop\Zoom In - j2.5_j3.0_v1.2.zip
2014-05-21 10:05 - 2014-05-21 10:05 - 00000000 ____D () C:\Windows\ERUNT
2014-05-21 09:55 - 2014-05-21 09:58 - 00000000 ____D () C:\AdwCleaner
2014-05-21 09:21 - 2014-05-21 09:22 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-21 09:21 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-21 09:21 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-21 09:21 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-19 14:05 - 2014-05-22 21:04 - 00000000 ____D () C:\Users\b\Desktop\Trojaner (webssearches.com, 19.05.2014)
2014-05-19 11:01 - 2014-05-22 21:04 - 00000000 ____D () C:\FRST
2014-05-19 10:25 - 2014-05-19 10:25 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-13 13:48 - 2014-05-13 13:48 - 00290864 _____ () C:\Windows\Minidump\051314-17206-01.dmp
2014-05-05 11:22 - 2014-05-05 11:22 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - c72b5f17d0534e369e06a396cfbc328bc4705dba9acb485db5796e12f0d468e2.job
2014-04-30 11:00 - 2014-04-30 11:00 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - 4af5a92c095c4169aadccfff10027f7d1d5a9ad1f6f74b228508eefeff21f10e.job
2014-04-22 10:27 - 2014-04-22 10:27 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - ef178c02cb934ff2be89baa6065a57346be2a15d187d44619db4c3f78f59263e.job
==================== One Month Modified Files and Folders =======
2014-05-22 21:04 - 2014-05-19 14:05 - 00000000 ____D () C:\Users\b\Desktop\********
2014-05-22 21:04 - 2014-05-19 11:01 - 00000000 ____D () C:\FRST
2014-05-22 21:03 - 2014-05-22 21:03 - 00000980 _____ () C:\Users\b\Desktop\Security Check checkup.txt
2014-05-22 11:58 - 2014-03-17 10:45 - 00000000 ____D () C:\Users\b\Desktop\********
2014-05-22 10:24 - 2011-04-12 09:43 - 40540932 _____ () C:\Windows\system32\perfh007.dat
2014-05-22 10:24 - 2011-04-12 09:43 - 13161384 _____ () C:\Windows\system32\perfc007.dat
2014-05-22 10:24 - 2009-07-14 07:13 - 00004760 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-22 10:23 - 2014-05-22 10:23 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-22 09:52 - 2014-05-22 09:52 - 00854367 _____ () C:\Users\b\Desktop\SecurityCheck.exe
2014-05-22 09:51 - 2014-05-22 09:51 - 02347384 _____ (ESET) C:\Users\b\Desktop\esetsmartinstaller_deu.exe
2014-05-22 08:56 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-22 08:56 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-22 08:47 - 2009-07-14 06:51 - 00146447 _____ () C:\Windows\setupact.log
2014-05-21 20:45 - 2014-05-21 20:45 - 00000000 ____D () C:\wech damit
2014-05-21 20:40 - 2011-12-22 13:41 - 00000000 ____D () C:\Users\b\AppData\Local\VirtualStore
2014-05-21 19:48 - 2014-05-21 19:48 - 00000000 _____ () C:\Users\b\Sti_Trace.log
2014-05-21 19:48 - 2011-12-22 13:41 - 00000000 ____D () C:\Users\b
2014-05-21 19:27 - 2011-12-22 14:50 - 00000000 ____D () C:\PPAG
2014-05-21 19:07 - 2014-04-13 07:23 - 00000000 ____D () C:\Users\b\Desktop\********
2014-05-21 18:01 - 2014-05-21 18:01 - 00012241 _____ () C:\Users\b\Desktop\Zoom - Mouse Over Zoom.zip
2014-05-21 17:55 - 2014-05-21 17:54 - 00071762 _____ () C:\Users\b\Desktop\Zoom In - j2.5_j3.0_v1.2.zip
2014-05-21 12:48 - 2013-09-05 12:14 - 00000290 _____ () C:\Windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2895535926-268550826-4121004969-1000.job
2014-05-21 10:07 - 2011-12-22 14:46 - 00000000 ___RD () C:\Users\b\Desktop\Programme
2014-05-21 10:05 - 2014-05-21 10:05 - 00000000 ____D () C:\Windows\ERUNT
2014-05-21 09:59 - 2011-12-30 10:15 - 00000000 ____D () C:\Windows\uninstall
2014-05-21 09:59 - 2010-11-21 05:47 - 00290654 _____ () C:\Windows\PFRO.log
2014-05-21 09:58 - 2014-05-21 09:55 - 00000000 ____D () C:\AdwCleaner
2014-05-21 09:58 - 2011-12-27 13:27 - 00001061 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-21 09:58 - 2011-12-23 11:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
2014-05-21 09:58 - 2011-12-22 13:42 - 00001158 _____ () C:\Users\b\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-21 09:58 - 2011-12-22 13:42 - 00000975 _____ () C:\Users\b\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-05-21 09:34 - 2011-12-27 12:34 - 00000000 ____D () C:\Users\b\AppData\Roaming\Mp3tag
2014-05-21 09:22 - 2014-05-21 09:21 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-21 09:21 - 2014-05-21 09:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-20 17:39 - 2014-04-20 06:56 - 00000000 ____D () C:\Users\b\Desktop\********
2014-05-19 10:25 - 2014-05-19 10:25 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-19 10:13 - 2011-12-22 13:42 - 00000000 ___RD () C:\Users\b\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-19 10:01 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-05-16 10:44 - 2013-01-24 11:10 - 00000000 ____D () C:\Users\b\AppData\Roaming\FileZilla
2014-05-13 13:48 - 2014-05-13 13:48 - 00290864 _____ () C:\Windows\Minidump\051314-17206-01.dmp
2014-05-13 13:48 - 2012-02-07 13:05 - 00000000 ____D () C:\Windows\Minidump
2014-05-05 11:22 - 2014-05-05 11:22 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - c72b5f17d0534e369e06a396cfbc328bc4705dba9acb485db5796e12f0d468e2.job
2014-04-30 11:00 - 2014-04-30 11:00 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - 4af5a92c095c4169aadccfff10027f7d1d5a9ad1f6f74b228508eefeff21f10e.job
2014-04-29 12:03 - 2013-03-27 14:00 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-04-29 12:03 - 2013-03-27 14:00 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-04-26 18:32 - 2011-12-23 10:45 - 00000000 ____D () C:\********
2014-04-22 10:27 - 2014-04-22 10:27 - 00000448 _____ () C:\Windows\Tasks\HP AR Program Upload - ef178c02cb934ff2be89baa6065a57346be2a15d187d44619db4c3f78f59263e.job
Files to move or delete:
====================
C:\Users\b\AppData\Roaming\swk.ini
Some content of TEMP:
====================
C:\Users\b\AppData\Local\Temp\AskSLib.dll
C:\Users\b\AppData\Local\Temp\atl.exe
C:\Users\b\AppData\Local\Temp\avgnt.exe
C:\Users\b\AppData\Local\Temp\BackupSetup.exe
C:\Users\b\AppData\Local\Temp\firefoxjre_exe-1.exe
C:\Users\b\AppData\Local\Temp\firefoxjre_exe.exe
C:\Users\b\AppData\Local\Temp\htmlayout.dll
C:\Users\b\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Users\b\AppData\Local\Temp\L6GPInst.dll
C:\Users\b\AppData\Local\Temp\MSN6A65.exe
C:\Users\b\AppData\Local\Temp\MSND78C.exe
C:\Users\b\AppData\Local\Temp\MSNDEAE.exe
C:\Users\b\AppData\Local\Temp\Nv3DVStreaming.dll
C:\Users\b\AppData\Local\Temp\nvStInst.exe
C:\Users\b\AppData\Local\Temp\ose00000.exe
C:\Users\b\AppData\Local\Temp\Quarantine.exe
C:\Users\b\AppData\Local\Temp\SBLCopyF.EXE
C:\Users\b\AppData\Local\Temp\stubhelper.dll
C:\Users\b\AppData\Local\Temp\toolbar4968122.exe
C:\Users\b\AppData\Local\Temp\toolbar4970210.exe
C:\Users\b\AppData\Local\Temp\toolbar4970371.exe
C:\Users\b\AppData\Local\Temp\toolbar5235267.exe
C:\Users\b\AppData\Local\Temp\UNINST.EXE
C:\Users\b\AppData\Local\Temp\uninstall290570.exe
C:\Users\b\AppData\Local\Temp\uninstall328629.exe
C:\Users\b\AppData\Local\Temp\unwise.exe
C:\Users\b\AppData\Local\Temp\Update1.EXE
C:\Users\b\AppData\Local\Temp\vcredist_x64.exe
C:\Users\b\AppData\Local\Temp\wmaudio.exe
C:\Users\b\AppData\Local\Temp\wmf9.exe
C:\Users\b\AppData\Local\Temp\wmpcdcs8.exe
C:\Users\b\AppData\Local\Temp\_isAD10.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2012-10-17 12:28
==================== End Of Log ============================ --- --- ---
--- --- ---
Ich wünsche Dir einen guten Start ins Wochenende.
Schöne Grüße,
Musiker |