Hallo Schrauber,
erneut vielen Dank für deine Hilfe!!
Einen komischen Fehler gabs und zwar ein CPU-Übertemperaturfehler beim Restart des PC's.
Ging dann aber mit Neustart.
Hier die Logs:
Mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 16.07.2014
Suchlauf-Zeit: 22:25:46
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.16.08
Rootkit Datenbank: v2014.07.14.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows Vista
CPU: x86
Dateisystem: NTFS
Benutzer: Cas
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 272262
Verstrichene Zeit: 8 Min, 37 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 3
PUP.Optional.Babylon.A, HKU\S-1-5-21-1399156017-4130152259-970843329-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [d563f9a7de9de74f1bf9e173c53d38c8],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-1399156017-4130152259-970843329-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, , [8aae217fb5c6cc6af29523d8e61de917],
PUP.Optional.BProtector.A, HKU\S-1-5-21-1399156017-4130152259-970843329-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, , [53e5b2ee45368fa74c90e31be51eea16],
Registrierungswerte: 2
PUP.BProtector, HKU\S-1-5-21-1399156017-4130152259-970843329-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, hxxp://search.babylon.com/?affID=109727&tt=4612_8&babsrc=HP_ss&mntrId=e49a2a8e000000000000002215a12c88, , [86b2e7b9bebd0531e0a97a81f80b8e72]
PUP.BProtector, HKU\S-1-5-21-1399156017-4130152259-970843329-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [b484138d3b4084b27d0dee0d966df20e]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 3
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\chrome@loadtubes.com, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\html, , [d2669b05ea913600c0f6f5d94cb79868],
Dateien: 55
PUP.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\ytdl.exe, , [4aee653b1764f73f714ecbe13ec23bc5],
PUP.LoadTubes, C:\Program Files\Mozilla Firefox\plugins\npmieze.dll, , [86b2b3ed116a2f07b609e1cb5fa1fa06],
PUP.Optional.OpenCandy, C:\Users\Cas\Downloads\DTLite4454-0314.exe, , [86b2e6ba5229c76fbfc39a2ec63eca36],
PUP.Optional.OpenCandy, C:\Users\Cas\Downloads\winamp563_full_emusic-7plus_all.exe, , [f93fe2bed4a72a0c9fe32e9a8e76f709],
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\babylon.xml, , [44f4d7c96912a78fedd27f5b9f630000],
PUP.Optional.BProtector.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\bprotector_extensions.sqlite, , [f93f3e62f6854ee8efdc5585857de719],
PUP.Optional.BProtector.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\bprotector_prefs.js, , [56e2f7a9b7c490a6ffcda33761a1c53b],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\keyHash.txt, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\config.txt, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\domHash.txt, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\evHash.txt, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\license.txt, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\updateHash.txt, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\chrome@loadtubes.com\background.html, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\chrome@loadtubes.com\background.js, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\chrome@loadtubes.com\download.js, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\chrome@loadtubes.com\fire.js, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\chrome@loadtubes.com\manifest.json, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\html\dimensions.ini, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\html\install.html, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\html\uninstall.html, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.LoadTubes, C:\Users\Cas\AppData\Roaming\loadtbs\html\uninstallComplete.html, , [d2669b05ea913600c0f6f5d94cb79868],
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.admin", false);), ,[83b5712f8dee4cead8521cb705ffd62a]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.aflt", "babsst");), ,[290fc2defd7e25112307686be32103fd]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");), ,[f048c1df88f37cbadd4d656ee024b14f]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.dfltLng", "en");), ,[75c3950bf685fd39da50ce059c68e917]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.excTlbr", false);), ,[4aee1a8663182e081317c31072920bf5]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.id", "e49a2a8e000000000000002215a12c88");), ,[d068970996e5aa8ce149a42f1fe5dd23]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.instlDay", "15661");), ,[74c4eab698e32b0bd753efe4c63eed13]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.instlRef", "sst");), ,[bf79dac61b605bdb19119f346a9a01ff]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");), ,[2414bae69be050e666c408cbd52fc33d]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.prtnrId", "babylon");), ,[65d3029ebcbf89ad2802e6ed7f8526da]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.tlbrId", "base");), ,[b583c2deaad157df9397379cdf256c94]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=e49a2a8e000000000000002215a12c88&q=");), ,[d8601f8198e389ad55d5d5fe48bc43bd]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsn", "1.8.3.8");), ,[5eda9f010279b1859397ba19ce36966a]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsni", "1.8.3.8");), ,[102889172c4ffb3b8aa08d4628dcb848]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), ,[44f45e426a119b9bca601fb4be46c040]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.3.811:08:14");), ,[94a4227ebac13cfa5cce399aca3aa45c]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://search.babylon.com/?affID=109727&tt=4612_8&babsrc=HP_ss&mntrId=e49a2a8e000000000000002215a12c88");), ,[1820168ab8c3c5717bc0ce0510f4e11f]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=e49a2a8e000000000000002215a12c88&q=");), ,[0b2ddec2df9c68ceb0fc59791fe58080]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.id", "e49a2a8e000000000000002215a12c88");), ,[58e07c24770489adaefef4de867e28d8]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");), ,[4aeeeab61d5e80b6baf2f5ddf90be020]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.instlDay", "15661");), ,[073199072754dc5ab6f6587a2cd8ae52]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsn", "1.8.3.8");), ,[f93f059b4e2ded497933ae2408fc669a]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsni", "1.8.3.8");), ,[8badc1df4239ee485c50d2008282fe02]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.3.811:08:14");), ,[da5ecdd3d3a8a3931d8f50827c88728e]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.prtnrId", "babylon");), ,[0c2cfda3166577bfb3f9d9f951b3718f]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");), ,[1226fba5bbc0c96dddcf11c1976db848]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.aflt", "babsst");), ,[3800faa6d1aab08619939b37b54f639d]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), ,[48f0f8a81c5f57dfbaf202d00afa06fa]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.tlbrId", "base");), ,[c771c1df4e2d73c300ac646ef113f907]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.instlRef", "sst");), ,[1b1d3d63c4b7b18586262ca6a262748c]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.dfltLng", "en");), ,[80b8fea22457ba7cbeee4e84e51fc937]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.excTlbr", false);), ,[67d12d730b7062d4109cc80a55af5da3]
PUP.Optional.Babylon.A, C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.admin", false);), ,[f048eab6c1babc7a9715a82aaa5ac63a]
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner
AdwCleaner Logfile: Code:
# AdwCleaner v3.215 - Bericht erstellt am 16/07/2014 um 22:38:40
# Aktualisiert 09/07/2014 von Xplode
# Betriebssystem : Windows Vista (TM) Ultimate (32 bits)
# Benutzername : Cas - CAS-PC
# Gestartet von : C:\Users\Cas\Desktop\adwcleaner_3.215.exe
# Option : Suchen
***** [ Dienste ] *****
Dienst Gefunden : SearchAnonymizer
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
Datei Gefunden : C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\foxydeal.sqlite
Datei Gefunden : C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\invalidprefs.js
Datei Gefunden : C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\11-suche.xml
Datei Gefunden : C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\user.js
Ordner Gefunden : C:\ProgramData\Babylon
Ordner Gefunden : C:\Users\Cas\AppData\Roaming\Babylon
Ordner Gefunden : C:\Users\Cas\AppData\Roaming\DesktopIconForAmazon
Ordner Gefunden : C:\Users\Cas\AppData\Roaming\loadtbs
Ordner Gefunden : C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\firejump@firejump.net
Ordner Gefunden : C:\Users\Cas\AppData\Roaming\OCS
Ordner Gefunden : C:\Users\Cas\AppData\Roaming\pdfforge
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\e2d788b66de414
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\loadtbs-3.0
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchAnonymizer
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKCU\Software\YahooPartnerToolbar
Schlüssel Gefunden : HKLM\Software\Babylon
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gefunden : HKLM\SOFTWARE\e2d788b66de414
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAnonymizer
Wert Gefunden : HKCU\Software\Mozilla\Firefox\Extensions [firejump@firejump.net]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Ocs_SM]
***** [ Browser ] *****
-\\ Internet Explorer v7.0.6000.16982
Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.babylon.com/?affID=109727&tt=4612_8&babsrc=HP_ss&mntrId=e49a2a8e000000000000002215a12c88
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\prefs.js ]
Zeile gefunden : user_pref("extensions.ntk.HISTORY", "[{\"title\":\"Babylon Search\",\"icon\":{\"spec\":\"moz-anno:favicon:hxxp://search.babylon.com/favicon.ico\"},\"uri\":\"hxxp://search.babylon.com/?affID=109727&tt=[...]
Zeile gefunden : user_pref("extensions.ntk.blacklist", "hxxp://gmail.com;hxxp://search.babylon.com/?affID=109727&tt=4612_8&babsrc=HP_ss&mntrId=e49a2a8e000000000000002215a12c88");
Zeile gefunden : user_pref("extensions.ntk.feedStore", "{\"URLtoFeedCount\":15,\"FeedStoriesCount\":4,\"data\":[{\"uri\":\"hxxp://search.babylon.com/%3FaffID=109727%26tt=4612_8%26babsrc=HP_ss%26mntrId=e49a2a8e00000000[...]
Zeile gefunden : user_pref("extensions.ntk.thumbsUrls", "hxxp://search.babylon.com/?affID=109727&tt=4612_8&babsrc=HP_ss&mntrId=e49a2a8e000000000000002215a12c88;hxxp://www.spiegel.de/;hxxps://web.de/;hxxps://www.facebo[...]
*************************
AdwCleaner[R0].txt - [5008 octets] - [16/07/2014 22:38:40]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [5068 octets] ########## --- --- ---
[/CODE]
JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows Vista (TM) Ultimate x86
Ran by Cas on 16.07.2014 at 22:57:38,39
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1399156017-4130152259-970843329-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchanonymizer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{d85ffe92-bf14-4e9b-bccd-e5c16069e65f}_is1
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\Users\Cas\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\Cas\AppData\Roaming\pdfforge"
~~~ FireFox
Successfully deleted: [File] C:\Users\Cas\AppData\Roaming\mozilla\firefox\profiles\8ka7i0u3.default\user.js
Successfully deleted: [File] C:\Users\Cas\AppData\Roaming\mozilla\firefox\profiles\8ka7i0u3.default\invalidprefs.js
Successfully deleted: [Folder] C:\Users\Cas\AppData\Roaming\mozilla\firefox\profiles\8ka7i0u3.default\extensions\staged
Successfully deleted: [Folder] C:\Users\Cas\AppData\Roaming\mozilla\firefox\profiles\8ka7i0u3.default\extensions\toolbar@web.de
Successfully deleted the following from C:\Users\Cas\AppData\Roaming\mozilla\firefox\profiles\8ka7i0u3.default\prefs.js
user_pref("browser.startup.homepage", "hxxp://search.babylon.com/?affID=109727&tt=4612_8&babsrc=HP_ss&mntrId=e49a2a8e000000000000002215a12c88");
user_pref("extensions.BabylonToolbar.admin", false);
user_pref("extensions.BabylonToolbar.aflt", "babsst");
user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
user_pref("extensions.BabylonToolbar.dfltLng", "en");
user_pref("extensions.BabylonToolbar.excTlbr", false);
user_pref("extensions.BabylonToolbar.id", "e49a2a8e000000000000002215a12c88");
user_pref("extensions.BabylonToolbar.instlDay", "15661");
user_pref("extensions.BabylonToolbar.instlRef", "sst");
user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar.tlbrId", "base");
user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=e49a2a8e000000000000002215a12c88&q=");
user_pref("extensions.BabylonToolbar.vrsn", "1.8.3.8");
user_pref("extensions.BabylonToolbar.vrsni", "1.8.3.8");
user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.3.811:08:14");
user_pref("extensions.ntk.HISTORY", "[{\"title\":\"Babylon Search\",\"icon\":{\"spec\":\"moz-anno:favicon:hxxp://search.babylon.com/favicon.ico\"},\"uri\":\"hxxp://search.baby
user_pref("extensions.ntk.blacklist", "hxxp://gmail.com;hxxp://search.babylon.com/?affID=109727&tt=4612_8&babsrc=HP_ss&mntrId=e49a2a8e000000000000002215a12c88");
user_pref("extensions.ntk.feedStore", "{\"URLtoFeedCount\":15,\"FeedStoriesCount\":4,\"data\":[{\"uri\":\"hxxp://search.babylon.com/%3FaffID=109727%26tt=4612_8%26babsrc=HP_ss%
user_pref("extensions.ntk.thumbsUrls", "hxxp://search.babylon.com/?affID=109727&tt=4612_8&babsrc=HP_ss&mntrId=e49a2a8e000000000000002215a12c88;hxxp://www.spiegel.de/;hxxps://w
Emptied folder: C:\Users\Cas\AppData\Roaming\mozilla\firefox\profiles\8ka7i0u3.default\minidumps [160 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.07.2014 at 23:04:32,79
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01
Ran by Cas (administrator) on CAS-PC on 16-07-2014 23:05:19
Running from C:\Users\Cas\Desktop
Platform: Microsoft® Windows Vista™ Ultimate (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
() C:\Windows\System32\PSIService.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
() C:\Users\Cas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\tv_w32.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Spotify Ltd) C:\Users\Cas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Spotify Ltd) C:\Users\Cas\AppData\Roaming\Spotify\spotify.exe
(Dropbox, Inc.) C:\Users\Cas\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
() C:\Users\Cas\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Cas\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Cas\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Cas\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\ipmgui.exe
() C:\Users\Cas\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-12] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2012-06-20] (Nullsoft, Inc.)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1603152 2007-04-03] (CANON INC.)
HKLM\...\Run: [TrayServer] => C:\Program Files\MAGIX\Video_deluxe_MX_Plus_Sonderedition\TrayServer_de.exe [90112 2008-08-07] (MAGIX AG)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM\...\Run: [Ocs_SM] => C:\Users\Cas\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [106496 2012-11-17] (OCS)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\Update\realsched.exe [295512 2013-03-21] (RealNetworks, Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-29] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [703888 2013-06-19] (Cisco Systems, Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [189520 2014-07-07] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\...\Run: [MRT] => C:\Windows\system32\MRT.exe [93585272 2014-06-26] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-07-16] (AVAST Software)
HKU\S-1-5-21-1399156017-4130152259-970843329-1000\...\Run: [Steam] => D:\Programme\Steam\steam.exe [1753280 2014-07-12] (Valve Corporation)
HKU\S-1-5-21-1399156017-4130152259-970843329-1000\...\Run: [Spotify Web Helper] => C:\Users\Cas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1178168 2014-07-16] (Spotify Ltd)
HKU\S-1-5-21-1399156017-4130152259-970843329-1000\...\Run: [Spotify] => C:\Users\Cas\AppData\Roaming\Spotify\spotify.exe [6162488 2014-07-16] (Spotify Ltd)
HKU\S-1-5-21-1399156017-4130152259-970843329-1000\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
Startup: C:\Users\Cas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Cas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - DefaultScope {0633ee93-d776-472f-a0ff-e1416b8b2e3a} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {8B9C785E-E8BC-44E4-84A2-75445A337DE0} URL = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=2b1589ca-6f97-451f-8387-9d9cadf50515&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {8C13D732-90BE-4CE9-9F57-E927CE15A13D} URL = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=2b1589ca-6f97-451f-8387-9d9cadf50515&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {99BE2E78-9F23-4B08-805A-949F9DAEBD33} URL = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=2b1589ca-6f97-451f-8387-9d9cadf50515&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {A1170089-D498-429F-9992-91C1AD86ED9D} URL = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=2b1589ca-6f97-451f-8387-9d9cadf50515&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {B84E8222-9DC4-4CF0-AB73-9013E1247EA8} URL = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=2b1589ca-6f97-451f-8387-9d9cadf50515&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {FA422BE7-39E3-4096-AE5D-A6015A9DDD23} URL = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=2b1589ca-6f97-451f-8387-9d9cadf50515&pid=fotofreeware&mode=bounce&k=0
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO: SwissAcademic.Citavi.Picker.IEPicker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.15.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.15.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.1.18 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.1.18 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @videolan.org/vlc,version=2.0.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\11-suche.xml
FF SearchPlugin: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\duckduckgo.xml
FF SearchPlugin: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\firefox-add-ons.xml
FF SearchPlugin: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\{8183CA04-D4D3-4322-9980-6E4BC4CC809E}.xml
FF SearchPlugin: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\{94701381-8CAB-4F73-9A01-6CD89B94FB6F}.xml
FF SearchPlugin: C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\searchplugins\{9AE7E708-1DC8-4294-81E4-AD0BECFC4EF0}.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Preispilot - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\extension@preispilot.com [2012-11-18]
FF Extension: FireJump - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\firejump@firejump.net [2012-11-17]
FF Extension: Google Search by Image - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\google@hitachi.com [2013-01-05]
FF Extension: ProxTube - Unblock YouTube - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\ich@maltegoetz.de [2014-07-16]
FF Extension: Go To Google - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{BCC877E7-7F3F-4632-8338-DAEE4475DE35} [2013-01-01]
FF Extension: Easy YouTube Video Downloader - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b} [2013-08-03]
FF Extension: Adblock Plus - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2014-07-09]
FF Extension: New Tab King - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{FC5BAC7D-D696-4ba6-B913-CF8F000C33DF} [2014-07-16]
FF Extension: Preispilot - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\extension@preispilot.com.xpi [2012-11-18]
FF Extension: Google Search by Image - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\google@hitachi.com.xpi [2013-01-05]
FF Extension: All-in-One Sidebar - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi [2012-09-23]
FF Extension: NoScript - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-04-16]
FF Extension: Go To Google - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{BCC877E7-7F3F-4632-8338-DAEE4475DE35}.xpi [2013-01-01]
FF Extension: Easy YouTube Video Downloader - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi [2013-03-23]
FF Extension: Adblock Plus - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-02-14]
FF Extension: DownThemAll! - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2012-09-23]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-09-19]
FF HKLM\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-09-26]
FF HKLM\...\Firefox\Extensions: [{DAC3F861-B30D-40dd-9166-F4E75327FAC7}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-03-21]
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-05-07]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKCU\...\Firefox\Extensions: [extension@preispilot.com] - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\extensions\extension@preispilot.com
FF HKCU\...\Firefox\Extensions: [firejump@firejump.net] - C:\Users\Cas\AppData\Roaming\Mozilla\Firefox\Profiles\8ka7i0u3.default\extensions\firejump@firejump.net
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-29] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-29] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-29] (Avira Operations GmbH & Co. KG)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-16] (AVAST Software)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-07] (Avira Operations GmbH & Co. KG)
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [174656 2006-11-02] () [File not signed]
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] ()
R2 SearchAnonymizer; C:\Users\Cas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2012-11-17] () [File not signed]
R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [557968 2013-06-19] (Cisco Systems, Inc.)
==================== Drivers (Whitelisted) ====================
S3 acsint; C:\Windows\System32\DRIVERS\acsint.sys [39888 2013-06-19] (Cisco Systems, Inc.)
S3 acsmux; C:\Windows\System32\DRIVERS\acsmux.sys [58320 2013-06-19] (Cisco Systems, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-07-16] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-07-16] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55112 2014-07-16] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-07-16] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-07-16] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [414520 2014-07-16] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57800 2014-07-16] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-07-16] ()
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdLH3.sys [75776 2013-01-15] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-09-23] (DT Soft Ltd)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2011-07-29] () [File not signed]
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2011-07-29] () [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-16] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [16472 2010-04-09] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [11104 2010-04-09] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-29] (Avira GmbH)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 catchme; \??\C:\Users\Cas\AppData\Local\Temp\catchme.sys [X]
S3 HTCAND32; System32\Drivers\ANDROIDUSB.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 xuxibnch; \??\C:\Windows\system32\drivers\xuxibnch.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-16 23:04 - 2014-07-16 23:04 - 00004556 _____ () C:\Users\Cas\Desktop\JRT.txt
2014-07-16 22:52 - 2014-07-16 22:52 - 00000000 ____D () C:\Windows\ERUNT
2014-07-16 22:51 - 2014-07-16 22:51 - 01016261 _____ (Thisisu) C:\Users\Cas\Desktop\JRT.exe
2014-07-16 22:50 - 2014-07-16 22:39 - 00005148 _____ () C:\Users\Cas\Desktop\AdwCleaner[R0].txt
2014-07-16 22:38 - 2014-07-16 22:39 - 00000000 ____D () C:\AdwCleaner
2014-07-16 22:37 - 2014-07-16 22:37 - 01348263 _____ () C:\Users\Cas\Desktop\adwcleaner_3.215.exe
2014-07-16 22:36 - 2014-07-16 22:36 - 00013014 _____ () C:\Users\Cas\Desktop\mbam.txt
2014-07-16 22:24 - 2014-07-16 23:00 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-16 22:24 - 2014-07-16 22:24 - 00000905 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-16 22:24 - 2014-07-16 22:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-16 22:24 - 2014-07-16 22:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-16 22:24 - 2014-07-16 22:24 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-16 22:24 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-16 22:24 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-16 22:24 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-16 22:23 - 2014-07-16 22:23 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Cas\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-16 18:56 - 2007-01-04 12:02 - 00663552 _____ (MAGIX AG) C:\Windows\system32\mgxoschk.dll
2014-07-16 11:46 - 2014-07-16 11:46 - 00013619 _____ () C:\ComboFix.txt
2014-07-16 11:35 - 2014-07-16 11:46 - 00000000 ____D () C:\Qoobox
2014-07-16 11:35 - 2014-07-16 11:46 - 00000000 ____D () C:\ComboFix
2014-07-16 11:35 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-16 11:35 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-16 11:35 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-16 11:35 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-16 11:35 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-16 11:35 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-07-16 11:35 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-16 11:35 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-16 11:35 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-16 11:34 - 2014-07-16 11:44 - 00000000 ____D () C:\Windows\erdnt
2014-07-16 11:29 - 2014-07-16 11:29 - 00139816 _____ () C:\Windows\Minidump\Mini071614-01.dmp
2014-07-16 11:19 - 2014-07-16 11:19 - 05221615 ____R (Swearware) C:\Users\Cas\Desktop\ComboFix.exe
2014-07-16 10:45 - 2014-07-16 10:45 - 00016413 _____ () C:\Users\Cas\Desktop\Gmer.txt
2014-07-16 10:30 - 2014-07-16 10:30 - 00380416 _____ () C:\Users\Cas\Desktop\Gmer-19357.exe
2014-07-16 10:29 - 2014-07-16 23:05 - 00025784 _____ () C:\Users\Cas\Desktop\FRST.txt
2014-07-16 10:28 - 2014-07-16 23:05 - 00000000 ____D () C:\FRST
2014-07-16 10:28 - 2014-07-16 10:28 - 01077248 _____ (Farbar) C:\Users\Cas\Desktop\FRST.exe
2014-07-16 10:26 - 2014-07-16 10:26 - 00050477 _____ () C:\Users\Cas\Desktop\Defogger.exe
2014-07-16 09:12 - 2014-07-16 09:12 - 00414520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-07-16 09:12 - 2014-07-16 09:12 - 00001879 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-07-16 09:12 - 2014-07-16 09:12 - 00000000 ____D () C:\Users\Cas\AppData\Roaming\AVAST Software
2014-07-16 09:12 - 2014-07-16 09:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-07-16 09:12 - 2014-07-16 09:11 - 00779536 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-07-16 09:12 - 2014-07-16 09:11 - 00276432 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-07-16 09:12 - 2014-07-16 09:11 - 00192352 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-07-16 09:12 - 2014-07-16 09:11 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-07-16 09:12 - 2014-07-16 09:11 - 00057800 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2014-07-16 09:12 - 2014-07-16 09:11 - 00055112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys
2014-07-16 09:12 - 2014-07-16 09:11 - 00049944 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-07-16 09:12 - 2014-07-16 09:11 - 00024184 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-07-16 09:11 - 2014-07-16 09:11 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-07-16 09:11 - 2014-07-16 09:11 - 00000000 ____D () C:\Program Files\AVAST Software
2014-07-16 09:09 - 2014-07-16 09:11 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-07-16 09:08 - 2014-07-16 09:09 - 91906368 _____ (AVAST Software) C:\Users\Cas\Downloads\avast_free_antivirus_setup_9_0_2021.exe
2014-07-09 13:16 - 2014-07-09 13:16 - 00000000 ____D () C:\Users\Cas\AppData\Local\Apple Computer
2014-07-09 13:13 - 2014-07-16 08:33 - 00000000 ____D () C:\Users\Cas\AppData\Roaming\Apple Computer
2014-07-09 11:44 - 2014-07-09 11:45 - 00000000 ____D () C:\Program Files\QuickTime
2014-07-09 11:44 - 2014-07-09 11:44 - 00001732 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk
2014-07-09 11:44 - 2014-07-09 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-07-09 11:44 - 2014-07-09 11:44 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-07-09 11:43 - 2014-07-09 11:43 - 00001830 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-07-09 11:43 - 2014-07-09 11:43 - 00000000 ____D () C:\Users\Cas\AppData\Local\Apple
2014-07-09 11:43 - 2014-07-09 11:43 - 00000000 ____D () C:\ProgramData\Apple
2014-07-09 11:43 - 2014-07-09 11:43 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-07-09 11:43 - 2014-07-09 11:43 - 00000000 ____D () C:\Program Files\Apple Software Update
2014-07-09 11:35 - 2014-07-09 11:36 - 41945432 _____ (Apple Inc.) C:\Users\Cas\Downloads\QuickTimeInstaller.exe
2014-07-09 10:47 - 2014-07-09 10:47 - 00001008 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-07-09 10:47 - 2014-07-09 10:47 - 00000000 ____D () C:\ProgramData\Package Cache
2014-07-09 10:46 - 2014-07-09 10:46 - 04621032 _____ (Avira Operations GmbH & Co. KG) C:\Users\Cas\Downloads\avira_de_av_4082828851__ws.exe
2014-07-09 10:40 - 2014-07-16 22:59 - 00000000 ____D () C:\Users\Cas\AppData\Roaming\DropboxMaster
==================== One Month Modified Files and Folders =======
2014-07-16 23:05 - 2014-07-16 10:29 - 00025784 _____ () C:\Users\Cas\Desktop\FRST.txt
2014-07-16 23:05 - 2014-07-16 10:28 - 00000000 ____D () C:\FRST
2014-07-16 23:04 - 2014-07-16 23:04 - 00004556 _____ () C:\Users\Cas\Desktop\JRT.txt
2014-07-16 23:02 - 2006-11-02 12:33 - 01461736 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-16 23:00 - 2014-07-16 22:24 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-16 23:00 - 2006-11-02 14:51 - 01235118 _____ () C:\Windows\WindowsUpdate.log
2014-07-16 22:59 - 2014-07-09 10:40 - 00000000 ____D () C:\Users\Cas\AppData\Roaming\DropboxMaster
2014-07-16 22:59 - 2012-11-04 18:36 - 00000000 ____D () C:\Users\Cas\AppData\Roaming\Dropbox
2014-07-16 22:58 - 2012-11-03 17:59 - 00000000 ____D () C:\Users\Cas\AppData\Roaming\Spotify
2014-07-16 22:56 - 2006-11-02 15:00 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-16 22:55 - 2006-11-02 14:59 - 00039560 _____ () C:\Windows\PFRO.log
2014-07-16 22:55 - 2006-11-02 14:46 - 00003936 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-16 22:55 - 2006-11-02 14:46 - 00003936 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-16 22:53 - 2006-11-02 15:00 - 00032606 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-16 22:52 - 2014-07-16 22:52 - 00000000 ____D () C:\Windows\ERUNT
2014-07-16 22:51 - 2014-07-16 22:51 - 01016261 _____ (Thisisu) C:\Users\Cas\Desktop\JRT.exe
2014-07-16 22:50 - 2013-04-17 18:12 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-16 22:46 - 2012-11-03 17:59 - 00000000 ____D () C:\Users\Cas\AppData\Local\Spotify
2014-07-16 22:39 - 2014-07-16 22:50 - 00005148 _____ () C:\Users\Cas\Desktop\AdwCleaner[R0].txt
2014-07-16 22:39 - 2014-07-16 22:38 - 00000000 ____D () C:\AdwCleaner
2014-07-16 22:39 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Resources
2014-07-16 22:37 - 2014-07-16 22:37 - 01348263 _____ () C:\Users\Cas\Desktop\adwcleaner_3.215.exe
2014-07-16 22:36 - 2014-07-16 22:36 - 00013014 _____ () C:\Users\Cas\Desktop\mbam.txt
2014-07-16 22:24 - 2014-07-16 22:24 - 00000905 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-16 22:24 - 2014-07-16 22:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-16 22:24 - 2014-07-16 22:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-16 22:24 - 2014-07-16 22:24 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-16 22:23 - 2014-07-16 22:23 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Cas\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-16 19:15 - 2012-09-19 16:17 - 00070144 _____ () C:\Users\Cas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-16 19:10 - 2012-09-23 20:09 - 00000000 ____D () C:\Users\Cas\AppData\Roaming\vlc
2014-07-16 15:23 - 2013-01-29 18:43 - 00000973 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
2014-07-16 15:23 - 2013-01-29 18:43 - 00000961 _____ () C:\Users\Public\Desktop\TeamViewer 8.lnk
2014-07-16 11:46 - 2014-07-16 11:46 - 00013619 _____ () C:\ComboFix.txt
2014-07-16 11:46 - 2014-07-16 11:35 - 00000000 ____D () C:\Qoobox
2014-07-16 11:46 - 2014-07-16 11:35 - 00000000 ____D () C:\ComboFix
2014-07-16 11:46 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default
2014-07-16 11:46 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public
2014-07-16 11:44 - 2014-07-16 11:34 - 00000000 ____D () C:\Windows\erdnt
2014-07-16 11:44 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini
2014-07-16 11:43 - 2012-09-13 23:06 - 00000000 ____D () C:\Users\Cas
2014-07-16 11:29 - 2014-07-16 11:29 - 00139816 _____ () C:\Windows\Minidump\Mini071614-01.dmp
2014-07-16 11:29 - 2012-11-12 23:26 - 304599041 _____ () C:\Windows\MEMORY.DMP
2014-07-16 11:29 - 2012-11-12 23:26 - 00000000 ____D () C:\Windows\Minidump
2014-07-16 11:19 - 2014-07-16 11:19 - 05221615 ____R (Swearware) C:\Users\Cas\Desktop\ComboFix.exe
2014-07-16 10:45 - 2014-07-16 10:45 - 00016413 _____ () C:\Users\Cas\Desktop\Gmer.txt
2014-07-16 10:30 - 2014-07-16 10:30 - 00380416 _____ () C:\Users\Cas\Desktop\Gmer-19357.exe
2014-07-16 10:28 - 2014-07-16 10:28 - 01077248 _____ (Farbar) C:\Users\Cas\Desktop\FRST.exe
2014-07-16 10:26 - 2014-07-16 10:26 - 00050477 _____ () C:\Users\Cas\Desktop\Defogger.exe
2014-07-16 10:16 - 2012-09-19 16:37 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-07-16 09:12 - 2014-07-16 09:12 - 00414520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-07-16 09:12 - 2014-07-16 09:12 - 00001879 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-07-16 09:12 - 2014-07-16 09:12 - 00000000 ____D () C:\Users\Cas\AppData\Roaming\AVAST Software
2014-07-16 09:12 - 2014-07-16 09:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-07-16 09:11 - 2014-07-16 09:12 - 00779536 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-07-16 09:11 - 2014-07-16 09:12 - 00276432 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-07-16 09:11 - 2014-07-16 09:12 - 00192352 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-07-16 09:11 - 2014-07-16 09:12 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-07-16 09:11 - 2014-07-16 09:12 - 00057800 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2014-07-16 09:11 - 2014-07-16 09:12 - 00055112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys
2014-07-16 09:11 - 2014-07-16 09:12 - 00049944 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-07-16 09:11 - 2014-07-16 09:12 - 00024184 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-07-16 09:11 - 2014-07-16 09:11 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-07-16 09:11 - 2014-07-16 09:11 - 00000000 ____D () C:\Program Files\AVAST Software
2014-07-16 09:11 - 2014-07-16 09:09 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-07-16 09:09 - 2014-07-16 09:08 - 91906368 _____ (AVAST Software) C:\Users\Cas\Downloads\avast_free_antivirus_setup_9_0_2021.exe
2014-07-16 08:43 - 2012-11-04 19:14 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-07-16 08:38 - 2013-07-11 08:31 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-16 08:37 - 2012-09-23 17:39 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-16 08:37 - 2012-09-23 17:39 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-16 08:36 - 2012-09-13 23:06 - 00001356 _____ () C:\Users\Cas\AppData\Local\d3d9caps.dat
2014-07-16 08:34 - 2012-09-19 17:54 - 00000000 ____D () C:\Program Files\Common Files\Steam
2014-07-16 08:33 - 2014-07-09 13:13 - 00000000 ____D () C:\Users\Cas\AppData\Roaming\Apple Computer
2014-07-09 13:16 - 2014-07-09 13:16 - 00000000 ____D () C:\Users\Cas\AppData\Local\Apple Computer
2014-07-09 11:45 - 2014-07-09 11:44 - 00000000 ____D () C:\Program Files\QuickTime
2014-07-09 11:44 - 2014-07-09 11:44 - 00001732 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk
2014-07-09 11:44 - 2014-07-09 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-07-09 11:44 - 2014-07-09 11:44 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-07-09 11:43 - 2014-07-09 11:43 - 00001830 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-07-09 11:43 - 2014-07-09 11:43 - 00000000 ____D () C:\Users\Cas\AppData\Local\Apple
2014-07-09 11:43 - 2014-07-09 11:43 - 00000000 ____D () C:\ProgramData\Apple
2014-07-09 11:43 - 2014-07-09 11:43 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-07-09 11:43 - 2014-07-09 11:43 - 00000000 ____D () C:\Program Files\Apple Software Update
2014-07-09 11:36 - 2014-07-09 11:35 - 41945432 _____ (Apple Inc.) C:\Users\Cas\Downloads\QuickTimeInstaller.exe
2014-07-09 10:47 - 2014-07-09 10:47 - 00001008 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-07-09 10:47 - 2014-07-09 10:47 - 00000000 ____D () C:\ProgramData\Package Cache
2014-07-09 10:47 - 2013-07-29 18:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-07-09 10:47 - 2013-07-29 18:41 - 00000000 ____D () C:\ProgramData\Avira
2014-07-09 10:47 - 2013-07-29 18:41 - 00000000 ____D () C:\Program Files\Avira
2014-07-09 10:46 - 2014-07-09 10:46 - 04621032 _____ (Avira Operations GmbH & Co. KG) C:\Users\Cas\Downloads\avira_de_av_4082828851__ws.exe
2014-07-09 10:40 - 2012-11-04 18:39 - 00000919 _____ () C:\Users\Cas\Desktop\Dropbox.lnk
2014-07-09 10:40 - 2012-11-04 18:37 - 00000000 ____D () C:\Users\Cas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-06-26 17:38 - 2006-11-02 12:24 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
Files to move or delete:
====================
C:\Users\Cas\AccessibleMarshal.dll
C:\Users\Cas\crashreporter.exe
C:\Users\Cas\D3DCompiler_43.dll
C:\Users\Cas\d3dx9_43.dll
C:\Users\Cas\freebl3.dll
C:\Users\Cas\gkmedias.dll
C:\Users\Cas\libEGL.dll
C:\Users\Cas\libGLESv2.dll
C:\Users\Cas\maintenanceservice.exe
C:\Users\Cas\maintenanceservice_installer.exe
C:\Users\Cas\MapiProxy.dll
C:\Users\Cas\MapiProxy_InUse.dll
C:\Users\Cas\mozalloc.dll
C:\Users\Cas\mozglue.dll
C:\Users\Cas\mozMapi32.dll
C:\Users\Cas\mozMapi32_InUse.dll
C:\Users\Cas\mozsqlite3.dll
C:\Users\Cas\msvcp100.dll
C:\Users\Cas\msvcr100.dll
C:\Users\Cas\nspr4.dll
C:\Users\Cas\nss3.dll
C:\Users\Cas\nssckbi.dll
C:\Users\Cas\nssdbm3.dll
C:\Users\Cas\nssutil3.dll
C:\Users\Cas\plc4.dll
C:\Users\Cas\plds4.dll
C:\Users\Cas\smime3.dll
C:\Users\Cas\softokn3.dll
C:\Users\Cas\ssl3.dll
C:\Users\Cas\thunderbird.exe
C:\Users\Cas\updater.exe
C:\Users\Cas\WSEnable.exe
C:\Users\Cas\xpcom.dll
C:\Users\Cas\xul.dll
Some content of TEMP:
====================
C:\Users\Cas\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpv7mcdi.dll
C:\Users\Cas\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-16 23:02
==================== End Of Log ============================ --- --- ---
--- --- ---
Babylon besiegt? ;)
Viele Grüße. |