![]() |
Windows 7 - Werbefenster öffnen sich überall Hallo, bin zum ersten Mal hier und hoffe ich mache nichts falsch - ihr habt ja viele Regeln ! Gut - ich habe auf meinem Laptop seit ein paar Tagen - so genau weiß ich nicht wann es begonnen hat- das Problem dass sich immer wieder Werbefenster öffnen und gewisse Wörter fett geschrieben und mit einem grünen Kreis und Pfeil unterlegt sind - dahinter dann immer eine Werbung. Hab Farbar Recovery Scan heruntergeladen und Scan ausgeführt: ich hoffe das ist jetzt nicht zuviel? Bitte um Hilfe - DANKE - mir kommt das jetzt wahnsinnig viel vor .... Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-08-2014 01 Ran by Petra (administrator) on PETRA-PC on 19-08-2014 16:35:12 Running from C:\Users\Petra\Downloads Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo) C:\Windows\System32\ibmpmsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Lenovo) C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe (Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE (Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Lenovo) C:\Program Files\Lenovo\Access Connections\AcSvc.exe (Microsoft Corporation) C:\Windows\System32\FXSSVC.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Apple Inc.) C:\Program Files\QuickTime\QTTask.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe (Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicatorCom.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe (Somoto) C:\Users\Petra\AppData\Local\FilesFrog Update Checker\update_checker.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe (Lenovo Group Limited) C:\Program Files\ThinkPad\Utilities\SCHTASK.EXE (Intel Corporation) C:\Windows\System32\igfxext.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (SaveSense) C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe (Lenovo) C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe (Lenovo.) C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo) C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSPUB.EXE (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSPUB.EXE (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSPUB.EXE (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE (Dropbox, Inc.) C:\Users\Petra\AppData\Roaming\Dropbox\bin\Dropbox.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKU\S-1-5-21-4103409644-2115618623-1480157512-1001\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [1837672 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-4103409644-2115618623-1480157512-1001\...\Run: [NextLive] => C:\Windows\system32\rundll32.exe "C:\Users\Petra\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l AppInit_DLLs: c:\progra~1\searchprotect\searchprotect\bin\spvc32loader.dll => c:\Program Files\searchprotect\searchprotect\bin\spvc32loader.dll [187328 2014-07-22] () AppInit_DLLs: c:\progra~2\winspeed\winspeed.dll => c:\ProgramData\WinSpeed\WinSpeed.dll [4127232 2014-08-17] () Lsa: [Notification Packages] scecli ACGina Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Petra\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 6700 (Netzwerk).lnk ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 6700 (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet 6700\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Petra\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Petra\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Petra\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fc84b881-dbc4-fd8c-c066-be1e7643f9a2&searchtype=ds&q={searchTerms}&installDate=21/12/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.max-start.com/?babsrc=HP_ss_mib2&mntrId=285C00A0D5FFFF85&affID=128492&tsp=5221 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xABF32BFAA22CCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www1.delta-search.com/?q=google&babsrc=HP_ss&s=web&rlz=0&as=0&ac=0%2C1 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fc84b881-dbc4-fd8c-c066-be1e7643f9a2&searchtype=ds&q={searchTerms}&installDate=21/12/2013 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=dvd_14_15_ff&cd=2XzuyEtN2Y1L1QzutDtD0AtD0DyD0F0F0F0FzzyDyDyC0EzytN0D0Tzu0SzztAtAtN1L2XzutBtFtBtDtFtCtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1 L1Qzu2StCyDtBzzyCyCtA0FtG0EtCtDyDtGyBzzyCtDtGtB0EyEyBtGyB0A0EtA0C0Ezz0DzztB0CyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtBzz0Fzy0D0EtDtGtDtByB0CtGtDyE0FyDtG0DyEtB0 FtGtB0A0ByCyC0Ezy0E0AyBtBtA2Q&cr=294409713&ir= SearchScopes: HKLM - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dvd_14_15_ff&cd=2XzuyEtN2Y1L1QzutDtD0AtD0DyD0F0F0F0FzzyDyDyC0EzytN0D0Tzu0SzztAtAtN1L2XzutBtFtBtDtFtCtFtDtN1L1CzutCyE tDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StCyDtBzzyCyCtA0FtG0EtCtDyDtGyBzzyCtDtGtB0EyEyBtGyB0A0EtA0C0Ezz0DzztB0CyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtBzz0Fzy0D0EtDtG tDtByB0CtGtDyE0FyDtG0DyEtB0FtGtB0A0ByCyC0Ezy0E0AyBtBtA2Q&cr=294409713&ir= SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dvd_14_15_ff&cd=2XzuyEtN2Y1L1QzutDtD0AtD0DyD0F0F0F0FzzyDyDyC0EzytN0D0Tzu0SzztAtAtN1L2XzutBtFtBtDtFtCtFtDtN1L1CzutCyE tDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StCyDtBzzyCyCtA0FtG0EtCtDyDtGyBzzyCtDtGtB0EyEyBtGyB0A0EtA0C0Ezz0DzztB0CyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtBzz0Fzy0D0EtDtG tDtByB0CtGtDyE0FyDtG0DyEtB0FtGtB0A0ByCyC0Ezy0E0AyBtBtA2Q&cr=294409713&ir= SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fc84b881-dbc4-fd8c-c066-be1e7643f9a2&searchtype=ds&q={searchTerms}&installDate=21/12/2013 SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=M53BE9289-5B71-404B-A9D4-15DB387ADCFE&SearchSource=58&CUI=&UM=5&UP=SP1E90BFB9-87F8-45E5-BA13-C8B6775B64F9&q={searchTerms}&SSPV= SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dvd_14_15_ff&cd=2XzuyEtN2Y1L1QzutDtD0AtD0DyD0F0F0F0FzzyDyDyC0EzytN0D0Tzu0SzztAtAtN1L2XzutBtFtBtDtFtCtFtDtN1L1CzutCyE tDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StCyDtBzzyCyCtA0FtG0EtCtDyDtGyBzzyCtDtGtB0EyEyBtGyB0A0EtA0C0Ezz0DzztB0CyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtBzz0Fzy0D0EtDtG tDtByB0CtGtDyE0FyDtG0DyEtB0FtGtB0A0ByCyC0Ezy0E0AyBtBtA2Q&cr=294409713&ir= SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=M53BE9289-5B71-404B-A9D4-15DB387ADCFE&SearchSource=58&CUI=&UM=5&UP=SP1E90BFB9-87F8-45E5-BA13-C8B6775B64F9&q={searchTerms}&SSPV= SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.doko-search.com/?q={searchTerms}&babsrc=SP_ss_mib2&mntrId=285C00A0D5FFFF85&affID=128492&tsp=5221 SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fc84b881-dbc4-fd8c-c066-be1e7643f9a2&searchtype=ds&q={searchTerms}&installDate=21/12/2013 BHO: SaveSense -> {0f21b1e5-5afc-43c9-9c66-515046e92ec2} -> C:\Program Files\SaveSense\SaveSenseIE.dll (SaveSense) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: delta Helper Object -> {C1AF5FA5-852C-4C90-812E-A7F75E011D87} -> C:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll No File BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) BHO: mysearchdial Helper Object -> {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} -> C:\Program Files\Mysearchdial\1.8.29.0\bh\mysearchdial.dll (MySearchDial) BHO: buenosearch Helper Object -> {F1C81E40-2485-4DB6-8C9D-04BD596B281E} -> C:\Program Files\buenosearch LTD\buenosearch\1.8.28.7\bh\buenosearch.dll (Montiera Technologies LTD) Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll (MySearchDial) Toolbar: HKLM - buenosearch Toolbar - {828DC97A-2277-4E10-92A9-4907FA0922A9} - C:\Program Files\buenosearch LTD\buenosearch\1.8.28.7\buenosearchTlbr.dll (Montiera Technologies LTD) DPF: {D27CDB6E-AE6D-11CF-96B8-720720720720} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 10.0.0.138 FireFox: ======== FF ProfilePath: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default FF NewTab: hxxp://www.trovi.com/?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=M53BE9289-5B71-404B-A9D4-15DB387ADCFE&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SP1E90BFB9-87F8-45E5-BA13-C8B6775B64F9 FF DefaultSearchEngine: WSE Rocket FF SearchEngineOrder.1: Mysearchdial FF SelectedSearchEngine: WSE Rocket FF Homepage: hxxp://www.google.at/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.updaterss.com/SaveSenseLive Update;version=3 -> C:\Program Files\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF Plugin: @tools.updaterss.com/SaveSenseLive Update;version=9 -> C:\Program Files\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF user.js: detected! => C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\user.js FF SearchPlugin: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\searchplugins\ask-search.xml FF SearchPlugin: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\searchplugins\buenosearch.xml FF SearchPlugin: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\searchplugins\Mysearchdial.xml FF SearchPlugin: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\searchplugins\WSE Rocket.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: BuenoSearch - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\Extensions\ffxtlbr@buenosearch.com [2014-04-18] FF Extension: mysearchdial.com - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\Extensions\ffxtlbr@mysearchdial.com [2014-04-13] FF Extension: SmartCompaRe - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\Extensions\hpbrdeuytjdd@oj-qhyt.edu [2014-08-17] FF Extension: SaveSense - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\Extensions\{8b337819-d1e8-48d3-8178-168ae8c99c36} [2013-12-01] FF Extension: Rocket New Tab - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\Extensions\{ecaa9181-d92a-47b9-8e14-bef9680f204b} [2014-07-27] FF Extension: Ask Toolbar - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-03-26] FF Extension: MySearchDial - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\tvr59cp9.default\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}.xpi [2014-04-13] FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff FF Extension: Download videos and MP3s from YouTube - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff [2013-05-20] Chrome: ======= CHR HomePage: hxxp://www.trovi.com/?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=M53BE9289-5B71-404B-A9D4-15DB387ADCFE&SearchSource=55&CUI=&UM=5&UP=SP1E90BFB9-87F8-45E5-BA13-C8B6775B64F9&SSPV= CHR StartupUrls: "hxxp://www.trovi.com/?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=M53BE9289-5B71-404B-A9D4-15DB387ADCFE&SearchSource=55&CUI=&UM=5&UP=SP1E90BFB9-87F8-45E5-BA13-C8B6775B64F9&SSPV=" CHR NewTab: "chrome-extension://iagcajndpnfncplednpbnkahadegklfa/content/newtab/newtab.html", "chrome-extension://amfclgbdpgndipgoegfpkkgobahigbcl/redirect.html" CHR DefaultSearchKeyword: trovi.search CHR DefaultSearchProvider: Trovi search CHR DefaultSearchURL: hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=M53BE9289-5B71-404B-A9D4-15DB387ADCFE&SearchSource=58&CUI=&UM=5&UP=SP1E90BFB9-87F8-45E5-BA13-C8B6775B64F9&q={searchTerms}&SSPV= CHR DefaultSuggestURL: hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\36.0.1985.143\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Extension: (New Tab Page) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl [2013-12-21] CHR Extension: (Google Docs) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-31] CHR Extension: (Wunderlist Panel) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnkkhbbhipldmgjflneimpacklkiogpo [2014-08-17] CHR Extension: (MySearchDial Neuer Tab) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\iagcajndpnfncplednpbnkahadegklfa [2014-08-19] CHR Extension: (SaveSense) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\khcceooakamlehbimaepcldnnlnkcmfk [2013-12-01] CHR Extension: (No Name) - C:\Users\Petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pljcgbedjplidkdjahbaalanadmjfgop [2013-11-16] CHR HKLM\...\Chrome\Extension: [iagcajndpnfncplednpbnkahadegklfa] - C:\Users\Petra\AppData\Local\speedial.crx [2014-04-13] CHR HKCU\...\Chrome\Extension: [iagcajndpnfncplednpbnkahadegklfa] - C:\Users\Petra\AppData\Local\speedial.crx [2014-04-13] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-05-20] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AcPrfMgrSvc; C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe [134240 2012-05-30] (Lenovo) R2 AcSvc; C:\Program Files\Lenovo\Access Connections\AcSvc.exe [273504 2012-05-30] (Lenovo) S4 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [165784 2014-06-24] () [File not signed] S4 CltMngSvc; C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe [2975168 2014-07-22] () [File not signed] R2 f1f78e38; c:\ProgramData\WinSpeed\WinSpeedSvc.dll [186192 2014-08-17] () [File not signed] R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation) S3 PwmEWSvc; C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE [1665120 2012-05-16] (Lenovo Group Limited) S2 savesenselive; C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [146920 2013-12-01] (SaveSense) S3 savesenselivem; C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [146920 2013-12-01] (SaveSense) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation) S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver_AMDASF.sys [22840 2012-07-05] (Synaptics Incorporated) S3 SmbDrvI; C:\Windows\system32\drivers\Smb_driver_Intel.sys [23608 2012-07-05] (Synaptics Incorporated) R3 SWNC8U01; C:\Windows\System32\DRIVERS\SWNC8U01.sys [102144 2007-01-12] (Sierra Wireless Inc.) R3 SWUMX01; C:\Windows\System32\DRIVERS\swumx01.sys [70656 2007-01-12] (Sierra Wireless Inc.) R1 wStLibG; C:\Windows\System32\drivers\wStLibG.sys [52920 2014-04-21] (StdLib) S3 HSF_DPV; system32\DRIVERS\HSX_DPV.sys [X] S3 HSXHWAZL; system32\DRIVERS\HSXHWAZL.sys [X] S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) S3 winachsf; system32\DRIVERS\HSX_CNXT.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-19 16:35 - 2014-08-19 16:35 - 00024510 _____ () C:\Users\Petra\Downloads\FRST.txt 2014-08-19 16:34 - 2014-08-19 16:35 - 00000000 ___DC () C:\FRST 2014-08-19 16:33 - 2014-08-19 16:33 - 01093632 _____ (Farbar) C:\Users\Petra\Downloads\FRST.exe 2014-08-19 16:13 - 2014-08-19 16:13 - 00000000 ___DC () C:\Program Files\SmarotCompAre 2014-08-19 11:15 - 2014-08-19 16:17 - 00065536 ___HT () C:\Users\Petra\~Outlook.pst.tmp 2014-08-17 09:33 - 2014-08-19 16:13 - 00000000 ____D () C:\ProgramData\SmarotCompAre 2014-08-17 09:33 - 2014-08-19 16:13 - 00000000 ____D () C:\ProgramData\b089358267e0237d 2014-08-17 09:13 - 2014-08-17 09:13 - 00000000 ____D () C:\ProgramData\WinSpeed 2014-08-14 08:05 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-14 08:04 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-14 08:04 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-14 08:04 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-13 10:17 - 2014-08-13 10:27 - 70454999 _____ () C:\Users\Petra\Downloads\Heidi_Folge_16_deutsch.mp4 2014-08-13 10:17 - 2014-08-13 10:27 - 69942527 _____ () C:\Users\Petra\Downloads\Heidi_Folge_17_deutsch.mp4 2014-08-13 10:16 - 2014-08-13 10:27 - 75299683 _____ () C:\Users\Petra\Downloads\Heidi_Folge_15_deutsch.mp4 2014-08-13 10:15 - 2014-08-13 10:26 - 73407198 _____ () C:\Users\Petra\Downloads\Heidi_Folge_14_deutsch.mp4 2014-08-13 10:14 - 2014-08-13 10:25 - 83459007 _____ () C:\Users\Petra\Downloads\Heidi_Folge_13_deutsch.mp4 2014-08-13 10:12 - 2014-08-13 10:24 - 81268667 _____ () C:\Users\Petra\Downloads\Heidi_Folge_11_deutsch.mp4 2014-08-13 10:12 - 2014-08-13 10:24 - 80383649 _____ () C:\Users\Petra\Downloads\Heidi_Folge_12_deutsch.mp4 2014-08-13 10:11 - 2014-08-13 10:14 - 70934097 _____ () C:\Users\Petra\Downloads\Heidi_Folge_10_deutsch.mp4 2014-08-13 09:06 - 2014-08-07 03:43 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-13 09:06 - 2014-08-07 03:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-13 09:06 - 2014-07-24 20:07 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-13 09:06 - 2014-07-24 19:58 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-13 09:06 - 2014-07-24 19:52 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-13 09:06 - 2014-07-24 19:51 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-13 09:06 - 2014-07-24 19:49 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-08-13 09:06 - 2014-07-24 19:49 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-13 09:06 - 2014-07-24 19:48 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-13 09:06 - 2014-07-24 19:48 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-13 09:06 - 2014-07-24 19:48 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-13 09:06 - 2014-07-24 19:48 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-08-13 09:06 - 2014-07-24 19:48 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-08-13 09:06 - 2014-07-24 19:48 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-08-13 09:06 - 2014-07-24 19:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-13 09:06 - 2014-07-16 04:47 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-13 09:06 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-13 09:06 - 2014-07-16 03:47 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-13 09:06 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-13 09:06 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-13 09:06 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2014-08-13 09:06 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2014-08-13 09:06 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-13 09:06 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-13 09:06 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-13 09:06 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-13 09:05 - 2014-07-24 19:57 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-13 09:05 - 2014-07-24 19:51 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-13 09:05 - 2014-07-24 19:50 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-08-13 09:05 - 2014-07-24 19:50 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-13 09:05 - 2014-07-24 19:49 - 01802240 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-13 09:05 - 2014-07-24 19:49 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-13 09:05 - 2014-07-24 19:49 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-13 09:05 - 2014-07-24 19:48 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-13 09:05 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-13 09:05 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-13 09:05 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-13 09:05 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-13 09:05 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-13 09:05 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-13 09:05 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-08 13:53 - 2014-08-08 13:54 - 29553288 _____ (DVDVideoSoft Ltd. ) C:\Users\Petra\Downloads\FreeYouTubeToMP3Converter(2).exe 2014-08-07 20:53 - 2014-08-07 20:53 - 00000964 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-08-05 19:58 - 2014-08-05 19:58 - 01868412 _____ () C:\Users\Petra\Downloads\PAKA5.psd 2014-07-31 10:04 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-07-31 10:04 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-07-31 10:04 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-07-31 10:04 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-07-31 10:04 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-07-31 10:04 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-07-31 10:04 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-07-31 10:04 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-07-31 10:04 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-07-30 14:49 - 2014-07-30 18:36 - 00000000 ____D () C:\Users\Petra\Downloads\GSpot270a 2014-07-30 14:36 - 2014-07-30 14:36 - 00000000 ____D () C:\Users\Petra\Documents\GSpot270a 2014-07-30 14:35 - 2014-07-30 14:35 - 00411509 _____ () C:\Users\Petra\Downloads\GSpot270a.zip 2014-07-27 20:42 - 2014-08-17 09:13 - 00000000 ____D () C:\ProgramData\2308189059 2014-07-27 20:40 - 2014-07-27 20:40 - 00000000 ____D () C:\ProgramData\TEMP 2014-07-27 20:35 - 2014-07-27 20:35 - 00001656 _____ () C:\Users\Public\Desktop\Free AVI Video Converter.lnk 2014-07-27 20:34 - 2014-07-27 20:37 - 00000000 ____D () C:\Users\Petra\AppData\Local\Rocket 2014-07-27 20:33 - 2014-08-19 16:33 - 00000292 _____ () C:\Windows\Tasks\Rocket Updater.job 2014-07-27 20:33 - 2014-07-27 20:33 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\RocketUpdater 2014-07-27 20:29 - 2014-07-27 20:30 - 01526024 _____ (Koyote-Lab Inc) C:\Users\Petra\Downloads\FreeVideoConverterSetup-r135-n-bf(1).exe 2014-07-27 20:29 - 2014-07-27 20:29 - 00723336 _____ ( ) C:\Users\Petra\Downloads\FreeAVIVideoConverter.exe 2014-07-27 20:18 - 2014-07-28 08:20 - 00000000 ____D () C:\Users\Petra\AppData\Local\{7B9F2A39-A1FC-4DDE-BD59-73914D1F96A7} 2014-07-24 20:29 - 2014-07-24 20:29 - 00004608 _____ () C:\Users\Petra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-21 20:31 - 2014-07-21 20:32 - 00000000 ____D () C:\Users\Petra\AppData\Local\{5F75AAF1-365A-4D11-9D79-8536E2D97E6A} ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-19 16:35 - 2014-08-19 16:35 - 00024510 _____ () C:\Users\Petra\Downloads\FRST.txt 2014-08-19 16:35 - 2014-08-19 16:34 - 00000000 ___DC () C:\FRST 2014-08-19 16:35 - 2009-07-14 06:34 - 00028944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-19 16:35 - 2009-07-14 06:34 - 00028944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-19 16:34 - 2013-12-24 15:53 - 25666560 _____ () C:\Users\Petra\Outlook.pst 2014-08-19 16:33 - 2014-08-19 16:33 - 01093632 _____ (Farbar) C:\Users\Petra\Downloads\FRST.exe 2014-08-19 16:33 - 2014-07-27 20:33 - 00000292 _____ () C:\Windows\Tasks\Rocket Updater.job 2014-08-19 16:33 - 2014-04-13 09:33 - 00000292 _____ () C:\Windows\Tasks\MySearchDial.job 2014-08-19 16:28 - 2014-01-22 15:18 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\inkscape 2014-08-19 16:17 - 2014-08-19 11:15 - 00065536 ___HT () C:\Users\Petra\~Outlook.pst.tmp 2014-08-19 16:17 - 2013-11-06 20:51 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-08-19 16:17 - 2013-05-31 07:17 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-19 16:16 - 2013-03-29 16:33 - 00000000 ____D () C:\Users\Petra 2014-08-19 16:15 - 2013-11-26 19:36 - 00000000 ____D () C:\Users\Petra\AppData\Local\CrashDumps 2014-08-19 16:15 - 2013-03-29 16:22 - 01153557 ____N () C:\Windows\WindowsUpdate.log 2014-08-19 16:15 - 2012-08-23 18:01 - 00000000 ____D () C:\Windows\Panther 2014-08-19 16:13 - 2014-08-19 16:13 - 00000000 ___DC () C:\Program Files\SmarotCompAre 2014-08-19 16:13 - 2014-08-17 09:33 - 00000000 ____D () C:\ProgramData\SmarotCompAre 2014-08-19 16:13 - 2014-08-17 09:33 - 00000000 ____D () C:\ProgramData\b089358267e0237d 2014-08-19 16:12 - 2013-04-27 19:26 - 00000000 ____D () C:\ProgramData\Adobe 2014-08-19 16:07 - 2013-06-24 10:30 - 00000000 ___RD () C:\Users\Petra\Dropbox 2014-08-19 16:07 - 2013-06-24 10:27 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-19 16:07 - 2013-06-24 10:27 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Dropbox 2014-08-19 11:17 - 2013-05-31 07:17 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-17 09:13 - 2014-08-17 09:13 - 00000000 ____D () C:\ProgramData\WinSpeed 2014-08-17 09:13 - 2014-07-27 20:42 - 00000000 ____D () C:\ProgramData\2308189059 2014-08-15 16:21 - 2010-11-20 23:01 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-15 08:43 - 2013-05-31 07:22 - 00002128 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-08-14 21:09 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-08-14 08:53 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-08-14 08:30 - 2013-12-21 17:55 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\newnext.me 2014-08-14 08:28 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-14 08:28 - 2009-07-14 06:33 - 00409176 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-14 08:26 - 2014-05-07 09:17 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-14 08:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-08-14 08:10 - 2013-04-07 15:35 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-13 10:27 - 2014-08-13 10:17 - 70454999 _____ () C:\Users\Petra\Downloads\Heidi_Folge_16_deutsch.mp4 2014-08-13 10:27 - 2014-08-13 10:17 - 69942527 _____ () C:\Users\Petra\Downloads\Heidi_Folge_17_deutsch.mp4 2014-08-13 10:27 - 2014-08-13 10:16 - 75299683 _____ () C:\Users\Petra\Downloads\Heidi_Folge_15_deutsch.mp4 2014-08-13 10:26 - 2014-08-13 10:15 - 73407198 _____ () C:\Users\Petra\Downloads\Heidi_Folge_14_deutsch.mp4 2014-08-13 10:25 - 2014-08-13 10:14 - 83459007 _____ () C:\Users\Petra\Downloads\Heidi_Folge_13_deutsch.mp4 2014-08-13 10:24 - 2014-08-13 10:12 - 81268667 _____ () C:\Users\Petra\Downloads\Heidi_Folge_11_deutsch.mp4 2014-08-13 10:24 - 2014-08-13 10:12 - 80383649 _____ () C:\Users\Petra\Downloads\Heidi_Folge_12_deutsch.mp4 2014-08-13 10:14 - 2014-08-13 10:11 - 70934097 _____ () C:\Users\Petra\Downloads\Heidi_Folge_10_deutsch.mp4 2014-08-08 13:59 - 2014-05-05 20:11 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-08-08 13:58 - 2013-05-20 21:00 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\DVDVideoSoft 2014-08-08 13:57 - 2014-05-05 20:14 - 00000000 ___DC () C:\Program Files\SearchProtect 2014-08-08 13:57 - 2013-05-20 21:01 - 00002283 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2014-08-08 13:57 - 2013-05-20 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2014-08-08 13:57 - 2013-05-20 21:00 - 00000000 ____D () C:\Program Files\DVDVideoSoft 2014-08-08 13:57 - 2013-05-20 21:00 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft 2014-08-08 13:56 - 2013-05-20 21:00 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\OpenCandy 2014-08-08 13:54 - 2014-08-08 13:53 - 29553288 _____ (DVDVideoSoft Ltd. ) C:\Users\Petra\Downloads\FreeYouTubeToMP3Converter(2).exe 2014-08-07 20:53 - 2014-08-07 20:53 - 00000964 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-08-07 20:53 - 2014-01-09 16:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-08-07 03:43 - 2014-08-13 09:06 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 03:39 - 2014-08-13 09:06 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-05 19:58 - 2014-08-05 19:58 - 01868412 _____ () C:\Users\Petra\Downloads\PAKA5.psd 2014-08-04 15:49 - 2013-11-24 13:28 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\HpUpdate 2014-08-03 16:48 - 2013-11-21 12:17 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-07-31 09:55 - 2014-05-11 20:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-07-30 18:36 - 2014-07-30 14:49 - 00000000 ____D () C:\Users\Petra\Downloads\GSpot270a 2014-07-30 14:36 - 2014-07-30 14:36 - 00000000 ____D () C:\Users\Petra\Documents\GSpot270a 2014-07-30 14:35 - 2014-07-30 14:35 - 00411509 _____ () C:\Users\Petra\Downloads\GSpot270a.zip 2014-07-28 08:20 - 2014-07-27 20:18 - 00000000 ____D () C:\Users\Petra\AppData\Local\{7B9F2A39-A1FC-4DDE-BD59-73914D1F96A7} 2014-07-27 20:40 - 2014-07-27 20:40 - 00000000 ____D () C:\ProgramData\TEMP 2014-07-27 20:37 - 2014-07-27 20:34 - 00000000 ____D () C:\Users\Petra\AppData\Local\Rocket 2014-07-27 20:35 - 2014-07-27 20:35 - 00001656 _____ () C:\Users\Public\Desktop\Free AVI Video Converter.lnk 2014-07-27 20:35 - 2013-05-20 21:01 - 00001208 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2014-07-27 20:33 - 2014-07-27 20:33 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\RocketUpdater 2014-07-27 20:32 - 2013-11-21 12:17 - 00001104 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-07-27 20:30 - 2014-07-27 20:29 - 01526024 _____ (Koyote-Lab Inc) C:\Users\Petra\Downloads\FreeVideoConverterSetup-r135-n-bf(1).exe 2014-07-27 20:29 - 2014-07-27 20:29 - 00723336 _____ ( ) C:\Users\Petra\Downloads\FreeAVIVideoConverter.exe 2014-07-27 20:15 - 2014-04-20 20:58 - 00000578 _____ () C:\Users\Petra\Desktop\DVDStyler.lnk 2014-07-26 08:11 - 2012-08-23 08:14 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-25 09:09 - 2012-08-23 08:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-24 20:29 - 2014-07-24 20:29 - 00004608 _____ () C:\Users\Petra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-24 20:07 - 2014-08-13 09:06 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-24 19:58 - 2014-08-13 09:06 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-24 19:57 - 2014-08-13 09:05 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-24 19:52 - 2014-08-13 09:06 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-24 19:51 - 2014-08-13 09:06 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-24 19:51 - 2014-08-13 09:05 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-24 19:50 - 2014-08-13 09:05 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-07-24 19:50 - 2014-08-13 09:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-24 19:49 - 2014-08-13 09:06 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-24 19:49 - 2014-08-13 09:06 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-24 19:49 - 2014-08-13 09:05 - 01802240 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-24 19:49 - 2014-08-13 09:05 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-24 19:49 - 2014-08-13 09:05 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-24 19:48 - 2014-08-13 09:06 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-24 19:48 - 2014-08-13 09:06 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-24 19:48 - 2014-08-13 09:06 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-24 19:48 - 2014-08-13 09:06 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-07-24 19:48 - 2014-08-13 09:06 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-07-24 19:48 - 2014-08-13 09:06 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-07-24 19:48 - 2014-08-13 09:05 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-24 19:47 - 2014-08-13 09:06 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-21 20:32 - 2014-07-21 20:31 - 00000000 ____D () C:\Users\Petra\AppData\Local\{5F75AAF1-365A-4D11-9D79-8536E2D97E6A} Some content of TEMP: ==================== C:\Users\Petra\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpyzxxur.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-17 09:56 ==================== End Of Log ============================ |
hi, ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Addition.txt fehlt noch. |
Sorry - hab ich überlesen! Addition.txt Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version:17-08-2014 01 FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-08-2014 01 --- --- --- |
Adware & Co. deinstallieren
Scan mit Combofix
|
Code: ComboFix 14-08-19.01 - Petra 20.08.2014 15:38:53.1.2 - x86 |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Code: Malwarebytes Anti-Malware Code: # AdwCleaner v3.308 - Bericht erstellt am 21/08/2014 um 14:06:06 Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-08-2014 01 lg Petra - bin überrascht was ich alles kann ! |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
Code: ESETSmartInstaller@High as downloader log: Code: UNSUPPORTED OPERATING SYSTEM! ABORTED! Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:21-08-2014 Nein Probleme hab ich seit gestern keine mehr - kannst du mir auch sagen wo ich mir das eingefangen haben könnte? Lg |
Da war jede Menge Adware. Backup auf E löschen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Code: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:23-08-2014 |
fertig :) |
Hallo Schrauber- hab gerade gesehen dass auf verschiedenen Webseiten Wörter doppelt blau unterstrichen sind - wenn ich den Courser draufstelle erscheint ein Fenster - Update your Flashplayer??? fängt das jetzt schon wieder an ???? |
In welchem Browser? |
Mozilla Firefox - außerdem soll ich immer irgendetwas neu updaten JAVA , Flash Player usw.- macht sich immer selbstständig auf Das ist vom uninstall Combofix - ist das so ok? Code: ComboFix 14-08-24.01 - Petra 24.08.2014 8:32.2.2 - x86 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 22:11 Uhr. |
Copyright ©2000-2025, Trojaner-Board