goerissen | 21.09.2014 09:48 | Hallo,
ich habe erst jetzt am Wochenende Zeit gefunden, die empfohlenen Programme laufen zu lassen. Hat aber alles problemlos geklappt. Hier sind die gewünschten Logdateien: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 21.09.2014
Suchlauf-Zeit: 09:51:37
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.09.21.02
Rootkit Datenbank: v2014.09.19.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: R.Görissen
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 306932
Verstrichene Zeit: 4 Min, 56 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 9
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-4091200504-1909673753-3696778210-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, In Quarantäne, [6adcc62a4b3055e135bbc0c924de12ee],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, In Quarantäne, [6adcc62a4b3055e135bbc0c924de12ee],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw, In Quarantäne, [91b541afd2a9cd69aa4d4ac155ae8d73],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [2f1727c984f7989e47fd73a172917b85],
PUP.Optional.Webget.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update webget, In Quarantäne, [e066628e2853c07602ba56ce3cc7a45c],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4091200504-1909673753-3696778210-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [a6a07c74b3c82f07137f380122e18080],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4091200504-1909673753-3696778210-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [d37309e7b4c760d615dd3916f60ef40c],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-4091200504-1909673753-3696778210-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [82c45e92ee8d2a0c222119fb24dff20e],
PUP.Optional.Updater.A, HKU\S-1-5-21-4091200504-1909673753-3696778210-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Digital Sites, In Quarantäne, [21257a76304b94a2e67335bf39c99c64],
Registrierungswerte: 2
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files\Mysearchdial\1.8.29.0\, In Quarantäne, [4cfa7977e69591a5ca90501f699be818]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4091200504-1909673753-3696778210-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0X2O1C0R2R1R, In Quarantäne, [d37309e7b4c760d615dd3916f60ef40c]
Registrierungsdaten: 2
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_18_ff&cd=2XzuyEtN2Y1L1QzuzyyE0D0EzztD0CyEyDyC0FtDzy0D0CtCtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0AyB0A0C0B0DyDtGtBtDyDzztG0EyCtB0DtGyCtB0BzytGyEyEtB0C0Czzzz0AtCzyyEyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtD0CtAtBtA0AtCtG0CyCzzyCtGtD0BzztCtGtDyDzzyCtGyCtA0E0E0ByEtDyB0DzyzztB2Q&cr=2025704475&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_18_ff&cd=2XzuyEtN2Y1L1QzuzyyE0D0EzztD0CyEyDyC0FtDzy0D0CtCtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0AyB0A0C0B0DyDtGtBtDyDzztG0EyCtB0DtGyCtB0BzytGyEyEtB0C0Czzzz0AtCzyyEyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtD0CtAtBtA0AtCtG0CyCzzyCtGtD0BzztCtGtDyDzzyCtGyCtA0E0E0ByEtDyB0DzyzztB2Q&cr=2025704475&ir=),Ersetzt,[80c6e808d6a5dc5a1a7765a13acb49b7]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-4091200504-1909673753-3696778210-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_18_ff&cd=2XzuyEtN2Y1L1QzuzyyE0D0EzztD0CyEyDyC0FtDzy0D0CtCtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0AyB0A0C0B0DyDtGtBtDyDzztG0EyCtB0DtGyCtB0BzytGyEyEtB0C0Czzzz0AtCzyyEyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtD0CtAtBtA0AtCtG0CyCzzyCtGtD0BzztCtGtDyDzzyCtGyCtA0E0E0ByEtDyB0DzyzztB2Q&cr=2025704475&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_18_ff&cd=2XzuyEtN2Y1L1QzuzyyE0D0EzztD0CyEyDyC0FtDzy0D0CtCtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0AyB0A0C0B0DyDtGtBtDyDzztG0EyCtB0DtGyCtB0BzytGyEyEtB0C0Czzzz0AtCzyyEyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtD0CtAtBtA0AtCtG0CyCzzyCtGtD0BzztCtGtDyDzzyCtGyCtA0E0E0ByEtDyB0DzyzztB2Q&cr=2025704475&ir=),Ersetzt,[fb4b2bc5572470c65c34f511ac59d62a]
Ordner: 7
PUP.Optional.MySearchDial.A, C:\Users\R.Görissen\AppData\Roaming\mysearchdial, In Quarantäne, [cd79e40c93e8c4727c0ffadc36ccf50b],
PUP.Optional.MySearchDial.A, C:\Users\R.Görissen\AppData\Roaming\mysearchdial\icons_2.20.6.0, In Quarantäne, [cd79e40c93e8c4727c0ffadc36ccf50b],
PUP.Optional.OpenCandy, C:\Users\R.Görissen\AppData\Roaming\OpenCandy, In Quarantäne, [3313bb354a3138fee6b30ec82cd69a66],
PUP.Optional.OpenCandy, C:\Users\R.Görissen\AppData\Roaming\OpenCandy\4FF80707EF9A40838AC8E27C9052A64A, In Quarantäne, [3313bb354a3138fee6b30ec82cd69a66],
PUP.Optional.OpenCandy, C:\Users\R.Görissen\AppData\Roaming\OpenCandy\92E78CCEC1BD4B61B7AB3E5E6F9372B3, In Quarantäne, [3313bb354a3138fee6b30ec82cd69a66],
PUP.Optional.SystemSpeedup, C:\Users\R.Görissen\AppData\Roaming\Systweak\ssd, In Quarantäne, [73d3ed03ee8d0333471c1dd26b97d52b],
PUP.Optional.Updater.A, C:\Users\R.Görissen\AppData\Roaming\DigitalSites\UpdateProc, In Quarantäne, [21257a76304b94a2e67335bf39c99c64],
Dateien: 10
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys, In Quarantäne, [91b541afd2a9cd69aa4d4ac155ae8d73],
PUP.Optional.OpenCandy, C:\Users\R.Görissen\AppData\Roaming\OpenCandy\4FF80707EF9A40838AC8E27C9052A64A\TuneUpUtilities2014_de-DE.exe, In Quarantäne, [3313bb354a3138fee6b30ec82cd69a66],
PUP.Optional.OpenCandy, C:\Users\R.Görissen\AppData\Roaming\OpenCandy\92E78CCEC1BD4B61B7AB3E5E6F9372B3\Whitesmoke_directN_p1v1.exe, In Quarantäne, [3313bb354a3138fee6b30ec82cd69a66],
PUP.Optional.SystemSpeedup, C:\Users\R.Görissen\AppData\Roaming\Systweak\ssd\SSDPTstub.exe, In Quarantäne, [73d3ed03ee8d0333471c1dd26b97d52b],
PUP.Optional.Updater.A, C:\Users\R.Görissen\AppData\Roaming\DigitalSites\UpdateProc\config.dat, In Quarantäne, [21257a76304b94a2e67335bf39c99c64],
PUP.Optional.Updater.A, C:\Users\R.Görissen\AppData\Roaming\DigitalSites\UpdateProc\info.dat, In Quarantäne, [21257a76304b94a2e67335bf39c99c64],
PUP.Optional.Updater.A, C:\Users\R.Görissen\AppData\Roaming\DigitalSites\UpdateProc\prod.dat, In Quarantäne, [21257a76304b94a2e67335bf39c99c64],
PUP.Optional.Updater.A, C:\Users\R.Görissen\AppData\Roaming\DigitalSites\UpdateProc\STTL.DAT, In Quarantäne, [21257a76304b94a2e67335bf39c99c64],
PUP.Optional.Updater.A, C:\Users\R.Görissen\AppData\Roaming\DigitalSites\UpdateProc\TTL.DAT, In Quarantäne, [21257a76304b94a2e67335bf39c99c64],
PUP.Optional.Updater.A, C:\Users\R.Görissen\AppData\Roaming\DigitalSites\UpdateProc\UpdateTask.exe, In Quarantäne, [21257a76304b94a2e67335bf39c99c64],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.310 - Bericht erstellt am 21/09/2014 um 10:25:48
# Aktualisiert 12/09/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : R.Görissen - RGÖRISSEN-PC
# Gestartet von : C:\Users\R.Görissen\Desktop\AdwCleaner_3.310.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\webget
Ordner Gelöscht : C:\Users\R.Görissen\AppData\Roaming\DigitalSites
Ordner Gelöscht : C:\Users\R.Görissen\AppData\Roaming\Systweak
Datei Gelöscht : C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\searchplugins\11-suche.xml
Datei Gelöscht : C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\searchplugins\Askcom.xml
Datei Gelöscht : C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\user.js
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updatewebget_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updatewebget_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\utilwebget_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\utilwebget_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\webget_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\webget_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17280
-\\ Mozilla Firefox v32.0.2 (x86 de)
[ Datei : C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.asktb.abar-war-timeout", "4000");
Zeile gelöscht : user_pref("extensions.asktb.autofill-competitor-query-enabled", true);
Zeile gelöscht : user_pref("extensions.asktb.cbid", "U3");
Zeile gelöscht : user_pref("extensions.asktb.config-updated", false);
Zeile gelöscht : user_pref("extensions.asktb.crumb", "2012.04.22+01.38.53-toolbar010iad-DE-SGFubm92ZXIsR2VybWFueQ%3D%3D");
Zeile gelöscht : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&o={o}&l={l}&gct=bar");
Zeile gelöscht : user_pref("extensions.asktb.displaybehavior", "");
Zeile gelöscht : user_pref("extensions.asktb.displaytext", "");
Zeile gelöscht : user_pref("extensions.asktb.dtid", "YYYYYYYYDE");
Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false);
Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "GMXX0051");
Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C");
Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q=");
Zeile gelöscht : user_pref("extensions.asktb.first-launch-url", "hxxp://newsletter.zweitausendeins.de/HS?a=ENX7Cqk5mL5d8SA9MKJB0C7nGHxKLY7EafcStGb5lw8W0bBhOG5mpqVsje_HhdBfQ1AX");
Zeile gelöscht : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \"WWW.google.com\", \"hxxps://websearch.ask.com\", [...]
Zeile gelöscht : user_pref("extensions.asktb.l", "dis");
Zeile gelöscht : user_pref("extensions.asktb.last-config-req", "1335083937408");
Zeile gelöscht : user_pref("extensions.asktb.last-v", "3.14.1.100009");
Zeile gelöscht : user_pref("extensions.asktb.locale", "de_DE");
Zeile gelöscht : user_pref("extensions.asktb.location", "Hannover,Germany");
Zeile gelöscht : user_pref("extensions.asktb.lstation", "");
Zeile gelöscht : user_pref("extensions.asktb.news-native-on", true);
Zeile gelöscht : user_pref("extensions.asktb.o", "100000027");
Zeile gelöscht : user_pref("extensions.asktb.pstate", "");
Zeile gelöscht : user_pref("extensions.asktb.qsrc", "2871");
Zeile gelöscht : user_pref("extensions.asktb.search-suggestions-enabled", true);
Zeile gelöscht : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Zeile gelöscht : user_pref("extensions.asktb.socialmini-first", true);
Zeile gelöscht : user_pref("extensions.asktb.socialmini-interval", "1200000");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-max-items", "30");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-native-on", true);
Zeile gelöscht : user_pref("extensions.asktb.socialmini-speed", "10000");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-transition-first-open", false);
Zeile gelöscht : user_pref("extensions.asktb.to", "");
*************************
AdwCleaner[R0].txt - [5139 octets] - [21/09/2014 10:20:41]
AdwCleaner[S0].txt - [5060 octets] - [21/09/2014 10:25:48]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5120 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.9 (09.20.2014:1)
OS: Windows 7 Professional x86
Ran by R.G”rissen on 21.09.2014 at 10:28:25,38
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update webget
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{637D6E3C-DF93-48A5-8362-159A8AC56B11}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
~~~ FireFox
Emptied folder: C:\Users\R.G”rissen\AppData\Roaming\mozilla\firefox\profiles\r1hudn24.default\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.09.2014 at 10:36:14,85
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-09-2014
Ran by R.Görissen (administrator) on RGÖRISSEN-PC on 21-09-2014 10:40:20
Running from C:\Users\R.Görissen\Downloads
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(ABBYY (BIT Software)) C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Elaborate Bytes AG) C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Siemens AG) C:\Windows\System32\SerExt.exe
() C:\Program Files\Avanquest\PDF Experte 8 Professional\vspdfprsrv.exe
(Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Sonic Solutions) C:\Program Files\Common Files\Sonic Shared\cinetray.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
() C:\Windows\System32\PSIService.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [4017296 2012-08-09] (VIA)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM\...\Run: [USB3MON] => C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [VirtualCloneDrive] => C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [751184 2014-07-30] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [QuickFinder Scheduler] => C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE [83568 2007-01-02] (Corel Corporation)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2296600 2013-07-31] (Logitech, Inc.)
HKLM\...\Run: [SerExt] => SerExt.exe /unplug
HKLM\...\Run: [vspdfprsrv.exe] => C:\Program Files\Avanquest\PDF Experte 8 Professional\vspdfprsrv.exe [7328256 2013-12-17] ()
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [164656 2014-08-27] (Avira Operations GmbH & Co. KG)
HKLM\...\RunServicesOnce: [capscanuninstall] => "C:\Windows\system32\command.com" /c del "C:\Users\R9F62~1.GRI\AppData\Local\Temp\uninstal.exe" <===== ATTENTION
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-4091200504-1909673753-3696778210-1000\...\Policies\Explorer: [NoCDBurning] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk
ShortcutTarget: Sonic CinePlayer Quick Launch.lnk -> C:\Program Files\Common Files\Sonic Shared\cinetray.exe (Sonic Solutions)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4FBB93199955CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default
FF DefaultSearchEngine: foxsearch
FF SearchEngineOrder.1: foxsearch
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\searchplugins\avira-safesearch.xml
FF SearchPlugin: C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\Extensions\abs@avira.com [2014-09-07]
FF Extension: German Dictionary - C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\Extensions\de-DE@dictionaries.addons.mozilla.org [2014-06-10]
FF Extension: Garmin Communicator - C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-04-16]
FF Extension: Google Toolbar for Firefox - C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}(2) [2014-04-16]
FF Extension: No Name - C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}-trash [2014-04-16]
FF Extension: DownloadHelper - C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-07]
FF Extension: Adblock Plus - C:\Users\R.Görissen\AppData\Roaming\Mozilla\Firefox\Profiles\r1hudn24.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-26]
FF HKLM\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-04-16]
Chrome:
=======
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ABBYY.Licensing.FineReader.Professional.9.0; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [759072 2008-10-27] (ABBYY (BIT Software))
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [804944 2014-07-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-07-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1021520 2014-07-30] (Avira Operations GmbH & Co. KG)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160048 2014-08-27] (Avira Operations GmbH & Co. KG)
S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [276288 2012-08-25] (Intel Corporation)
R3 ICCS; C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [174656 2006-11-02] () [File not signed]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.)
S3 xControlCOM; C:\Program Files\Gigaset DECT\talk&surf\xcontrolcom.exe [327680 2005-03-01] (Siemens) [File not signed]
S3 NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 anvsnddrv; C:\Windows\System32\drivers\anvsnddrv.sys [32896 2011-11-28] (AnvSoft Inc.) [File not signed]
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [19608 2012-10-25] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [97648 2014-06-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [35848 2014-07-10] (Avira Operations GmbH & Co. KG)
R1 Cinemsup; C:\Windows\system32\drivers\cinemsup.sys [6656 2002-07-19] (Sonic Solutions) [File not signed]
R3 DectEnum; C:\Windows\System32\Drivers\DectEnum.sys [8448 2005-03-01] (Siemens AG) [File not signed]
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG)
R3 EtronHub3; C:\Windows\System32\Drivers\EtronHub3.sys [51328 2012-08-07] (Etron Technology Inc)
R3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [71552 2012-08-07] (Etron Technology Inc)
S3 gdrv; C:\Windows\gdrv.sys [17488 2014-09-17] (Windows (R) 2000 DDK provider)
R3 Gigusb; C:\Windows\System32\Drivers\Gigusb.sys [53632 2005-03-01] (Siemens AG) [File not signed]
S3 HRCMPA; C:\Windows\System32\DRIVERS\hrcmpa.sys [263751 2004-09-08] (SIEMENS AG) [File not signed]
R3 IUAPIWDM; C:\Windows\System32\DRIVERS\IUAPIWDM.sys [50759 2004-09-08] (SIEMENS AG) [File not signed]
R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [15680 2012-05-20] (Intel Corporation)
R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [350016 2012-05-20] (Intel Corporation)
R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [793920 2012-05-20] (Intel Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [99992 2012-07-19] (Qualcomm Atheros Co., Ltd.)
R3 LEqdUsb; C:\Windows\System32\Drivers\LEqdUsb.Sys [42264 2013-05-23] (Logitech, Inc.)
R3 LHidEqd; C:\Windows\System32\Drivers\LHidEqd.Sys [10136 2013-05-23] (Logitech, Inc.)
R3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [28312 2013-05-23] (Logitech, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-09-21] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-17] (Intel Corporation)
R3 siellif; C:\Windows\System32\Drivers\siellif.sys [113408 2005-03-01] (Siemens AG) [File not signed]
R3 SkyNetBDA; C:\Windows\System32\DRIVERS\SkyNetBDA.sys [622040 2011-04-13] (TechniSat Digital, S.A.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-02-25] (Avira GmbH)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1840272 2012-08-03] (VIA Technologies, Inc.)
S3 catchme; \??\C:\Users\R9F62~1.GRI\AppData\Local\Temp\catchme.sys [X]
U3 DfSdkS; No ImagePath
U5 GVTDrv; C:\Windows\system32\Drivers\GVTDrv.sys [24944 2014-09-17] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-21 10:40 - 2014-09-21 10:40 - 00016241 _____ () C:\Users\R.Görissen\Downloads\FRST.txt
2014-09-21 10:36 - 2014-09-21 10:36 - 00001109 _____ () C:\Users\R.Görissen\Desktop\JRT.txt
2014-09-21 10:28 - 2014-09-21 10:28 - 00000000 ____D () C:\Windows\ERUNT
2014-09-21 10:27 - 2014-09-21 10:27 - 00005200 _____ () C:\Users\R.Görissen\Desktop\AdwCleaner[S0].txt
2014-09-21 10:20 - 2014-09-21 10:25 - 00000000 ____D () C:\AdwCleaner
2014-09-21 10:19 - 2014-09-21 10:19 - 00007602 _____ () C:\Users\R.Görissen\Desktop\mbam.txt
2014-09-21 09:51 - 2014-09-21 10:27 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-21 09:50 - 2014-09-21 09:50 - 00001077 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-21 09:50 - 2014-09-21 09:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-21 09:50 - 2014-09-21 09:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-21 09:50 - 2014-09-21 09:50 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-09-21 09:50 - 2014-09-15 16:57 - 01097728 _____ (Farbar) C:\Users\R.Görissen\Downloads\FRST.exe
2014-09-21 09:50 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-21 09:50 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-21 09:50 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-21 09:47 - 2014-09-21 09:47 - 01027006 _____ (Thisisu) C:\Users\R.Görissen\Downloads\JRT.exe
2014-09-21 09:45 - 2014-09-21 09:45 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\R.Görissen\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-19 15:29 - 2014-09-19 15:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-09-17 15:51 - 2014-09-17 15:51 - 00016964 _____ () C:\ComboFix.txt
2014-09-17 15:49 - 2014-09-21 10:26 - 00005998 _____ () C:\Windows\PFRO.log
2014-09-17 15:38 - 2014-09-17 15:51 - 00000000 ____D () C:\ComboFix
2014-09-17 15:38 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-17 15:38 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-17 15:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-17 15:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-17 15:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-17 15:38 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-17 15:38 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-17 15:38 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-17 15:37 - 2014-09-17 15:51 - 00000000 ____D () C:\Qoobox
2014-09-17 15:37 - 2014-09-17 15:50 - 00000000 ____D () C:\Windows\erdnt
2014-09-17 15:36 - 2014-09-17 15:36 - 05579386 ____R (Swearware) C:\Users\R.Görissen\Downloads\ComboFix.exe
2014-09-15 17:18 - 2014-09-15 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-09-15 17:18 - 2014-09-15 17:18 - 00000000 ____D () C:\Program Files\7-Zip
2014-09-15 16:58 - 2014-09-21 10:40 - 00000000 ____D () C:\FRST
2014-09-14 15:19 - 2014-09-14 15:19 - 00000994 _____ () C:\Users\Public\Desktop\DVBViewer.lnk
2014-09-12 19:00 - 2014-09-12 19:00 - 00149936 _____ () C:\Windows\Minidump\091214-14305-01.dmp
2014-09-12 14:48 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-12 14:48 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-12 14:48 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-12 14:48 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-12 14:48 - 2014-08-18 23:57 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-12 14:48 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-12 14:48 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-12 14:48 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-12 14:48 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-12 14:48 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-12 14:48 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-12 14:48 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-12 14:48 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-12 14:48 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-12 14:48 - 2014-08-18 23:36 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-12 14:48 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-12 14:48 - 2014-08-18 23:30 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-12 14:48 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-12 14:48 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-12 14:48 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-12 14:48 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-12 14:48 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-12 14:48 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-12 14:48 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-12 14:48 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-12 14:48 - 2014-08-18 23:08 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-12 14:48 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-12 14:48 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-12 14:48 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-12 14:48 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-12 14:48 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-12 13:58 - 2014-09-05 03:52 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-12 13:58 - 2014-09-05 03:47 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-12 13:58 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-12 13:58 - 2014-07-07 03:40 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-12 13:58 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-12 13:58 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-08 00:01 - 2014-09-08 00:01 - 00149936 _____ () C:\Windows\Minidump\090814-14305-01.dmp
2014-09-07 18:31 - 2014-09-07 18:31 - 00001426 _____ () C:\Users\Public\Desktop\LibreOffice 4.2.lnk
2014-09-07 18:31 - 2014-09-07 18:31 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2014-08-30 17:48 - 2014-08-30 17:48 - 00000000 ____D () C:\Users\R.Görissen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MainConcept
2014-08-30 17:48 - 2014-08-30 17:48 - 00000000 ____D () C:\Program Files\MainConcept
2014-08-29 18:00 - 2014-08-29 18:00 - 00149936 _____ () C:\Windows\Minidump\082914-13618-01.dmp
2014-08-29 03:26 - 2014-08-29 03:26 - 00149936 _____ () C:\Windows\Minidump\082914-12168-01.dmp
2014-08-27 19:46 - 2014-08-23 03:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-27 19:46 - 2014-08-23 02:42 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 13:43 - 2014-09-21 10:26 - 00003528 _____ () C:\Windows\setupact.log
2014-08-27 13:43 - 2014-08-27 13:43 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-25 18:54 - 2014-08-25 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Axantum AxCrypt
2014-08-25 18:54 - 2014-08-25 18:54 - 00000000 ____D () C:\Program Files\Axantum
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-21 10:40 - 2014-09-21 10:40 - 00016241 _____ () C:\Users\R.Görissen\Downloads\FRST.txt
2014-09-21 10:40 - 2014-09-15 16:58 - 00000000 ____D () C:\FRST
2014-09-21 10:36 - 2014-09-21 10:36 - 00001109 _____ () C:\Users\R.Görissen\Desktop\JRT.txt
2014-09-21 10:34 - 2009-07-14 06:34 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-21 10:34 - 2009-07-14 06:34 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-21 10:32 - 2010-11-20 23:01 - 01628312 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-21 10:28 - 2014-09-21 10:28 - 00000000 ____D () C:\Windows\ERUNT
2014-09-21 10:27 - 2014-09-21 10:27 - 00005200 _____ () C:\Users\R.Görissen\Desktop\AdwCleaner[S0].txt
2014-09-21 10:27 - 2014-09-21 09:51 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-21 10:26 - 2014-09-17 15:49 - 00005998 _____ () C:\Windows\PFRO.log
2014-09-21 10:26 - 2014-08-27 13:43 - 00003528 _____ () C:\Windows\setupact.log
2014-09-21 10:26 - 2014-04-11 19:43 - 01397006 _____ () C:\Windows\WindowsUpdate.log
2014-09-21 10:26 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-21 10:25 - 2014-09-21 10:20 - 00000000 ____D () C:\AdwCleaner
2014-09-21 10:19 - 2014-09-21 10:19 - 00007602 _____ () C:\Users\R.Görissen\Desktop\mbam.txt
2014-09-21 10:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\SchCache
2014-09-21 10:12 - 2014-04-11 17:25 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-21 09:50 - 2014-09-21 09:50 - 00001077 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-21 09:50 - 2014-09-21 09:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-21 09:50 - 2014-09-21 09:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-21 09:50 - 2014-09-21 09:50 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-09-21 09:47 - 2014-09-21 09:47 - 01027006 _____ (Thisisu) C:\Users\R.Görissen\Downloads\JRT.exe
2014-09-21 09:45 - 2014-09-21 09:45 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\R.Görissen\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-21 09:38 - 2014-05-04 15:34 - 00013603 _____ () C:\hoTrace.log
2014-09-20 12:44 - 2014-04-14 17:42 - 00000000 ____D () C:\Program Files\ABBYY FineReader 9.0
2014-09-19 19:40 - 2014-04-12 13:53 - 00000900 ___SH () C:\Windows\system32\KGyGaAvL.sys
2014-09-19 19:40 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-09-19 19:14 - 2014-04-11 20:02 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-09-19 15:29 - 2014-09-19 15:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-09-17 15:51 - 2014-09-17 15:51 - 00016964 _____ () C:\ComboFix.txt
2014-09-17 15:51 - 2014-09-17 15:38 - 00000000 ____D () C:\ComboFix
2014-09-17 15:51 - 2014-09-17 15:37 - 00000000 ____D () C:\Qoobox
2014-09-17 15:51 - 2014-05-04 18:45 - 00000000 ___RD () C:\Users\Public
2014-09-17 15:50 - 2014-09-17 15:37 - 00000000 ____D () C:\Windows\erdnt
2014-09-17 15:49 - 2014-04-11 17:19 - 00017488 _____ (Windows (R) 2000 DDK provider) C:\Windows\gdrv.sys
2014-09-17 15:49 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-09-17 15:36 - 2014-09-17 15:36 - 05579386 ____R (Swearware) C:\Users\R.Görissen\Downloads\ComboFix.exe
2014-09-17 15:29 - 2014-05-01 15:29 - 00000087 _____ () C:\Users\R.Görissen\AppData\Roaming\WB.CFG
2014-09-17 15:29 - 2014-04-11 17:19 - 00024944 _____ () C:\Windows\system32\Drivers\GVTDrv.sys
2014-09-17 12:45 - 2014-04-11 17:22 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-15 17:18 - 2014-09-15 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-09-15 17:18 - 2014-09-15 17:18 - 00000000 ____D () C:\Program Files\7-Zip
2014-09-15 16:57 - 2014-09-21 09:50 - 01097728 _____ (Farbar) C:\Users\R.Görissen\Downloads\FRST.exe
2014-09-14 15:44 - 2014-05-20 14:40 - 00000205 _____ () C:\Users\R.Görissen\AppData\Roaming\default.rss
2014-09-14 15:44 - 2014-05-04 11:45 - 00000069 _____ () C:\Windows\NeroDigital.ini
2014-09-14 15:19 - 2014-09-14 15:19 - 00000994 _____ () C:\Users\Public\Desktop\DVBViewer.lnk
2014-09-14 15:19 - 2014-04-13 18:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVBViewer
2014-09-14 15:19 - 2014-04-13 18:07 - 00000000 ____D () C:\Program Files\DVBViewer
2014-09-14 14:08 - 2014-04-16 18:26 - 00000000 ____D () C:\Users\R.Görissen\AppData\Roaming\Canon
2014-09-13 14:58 - 2014-05-06 16:51 - 00000000 __RHD () C:\Users\Public\Libraries
2014-09-13 12:26 - 2014-04-16 13:37 - 00000000 ____D () C:\Program Files\LAV Filters
2014-09-12 19:00 - 2014-09-12 19:00 - 00149936 _____ () C:\Windows\Minidump\091214-14305-01.dmp
2014-09-12 19:00 - 2014-05-01 13:21 - 358765658 _____ () C:\Windows\MEMORY.DMP
2014-09-12 19:00 - 2014-05-01 13:21 - 00000000 ____D () C:\Windows\Minidump
2014-09-12 15:39 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-09-12 14:48 - 2014-04-11 18:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-12 14:47 - 2014-05-02 09:56 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-12 14:47 - 2014-04-11 18:00 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-10 20:12 - 2014-04-11 17:25 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-09-10 20:12 - 2014-04-11 17:25 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-09-10 19:48 - 2014-05-12 12:04 - 00001108 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-09-10 19:48 - 2014-04-11 20:05 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-10 19:48 - 2014-04-11 20:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-09-10 19:48 - 2014-04-11 20:05 - 00000000 ____D () C:\Program Files\Avira
2014-09-09 18:16 - 2014-06-11 14:47 - 00000000 ____D () C:\Users\R.Görissen\AppData\Local\Adobe
2014-09-08 00:01 - 2014-09-08 00:01 - 00149936 _____ () C:\Windows\Minidump\090814-14305-01.dmp
2014-09-08 00:01 - 2014-04-11 17:21 - 00292120 _____ () C:\Users\R.Görissen\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-08 00:01 - 2009-07-14 06:33 - 01090864 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-08 00:00 - 2014-05-06 16:56 - 00000380 _____ () C:\Windows\Tasks\NeroLiveEpgUpdate-RGörissen-PC_R.Görissen.job
2014-09-07 18:31 - 2014-09-07 18:31 - 00001426 _____ () C:\Users\Public\Desktop\LibreOffice 4.2.lnk
2014-09-07 18:31 - 2014-09-07 18:31 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2014-09-07 18:31 - 2014-04-13 10:56 - 00000000 ____D () C:\Program Files\LibreOffice 4
2014-09-05 03:52 - 2014-09-12 13:58 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-05 03:47 - 2014-09-12 13:58 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-30 17:48 - 2014-08-30 17:48 - 00000000 ____D () C:\Users\R.Görissen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MainConcept
2014-08-30 17:48 - 2014-08-30 17:48 - 00000000 ____D () C:\Program Files\MainConcept
2014-08-29 18:00 - 2014-08-29 18:00 - 00149936 _____ () C:\Windows\Minidump\082914-13618-01.dmp
2014-08-29 03:26 - 2014-08-29 03:26 - 00149936 _____ () C:\Windows\Minidump\082914-12168-01.dmp
2014-08-27 13:43 - 2014-08-27 13:43 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-27 10:08 - 2014-05-17 12:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kyocera
2014-08-25 18:54 - 2014-08-25 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Axantum AxCrypt
2014-08-25 18:54 - 2014-08-25 18:54 - 00000000 ____D () C:\Program Files\Axantum
2014-08-25 17:31 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-25 06:53 - 2014-04-11 17:39 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-23 03:46 - 2014-08-27 19:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 02:42 - 2014-08-27 19:46 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
Some content of TEMP:
====================
C:\Users\R.Görissen\AppData\Local\temp\avgnt.exe
C:\Users\R.Görissen\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-17 18:45
==================== End Of Log ============================ --- --- ---
und... Vielen Dank!! |