Hallo Schrauber :D
Ich sach mal wieder :dankeschoen: und poste dir meine neusten Logfiles :daumenhoc mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 05.12.2014
Suchlauf-Zeit: 14:22:32
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2014.12.05.05
Rootkit Datenbank: v2014.12.03.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Doris
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 370905
Verstrichene Zeit: 13 Min, 21 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 3
PUP.Optional.Snapdo.T, HKU\S-1-5-21-781550069-2462040875-601678507-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [38015f00a0dcde58048f14f01de65ea2],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-781550069-2462040875-601678507-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [38015f00a0dcde58048f14f01de65ea2],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [38015f00a0dcde58048f14f01de65ea2],
Registrierungswerte: 4
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [bd7ce67909734aec379a8dc836cdad53]
PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [19201e41ed8fb185646dcb8af40f639d]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-781550069-2462040875-601678507-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [3cfd99c63e3ed6607df4f76832d137c9]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-781550069-2462040875-601678507-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [2b0e5c0391eb2b0be58cc39c7a89f40c]
Registrierungsdaten: 11
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}),Ersetzt,[3dfcf76807758ea8bb5e89cfd431c63a]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-781550069-2462040875-601678507-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}),Ersetzt,[fb3ee17ec8b4bc7a2bf1461231d42ad6]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-781550069-2462040875-601678507-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6KKuzLN3PH1wC-k9UviqLHwkQeVgWEvIwyndenzDzHEoqTfuw7nKReolUXVQFo8JDq5yEIBlrJL79vnRvcdtHVUQUD5-hHxm7Q8A,,, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6KKuzLN3PH1wC-k9UviqLHwkQeVgWEvIwyndenzDzHEoqTfuw7nKReolUXVQFo8JDq5yEIBlrJL79vnRvcdtHVUQUD5-hHxm7Q8A,,),Ersetzt,[5fda0a551d5f41f59c8186d207fe0ef2]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-781550069-2462040875-601678507-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}),Ersetzt,[97a2b4ab13695fd79586332531d46898]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-781550069-2462040875-601678507-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}),Ersetzt,[ce6b510e5b2194a296884a0e34d144bc]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-781550069-2462040875-601678507-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}),Ersetzt,[e257f36cc5b7a19547d886d29e6727d9]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-781550069-2462040875-601678507-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdSqJmMPTJRT9j6BqV34A,,&q={searchTerms}),Ersetzt,[7abf77e883f98aacc4567bdd1ce909f7]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-781550069-2462040875-601678507-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6KKuzLN3PH1wC-k9UviqLHwkQeVgWEvIwyndenzDzHEoqTfuw7nKReolUXVQFo8JDq5yEIBlrJL79vnRvb8PKpNfSiarMuMaUGFQ,,, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6KKuzLN3PH1wC-k9UviqLHwkQeVgWEvIwyndenzDzHEoqTfuw7nKReolUXVQFo8JDq5yEIBlrJL79vnRvb8PKpNfSiarMuMaUGFQ,,),Ersetzt,[2a0ff966c5b731054cd192c6e61ff50b]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-781550069-2462040875-601678507-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdV7dVZUMOhN8QoTZRQfQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdV7dVZUMOhN8QoTZRQfQ,,&q={searchTerms}),Ersetzt,[ec4df26da6d6b482041a90c8bf4635cb]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-781550069-2462040875-601678507-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdV7dVZUMOhN8QoTZRQfQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdV7dVZUMOhN8QoTZRQfQ,,&q={searchTerms}),Ersetzt,[2316510e9ddff343f02f8dcbf41108f8]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-781550069-2462040875-601678507-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdV7dVZUMOhN8QoTZRQfQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdV7dVZUMOhN8QoTZRQfQ,,&q={searchTerms}),Ersetzt,[bb7eec73ef8d6cca91894810ae57c040]
Ordner: 5
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\Resources, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Common, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Common\iconsWide, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
Dateien: 19
PUP.Optional.SmartBar, C:\Windows\Installer\MSIA3F1.tmp, In Quarantäne, [af8a4e115d1faa8c64092707ac549d63],
PUP.Optional.SmartBar, C:\Windows\Installer\MSIEFC9.tmp, In Quarantäne, [f247d58ae795f93df677ab83f60a659b],
PUP.Optional.SmartBar, C:\Windows\Installer\MSIA3F1.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [3108f16ec1bb191d3439f737f40cd927],
PUP.Optional.WebSearch.A, C:\Users\Doris\AppData\Roaming\Mozilla\Firefox\Profiles\163lj4d5.default\searchplugins\Web Search.xml, In Quarantäne, [7ebb4718e09c0036398f8af246bdd22e],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\DomainBlackList.xml, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\Smartbar.exe.unused, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll.unused, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\Resources\crdli.dll.tmp, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\Resources\crdli64.dll.tmp, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\Resources\crdlil.dll.tmp, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Application\Resources\crdlil64.dll.tmp, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Common\iconsWide\youtube.png, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Common\iconsWide\youtubehover.png, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.SmartBar.A, C:\Users\Doris\AppData\Local\Smartbar\Common\iconsWide\youtubepress.png, In Quarantäne, [4ced88d79ddfe254f6c63bd949ba13ed],
PUP.Optional.HelperBar.A, C:\Users\Doris\AppData\Roaming\Mozilla\Firefox\Profiles\163lj4d5.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StPOamTTqzur3wb8K-Ou-Ve_tolwkCoFEtV9h8HxjH3gjJ-ZbVRW-6eJ1ZERr96Aycfe6cnZlBW1SL4HQJoNiJx5ta_89Dn7YOxGkjIC6GDu83OZgvqSzWVyrtvhkG_FfCtagS9LnnEiMxiGiC5yZkEAmwZwNY0_K4PUduRnHbodT0Bbimj1mPBKdV7dVZUMOhN8QoTZRQfQ,,&q=");), Ersetzt,[56e34916a0dced499a169dfc1de8847c]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) AdwCleaner[Sx].txt Code:
# AdwCleaner v4.104 - Bericht erstellt am 05/12/2014 um 15:23:45
# Aktualisiert 05/12/2014 von Xplode
# Database : 2014-12-03.1 [Live]
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Doris - DORIS
# Gestartet von : C:\Users\Doris\Desktop\adwcleaner_4.104.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\Users\Doris\Favorites\Startfenster.lnk
Datei Gelöscht : C:\Users\Doris\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk
Datei Gelöscht : C:\Users\Doris\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster.lnk
Datei Gelöscht : C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\PIP
Schlüssel Gelöscht : HKLM\SOFTWARE\PIP
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16453
-\\ Mozilla Firefox v34.0.5 (x86 de)
[163lj4d5.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
*************************
AdwCleaner[R0].txt - [2141 octets] - [05/12/2014 15:20:58]
AdwCleaner[S0].txt - [1861 octets] - [05/12/2014 15:23:45]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1921 octets] ########## JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 8 x64
Ran by Doris on 05.12.2014 at 15:29:01,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Users\Doris\favorites\links\startfenster.lnk"
Successfully deleted: [File] C:\Windows\prefetch\ASKPIP_FF_.EXE-4593C202.pf
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Doris\AppData\Roaming\mozilla\firefox\profiles\163lj4d5.default\minidumps [3 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.12.2014 at 15:30:52,15
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und das neuste FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2014
Ran by Doris (administrator) on DORIS on 05-12-2014 15:34:44
Running from C:\Users\Doris\Desktop
Loaded Profiles: UpdatusUser & Doris (Available profiles: UpdatusUser & Doris)
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Dropbox, Inc.) C:\Users\Doris\AppData\Roaming\Dropbox\bin\Dropbox.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [765056 2012-09-29] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-09-29] (Atheros Communications)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-09-11] (ASUS)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [78352 2012-05-23] (cyberlink)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [3417984 2012-08-28] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1724728 2013-12-19] (G Data Software AG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-781550069-2462040875-601678507-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
Startup: C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Doris\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-781550069-2462040875-601678507-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-781550069-2462040875-601678507-1001\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\S-1-5-21-781550069-2462040875-601678507-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-781550069-2462040875-601678507-1002\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.88.1
FireFox:
========
FF ProfilePath: C:\Users\Doris\AppData\Roaming\Mozilla\Firefox\Profiles\163lj4d5.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: DownloadHelper - C:\Users\Doris\AppData\Roaming\Mozilla\Firefox\Profiles\163lj4d5.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-11-30]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [220288 2012-09-29] (Qualcomm Atheros Commnucations)
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2244728 2014-02-12] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlX64.exe [2722888 2014-01-30] (G Data Software AG)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [243728 2012-05-23] (CyberLink)
R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2992760 2014-01-30] (G Data Software AG)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700024 2014-02-03] (G Data Software AG)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [15440 2012-07-26] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-09-29] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [57344 2014-11-28] (G Data Software AG)
R3 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [22016 2014-11-28] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [135168 2014-11-28] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [71168 2014-11-28] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [67584 2014-11-28] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-11-28] (G Data Software)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65024 2014-11-28] (G Data Software AG)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U0 msahci; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-05 15:34 - 2014-12-05 15:34 - 02117632 _____ (Farbar) C:\Users\Doris\Desktop\FRST64.exe
2014-12-05 15:34 - 2014-12-05 15:34 - 00000000 ____D () C:\Users\Doris\Desktop\FRST-OlderVersion
2014-12-05 15:30 - 2014-12-05 15:30 - 00000902 _____ () C:\Users\Doris\Desktop\JRT.txt
2014-12-05 15:29 - 2014-12-05 15:29 - 00000000 ____D () C:\Windows\ERUNT
2014-12-05 15:27 - 2014-12-05 12:38 - 01707646 _____ (Thisisu) C:\Users\Doris\Desktop\JRT.exe
2014-12-05 15:20 - 2014-12-05 15:23 - 00000000 ____D () C:\AdwCleaner
2014-12-05 15:20 - 2014-12-05 15:20 - 02153472 _____ () C:\Users\Doris\Desktop\adwcleaner_4.104.exe
2014-12-05 15:20 - 2014-12-05 15:20 - 00000055 _____ () C:\AdwCleanerDebug.txt
2014-12-05 14:18 - 2014-12-05 14:18 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-05 14:17 - 2014-12-05 14:17 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-05 14:17 - 2014-12-05 14:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-05 14:17 - 2014-12-05 14:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-05 14:17 - 2014-12-05 14:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-05 14:17 - 2014-12-05 12:36 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Doris\Desktop\mbam-setup-2.0.4.1028.exe
2014-12-05 14:17 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-05 14:17 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-05 14:17 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-03 21:23 - 2014-12-03 21:23 - 00015677 _____ () C:\ComboFix.txt
2014-12-03 21:15 - 2014-12-03 21:23 - 00000000 ____D () C:\Qoobox
2014-12-03 21:15 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-03 21:15 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-03 21:15 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-03 21:15 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-03 21:15 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-03 21:15 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-12-03 21:15 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-03 21:15 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-03 21:15 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-03 21:14 - 2014-12-03 21:22 - 00000000 ____D () C:\Windows\erdnt
2014-12-03 21:14 - 2014-12-03 20:49 - 05600127 ____R (Swearware) C:\Users\Doris\Desktop\ComboFix.exe
2014-12-02 21:55 - 2014-12-02 21:56 - 00020635 _____ () C:\Users\Doris\Desktop\Addition.txt
2014-12-02 21:54 - 2014-12-05 15:34 - 00014188 _____ () C:\Users\Doris\Desktop\FRST.txt
2014-12-02 21:54 - 2014-12-05 15:34 - 00000000 ____D () C:\FRST
2014-12-02 16:14 - 2014-12-02 16:14 - 00000000 ____D () C:\Users\Doris\AppData\Roaming\dlg
2014-12-02 16:03 - 2014-12-02 16:03 - 00001161 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-12-02 16:03 - 2014-12-02 16:03 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-12-02 16:03 - 2014-12-02 16:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-02 16:02 - 2014-12-02 16:02 - 00244264 _____ () C:\Users\Doris\Downloads\Firefox Setup Stub 34.0.5.exe
2014-12-02 15:02 - 2014-12-02 15:02 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-12-02 15:02 - 2014-12-02 15:02 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-29 16:10 - 2014-12-02 15:04 - 00000000 ____D () C:\Program Files (x86)\Google
2014-11-29 16:10 - 2014-12-02 15:02 - 00000000 ____D () C:\Users\Doris\AppData\Local\Google
2014-11-29 16:07 - 2011-05-13 11:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-11-29 16:07 - 2011-03-25 19:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-11-29 15:56 - 2014-11-29 15:56 - 00880784 _____ (Google Inc.) C:\Users\Doris\Downloads\ChromeSetup.exe
2014-11-29 15:55 - 2014-11-29 15:55 - 01174352 _____ () C:\Users\Doris\Downloads\Firefox - CHIP-Installer.exe
2014-11-28 15:05 - 2014-11-28 15:05 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-11-28 15:05 - 2014-11-28 15:05 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-11-28 14:47 - 2014-11-28 14:47 - 00022016 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt64.sys
2014-11-28 14:47 - 2014-11-28 14:47 - 00000197 _____ () C:\Users\Doris\AppData\Roaming\gdscan.log
2014-11-28 14:47 - 2014-11-28 14:47 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_GDKBFlt64_01007.Wdf
2014-11-28 14:47 - 2014-11-28 14:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G Data InternetSecurity
2014-11-28 14:47 - 2014-11-28 14:47 - 00000000 _____ () C:\Users\Doris\AppData\Roaming\gdfw.log
2014-11-27 08:39 - 2014-11-27 09:29 - 00002164 _____ () C:\Users\Doris\Desktop\Maleware.txt
2014-11-26 17:42 - 2014-11-26 17:43 - 00000013 _____ () C:\Users\Doris\Desktop\Mister Lady.txt
2014-11-24 02:58 - 2014-11-24 02:58 - 00000000 ____D () C:\Users\Doris\AppData\Roaming\mp3DirectCut
2014-11-24 02:57 - 2014-11-24 02:57 - 00001057 _____ () C:\Users\Doris\Desktop\mp3DirectCut.lnk
2014-11-24 02:56 - 2014-11-24 02:55 - 00308709 _____ () C:\Users\Doris\Downloads\mp3DC220_CB-DL-Manager [1].exe
2014-11-24 02:55 - 2014-11-24 02:55 - 00845888 _____ ( ) C:\Users\Doris\Downloads\mp3DC220_CB-DL-Manager.exe
2014-11-24 02:49 - 2014-11-24 02:57 - 00000000 ____D () C:\Program Files (x86)\mp3DirectCut
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-05 15:34 - 2013-01-05 02:21 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-781550069-2462040875-601678507-1002
2014-12-05 15:27 - 2012-11-12 13:28 - 01317910 _____ () C:\Windows\WindowsUpdate.log
2014-12-05 15:26 - 2013-05-09 17:22 - 00000000 ___RD () C:\Users\Doris\Dropbox
2014-12-05 15:26 - 2013-05-09 08:54 - 00000000 ____D () C:\Users\Doris\AppData\Roaming\Dropbox
2014-12-05 15:25 - 2013-01-05 02:14 - 00000500 _____ () C:\Users\Doris\AppData\Roaming\sp_data.sys
2014-12-05 15:24 - 2012-08-02 14:24 - 00287774 _____ () C:\Windows\PFRO.log
2014-12-05 15:24 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-05 15:24 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-12-05 15:07 - 2013-10-24 18:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-05 15:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru
2014-12-05 14:17 - 2012-08-03 00:02 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-12-05 14:17 - 2012-08-03 00:02 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-12-05 14:17 - 2012-07-26 08:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-03 22:36 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-03 21:23 - 2012-07-26 06:37 - 00000000 __RHD () C:\Users\Default
2014-12-03 21:21 - 2012-07-26 06:26 - 00000215 _____ () C:\Windows\system.ini
2014-12-02 16:46 - 2013-01-05 03:02 - 00000000 ____D () C:\Program Files (x86)\Audiograbber
2014-12-02 16:37 - 2013-01-05 02:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-02 15:01 - 2012-07-26 08:21 - 00050539 _____ () C:\Windows\setupact.log
2014-12-01 17:08 - 2012-11-12 13:09 - 00000000 ____D () C:\Windows\SysWOW64\NV
2014-12-01 17:08 - 2012-11-12 13:09 - 00000000 ____D () C:\Windows\system32\NV
2014-12-01 00:01 - 2012-11-12 13:08 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-11-30 23:37 - 2013-03-28 08:16 - 00000000 ____D () C:\Users\Doris\dwhelper
2014-11-30 22:09 - 2013-01-05 19:44 - 00000000 ____D () C:\Users\Doris\AppData\Roaming\vlc
2014-11-29 17:24 - 2014-10-05 01:20 - 00003454 _____ () C:\Users\Doris\Desktop\Neues Textdokument.txt
2014-11-29 16:08 - 2013-01-05 02:33 - 00000000 ____D () C:\Users\Doris\AppData\Roaming\Mozilla
2014-11-29 15:56 - 2013-01-19 22:13 - 00000000 ____D () C:\Users\Doris\AppData\Local\CrashDumps
2014-11-28 18:22 - 2013-01-05 04:11 - 00000000 ____D () C:\ProgramData\G DATA
2014-11-28 14:55 - 2013-01-05 04:12 - 00071168 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys
2014-11-28 14:47 - 2013-01-05 04:11 - 00135168 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-11-28 14:47 - 2013-01-05 04:11 - 00067584 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2014-11-28 14:47 - 2013-01-05 04:11 - 00065024 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys
2014-11-28 14:47 - 2013-01-05 04:11 - 00057344 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-11-28 14:47 - 2013-01-05 04:11 - 00002052 _____ () C:\Users\Public\Desktop\G Data InternetSecurity.lnk
2014-11-28 14:47 - 2013-01-05 04:09 - 00000000 ____D () C:\Users\Doris\AppData\Local\Downloaded Installations
2014-11-28 14:47 - 2012-11-12 13:18 - 00028896 _____ () C:\Windows\DPINST.LOG
2014-11-26 11:07 - 2013-10-24 18:27 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-23 09:58 - 2013-01-05 03:14 - 00000000 ____D () C:\Users\Doris\AppData\Roaming\UseNeXT
2014-11-17 00:25 - 2014-02-02 11:32 - 00025305 _____ () C:\Users\Doris\Documents\Ausgaben 2014.xlsx
2014-11-16 16:02 - 2012-07-24 09:50 - 00000000 ____D () C:\Users\Doris\Documents\Arbeit
2014-11-15 07:19 - 2013-05-09 17:22 - 00001018 _____ () C:\Users\Doris\Desktop\Dropbox.lnk
2014-11-15 07:19 - 2013-05-09 08:56 - 00000000 ____D () C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
Some content of TEMP:
====================
C:\Users\Doris\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp1bgg0a.dll
C:\Users\Doris\AppData\Local\temp\Quarantine.exe
C:\Users\Doris\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-03 21:10
==================== End Of Log ============================ --- --- ---
ist mir ja immer noch ein Rätsel wie man aus den ganzen logfiles schlau werden soll :confused:
Gruß
ph0n9 |