Moinsen und danke für die Hilfe. Wirklich toll!
Bis jetzt schmierte er mir inkl. gestern so ganze acht Mal ab :D Nach dem ich jetzt auch noch Adwcleaner verwendet habe, gab es noch keine weiteren Geräusche. Vorher (als bei der Ausführung der ersten Schritte mit Malwarebytes) gab es von RTL- bis Techno alles.
Bis jetzt (18:27 - seit dem Neustart), gab es keine weiteren Geräusche. Ich warte jetzt das weitere Verhalten ab, kann aber schreiben, dass er schon wieder normal läuft - also er ist in der Durchführung nicht so lahm und ich kann ohne Probleme Fenster öffnen. Diese kommen sogar schnell bei mir an^^
Hier die Ergebnisse: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 19.01.2015
Suchlauf-Zeit: 13:08:29
Logdatei: VerlausprotokollMalwareb..txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.19.07
Rootkit Datenbank: v2015.01.14.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: JMAGY
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 383530
Verstrichene Zeit: 2 Std, 25 Min, 11 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 12
RiskWare.Tool.CK, C:\Windows\KMService.exe, 2268, , [f152ae4b4e3bcd697810ed6c42c032ce]
PUP.Optional.AdPeak.A, C:\Program Files\005\vulsrsebjh64.exe, 2824, , [49fa8d6c7f0afb3b92e3333f3dc8ed13]
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 1168, , [72d153a6226774c262cc5c174eb505fb]
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 3044, , [72d153a6226774c262cc5c174eb505fb]
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 1548, , [72d153a6226774c262cc5c174eb505fb]
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 2264, , [72d153a6226774c262cc5c174eb505fb]
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 3408, , [72d153a6226774c262cc5c174eb505fb]
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 680, , [72d153a6226774c262cc5c174eb505fb]
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 2892, , [72d153a6226774c262cc5c174eb505fb]
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 4360, , [72d153a6226774c262cc5c174eb505fb]
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 7640, , [72d153a6226774c262cc5c174eb505fb]
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe, 2796, , [72d153a6226774c262cc5c174eb505fb]
Module: 10
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\libEGL.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\libEGL.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, , [72d153a6226774c262cc5c174eb505fb],
Registrierungsschlüssel: 15
PUP.Optional.AdPeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vulsrsebjh64, , [49fa8d6c7f0afb3b92e3333f3dc8ed13],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-408853863-4164539595-2725253896-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, , [271cb44577126fc70e2500ed52b0669a],
PUP.Optional.CompatibilityVerifier.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Verifies and fixes application compatibility issues, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.DefaultSearch, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}, , [8ab904f56e1bf73f6b51dd16a460cb35],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, , [49fa00f93c4d6cca120ba15151b337c9],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, , [87bc4dac8108a195d448d61cad575aa6],
PUP.Optional.SystemK.A, HKLM\SOFTWARE\WOW6432NODE\SystemK, , [81c29465f59457dfdbde7e0f1ee5926e],
PUP.Optional.DefaultSearch, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}, , [2f14e811612881b5427a9360e123619f],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT, , [b58e9960f5941026928c95006a9901ff],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SYSTEMK\General, , [89ba46b35e2bcc6a6d9cb8f3887b56aa],
PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD, , [c67d50a9503947eff18f721cdb2805fb],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-4.9, , [7ec598611b6e6bcbdea8703b42c15ca4],
PUP.Optional.Softonic.A, HKU\S-1-5-21-408853863-4164539595-2725253896-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, , [8bb8a752d7b2280e6322f68160a36c94],
PUP.Optional.SystemK.A, HKU\S-1-5-21-408853863-4164539595-2725253896-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SystemK, , [db68ae4ba8e112241a5b7c1de0235ca4],
PUP.Optional.DefaultSearch, HKU\S-1-5-21-408853863-4164539595-2725253896-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}, , [222100f9deabd264912cdc17b0544cb4],
Registrierungswerte: 6
PUP.Optional.DefaultSearch, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}|DisplayName, default-search.net, , [8ab904f56e1bf73f6b51dd16a460cb35]
PUP.Optional.DefaultSearch, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}|DisplayName, default-search.net, , [2f14e811612881b5427a9360e123619f]
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT|InstallDir, C:\PROGRA~2\SearchProtect, , [b58e9960f5941026928c95006a9901ff]
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SYSTEMK|browser, ie ff cr, , [83c03cbd2d5cf2449773eac193703dc3]
PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD|ImagePath, \??\C:\Windows\system32\drivers\SPPD.sys, , [c67d50a9503947eff18f721cdb2805fb]
PUP.Optional.DefaultSearch, HKU\S-1-5-21-408853863-4164539595-2725253896-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}|DisplayName, default-search.net, , [222100f9deabd264912cdc17b0544cb4]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 18
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\locales, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\16DB350226F7418EAD01E72219ABA317, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\27F661562FC54E25872241318C85E566, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\2C1A16DE4F9146F4B6317BF52047A162, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\42F392404F9C43C2BD3434DFD2CBE8BF, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\57B3D20483D64EE5AC466021F0E451A3, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\85BB36CC17C54C97A33E9A56386E99C6, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\8AD7F28E910E454CA93CABABA1EE5D80, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\A8A1DAB14B3345E98D4CAFBC26A75357, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjflmfkjppbmejlfbhlpgjnomdoefkfa, , [8fb422d7becb94a2f451ff4e8d763ac6],
PUP.Optional.SearchProtect.A, C:\Users\JMAGY\AppData\Local\SearchProtect, , [cb7846b30287ab8b6370ec63da29b749],
PUP.Optional.SearchProtect.A, C:\Users\JMAGY\AppData\Local\SearchProtect\SearchProtect, , [cb7846b30287ab8b6370ec63da29b749],
PUP.Optional.SearchProtect.A, C:\Users\JMAGY\AppData\Local\SearchProtect\SearchProtect\rep, , [cb7846b30287ab8b6370ec63da29b749],
PUP.Optional.SearchProtect.A, C:\Users\JMAGY\AppData\Local\SearchProtect\SearchProtect\STG, , [cb7846b30287ab8b6370ec63da29b749],
Dateien: 63
RiskWare.Tool.CK, C:\Windows\KMService.exe, , [f152ae4b4e3bcd697810ed6c42c032ce],
PUP.Optional.AdPeak.A, C:\Program Files\005\vulsrsebjh64.exe, , [49fa8d6c7f0afb3b92e3333f3dc8ed13],
PUP.Optional.OpenCandy.A, C:\Users\JMAGY\AppData\Roaming\OpenCandy\27F661562FC54E25872241318C85E566\dlm.exe, , [5fe42dcca4e562d468d44200d32e936d],
PUP.Optional.Conduit.A, C:\Users\JMAGY\AppData\Roaming\OpenCandy\27F661562FC54E25872241318C85E566\SearchProtect_p1v1.exe, , [d46f5a9f44454beb7dfd3708966b5aa6],
PUP.Optional.Conduit.A, C:\Users\JMAGY\AppData\Roaming\OpenCandy\27F661562FC54E25872241318C85E566\sp-downloader.exe, , [fc47ac4d7019b284c5b5fe4143be0ff1],
PUP.Optional.Conduit.A, C:\Users\JMAGY\AppData\Roaming\OpenCandy\2C1A16DE4F9146F4B6317BF52047A162\sp-downloader.exe, , [9fa4da1f642571c5a2d85ee1d829fb05],
PUP.Optional.Linkey.A, C:\Users\JMAGY\AppData\Roaming\OpenCandy\57B3D20483D64EE5AC466021F0E451A3\SettingsManagerSetup.exe, , [7fc408f1c6c3bc7a639f7535887928d8],
PUP.Optional.Conduit.A, C:\Users\JMAGY\AppData\Roaming\OpenCandy\8AD7F28E910E454CA93CABABA1EE5D80\sp-downloader.exe, , [44ffbb3eb0d9bb7b7307b788f011ab55],
PUP.Optional.OpenCandy.A, C:\Users\JMAGY\AppData\Roaming\OpenCandy\A8A1DAB14B3345E98D4CAFBC26A75357\dlm.exe, , [a1a217e2deab5cda0834241ece3329d7],
PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\AppPatch64\SPVCLdr64.dll, , [9ba88e6b3059b482249358576e9326da],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\cef.pak, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\cef_100_percent.pak, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\cef_200_percent.pak, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\debug.log, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\icudtl.dat, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\libEGL.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.CompatibilityVerifier.A, C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\vcredist_x86.exe, , [72d153a6226774c262cc5c174eb505fb],
PUP.Optional.Conduit.A, C:\Users\JMAGY\AppData\Roaming\Mozilla\Firefox\Profiles\1ftdmo1h.default\searchplugins\conduit-search.xml, , [de657a7fbfca4beb7eed3e4692715fa1],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jjflmfkjppbmejlfbhlpgjnomdoefkfa_0.localstorage, , [0f34c93050395dd9e9afcfcc748fb050],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jjflmfkjppbmejlfbhlpgjnomdoefkfa_0.localstorage-journal, , [4ef51cddafda65d19cfceab115ee3fc1],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\16DB350226F7418EAD01E72219ABA317\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\27F661562FC54E25872241318C85E566\7366.ico, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\42F392404F9C43C2BD3434DFD2CBE8BF\TuneUpUtilities2014_de-DE.exe, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\85BB36CC17C54C97A33E9A56386E99C6\TuneUpUtilities2014_de-DE.exe, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\A8A1DAB14B3345E98D4CAFBC26A75357\47A647BD-4905-48C7-9539-A95F199019A4, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.OpenCandy, C:\Users\JMAGY\AppData\Roaming\OpenCandy\A8A1DAB14B3345E98D4CAFBC26A75357\B8DCC36F-4F05-445F-B1EE-FD8FC38CBBDA, , [31121cdd9eeb7fb75913d169be45e719],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\favicon.ico, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\Internet Explorer Settings.exe, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\syskldr.dll, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\syskldr_u.dll, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemk.dll, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemkbho.dll, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemkChrome.dll, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemkmgrc1.cfg, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemku.exe, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\Internet Explorer Settings.exe, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\syskldr.dll, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\syskldr_u.dll, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\systemk.dll, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\systemkbho.dll, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc1.cfg, , [eb588b6ec4c556e05cd4122fed16dc24],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjflmfkjppbmejlfbhlpgjnomdoefkfa\000646.ldb, , [8fb422d7becb94a2f451ff4e8d763ac6],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjflmfkjppbmejlfbhlpgjnomdoefkfa\000654.ldb, , [8fb422d7becb94a2f451ff4e8d763ac6],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjflmfkjppbmejlfbhlpgjnomdoefkfa\000657.ldb, , [8fb422d7becb94a2f451ff4e8d763ac6],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjflmfkjppbmejlfbhlpgjnomdoefkfa\000658.log, , [8fb422d7becb94a2f451ff4e8d763ac6],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjflmfkjppbmejlfbhlpgjnomdoefkfa\CURRENT, , [8fb422d7becb94a2f451ff4e8d763ac6],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjflmfkjppbmejlfbhlpgjnomdoefkfa\LOCK, , [8fb422d7becb94a2f451ff4e8d763ac6],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjflmfkjppbmejlfbhlpgjnomdoefkfa\LOG, , [8fb422d7becb94a2f451ff4e8d763ac6],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjflmfkjppbmejlfbhlpgjnomdoefkfa\LOG.old, , [8fb422d7becb94a2f451ff4e8d763ac6],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjflmfkjppbmejlfbhlpgjnomdoefkfa\MANIFEST-000656, , [8fb422d7becb94a2f451ff4e8d763ac6],
PUP.Optional.SearchProtect.A, C:\Users\JMAGY\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, , [cb7846b30287ab8b6370ec63da29b749],
PUP.Optional.SearchProtect.A, C:\Users\JMAGY\AppData\Local\SearchProtect\SearchProtect\STG\Init_3292.tmp, , [cb7846b30287ab8b6370ec63da29b749],
PUP.Optional.SearchProtect.A, C:\Users\JMAGY\AppData\Local\SearchProtect\SearchProtect\STG\Init_333F.tmp, , [cb7846b30287ab8b6370ec63da29b749],
PUP.Optional.CrossRider.A, C:\Users\JMAGY\AppData\Roaming\Mozilla\Firefox\Profiles\1ftdmo1h.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "14373160441657b3165294102a7bf794");), ,[2a191fdac6c3ee4817a6cd08cf3643bd]
PUP.Optional.Conduit.A, C:\Users\JMAGY\AppData\Roaming\Mozilla\Firefox\Profiles\1ftdmo1h.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3322287&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP07135987-AB8F-4E3F-B8BB-4CD383FEA734&SSPV=");), ,[9fa4c5342465e35344a09d38ee17de22]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Die weiteren Ergebnisse
Adwcleaner: Code:
# AdwCleaner v4.108 - Bericht erstellt am 19/01/2015 um 18:12:28
# Aktualisiert 17/01/2015 von Xplode
# Database : 2015-01-18.1 [Live]
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : JMAGY - JMAGY-PC
# Gestartet von : C:\Users\JMAGY\Desktop\AdwCleaner_4.108.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : SPPD
[#] Dienst Gelöscht : vulsrsebjh64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\systemk
Ordner Gelöscht : C:\Program Files (x86)\HiDefMedia
Ordner Gelöscht : C:\Program Files (x86)\Settings Manager
Ordner Gelöscht : C:\Windows\SysWOW64\SearchProtect
Ordner Gelöscht : C:\Program Files\005
Ordner Gelöscht : C:\Users\JMAGY\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\JMAGY\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\JMAGY\AppData\Roaming\pdfforge
[!] Ordner Gelöscht : C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Ordner Gelöscht : C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Datei Gelöscht : C:\Users\JMAGY\AppData\Roaming\Mozilla\Firefox\Profiles\1ftdmo1h.default\searchplugins\bingp.xml
Datei Gelöscht : C:\Users\JMAGY\AppData\Roaming\Mozilla\Firefox\Profiles\1ftdmo1h.default\searchplugins\conduit-search.xml
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\SystemK
Schlüssel Gelöscht : HKLM\SOFTWARE\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\SystemK
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v
[1ftdmo1h.default\prefs.js] - Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3322287&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP07135987-AB8F-4E3F-B8BB-4CD383FEA734&SSPV=");
[1ftdmo1h.default\prefs.js] - Zeile gelöscht : user_pref("extensions.crossrider.bic", "14373160441657b3165294102a7bf794");
-\\ Google Chrome v39.0.2171.99
[C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MD37AE709-2C2B-492F-AA3A-76A0BD6AA0F2&SearchSource=58&CUI=&UM=5&UP=SPB972C596-BE67-4DC3-A8FB-8C39FB5F8136&q={searchTerms}&SSPV=
[C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MD37AE709-2C2B-492F-AA3A-76A0BD6AA0F2&SearchSource=58&CUI=&UM=5&UP=SPB972C596-BE67-4DC3-A8FB-8C39FB5F8136&q={searchTerms}&SSPV=
*************************
AdwCleaner[R0].txt - [4265 octets] - [19/01/2015 18:09:17]
AdwCleaner[S0].txt - [3505 octets] - [19/01/2015 18:12:28]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3565 octets] ########## Code:
# AdwCleaner v4.108 - Bericht erstellt am 19/01/2015 um 18:09:17
# Aktualisiert 17/01/2015 von Xplode
# Database : 2015-01-18.1 [Live]
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : JMAGY - JMAGY-PC
# Gestartet von : C:\Users\JMAGY\Desktop\AdwCleaner_4.108.exe
# Option : Suchen
***** [ Dienste ] *****
Dienst Gefunden : SPPD
Dienst Gefunden : vulsrsebjh64
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\JMAGY\AppData\Roaming\Mozilla\Firefox\Profiles\1ftdmo1h.default\searchplugins\bingp.xml
Datei Gefunden : C:\Users\JMAGY\AppData\Roaming\Mozilla\Firefox\Profiles\1ftdmo1h.default\searchplugins\conduit-search.xml
Ordner Gefunden : C:\Program Files (x86)\HiDefMedia
Ordner Gefunden : C:\Program Files (x86)\Settings Manager
Ordner Gefunden : C:\Program Files\005
Ordner Gefunden : C:\ProgramData\systemk
Ordner Gefunden : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Ordner Gefunden : C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Ordner Gefunden : C:\Users\JMAGY\AppData\Local\SearchProtect
Ordner Gefunden : C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier
Ordner Gefunden : C:\Users\JMAGY\AppData\Roaming\OpenCandy
Ordner Gefunden : C:\Users\JMAGY\AppData\Roaming\pdfforge
Ordner Gefunden : C:\Windows\SysWOW64\SearchProtect
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKCU\Software\SystemK
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}
Schlüssel Gefunden : [x64] HKCU\Software\Softonic
Schlüssel Gefunden : [x64] HKCU\Software\SystemK
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}
Schlüssel Gefunden : HKLM\SOFTWARE\SearchProtect
Schlüssel Gefunden : HKLM\SOFTWARE\SystemK
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v
[1ftdmo1h.default] - Zeile gefunden : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3322287&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP07135987-AB8F-4E3F-B8BB-4CD383FEA734&SSPV=");
[1ftdmo1h.default] - Zeile gefunden : user_pref("extensions.crossrider.bic", "14373160441657b3165294102a7bf794");
-\\ Google Chrome v39.0.2171.99
[C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MD37AE709-2C2B-492F-AA3A-76A0BD6AA0F2&SearchSource=58&CUI=&UM=5&UP=SPB972C596-BE67-4DC3-A8FB-8C39FB5F8136&q={searchTerms}&SSPV=
[C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MD37AE709-2C2B-492F-AA3A-76A0BD6AA0F2&SearchSource=58&CUI=&UM=5&UP=SPB972C596-BE67-4DC3-A8FB-8C39FB5F8136&q={searchTerms}&SSPV=
*************************
AdwCleaner[R0].txt - [4093 octets] - [19/01/2015 18:09:17]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4153 octets] ########## Und zum Schluss
FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2015
Ran by JMAGY (administrator) on JMAGY-PC on 19-01-2015 18:19:53
Running from C:\Users\JMAGY\Desktop\Trojaner-web
Loaded Profiles: JMAGY (Available profiles: JMAGY & Gast)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [589176 2011-12-20] (Alps Electric Co., Ltd.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-09] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-408853863-4164539595-2725253896-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [911032 2014-10-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
CHR HKU\S-1-5-21-408853863-4164539595-2725253896-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-408853863-4164539595-2725253896-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-408853863-4164539595-2725253896-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-408853863-4164539595-2725253896-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-408853863-4164539595-2725253896-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - avast! Online Security - {8ADF36AB-7485-4EA9-8C6C-381EF3923A43} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\JMAGY\AppData\Roaming\Mozilla\Firefox\Profiles\1ftdmo1h.default
FF SearchEngineOrder.3: Bing
FF Keyword.URL: hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-10]
FF Extension: No Name - C:\Users\JMAGY\AppData\Roaming\Mozilla\Firefox\Profiles\1ftdmo1h.default\extensions\d019febe-eb2b-4057-a3f2-7def88f2c9cd@1cced8ec-0ffe-43ea-b4b2-fbce5de8e9a4.com [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.bing.com/
CHR StartupUrls: Default -> "hxxp://www.wiwi.uni-jena.de/tax/aktuelles", "hxxp://www.dio.uni-jena.de/index.php?id=72&site=wiwiint&lang=de&path=11", "hxxp://www.traineeship.de/bewerbung.html#", "hxxp://www.suhrkamp.de/buecher/philosophie_des_jazz-daniel_martin_feige_29696.html", "hxxp://www.codecademy.com/", "https://neulichinjapan.wordpress.com/", "hxxp://www.anerkennung-in-deutschland.de/html/de/ausbildungsberufe.php", "hxxp://books.google.de/books?id=yDs8AwAAQBAJ&pg=PA93&lpg=PA93&dq=kaufm%C3%A4nnische+Berufsausbildung+in+Deutschland+und+der+Schweiz+im+Vergleich&source=bl&ots=A77y-qj0sK&sig=gURc8FeKYPUx52t5hbWQLBB4rxE&hl=de&sa=X&ei=pxxrVNjQC4iaygPz0YHwCA&ved=0CEMQ6AEwAjgK#v=onepage&q=kaufm%C3%A4nnische%20Berufsausbildung%20in%20Deutschland%20und%20der%20Schweiz%20im%20Vergleich&f=false", "hxxp://wiki.bildungsserver.de/infoboerse/index.php/Berufsbildungssystem_Deutschland_und_andere_L%C3%A4nder", "hxxp://ianus.uaic.ro/ianusII/partner-universities-2/university-of-lodz-%e2%80%93-information-sheet", "https://emecw.gis.lu.se/info.aspx?oid=170715", "https://emecw.gis.lu.se/info.aspx?oid=170658", "https://emecw.gis.lu.se/info.aspx?oid=170782", "https://emecw.gis.lu.se/info.aspx?oid=169925", "https://emecw.gis.lu.se/priorityHelper.aspx?&lot=EMBER", "hxxp://www.bing.com/?cc=de"
CHR Profile: C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-09]
CHR Extension: (Google Drive) - C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-05]
CHR Extension: (YouTube) - C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-09]
CHR Extension: (Google-Suche) - C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-09]
CHR Extension: (Regentropfen(Non-Aero)) - C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpagcfbbmlebfnkeogkigellbgmfkjfg [2014-03-25]
CHR Extension: (AdBlock) - C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-01-26]
CHR Extension: (Google Wallet) - C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-09]
CHR Extension: (Google Mail) - C:\Users\JMAGY\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-27]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-27] (AVAST Software)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [225280 2011-08-05] (DTS, Inc)
S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2013-12-09] () [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-04-17] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2671376 2012-04-17] (Intel® Corporation)
S2 Verifies and fixes application compatibility issues; C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-27] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-27] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-27] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-27] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-27] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-27] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-19] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1849608 2012-09-05] (Sonix Co. Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-19 18:09 - 2015-01-19 18:13 - 00000000 ____D () C:\AdwCleaner
2015-01-19 18:07 - 2015-01-19 18:08 - 02186752 _____ () C:\Users\JMAGY\Desktop\AdwCleaner_4.108.exe
2015-01-19 15:49 - 2015-01-19 15:49 - 00020406 _____ () C:\Users\JMAGY\Desktop\VerlausprotokollMalwareb..txt
2015-01-19 11:45 - 2015-01-19 11:45 - 00284728 _____ () C:\Windows\Minidump\011915-22370-01.dmp
2015-01-19 08:52 - 2015-01-19 18:17 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-19 08:51 - 2015-01-19 08:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-19 08:50 - 2015-01-19 08:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-19 08:50 - 2015-01-19 08:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-19 08:50 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-19 08:50 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-19 08:50 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-18 20:39 - 2015-01-18 20:39 - 00284728 _____ () C:\Windows\Minidump\011815-20841-01.dmp
2015-01-18 20:05 - 2015-01-18 20:05 - 00284728 _____ () C:\Windows\Minidump\011815-24913-01.dmp
2015-01-18 19:34 - 2015-01-19 18:19 - 00000000 ____D () C:\Users\JMAGY\Desktop\Trojaner-web
2015-01-18 18:56 - 2015-01-18 19:12 - 00000000 ____D () C:\Qoobox
2015-01-18 18:56 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-01-18 18:56 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-01-18 18:56 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-01-18 18:56 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-01-18 18:56 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-01-18 18:56 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-01-18 18:56 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-01-18 18:56 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-01-18 18:52 - 2015-01-18 19:10 - 00000000 ____D () C:\Windows\erdnt
2015-01-18 18:47 - 2015-01-18 18:49 - 05608785 ____R (Swearware) C:\Users\JMAGY\Desktop\ComboFix.exe
2015-01-18 16:44 - 2015-01-19 18:19 - 00000000 ____D () C:\FRST
2015-01-17 16:32 - 2015-01-17 16:32 - 00284728 _____ () C:\Windows\Minidump\011715-17331-01.dmp
2015-01-17 14:15 - 2015-01-19 11:45 - 427532242 _____ () C:\Windows\MEMORY.DMP
2015-01-17 14:15 - 2015-01-19 11:45 - 00000000 ____D () C:\Windows\Minidump
2015-01-17 14:15 - 2015-01-17 14:15 - 00284728 _____ () C:\Windows\Minidump\011715-35739-01.dmp
2015-01-14 19:59 - 2015-01-14 19:59 - 04877488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-01-14 18:58 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 18:58 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 18:58 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 18:58 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 18:58 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 18:56 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 18:56 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 18:56 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 18:56 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 18:56 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 18:56 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 18:56 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 18:56 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-13 21:11 - 2015-01-13 21:11 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-01-13 21:11 - 2015-01-13 21:11 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-01-13 21:11 - 2015-01-13 21:11 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-01-13 21:11 - 2015-01-13 21:11 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-01-13 10:42 - 2015-01-13 10:42 - 00000000 ____D () C:\Users\JMAGY\Documents\Sa
2015-01-13 10:42 - 2015-01-13 10:42 - 00000000 ____D () C:\Users\JMAGY\Documents\GoJu
2015-01-13 10:28 - 2015-01-19 14:16 - 00000112 _____ () C:\ProgramData\P0Hc2AO4.dat
2015-01-12 22:33 - 2015-01-12 22:33 - 00000000 ____D () C:\Users\JMAGY\AppData\Local\FLT
2015-01-12 22:31 - 2015-01-12 22:31 - 00000000 ____D () C:\Users\JMAGY\Documents\Klei
2015-01-12 22:11 - 2015-01-12 22:11 - 00000000 ____D () C:\Users\JMAGY\AppData\Local\Gaijin Games
2015-01-12 21:58 - 2015-01-13 10:23 - 00000000 ____D () C:\Program Files (x86)\Gaijin Games
2015-01-12 21:20 - 2015-01-12 21:20 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-12 21:18 - 2015-01-19 18:15 - 00000000 ____D () C:\Users\JMAGY\AppData\Roaming\Compatibility Verifier
2015-01-12 15:08 - 2015-01-12 15:10 - 00002247 _____ () C:\Users\Gast\Desktop\Google Chrome.lnk
2015-01-12 15:08 - 2015-01-12 15:08 - 00001381 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-12 15:08 - 2015-01-12 15:08 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Intel
2015-01-12 15:08 - 2015-01-12 15:08 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\AVAST Software
2015-01-12 15:08 - 2015-01-12 15:08 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe
2015-01-12 15:08 - 2015-01-12 15:08 - 00000000 ____D () C:\Users\Gast\AppData\Local\VirtualStore
2015-01-12 15:08 - 2015-01-12 15:08 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2015-01-12 15:07 - 2015-01-12 15:08 - 00000000 ____D () C:\Users\Gast
2015-01-12 15:07 - 2015-01-12 15:07 - 00000020 ___SH () C:\Users\Gast\ntuser.ini
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\Vorlagen
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\Startmenü
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\Lokale Einstellungen
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\Eigene Dateien
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Musik
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Bilder
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Anwendungsdaten
2015-01-12 15:07 - 2015-01-12 15:07 - 00000000 _SHDL () C:\Users\Gast\Anwendungsdaten
2015-01-12 15:07 - 2013-12-10 00:35 - 00000000 ____D () C:\Users\Gast\AppData\Local\Microsoft Help
2015-01-12 15:07 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-12 15:07 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-05 10:32 - 2015-01-05 10:32 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-01-05 10:32 - 2015-01-05 10:32 - 00410624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\systemcpl.dll
2015-01-05 10:32 - 2015-01-05 10:32 - 00113543 _____ () C:\Windows\SysWOW64\slmgr.vbs
2015-01-05 10:32 - 2015-01-05 10:32 - 00002048 _____ () C:\Windows\SysWOW64\winver.exe
2015-01-05 10:32 - 2015-01-05 10:32 - 00001536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppcomapi.dll
2015-01-03 20:56 - 2015-01-03 22:07 - 00000000 ____D () C:\Users\JMAGY\AppData\Roaming\A Bird Story
2015-01-03 20:18 - 2015-01-03 20:18 - 00000000 ____D () C:\Users\JMAGY\AppData\Roaming\TripleTown
2014-12-31 13:34 - 2014-12-31 13:40 - 00000000 ____D () C:\Users\JMAGY\Desktop\Wipäd-Präsi-Material
2014-12-27 20:22 - 2014-12-27 20:22 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-19 18:21 - 2013-12-09 08:31 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-19 18:16 - 2013-12-09 08:30 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-19 18:15 - 2010-11-21 04:47 - 00461770 _____ () C:\Windows\PFRO.log
2015-01-19 18:15 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-19 18:15 - 2009-07-14 05:51 - 00093383 _____ () C:\Windows\setupact.log
2015-01-19 18:14 - 2013-12-07 15:51 - 01220078 _____ () C:\Windows\WindowsUpdate.log
2015-01-19 18:13 - 2009-07-14 05:45 - 00016880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-19 18:13 - 2009-07-14 05:45 - 00016880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-19 17:58 - 2014-01-26 12:20 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-19 11:50 - 2011-04-12 08:43 - 00654400 _____ () C:\Windows\system32\perfh007.dat
2015-01-19 11:50 - 2011-04-12 08:43 - 00130240 _____ () C:\Windows\system32\perfc007.dat
2015-01-19 11:50 - 2009-07-14 06:13 - 01498742 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-19 08:51 - 2014-01-30 08:24 - 00000000 ____D () C:\Users\JMAGY\Downloads\Bilder
2015-01-18 20:08 - 2014-01-10 20:43 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-01-18 19:59 - 2014-10-19 10:49 - 00000000 ____D () C:\Users\JMAGY\Documents\Spiele
2015-01-18 19:08 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-01-17 20:38 - 2014-09-29 12:39 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-17 20:34 - 2014-09-19 16:10 - 00000000 ____D () C:\Users\JMAGY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\S.A.D
2015-01-17 20:34 - 2014-09-19 16:10 - 00000000 ____D () C:\Program Files (x86)\S.A.D
2015-01-17 20:34 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-17 20:32 - 2013-12-09 08:07 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-17 20:31 - 2014-10-04 11:38 - 00000000 ____D () C:\Users\JMAGY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-01-14 22:01 - 2013-12-10 00:17 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 21:39 - 2013-12-10 00:17 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-14 20:00 - 2014-01-26 12:20 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-14 20:00 - 2014-01-26 12:20 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-14 20:00 - 2014-01-26 12:20 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-13 10:41 - 2014-01-25 07:14 - 00000000 ____D () C:\Users\JMAGY\Documents\Vieles
2015-01-13 10:38 - 2014-07-18 15:06 - 00000000 ____D () C:\Users\JMAGY\Desktop\Masterstudium
2015-01-13 09:04 - 2014-09-25 14:15 - 00000000 ____D () C:\Users\JMAGY\Desktop\Praktikum
2015-01-12 22:07 - 2014-10-19 17:43 - 00000000 ____D () C:\Windows\SysWOW64\directx
2015-01-12 21:21 - 2013-12-09 18:54 - 00000000 ____D () C:\Users\JMAGY\AppData\Roaming\Skype
2015-01-12 21:12 - 2013-12-09 08:30 - 00000000 ____D () C:\Program Files\WinRAR
2015-01-12 18:19 - 2013-12-09 08:30 - 00000000 ____D () C:\Users\JMAGY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-01-12 18:19 - 2013-12-09 08:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-01-12 12:42 - 2014-07-08 11:58 - 00000000 ____D () C:\Users\JMAGY\Desktop\Mastersemester 9
2015-01-11 18:44 - 2014-09-25 11:58 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-11 18:44 - 2013-12-09 18:53 - 00000000 ____D () C:\ProgramData\Skype
2015-01-09 23:48 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-08 08:17 - 2014-12-10 13:58 - 00000000 ____D () C:\Users\JMAGY\Desktop\Philo VL 7+8
2015-01-04 20:47 - 2014-12-08 19:05 - 00000000 ____D () C:\Users\JMAGY\Documents\AIESEC
2015-01-03 20:55 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
==================== Files in the root of some directories =======
2015-01-13 10:28 - 2015-01-19 14:16 - 0000112 _____ () C:\ProgramData\P0Hc2AO4.dat
Files to move or delete:
====================
C:\ProgramData\P0Hc2AO4.dat
Some content of TEMP:
====================
C:\Users\JMAGY\AppData\Local\Temp\Quarantine.exe
C:\Users\JMAGY\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-17 15:56
==================== End Of Log ============================ --- --- ---
--- --- --- |