sorry. Nachfolgend die eingefügten Dateiinhalte. Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 13:03 on 25/01/2015 (User)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01
Ran by User (administrator) on USER-PC on 25-01-2015 13:08:09
Running from C:\Users\Ingo\Downloads\Trojaner\FRST
Loaded Profiles: User & Ingo (Available profiles: User & Ingo & Uli & Jasper & Gast)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Fuyu LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
(XTab system) C:\Program Files (x86)\XTab\ProtectService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Marek Jasinski - www.FreeCommander.com) C:\Program Files (x86)\FreeCommander\FreeCommander.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7016520 2013-02-05] (Realtek Semiconductor)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-09] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4093833643-2685545966-1431014470-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_287_Plugin.exe [960176 2015-01-23] (Adobe Systems Incorporated)
HKU\S-1-5-21-4093833643-2685545966-1431014470-1000\...\MountPoints2: {85a56fc9-4e0d-11e3-a53b-806e6f6e6963} - E:\Setup.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?type=hp&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?type=hp&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215&q={searchTerms}
HKU\S-1-5-21-4093833643-2685545966-1431014470-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?type=hp&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215
HKU\S-1-5-21-4093833643-2685545966-1431014470-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
HKU\S-1-5-21-4093833643-2685545966-1431014470-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4093833643-2685545966-1431014470-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1421270582&from=cvs&uid=WDCXWD3200KS-75PFB0_WD-WCAPD333321533215&q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\wbexjcvf.default-1421527888779
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_287.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_287.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-25]
FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\bu6wo346.default\extensions\fftoolbar2014@etech.com
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\bu6wo346.default\extensions\faststartff@gmail.com
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-25]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-25] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-11-25] (Avast Software)
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158864 2014-12-29] (XTab system)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [149032 2012-08-16] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2013-01-14] (Intel Corporation)
R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-03-20] (MICRO-STAR INTERNATIONAL CO., LTD.)
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-30] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-30] (pdfforge GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [473088 2015-01-14] (Fuyu LIMITED) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-25] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-25] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-25] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-25] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-25] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-25] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-25] ()
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [20968 2012-08-16] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [19944 2012-08-16] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46016 2012-08-16] ()
S3 ncplelhp; C:\Windows\System32\DRIVERS\ncplelhp.sys [108112 2014-02-28] (NCP Engineering GmbH)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-11-25] (Avast Software)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2015-01-25] ()
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-25 13:08 - 2015-01-25 13:08 - 00000000 ____D () C:\FRST
2015-01-25 13:03 - 2015-01-25 13:03 - 00000000 _____ () C:\Users\User\defogger_reenable
2015-01-25 12:56 - 2015-01-25 12:58 - 00000000 ____D () C:\Users\Ingo\Downloads\Trojaner
2015-01-25 12:04 - 2015-01-25 12:04 - 00000197 _____ () C:\Windows\system32\2015-01-25-11-04-23.070-AvastVBoxSVC.exe-2600.log
2015-01-25 12:02 - 2015-01-25 12:02 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2015-01-24 19:33 - 2015-01-24 19:33 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-01-24 19:33 - 2015-01-24 19:33 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-01-24 19:14 - 2015-01-24 19:14 - 00000197 _____ () C:\Windows\system32\2015-01-24-18-14-04.000-AvastVBoxSVC.exe-3456.log
2015-01-23 19:10 - 2015-01-23 19:11 - 00000197 _____ () C:\Windows\system32\2015-01-23-18-10-41.027-AvastVBoxSVC.exe-3316.log
2015-01-21 22:37 - 2015-01-21 22:37 - 00000197 _____ () C:\Windows\system32\2015-01-21-21-37-43.005-AvastVBoxSVC.exe-3388.log
2015-01-21 20:57 - 2015-01-21 20:57 - 00000197 _____ () C:\Windows\system32\2015-01-21-19-57-22.037-AvastVBoxSVC.exe-2816.log
2015-01-21 19:17 - 2015-01-21 19:18 - 00000197 _____ () C:\Windows\system32\2015-01-21-18-17-45.071-AvastVBoxSVC.exe-2500.log
2015-01-21 16:28 - 2015-01-21 16:28 - 00000104 _____ () C:\Users\Uli\Desktop\Standardprogramme - Verknüpfung.lnk
2015-01-21 14:58 - 2015-01-21 14:58 - 00000197 _____ () C:\Windows\system32\2015-01-21-13-58-02.040-AvastVBoxSVC.exe-2740.log
2015-01-20 22:45 - 2015-01-20 22:45 - 00000197 _____ () C:\Windows\system32\2015-01-20-21-45-20.061-AvastVBoxSVC.exe-2184.log
2015-01-20 07:59 - 2015-01-20 07:59 - 00000197 _____ () C:\Windows\system32\2015-01-20-06-59-17.033-AvastVBoxSVC.exe-2152.log
2015-01-18 21:09 - 2015-01-18 21:58 - 00002585 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SyncToy 2.1(x64).lnk
2015-01-18 21:09 - 2015-01-18 21:09 - 00000000 ____D () C:\Program Files\SyncToy 2.1
2015-01-18 21:01 - 2015-01-18 21:01 - 00000000 ____D () C:\Program Files\Microsoft Sync Framework
2015-01-18 21:00 - 2015-01-18 21:00 - 00000000 ____D () C:\Users\Ingo\Downloads\synctoy
2015-01-18 20:18 - 2015-01-18 20:18 - 00000197 _____ () C:\Windows\system32\2015-01-18-19-18-05.063-AvastVBoxSVC.exe-3008.log
2015-01-18 00:11 - 2015-01-18 00:11 - 00000197 _____ () C:\Windows\system32\2015-01-17-23-11-15.012-AvastVBoxSVC.exe-2960.log
2015-01-18 00:04 - 2015-01-18 00:05 - 00000197 _____ () C:\Windows\system32\2015-01-17-23-04-50.009-AvastVBoxSVC.exe-2800.log
2015-01-17 22:28 - 2015-01-17 22:29 - 00000000 ____D () C:\Users\User\Documents\WD-externe Festplatte
2015-01-17 22:08 - 2015-01-21 20:59 - 00000072 _____ () C:\Users\Public\LMDebug.log
2015-01-17 21:51 - 2015-01-17 21:51 - 00000000 ____D () C:\Users\User\Desktop\Alte Firefox-Daten
2015-01-17 21:49 - 2015-01-17 21:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-17 21:40 - 2015-01-17 21:40 - 00000000 ____D () C:\ProgramData\Samsung
2015-01-17 21:40 - 2015-01-17 21:40 - 00000000 ____D () C:\Program Files (x86)\SamsungPrinterLiveUpdate
2015-01-17 20:41 - 2015-01-17 22:28 - 00000000 ____D () C:\Users\User\Documents\Samsung Drucker
2015-01-17 20:38 - 2015-01-17 20:38 - 00000000 ____D () C:\Users\User\AppData\Roaming\WinRAR
2015-01-17 20:37 - 2015-01-17 20:37 - 00000197 _____ () C:\Windows\system32\2015-01-17-19-37-02.038-AvastVBoxSVC.exe-2292.log
2015-01-17 16:08 - 2015-01-17 16:09 - 00000197 _____ () C:\Windows\system32\2015-01-17-15-08-40.097-AvastVBoxSVC.exe-3516.log
2015-01-17 11:57 - 2015-01-17 11:57 - 00000197 _____ () C:\Windows\system32\2015-01-17-10-57-07.081-AvastVBoxSVC.exe-2824.log
2015-01-15 22:19 - 2015-01-15 22:19 - 00000197 _____ () C:\Windows\system32\2015-01-15-21-19-11.037-AvastVBoxSVC.exe-2624.log
2015-01-14 22:28 - 2015-01-14 22:28 - 00000000 ____D () C:\Users\User\AppData\Roaming\DVDVideoSoft
2015-01-14 22:24 - 2015-01-14 22:24 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2015-01-14 22:24 - 2015-01-14 22:24 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-01-14 22:23 - 2015-01-14 22:23 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2015-01-14 22:06 - 2015-01-14 22:06 - 00000197 _____ () C:\Windows\system32\2015-01-14-21-06-22.018-AvastVBoxSVC.exe-2756.log
2015-01-14 18:34 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 18:34 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 18:34 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 18:34 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 18:34 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 18:34 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 18:34 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 18:34 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 18:34 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 18:34 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 18:34 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 18:34 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 18:34 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 18:27 - 2015-01-14 18:28 - 00000197 _____ () C:\Windows\system32\2015-01-14-17-27-55.085-AvastVBoxSVC.exe-2696.log
2015-01-14 09:09 - 2015-01-14 09:09 - 00000197 _____ () C:\Windows\system32\2015-01-14-08-09-04.004-AvastVBoxSVC.exe-2500.log
2015-01-13 22:50 - 2015-01-13 22:50 - 00000197 _____ () C:\Windows\system32\2015-01-13-21-50-26.086-AvastVBoxSVC.exe-3156.log
2015-01-13 18:46 - 2015-01-13 18:46 - 00000197 _____ () C:\Windows\system32\2015-01-13-17-46-28.031-AvastVBoxSVC.exe-3160.log
2015-01-13 08:37 - 2015-01-13 08:38 - 00000197 _____ () C:\Windows\system32\2015-01-13-07-37-42.022-AvastVBoxSVC.exe-2568.log
2015-01-12 19:56 - 2015-01-12 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FILEminimizer Pictures 3.0
2015-01-12 19:55 - 2015-01-12 19:55 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieBrowserModeList
2015-01-12 19:53 - 2015-01-12 19:53 - 00000000 ____D () C:\Users\Ingo\Downloads\fileminimizer
2015-01-12 19:37 - 2015-01-12 19:37 - 00000197 _____ () C:\Windows\system32\2015-01-12-18-37-27.086-AvastVBoxSVC.exe-3004.log
2015-01-11 19:57 - 2015-01-11 19:57 - 00000197 _____ () C:\Windows\system32\2015-01-11-18-57-35.073-AvastVBoxSVC.exe-2868.log
2015-01-11 17:47 - 2015-01-11 17:48 - 00000197 _____ () C:\Windows\system32\2015-01-11-16-47-28.073-AvastVBoxSVC.exe-2824.log
2015-01-11 14:04 - 2015-01-11 14:05 - 00000197 _____ () C:\Windows\system32\2015-01-11-13-04-47.086-AvastVBoxSVC.exe-2696.log
2015-01-11 09:08 - 2015-01-11 09:09 - 00000197 _____ () C:\Windows\system32\2015-01-11-08-08-54.087-AvastVBoxSVC.exe-2684.log
2015-01-10 14:57 - 2015-01-10 14:57 - 00000197 _____ () C:\Windows\system32\2015-01-10-13-57-15.094-AvastVBoxSVC.exe-3624.log
2015-01-10 12:19 - 2015-01-10 12:20 - 00000197 _____ () C:\Windows\system32\2015-01-10-11-19-33.040-AvastVBoxSVC.exe-2964.log
2015-01-09 18:21 - 2015-01-09 18:21 - 00000197 _____ () C:\Windows\system32\2015-01-09-17-21-21.072-AvastVBoxSVC.exe-2756.log
2015-01-08 20:27 - 2015-01-08 20:27 - 00000197 _____ () C:\Windows\system32\2015-01-08-19-27-29.012-AvastVBoxSVC.exe-2888.log
2015-01-08 18:04 - 2015-01-08 18:04 - 00000197 _____ () C:\Windows\system32\2015-01-08-17-04-41.062-AvastVBoxSVC.exe-1268.log
2015-01-08 10:43 - 2015-01-08 10:44 - 00000197 _____ () C:\Windows\system32\2015-01-08-09-43-59.017-AvastVBoxSVC.exe-2660.log
2015-01-08 08:08 - 2015-01-08 08:08 - 00000197 _____ () C:\Windows\system32\2015-01-08-07-08-20.073-AvastVBoxSVC.exe-2616.log
2015-01-08 07:46 - 2015-01-08 07:46 - 00000197 _____ () C:\Windows\system32\2015-01-08-06-46-35.082-AvastVBoxSVC.exe-2808.log
2015-01-07 23:01 - 2015-01-07 23:01 - 00000197 _____ () C:\Windows\system32\2015-01-07-22-01-08.065-AvastVBoxSVC.exe-2352.log
2015-01-07 19:40 - 2015-01-07 19:40 - 00000197 _____ () C:\Windows\system32\2015-01-07-18-40-18.075-AvastVBoxSVC.exe-2676.log
2015-01-07 18:13 - 2015-01-07 18:14 - 00000197 _____ () C:\Windows\system32\2015-01-07-17-13-28.063-AvastVBoxSVC.exe-3388.log
2015-01-07 06:51 - 2015-01-07 06:51 - 00000197 _____ () C:\Windows\system32\2015-01-07-05-51-28.080-AvastVBoxSVC.exe-2812.log
2015-01-06 21:40 - 2015-01-06 21:40 - 00001468 _____ () C:\Users\Public\Desktop\LibreOffice 4.2.lnk
2015-01-06 21:40 - 2015-01-06 21:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2015-01-06 21:24 - 2015-01-06 21:25 - 00000197 _____ () C:\Windows\system32\2015-01-06-20-24-55.053-AvastVBoxSVC.exe-2752.log
2015-01-06 15:11 - 2015-01-06 15:11 - 00000197 _____ () C:\Windows\system32\2015-01-06-14-11-02.090-AvastVBoxSVC.exe-2952.log
2015-01-06 11:53 - 2015-01-06 11:53 - 00000197 _____ () C:\Windows\system32\2015-01-06-10-53-11.073-AvastVBoxSVC.exe-2736.log
2015-01-05 17:58 - 2015-01-05 17:59 - 00000197 _____ () C:\Windows\system32\2015-01-05-16-58-26.031-AvastVBoxSVC.exe-2688.log
2015-01-03 14:18 - 2015-01-03 14:18 - 00000197 _____ () C:\Windows\system32\2015-01-03-13-18-20.086-AvastVBoxSVC.exe-2688.log
2015-01-03 11:08 - 2015-01-03 11:09 - 00000197 _____ () C:\Windows\system32\2015-01-03-10-08-40.082-AvastVBoxSVC.exe-2864.log
2015-01-02 16:41 - 2015-01-02 16:41 - 00000197 _____ () C:\Windows\system32\2015-01-02-15-41-04.089-AvastVBoxSVC.exe-2724.log
2015-01-02 13:49 - 2015-01-02 13:49 - 00000197 _____ () C:\Windows\system32\2015-01-02-12-49-49.015-AvastVBoxSVC.exe-1460.log
2015-01-02 10:51 - 2015-01-02 10:52 - 00000197 _____ () C:\Windows\system32\2015-01-02-09-51-52.063-AvastVBoxSVC.exe-2324.log
2014-12-31 14:03 - 2014-12-31 14:03 - 00000197 _____ () C:\Windows\system32\2014-12-31-13-03-25.051-AvastVBoxSVC.exe-2868.log
2014-12-30 14:27 - 2014-12-30 14:27 - 00000197 _____ () C:\Windows\system32\2014-12-30-13-27-22.006-AvastVBoxSVC.exe-2776.log
2014-12-30 11:26 - 2014-12-30 11:26 - 00000247 _____ () C:\Windows\system32\2014-12-30-10-26-52.005-aswFe.exe-2772.log
2014-12-30 11:20 - 2014-12-30 11:26 - 00000247 _____ () C:\Windows\system32\2014-12-30-10-20-55.030-aswFe.exe-3488.log
2014-12-30 11:20 - 2014-12-30 11:20 - 00000197 _____ () C:\Windows\system32\2014-12-30-10-20-49.080-AvastVBoxSVC.exe-4172.log
2014-12-29 11:55 - 2014-12-29 11:56 - 00000197 _____ () C:\Windows\system32\2014-12-29-10-55-53.057-AvastVBoxSVC.exe-2788.log
2014-12-28 17:16 - 2014-12-28 17:16 - 00000197 _____ () C:\Windows\system32\2014-12-28-16-16-15.095-AvastVBoxSVC.exe-2940.log
2014-12-28 11:04 - 2014-12-28 11:05 - 00000197 _____ () C:\Windows\system32\2014-12-28-10-04-54.042-AvastVBoxSVC.exe-1292.log
2014-12-27 19:32 - 2014-12-27 19:32 - 00000197 _____ () C:\Windows\system32\2014-12-27-18-32-59.054-AvastVBoxSVC.exe-2556.log
2014-12-27 13:40 - 2014-12-27 13:41 - 00000197 _____ () C:\Windows\system32\2014-12-27-12-40-31.072-AvastVBoxSVC.exe-2120.log
2014-12-26 14:12 - 2014-12-26 14:12 - 00000197 _____ () C:\Windows\system32\2014-12-26-13-12-35.053-AvastVBoxSVC.exe-2600.log
2014-12-26 12:54 - 2014-12-26 12:54 - 00000197 _____ () C:\Windows\system32\2014-12-26-11-54-34.025-AvastVBoxSVC.exe-3532.log
2014-12-26 00:46 - 2014-12-26 00:46 - 00000197 _____ () C:\Windows\system32\2014-12-25-23-46-41.039-AvastVBoxSVC.exe-3276.log
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-25 12:55 - 2013-02-09 22:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-25 12:46 - 2014-11-09 12:46 - 00000000 ____D () C:\Users\Ingo\Downloads\firefox
2015-01-25 12:46 - 2014-01-28 00:25 - 00000000 ____D () C:\Users\Ingo\Downloads\freecommander
2015-01-25 12:46 - 2014-01-25 18:22 - 00000000 ____D () C:\Users\User\Downloads\freecommander
2015-01-25 12:09 - 2009-07-14 05:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-25 12:09 - 2009-07-14 05:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-25 12:06 - 2011-04-12 08:43 - 00699432 _____ () C:\Windows\system32\perfh007.dat
2015-01-25 12:06 - 2011-04-12 08:43 - 00149572 _____ () C:\Windows\system32\perfc007.dat
2015-01-25 12:06 - 2009-07-14 06:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-25 12:05 - 2013-11-15 17:00 - 02063932 _____ () C:\Windows\WindowsUpdate.log
2015-01-25 12:02 - 2013-11-15 17:10 - 00034752 _____ () C:\Windows\system32\Drivers\WPRO_41_2001.sys
2015-01-25 12:02 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-25 12:02 - 2009-07-14 05:51 - 00104944 _____ () C:\Windows\setupact.log
2015-01-25 12:01 - 2010-11-21 04:47 - 00380694 _____ () C:\Windows\PFRO.log
2015-01-24 19:33 - 2014-10-14 18:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-01-24 19:33 - 2014-10-14 18:54 - 00000000 ____D () C:\Program Files\WinRAR
2015-01-24 19:13 - 2014-01-25 18:31 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-01-23 19:55 - 2013-02-09 22:29 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-23 19:55 - 2013-02-09 22:29 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-23 19:55 - 2013-02-09 22:29 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-18 23:02 - 2014-03-15 23:38 - 00000000 ____D () C:\Users\Ingo\AppData\Roaming\vlc
2015-01-18 00:02 - 2013-02-09 19:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-17 22:26 - 2014-12-23 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe
2015-01-17 22:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-17 21:01 - 2013-11-15 17:01 - 00001425 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-17 21:01 - 2013-02-09 19:42 - 00001169 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-17 21:01 - 2013-02-09 19:42 - 00001157 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-14 22:23 - 2014-01-27 21:16 - 00000000 ____D () C:\Users\Ingo\AppData\Local\CrashDumps
2015-01-14 21:33 - 2013-11-15 17:26 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 21:31 - 2013-02-09 16:51 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-14 21:30 - 2014-12-04 21:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2015-01-13 19:19 - 2014-01-29 22:39 - 00000000 ____D () C:\Users\Ingo\AppData\Roaming\MyPhoneExplorer
2015-01-12 19:54 - 2013-11-15 17:49 - 00063136 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-11 18:14 - 2014-01-26 13:19 - 00063136 _____ () C:\Users\Ingo\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-11 16:20 - 2014-01-26 19:21 - 00063136 _____ () C:\Users\Uli\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-07 06:49 - 2009-07-14 05:45 - 00292040 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-06 21:40 - 2014-05-08 21:29 - 00000000 ____D () C:\Program Files (x86)\LibreOffice 4
2015-01-06 21:36 - 2014-11-09 12:45 - 00000000 ____D () C:\Users\Ingo\Downloads\libreoffice
2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
Some content of TEMP:
====================
C:\Users\Ingo\AppData\Local\Temp\vlc-2.1.4-win64.exe
C:\Users\Ingo\AppData\Local\Temp\vlc-2.1.5-win64.exe
C:\Users\User\AppData\Local\Temp\AutoRun.exe
C:\Users\User\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\User\AppData\Local\Temp\devcon64.exe
C:\Users\User\AppData\Local\Temp\ICReinstall_ZipSetup.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-08 11:16
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-01-2015 01
Ran by User at 2015-01-25 13:08:40
Running from C:\Users\Ingo\Downloads\Trojaner\FRST
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.287 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Audiograbber 1.83 SE (HKLM-x32\...\Audiograbber) (Version: 1.83 SE - Audiograbber)
Audiograbber MP3-Plugin (HKLM-x32\...\Audiograbber-Lame) (Version: 1.0 - AG)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.4852 - CDBurnerXP)
FILEminimizer Pictures (HKLM-x32\...\FILEminimizer Pictures_is1) (Version: - balesio AG)
FreeCommander 2009.02b (HKLM-x32\...\FreeCommander_is1) (Version: 2009.02 - Marek Jasinski)
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.07) (Version: 9.07 - Artifex Software Inc.)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) Smart Connect Technology 3.0 x64 (HKLM\...\{01C324B7-3744-4EC0-9C4F-40BCCDD47CFB}) (Version: 3.0.41.1571 - Intel)
LibreOffice 4.2 Help Pack (German) (HKLM-x32\...\{DA6AF414-24FA-4815-A4FB-5EFD6173E6F5}) (Version: 4.2.4.2 - The Document Foundation)
LibreOffice 4.2.8.2 (HKLM-x32\...\{2D3234B2-FC7B-41CD-9FC8-4F9C2C20C131}) (Version: 4.2.8.2 - The Document Foundation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Core Components (x64) ENU (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Provider Services (x64) ENU (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MiKTeX 2.9 (HKU\S-1-5-21-4093833643-2685545966-1431014470-1003\...\MiKTeX 2.9) (Version: 2.9 - MiKTeX.org)
Mozilla Firefox 35.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
Mozilla Thunderbird 31.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.4.0 (x86 de)) (Version: 31.4.0 - Mozilla)
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.5 - F.J. Wechselberger)
Need for Speed™ Most Wanted (HKLM-x32\...\{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}) (Version: - )
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
PDF Architect 2 View Module (HKLM-x32\...\{46889070-D447-4936-A5D3-246DB972FA2E}) (Version: 2.0.6.16537 - pdfforge GmbH)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.67.1226.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6839 - Realtek Semiconductor Corp.)
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: 1.90 - Ghostgum Software Pty Ltd)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
SyncToy 2.1 (x64) (HKLM\...\{88DAAF05-5A72-46D2-A7C5-C3759697E943}) (Version: 2.1.0 - Microsoft)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.26297 - TeamViewer)
Texmaker (HKLM-x32\...\Texmaker) (Version: - )
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WinRAR 5.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
04-11-2014 15:10:11 Windows Update
09-11-2014 11:57:25 Windows Update
09-11-2014 12:42:31 Installed LibreOffice 4.2.6.3
11-11-2014 22:15:15 Windows Update
15-11-2014 16:20:04 Windows Update
19-11-2014 22:37:42 Windows Update
23-11-2014 09:58:27 Windows Update
25-11-2014 22:50:45 avast! antivirus system restore point
29-11-2014 21:28:02 Windows Update
03-12-2014 07:57:01 Windows Update
12-12-2014 15:24:22 Windows Update
12-12-2014 15:51:57 Windows Update
15-12-2014 21:34:42 Windows Update
17-12-2014 22:21:05 Windows Update
23-12-2014 11:13:09 Windows Update
26-12-2014 12:58:26 Windows Update
30-12-2014 11:20:11 Windows Update
06-01-2015 11:57:03 Windows Update
06-01-2015 21:37:53 Installed LibreOffice 4.2.8.2
09-01-2015 18:25:32 Windows Update
13-01-2015 22:51:44 Windows Update
14-01-2015 21:31:30 Windows Update
18-01-2015 21:09:37 Installed SyncToy 2.1 (x64)
20-01-2015 08:03:26 Windows Update
23-01-2015 19:15:58 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {64D1FB2A-375B-4335-9759-733AFF4700C6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {68493A76-FF86-473B-8C96-CB0F9B32A31E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-25] (AVAST Software)
Task: {E3422092-5FD1-40D9-9E33-C08392C38D6C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-23] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2014-07-31 22:50 - 2014-07-31 22:50 - 00034304 _____ () C:\Windows\System32\sst7clm.dll
2012-08-16 20:36 - 2012-08-16 20:36 - 00149032 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2012-08-16 20:36 - 2012-08-16 20:36 - 00058920 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2014-11-25 22:51 - 2014-11-25 22:51 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2014-11-25 22:51 - 2014-11-25 22:51 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2013-11-15 17:05 - 2012-09-28 19:51 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-01-24 19:13 - 2015-01-24 19:13 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15012401\algo.dll
2014-11-25 22:51 - 2014-11-25 22:51 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2013-11-15 17:08 - 2013-01-14 19:25 - 01200088 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2014-11-25 22:51 - 2014-11-25 22:51 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-01-17 21:49 - 2015-01-17 21:49 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-4093833643-2685545966-1431014470-500 - Administrator - Disabled)
Gast (S-1-5-21-4093833643-2685545966-1431014470-501 - Limited - Enabled) => C:\Users\Gast
HomeGroupUser$ (S-1-5-21-4093833643-2685545966-1431014470-1002 - Limited - Enabled)
Ingo (S-1-5-21-4093833643-2685545966-1431014470-1003 - Limited - Enabled) => C:\Users\Ingo
Jasper (S-1-5-21-4093833643-2685545966-1431014470-1006 - Limited - Enabled) => C:\Users\Jasper
Uli (S-1-5-21-4093833643-2685545966-1431014470-1004 - Limited - Enabled) => C:\Users\Uli
User (S-1-5-21-4093833643-2685545966-1431014470-1000 - Administrator - Enabled) => C:\Users\User
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/25/2015 00:02:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/24/2015 07:13:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/23/2015 07:10:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/21/2015 10:35:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/21/2015 08:55:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/21/2015 07:17:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/21/2015 02:58:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/20/2015 10:45:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/20/2015 07:59:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/18/2015 08:18:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (01/21/2015 10:36:01 PM) (Source: DCOM) (EventID: 10016) (User: User-PC)
Description: AnwendungsspezifischLokalAktivierung{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}User-PCGastS-1-5-21-4093833643-2685545966-1431014470-501LocalHost (unter Verwendung von LRPC)
Error: (01/21/2015 10:35:31 PM) (Source: DCOM) (EventID: 10016) (User: User-PC)
Description: AnwendungsspezifischLokalAktivierung{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}User-PCGastS-1-5-21-4093833643-2685545966-1431014470-501LocalHost (unter Verwendung von LRPC)
Error: (01/21/2015 10:35:08 PM) (Source: Microsoft-Windows-Eventlog) (EventID: 106) (User: NT-AUTORITÄT)
Description: Das Protokoll für Kanal Security war beschädigt und einige Daten sind gelöscht worden.
Error: (01/21/2015 07:17:23 PM) (Source: Microsoft-Windows-Eventlog) (EventID: 106) (User: NT-AUTORITÄT)
Description: Das Protokoll für Kanal Microsoft-Windows-Kernel-Power/Thermal-Operational war beschädigt und einige Daten sind gelöscht worden.
Error: (01/20/2015 10:51:35 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (01/20/2015 10:51:34 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (01/20/2015 10:51:34 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (01/20/2015 10:51:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (01/20/2015 10:51:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (01/14/2015 08:32:37 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E579AB5F-1CC4-44B4-BED9-DE0991FF0623}
Microsoft Office Sessions:
=========================
Error: (01/25/2015 00:02:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/24/2015 07:13:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/23/2015 07:10:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/21/2015 10:35:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/21/2015 08:55:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/21/2015 07:17:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/21/2015 02:58:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/20/2015 10:45:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/20/2015 07:59:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/18/2015 08:18:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz
Percentage of memory in use: 24%
Total physical RAM: 8076.35 MB
Available physical RAM: 6114.41 MB
Total Pagefile: 16150.89 MB
Available Pagefile: 14125.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:200 GB) (Free:81.12 GB) NTFS
Drive d: (Data) (Fixed) (Total:1662.92 GB) (Free:1573.27 GB) NTFS
Drive f: () (Fixed) (Total:194.5 GB) (Free:104.43 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: 79751EB5)
Partition 1: (Not Active) - (Size=63 MB) - (Type=DE)
Partition 2: (Active) - (Size=194.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=4.6 GB) - (Type=DB)
Partition 4: (Not Active) - (Size=98.9 GB) - (Type=OF Extended)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 99BF1283)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=200 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=1662.9 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-01-25 13:29:38
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_DT01ACA200 rev.MX4OABB0 1863,02GB
Running: Gmer-19357.exe; Driver: C:\Users\User\AppData\Local\Temp\kwtdapob.sys
---- User code sections - GMER 2.1 ----
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076bf1465 2 bytes [BF, 76]
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076bf14bb 2 bytes [BF, 76]
.text ... * 2
.text C:\Program Files (x86)\XTab\ProtectService.exe[1276] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076bf1465 2 bytes [BF, 76]
.text C:\Program Files (x86)\XTab\ProtectService.exe[1276] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076bf14bb 2 bytes [BF, 76]
.text ... * 2
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2052] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000768c8791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
---- Processes - GMER 2.1 ----
Process C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (*** suspicious ***) @ C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [1384] (WindowsProtectManger Service/Fuyu LIMITED)(2015-01-14 21:23:57) 0000000000c30000
---- EOF - GMER 2.1 ---- |