IneedHelp1 | 03.02.2015 07:23 | Hier Teil 2 von FRST.txt: Code:
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-02 21:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-02-02 20:44 - 2013-08-22 15:46 - 00310287 _____ () C:\WINDOWS\setupact.log
2015-02-02 19:58 - 2014-11-21 04:35 - 01963610 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-02 19:58 - 2014-11-21 03:45 - 00831932 _____ () C:\WINDOWS\system32\perfh007.dat
2015-02-02 19:58 - 2014-11-21 03:45 - 00184304 _____ () C:\WINDOWS\system32\perfc007.dat
2015-02-02 07:30 - 2013-04-15 22:37 - 00000000 ____D () C:\ProgramData\WinClon
2015-02-02 07:27 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-02-02 07:26 - 2014-11-20 19:24 - 00024436 _____ () C:\WINDOWS\PFRO.log
2015-02-02 07:26 - 2013-08-22 15:44 - 00533664 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-02-01 22:06 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-02-01 18:09 - 2013-08-22 14:25 - 00000194 _____ () C:\WINDOWS\win.ini
2015-01-28 08:00 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-01-24 21:20 - 2014-11-21 12:01 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-01-24 21:20 - 2014-11-21 12:01 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 11:57 - 2013-04-15 21:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2015-01-24 00:45 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\GroupPolicy
2015-01-23 15:55 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-01-23 07:18 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-01-22 18:55 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\LiveKernelReports
2015-01-19 23:25 - 2014-11-21 04:13 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-19 23:25 - 2014-11-21 03:45 - 00000000 ____D () C:\WINDOWS\SysWOW64\winrm
2015-01-19 23:25 - 2014-11-21 03:45 - 00000000 ____D () C:\WINDOWS\SysWOW64\WCN
2015-01-19 23:25 - 2014-11-21 03:45 - 00000000 ____D () C:\WINDOWS\SysWOW64\slmgr
2015-01-19 23:25 - 2014-11-21 03:45 - 00000000 ____D () C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2015-01-19 23:25 - 2014-11-21 03:45 - 00000000 ____D () C:\WINDOWS\system32\winrm
2015-01-19 23:25 - 2014-11-21 03:45 - 00000000 ____D () C:\WINDOWS\system32\WCN
2015-01-19 23:25 - 2014-11-21 03:45 - 00000000 ____D () C:\WINDOWS\system32\slmgr
2015-01-19 23:25 - 2014-11-21 03:45 - 00000000 ____D () C:\WINDOWS\system32\Printing_Admin_Scripts
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ___SD () C:\WINDOWS\system32\dsc
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\WinStore
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\MUI
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\en-GB
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Com
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\SystemResetPlatform
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\MUI
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\migwiz
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\en-GB
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\Com
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\IME
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Help
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Defender
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-01-19 23:25 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-01-19 23:25 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\oobe
2015-01-19 23:25 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism
2015-01-19 23:25 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
2015-01-19 23:25 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2015-01-19 23:25 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Dism
2015-01-19 23:25 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\servicing
2015-01-19 13:38 - 2013-04-15 21:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-15 22:41 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-01-15 22:39 - 2013-04-15 22:41 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-01-15 21:06 - 2013-04-15 22:41 - 00001398 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-01-15 21:06 - 2013-04-15 22:41 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-01-15 21:05 - 2013-04-15 22:41 - 00001653 _____ () C:\WINDOWS\DirectX.log
2015-01-15 20:39 - 2013-04-15 21:50 - 00000000 ____D () C:\Program Files (x86)\Samsung
2015-01-15 20:17 - 2013-04-15 22:38 - 00000000 ____D () C:\ProgramData\Samsung
2015-01-15 20:07 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2015-01-15 20:07 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\setup
2015-01-15 20:07 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-RS
2015-01-15 20:07 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-CS
2015-01-15 20:07 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\setup
2015-01-15 19:45 - 2013-04-15 21:48 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-01-15 19:45 - 2013-04-15 21:48 - 00000000 ____D () C:\ProgramData\Intel
2015-01-15 19:45 - 2013-04-15 21:48 - 00000000 ____D () C:\Program Files\Intel
2015-01-15 19:44 - 2013-04-15 21:48 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-01-15 19:42 - 2013-04-15 21:49 - 00028034 _____ () C:\WINDOWS\DPINST.LOG
2015-01-15 19:36 - 2013-08-22 15:46 - 00000262 _____ () C:\WINDOWS\setuperr.log
2015-01-15 19:36 - 2013-04-15 22:46 - 00019318 _____ () C:\WINDOWS\system32\results.xml
2015-01-15 19:26 - 2013-04-15 22:34 - 00000000 ____D () C:\ProgramData\AMD
2015-01-15 19:25 - 2013-04-15 22:33 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2015-01-15 19:25 - 2013-04-15 21:49 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-15 18:46 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-01-15 18:46 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-01-15 18:28 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\restore
2015-01-15 18:20 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Registration
2015-01-15 18:20 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows NT
2015-01-15 18:20 - 2013-08-22 14:36 - 00000000 __RHD () C:\Users\Default
2015-01-15 18:19 - 2013-08-22 16:36 - 00000000 __RSD () C:\WINDOWS\Media
2015-01-15 18:19 - 2013-08-22 16:36 - 00000000 __RHD () C:\Users\Public\Libraries
2015-01-15 18:18 - 2014-11-21 03:45 - 00000000 ____D () C:\WINDOWS\SysWOW64\sysprep
2015-01-15 18:18 - 2013-08-22 16:43 - 00000000 ____D () C:\WINDOWS\DigitalLocker
2015-01-15 18:18 - 2013-08-22 16:37 - 00005217 _____ () C:\WINDOWS\DtcInstall.log
2015-01-15 18:18 - 2013-08-22 16:36 - 00000000 __SHD () C:\Program Files\Windows Sidebar
2015-01-15 18:18 - 2013-08-22 16:36 - 00000000 __SHD () C:\Program Files (x86)\Windows Sidebar
2015-01-15 18:18 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz
2015-01-15 18:18 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\IME
2015-01-15 18:18 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\WinBioPlugIns
2015-01-15 18:18 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\spool
2015-01-15 18:18 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\IME
2015-01-15 18:18 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\SMI
2015-01-15 18:18 - 2013-08-22 14:25 - 00008192 ___SH () C:\WINDOWS\system32\config\ELAM
2015-01-15 18:18 - 2013-04-15 22:39 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 10
2015-01-15 18:18 - 2013-04-15 22:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitcasa
2015-01-15 18:18 - 2013-04-15 22:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games
2015-01-15 18:18 - 2013-04-15 22:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Absolute Software
2015-01-15 18:18 - 2013-04-15 22:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Corporation
2015-01-15 18:18 - 2012-08-05 22:11 - 00000000 ____D () C:\ProgramData\PRICache
2015-01-15 18:18 - 2012-07-26 06:37 - 00000000 ____D () C:\Users\Default.migrated
2015-01-15 18:17 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\Recovery
2015-01-15 18:12 - 2013-08-22 16:36 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template
2015-01-15 18:11 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\FileManager
2015-01-15 17:58 - 2013-04-15 21:49 - 01771989 _____ () C:\WINDOWS\WindowsUpdate (1).log
2015-01-15 17:56 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent
2015-01-15 17:32 - 2013-04-15 21:48 - 00002787 _____ () C:\RHDSetup.log
2015-01-15 17:32 - 2013-04-15 21:48 - 00000000 ___HD () C:\Program Files (x86)\Temp
2015-01-15 13:07 - 2013-04-15 22:38 - 00000000 ____D () C:\ProgramData\Temp
2015-01-15 09:48 - 2013-04-15 21:50 - 00000000 ____D () C:\Program Files\Samsung
2015-01-14 14:40 - 2013-04-15 22:38 - 00000000 ____D () C:\Users\EasySurvey
2015-01-14 14:39 - 2013-04-15 21:48 - 00000000 ____D () C:\Intel
2015-01-14 12:48 - 2013-04-15 22:36 - 00000000 ____D () C:\ProgramData\Norton
2015-01-14 12:46 - 2012-07-26 09:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
==================== Files in the root of some directories =======
2015-01-14 12:23 - 2015-01-31 12:09 - 0005347 _____ () C:\Users\Nico\AppData\Roaming\AbsoluteReminder.xml
2015-01-15 21:32 - 2015-01-18 15:59 - 0004062 _____ () C:\Users\Nico\AppData\Roaming\LTspiceIV.ini
2015-01-15 21:16 - 2015-01-15 21:16 - 0000039 _____ () C:\Users\Nico\AppData\Roaming\SupportBox_MSUL.cfg
2015-01-15 18:15 - 2015-01-15 18:15 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2013-04-15 22:43 - 2013-02-19 08:34 - 2064264 _____ (Samsung Electronics) C:\ProgramData\MakeMarkerFile.exe
2013-04-15 22:43 - 2013-01-12 15:51 - 0003004 _____ () C:\ProgramData\MakeMarkerFile.xml
Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe
Some content of TEMP:
====================
C:\Users\Nico\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsaz467.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-26 07:33
==================== End Of Log ============================
Gmer.txt: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-02-02 21:22:52
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002e Samsung_SSD_840_EVO_500GB rev.EXT0BB6Q 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Nico\AppData\Local\Temp\pwryyfog.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff9600009e200 15 bytes [00, 28, F6, 01, 80, 1C, 6C, ...]
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16 fffff9600009e210 11 bytes [00, 0E, FC, FF, 00, 05, C4, ...]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [992:100] fffff9600090b2d0
---- Processes - GMER 2.1 ----
Process C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (*** suspicious ***) @ C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [1864] (Windows SysTool Service/SysTool PasSame LIMITED)(2015-01-23 14:51:48) 0000000000960000
Process C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (FILE NOT FOUND) 0000000000400000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5Widgets.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:09) 0000000065490000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5Gui.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:08) 0000000065190000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5Core.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:08) 0000000064da0000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\libGLESv2.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096](2015-01-15 21:09:09) 0000000064ce0000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\icuin52.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (ICU I18N DLL/The ICU Project)(2015-01-15 21:09:09) 000000004a900000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\icuuc52.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (ICU Common DLL/The ICU Project)(2015-01-15 21:09:09) 0000000004300000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\icudt52.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (ICU Data DLL/The ICU Project)(2015-01-15 21:09:09) 000000004ad00000
Library c:\users\nico\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsaz467.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096](2015-02-02 06:28:08) 0000000003ee0000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5Network.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:08) 0000000062b30000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5WebKit.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:09) 0000000061120000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5Quick.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:09) 0000000060f00000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5Qml.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:08) 0000000060ca0000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5Sql.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:09) 0000000060c70000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\libEGL.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096](2015-01-15 21:09:09) 000000006a1b0000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5WebKitWidgets.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:09) 0000000060c40000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5OpenGL.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:08) 0000000060c00000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\Qt5PrintSupport.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-01-15 21:09:08) 0000000060bb0000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096](2015-01-15 21:09:09) 0000000062a50000
Library C:\Users\Nico\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll (*** suspicious ***) @ C:\Users\Nico\AppData\Roaming\Dropbox\bin\Dropbox.exe [7096](2015-01-15 21:09:09) 0000000062a10000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
adwcleaner: Code:
# AdwCleaner v4.109 - Bericht erstellt am 02/02/2015 um 18:40:12
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-01-26.1 [Live]
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Nico - NICO_STUDY
# Gestartet von : C:\Users\Nico\Desktop\adwcleaner_4.109.exe
# Option : Suchen
***** [ Dienste ] *****
Dienst Gefunden : WindowsMangerProtect
Dienst Gefunden : IHProtect Service
Dienst Gefunden : Util Dynamo Combo
Dienst Gefunden : Update Dynamo Combo
Dienst Gefunden : Update Dynamo Combo
Dienst Gefunden : Util Dynamo Combo
Dienst Gefunden : {16a92140-918d-4afb-9edb-46f22437bb10}Gw64
Dienst Gefunden : {3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}Gw64
Dienst Gefunden : {915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gefunden : C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gefunden : C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
Datei Gefunden : C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
Datei Gefunden : C:\WINDOWS\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}Gw64.sys
Datei Gefunden : C:\WINDOWS\System32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}Gw64.sys
Datei Gefunden : C:\WINDOWS\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64.sys
Ordner Gefunden : C:\Program Files (x86)\Dynamo Combo
Ordner Gefunden : C:\Program Files (x86)\Dynamo Combo
Ordner Gefunden : C:\Program Files (x86)\SearchProtect
Ordner Gefunden : C:\Program Files (x86)\XTab
Ordner Gefunden : C:\ProgramData\IHProtectUpDate
Ordner Gefunden : C:\ProgramData\WindowsMangerProtect
Ordner Gefunden : C:\Users\Nico\AppData\Local\SearchProtect
Ordner Gefunden : C:\Users\Nico\AppData\Roaming\vi-view
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Daten Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
Daten Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll
Schlüssel Gefunden : HKCU\Software\Dynamo Combo
Schlüssel Gefunden : HKCU\Software\Dynamo Combo
Schlüssel Gefunden : HKCU\Software\InstallCore
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Schlüssel Gefunden : HKCU\Software\Mozilla\Extends
Schlüssel Gefunden : [x64] HKCU\Software\Dynamo Combo
Schlüssel Gefunden : [x64] HKCU\Software\Dynamo Combo
Schlüssel Gefunden : [x64] HKCU\Software\InstallCore
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{986c37a1-7b65-476f-80dc-54f80bd4b0d6}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{986C37A1-7B65-476F-80DC-54F80BD4B0D6}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{53f00938-0214-4c62-b6d8-9e2034314ebb}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gefunden : HKLM\SOFTWARE\Dynamo Combo
Schlüssel Gefunden : HKLM\SOFTWARE\Dynamo Combo
Schlüssel Gefunden : HKLM\SOFTWARE\IHProtect
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{986c37a1-7b65-476f-80dc-54f80bd4b0d6}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{986C37A1-7B65-476F-80DC-54F80BD4B0D6}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\vi-view uninstall
Schlüssel Gefunden : HKLM\SOFTWARE\SearchProtect
Schlüssel Gefunden : HKLM\SOFTWARE\SPPDCOM
Schlüssel Gefunden : HKLM\SOFTWARE\SupDp
Schlüssel Gefunden : HKLM\SOFTWARE\SupTab
Schlüssel Gefunden : HKLM\SOFTWARE\supWindowsMangerProtect
Schlüssel Gefunden : HKLM\SOFTWARE\vi-viewSoftware
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update Dynamo Combo
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util Dynamo Combo
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ac225167-00fc-452d-94c5-bb93600e7d9a}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dynamo Combo
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dynamo Combo
Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [fftoolbar2014@etech.com]
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17416
Einstellung Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://myhome.vi-view.com/web/?type=ds&ts=1422024598&from=cor&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF824519D&q={searchTerms}
Einstellung Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://myhome.vi-view.com/?type=hp&ts=1422024598&from=cor&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF824519D
Einstellung Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://myhome.vi-view.com/?type=hp&ts=1422024598&from=cor&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF824519D
Einstellung Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://myhome.vi-view.com/web/?type=ds&ts=1422024598&from=cor&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF824519D&q={searchTerms}
-\\ Mozilla Firefox v35.0.1 (x86 de)
[045rdp04.default] - Zeile gefunden : user_pref("browser.search.searchengine.alias", "vi-view");
[045rdp04.default] - Zeile gefunden : user_pref("browser.search.searchengine.iconURL", "hxxp://myhome.vi-view.com/favicon.ico");
[045rdp04.default] - Zeile gefunden : user_pref("browser.search.searchengine.name", "vi-view");
[045rdp04.default] - Zeile gefunden : user_pref("browser.search.searchengine.url", "hxxp://myhome.vi-view.com/web/?type=ds&ts=1422024598&from=cor&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF824519D&q={searchTerms}");
[045rdp04.default] - Zeile gefunden : user_pref("extensions.quick_start.enable_search1", false);
[045rdp04.default] - Zeile gefunden : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
-\\ Google Chrome v40.0.2214.93
[C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://myhome.vi-view.com/web/?type=ds&ts=1422024598&from=cor&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF824519D&q={searchTerms}
[C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://myhome.vi-view.com/web/?type=ds&ts=1422024598&from=cor&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF824519D&q={searchTerms}
[C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://myhome.vi-view.com/web/?type=ds&ts=1422024598&from=cor&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF824519D&q={searchTerms}
[C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://myhome.vi-view.com/web/?type=ds&ts=1422024598&from=cor&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF824519D&q={searchTerms}
*************************
AdwCleaner[R0].txt - [11485 octets] - [02/02/2015 18:40:12]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [11546 octets] ##########
Avast-BrowserCleanUp: Code:
02.02.2015 21:31:48 (TID: 5808)
Product version: 10.0.2208.84
02.02.2015 21:31:48 (TID: 5808)
BCUEngine version : 9.0.0.496
ProductLanguage : de
OSLanguage : de-de
Location : de-de
OSType : 6.2
IsStandalone : 0
PartnerId : avastbcl
Priority : 10
Microsoft IE
Install Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Version: 9.11.9600.17498
Mozilla Firefox Browser
Install Path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Version: 35.0.1.5500
Profile Path: C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\
Mozilla Firefox Profiles
Name: default Path: C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\045rdp04.default
Google Chrome Browser
Version: 40.0.2214.93
Install Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Profile Path: C:\Users\Nico\AppData\Local\Google\Chrome\User Data\
Google Chrome Profiles
Name: Default Path: C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default
Google Chrome64 Browser
Version:
Browser not found
Google Chrome
Extensions
Profile: Default
ID: aohghmighlieiainnegkcijnfilokake Name: Google Docs
ID: felcaaldnbdncclmgdcncolpebgiejap Name: Google Tabellen
ID: gomekmidlodglbbmalcneegieacbdmki Name: Avast Online Security
Mozilla Firefox
Extensions
Profile: default
ID: youtubeunblocker@unblocker.yt Name: YouTube Unblocker
ID: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} Name: Adblock Plus
ID: wrc@avast.com Name: Avast Online Security
Google Chrome
Homepages
Profile: Default
Url : https://www.google.com/?trackid=sp-006
Search Engines
Profile: Default
Name : Google
Url : https://www.google.de/search?q={searchTerms}?trackid=sp-006
FireFox
Homepages
Profile: default
URL : https://www.google.com/?trackid=sp-006
Search Engines
Profile: default
Name : Google (avast)
Url : hxxp://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&channel=fs&trackid=sp-006
Microsoft IE
Homepages
Profile: HKCU
Url : https://www.google.com/?trackid=sp-006
Search Engines
Profile: HKCU
Name : Google
Url : https://www.google.com/search?trackid=sp-006&q={searchTerms}
BCURequest:
GlobalStat
ProductLanguage : de
EngineVersion : 9.0.0.496
OSLanguage : de-de
Location : de-de
OSType : 6.2
IsStandalone : 0
Version : 10.0.2208.84
PartnerId : avastbcl
Priority : 10
AvastProductType: 0
DefaultBrowser : FIREFOXURL
Google Chrome:
IsDefault: 0
Homepages
Url: https://www.google.com/?trackid=sp-006
Search Engines
Name : Google
Url : https://www.google.de/search?q={searchTerms}?trackid=sp-006
Extensions
ID: aohghmighlieiainnegkcijnfilokake Name: Google Docs
ID: felcaaldnbdncclmgdcncolpebgiejap Name: Google Tabellen
ID: gomekmidlodglbbmalcneegieacbdmki Name: Avast Online Security
FireFox:
IsDefault: 1
Homepages
Url: https://www.google.com/?trackid=sp-006
Search Engines
Name : Google (avast)
Url : hxxp://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&channel=fs&trackid=sp-006
Extensions
ID: wrc@avast.com Name: Avast Online Security
ID: youtubeunblocker@unblocker.yt Name: YouTube Unblocker
ID: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} Name: Adblock Plus
Microsoft IE:
IsDefault: 0
Homepages
Url: https://www.google.com/?trackid=sp-006
Search Engines
Name : Google
Url : https://www.google.com/search?trackid=sp-006&q={searchTerms}
Extensions
ID: {18df081c-e8ad-4283-a596-fa578c2ebdc3} Name: Adobe PDF Link Helper
ID: {31d09ba0-12f5-4cce-be8a-2923e76605da} Name: Lync Browser Helper
BCUResponse:
OfferId : ID_DE_DE_YB_RB_V10
TemplateId: TPL_RADIO
BCUConfig
RrescanDelay : 0
CacheIntervalPos : 604800
CacheIntervalNeg : 604800
CmsTimeout : 15000
UseCorporate : 0
BCUProviders
ID: TPL_YAHOO9_DE Name: Yahoo! (Avast)
ID: TPL_BING02_ALL Name: Bing (by Microsoft)
ID: PID_BLEKKO_ALL Name: Blekko
ID: PID_GOOGLE_ALL Name: Google
ID: PID_STARTPAGE_ALL Name: Startpage
ID: PID_WOLFRAM_ALL Name: WolframAlpha
ID: PID_KEEPEXISTING Name: Keep Existing (not recommended)
Google Chrome:
IsProviderModified: 0
Extensions
ID: aohghmighlieiainnegkcijnfilokake Rating: 4 InternalId: 1
ID: felcaaldnbdncclmgdcncolpebgiejap Rating: 4 InternalId: 8000
ID: gomekmidlodglbbmalcneegieacbdmki Rating: 5 InternalId: 8000
Search Engine
Name: Google
Url : https://www.google.de/search?q={searchTerms}?trackid=sp-006
FireFox:
IsProviderModified: 0
Extensions
ID: wrc@avast.com Rating: 5 InternalId: 1
ID: youtubeunblocker@unblocker.yt Rating: 4 InternalId: 3
ID: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} Rating: 5 InternalId: 8000
Search Engine
Name: Google (avast)
Url : hxxp://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&channel=fs&trackid=sp-006
Microsoft IE:
IsProviderModified: 0
Extensions
ID: {18df081c-e8ad-4283-a596-fa578c2ebdc3} Rating: 5 InternalId: 8000
ID: {31d09ba0-12f5-4cce-be8a-2923e76605da} Rating: 5 InternalId: 5200
Search Engine
Name: Google
Url : https://www.google.com/search?trackid=sp-006&q={searchTerms}
Detected a potential browser protector: {
"Services" : {
"iumsvc" : {
"Description" : "intel(r) update manager helps you keep your system up-to-date.",
"DisplayName" : "intel(r) update manager",
"FileInfo" : {
"Path" : "\"c:\\program files (x86)\\intel\\intel(r) update manager\\bin\\iumsvc.exe\"",
"md5" : ""
}
}
}
}
Detected a potential browser protector: {
"Services" : {
"WdNisSvc" : {
"Description" : "@%programfiles%\\windows defender\\mpasdesc.dll,-242",
"DisplayName" : "@%programfiles%\\windows defender\\mpasdesc.dll,-320",
"FileInfo" : {
"Path" : "\"c:\\program files (x86)\\windows defender\\nissrv.exe\"",
"md5" : ""
}
},
"WinDefend" : {
"Description" : "@%programfiles%\\windows defender\\mpasdesc.dll,-240",
"DisplayName" : "@%programfiles%\\windows defender\\mpasdesc.dll,-310",
"FileInfo" : {
"Path" : "\"c:\\program files (x86)\\windows defender\\msmpeng.exe\"",
"md5" : ""
}
}
}
}
Detected a potential browser protector:3BF731130158C1F78DA21D7B8026CBB6EFA0F0F5F8DE4994728CA3D0A06B8819 {
"runKeys" : {
"SamsungRapidApp" : "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\SamsungRapidApp=c:\\program files (x86)\\samsung\\rapid\\cachefilter\\samsungrapidapp.exe"
},
"runningProcess" : {
"SamsungRapidApp.exe" : {
"CompanyName" : "Samsung Electronics Co., Ltd.",
"FileDescription" : "Samsung RAPID Mode Notification Utility",
"FileVersion" : "1.0.1.81 built by: WinDDK",
"Path" : "c:\\program files (x86)\\samsung\\rapid\\cachefilter\\samsungrapidapp.exe",
"ProductVersion" : "Samsung RAPID Mode 1.0.1.81",
"md5" : "6F4E71A0C3817FC8F36532796632A259"
}
}
}
Detected a potential browser protector:CDE1D980F85F9ECE745A06DDE3E4616F2E7232D9086FA6E4C984BB65D9746F2C {
"Services" : {
"IHProtect Service" : {
"Description" : "",
"DisplayName" : "ihprotect service",
"FileInfo" : {
"CompanyName" : "XTab system",
"FileDescription" : "ProtectSvc.exe",
"FileVersion" : "4.0.1.1716",
"Path" : "c:\\program files (x86)\\xtab\\protectservice.exe",
"ProductVersion" : "4.0.1.1716",
"md5" : "B32A88B91E59BFB553A9BEBF78A1E567"
}
}
}
}
Detected a potential browser protector:4B88C39D12D8A7E0387766C4FDEAB6F5D7639ED38F9CEF7B7363538B5645EC72 {
"runKeys" : {
"RtHDVBg" : "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\RtHDVBg=\"c:\\program files\\realtek\\audio\\hda\\ravbg64.exe\" /s3hpprotect",
"RtHDVBg_SRSSA" : "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\RtHDVBg_SRSSA=\"c:\\program files\\realtek\\audio\\hda\\ravbg64.exe\" /srssa",
"RtHDVCpl" : "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\RtHDVCpl=c:\\program files\\realtek\\audio\\hda\\ravcpl64.exe -s"
},
"runningProcess" : {
"RAVBg64.exe" : {
"CompanyName" : "Realtek Semiconductor",
"FileDescription" : "HD Audio Background Process",
"FileVersion" : "1, 0, 0, 203",
"Path" : "c:\\program files\\realtek\\audio\\hda\\ravbg64.exe",
"ProductVersion" : "1, 0, 0, 203",
"md5" : "4D3341C3D5AF1A1B8B93A5A6C08902BD"
},
"RAVCpl64.exe" : {
"CompanyName" : "Realtek Semiconductor",
"FileDescription" : "Realtek HD Audio-Manager",
"FileVersion" : "1, 0, 0, 935",
"Path" : "c:\\program files\\realtek\\audio\\hda\\ravcpl64.exe",
"ProductVersion" : "1, 0, 0, 935",
"md5" : "8F9343E9015DA92CDC455A92FE320AB0"
}
},
"uninstallInfo" : {
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" : {
"DisplayName" : "Realtek High Definition Audio Driver",
"Publisher" : "Realtek Semiconductor Corp.",
"UninstallString" : "c:\\program files\\realtek\\audio\\hda\\rtlupd64.exe -r -m -nrg2709"
}
}
}
Detected a potential browser protector: {
"Services" : {
"WindowsMangerProtect" : {
"Description" : "windowsmangerprotect service",
"DisplayName" : "windowsmangerprotect service",
"FileInfo" : {
"Path" : "c:\\programdata\\windowsmangerprotect\\protectwindowsmanager.exe -service",
"md5" : ""
}
}
}
}
Detected a potential browser protector:8AF70D124AE6E89B486BD1D97E0ECA70CB423316CA9EF44BF51373998CA80645 {
"AppInitDll" : {
"CompanyName" : "Client Connect LTD",
"FileDescription" : "Search Protect",
"FileVersion" : "2.19.30.69",
"Path" : "c:\\progra~2\\searchprotect\\searchprotect\\bin\\vc32loader.dll",
"ProductVersion" : "2.19.30.69",
"md5" : "F56FDE850079E5D7FFAFF38E090485C5"
}
}
Detected a potential browser protector: {
"uninstallInfo" : {
"vi-view uninstall" : {
"DisplayName" : "vi-view uninstall",
"Publisher" : "vi-view",
"UninstallString" : "c:\\users\\nico\\appdata\\roaming\\vi-view\\uninstallmanager.exe -ptid=cor"
}
}
}
Detected a potential browser protector:3DE978B005BF2E88BA858CE37D9E27BD3584642B8412E22C300A1E739743838A {
"Services" : {
"AdobeFlashPlayerUpdateSvc" : {
"Description" : "mit diesem dienst ist ihre flash player-installation immer aktuell und verwendet die neuesten verbesserungen und sicherheits-fixes.",
"DisplayName" : "adobe flash player update service",
"FileInfo" : {
"CompanyName" : "Adobe Systems Incorporated",
"FileDescription" : "Adobe® Flash® Player Update Service 16.0 r0",
"FileVersion" : "16,0,0,296",
"Path" : "c:\\windows\\syswow64\\macromed\\flash\\flashplayerupdateservice.exe",
"ProductVersion" : "16,0,0,296",
"md5" : "A2A9C100FE1BE20A76C0B80D4CA44103"
}
},
"PerfHost" : {
"Description" : "@%systemroot%\\syswow64\\perfhost.exe,-1",
"DisplayName" : "@%systemroot%\\syswow64\\perfhost.exe,-2",
"FileInfo" : {
"CompanyName" : "Microsoft Corporation",
"FileDescription" : "x86-Leistungsindikatorhost",
"FileVersion" : "6.3.9600.16384 (winblue_rtm.130821-1623)",
"Path" : "c:\\windows\\syswow64\\perfhost.exe",
"ProductVersion" : "6.3.9600.16384",
"md5" : "8E3C640FFF5A963F570233AE99C0FFF3"
}
},
"cphs" : {
"Description" : "intel(r) content protection heci service - enables communication with the content protection fw",
"DisplayName" : "intel(r) content protection heci service",
"FileInfo" : {
"CompanyName" : "Intel Corporation",
"FileDescription" : "IntelCpHeciSvc Executable",
"Path" : "c:\\windows\\syswow64\\intelcphecisvc.exe",
"ProductVersion" : "9.0.20.9000",
"md5" : "7459091986F5A926AC807F2C85B49BA8"
}
}
},
"runKeys" : {
"StubPath" : "HKLM\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B02.02.2015 21:32:04 (TID: 7440)
Product version: 10.0.2208.84
02.02.2015 21:32:04 (TID: 7440)
BCUEngine version : 9.0.0.496
ProductLanguage : de
OSLanguage : de-de
Location : de-de
OSType : 6.2
IsStandalone : 0
PartnerId : avastbcl
Priority : 10
Microsoft IE
Install Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Version: 9.11.9600.17498
Mozilla Firefox Browser
Install Path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Version: 35.0.1.5500
Profile Path: C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\
Mozilla Firefox Profiles
Name: default Path: C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\045rdp04.default
Google Chrome Browser
Version: 40.0.2214.93
Install Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Profile Path: C:\Users\Nico\AppData\Local\Google\Chrome\User Data\
Google Chrome Profiles
Name: Default Path: C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default
Google Chrome64 Browser
Version:
Browser not found
Google Chrome
Extensions
Profile: Default
ID: aohghmighlieiainnegkcijnfilokake Name: Google Docs
ID: felcaaldnbdncclmgdcncolpebgiejap Name: Google Tabellen
ID: gomekmidlodglbbmalcneegieacbdmki Name: Avast Online Security
Mozilla Firefox
Extensions
Profile: default
ID: youtubeunblocker@unblocker.yt Name: YouTube Unblocker
ID: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} Name: Adblock Plus
ID: wrc@avast.com Name: Avast Online Security
Google Chrome
Homepages
Profile: Default
Url : https://www.google.com/?trackid=sp-006
Search Engines
Profile: Default
Name : Google
Url : https://www.google.de/search?q={searchTerms}?trackid=sp-006
FireFox
Homepages
Profile: default
URL : https://www.google.com/?trackid=sp-006
Search Engines
Profile: default
Name : Google (avast)
Url : hxxp://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&channel=fs&trackid=sp-006
Microsoft IE
Homepages
Profile: HKCU
Url : https://www.google.com/?trackid=sp-006
Search Engines
Profile: HKCU
Name : Google
Url : https://www.google.com/search?trackid=sp-006&q={searchTerms}
BCURequest:
GlobalStat
ProductLanguage : de
EngineVersion : 9.0.0.496
OSLanguage : de-de
Location : de-de
OSType : 6.2
IsStandalone : 0
Version : 10.0.2208.84
PartnerId : avastbcl
Priority : 10
AvastProductType: 0
DefaultBrowser : FIREFOXURL
Google Chrome:
IsDefault: 0
Homepages
Url: https://www.google.com/?trackid=sp-006
Search Engines
Name : Google
Url : https://www.google.de/search?q={searchTerms}?trackid=sp-006
Extensions
ID: aohghmighlieiainnegkcijnfilokake Name: Google Docs
ID: felcaaldnbdncclmgdcncolpebgiejap Name: Google Tabellen
ID: gomekmidlodglbbmalcneegieacbdmki Name: Avast Online Security
FireFox:
IsDefault: 1
Homepages
Url: https://www.google.com/?trackid=sp-006
Search Engines
Name : Google (avast)
Url : hxxp://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&channel=fs&trackid=sp-006
Extensions
ID: wrc@avast.com Name: Avast Online Security
ID: youtubeunblocker@unblocker.yt Name: YouTube Unblocker
ID: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} Name: Adblock Plus
Microsoft IE:
IsDefault: 0
Homepages
Url: https://www.google.com/?trackid=sp-006
Search Engines
Name : Google
Url : https://www.google.com/search?trackid=sp-006&q={searchTerms}
Extensions
ID: {18df081c-e8ad-4283-a596-fa578c2ebdc3} Name: Adobe PDF Link Helper
ID: {31d09ba0-12f5-4cce-be8a-2923e76605da} Name: Lync Browser Helper
BCUResponse:
OfferId : ID_DE_DE_YB_RB_V10
TemplateId: TPL_RADIO
BCUConfig
RrescanDelay : 0
CacheIntervalPos : 604800
CacheIntervalNeg : 604800
CmsTimeout : 15000
UseCorporate : 0
BCUProviders
ID: TPL_YAHOO9_DE Name: Yahoo! (Avast)
ID: TPL_BING02_ALL Name: Bing (by Microsoft)
ID: PID_BLEKKO_ALL Name: Blekko
ID: PID_GOOGLE_ALL Name: Google
ID: PID_STARTPAGE_ALL Name: Startpage
ID: PID_WOLFRAM_ALL Name: WolframAlpha
ID: PID_KEEPEXISTING Name: Keep Existing (not recommended)
Google Chrome:
IsProviderModified: 0
Extensions
ID: aohghmighlieiainnegkcijnfilokake Rating: 4 InternalId: 1
ID: felcaaldnbdncclmgdcncolpebgiejap Rating: 4 InternalId: 8000
ID: gomekmidlodglbbmalcneegieacbdmki Rating: 5 InternalId: 8000
Search Engine
Name: Google
Url : https://www.google.de/search?q={searchTerms}?trackid=sp-006
FireFox:
IsProviderModified: 0
Extensions
ID: wrc@avast.com Rating: 5 InternalId: 1
ID: youtubeunblocker@unblocker.yt Rating: 4 InternalId: 3
ID: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} Rating: 5 InternalId: 8000
Search Engine
Name: Google (avast)
Url : hxxp://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&channel=fs&trackid=sp-006
Microsoft IE:
IsProviderModified: 0
Extensions
ID: {18df081c-e8ad-4283-a596-fa578c2ebdc3} Rating: 5 InternalId: 8000
ID: {31d09ba0-12f5-4cce-be8a-2923e76605da} Rating: 5 InternalId: 5200
Search Engine
Name: Google
Url : https://www.google.com/search?trackid=sp-006&q={searchTerms}
Detected a potential browser protector: {
"Services" : {
"iumsvc" : {
"Description" : "intel(r) update manager helps you keep your system up-to-date.",
"DisplayName" : "intel(r) update manager",
"FileInfo" : {
"Path" : "\"c:\\program files (x86)\\intel\\intel(r) update manager\\bin\\iumsvc.exe\"",
"md5" : ""
}
}
}
}
Detected a potential browser protector: {
"Services" : {
"WdNisSvc" : {
"Description" : "@%programfiles%\\windows defender\\mpasdesc.dll,-242",
"DisplayName" : "@%programfiles%\\windows defender\\mpasdesc.dll,-320",
"FileInfo" : {
"Path" : "\"c:\\program files (x86)\\windows defender\\nissrv.exe\"",
"md5" : ""
}
},
"WinDefend" : {
"Description" : "@%programfiles%\\windows defender\\mpasdesc.dll,-240",
"DisplayName" : "@%programfiles%\\windows defender\\mpasdesc.dll,-310",
"FileInfo" : {
"Path" : "\"c:\\program files (x86)\\windows defender\\msmpeng.exe\"",
"md5" : ""
}
}
}
}
Detected a potential browser protector:3BF731130158C1F78DA21D7B8026CBB6EFA0F0F5F8DE4994728CA3D0A06B8819 {
"runKeys" : {
"SamsungRapidApp" : "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\SamsungRapidApp=c:\\program files (x86)\\samsung\\rapid\\cachefilter\\samsungrapidapp.exe"
},
"runningProcess" : {
"SamsungRapidApp.exe" : {
"CompanyName" : "Samsung Electronics Co., Ltd.",
"FileDescription" : "Samsung RAPID Mode Notification Utility",
"FileVersion" : "1.0.1.81 built by: WinDDK",
"Path" : "c:\\program files (x86)\\samsung\\rapid\\cachefilter\\samsungrapidapp.exe",
"ProductVersion" : "Samsung RAPID Mode 1.0.1.81",
"md5" : "6F4E71A0C3817FC8F36532796632A259"
}
}
}
Detected a potential browser protector:CDE1D980F85F9ECE745A06DDE3E4616F2E7232D9086FA6E4C984BB65D9746F2C {
"Services" : {
"IHProtect Service" : {
"Description" : "",
"DisplayName" : "ihprotect service",
"FileInfo" : {
"CompanyName" : "XTab system",
"FileDescription" : "ProtectSvc.exe",
"FileVersion" : "4.0.1.1716",
"Path" : "c:\\program files (x86)\\xtab\\protectservice.exe",
"ProductVersion" : "4.0.1.1716",
"md5" : "B32A88B91E59BFB553A9BEBF78A1E567"
}
}
}
}
Detected a potential browser protector:4B88C39D12D8A7E0387766C4FDEAB6F5D7639ED38F9CEF7B7363538B5645EC72 {
"runKeys" : {
"RtHDVBg" : "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\RtHDVBg=\"c:\\program files\\realtek\\audio\\hda\\ravbg64.exe\" /s3hpprotect",
"RtHDVBg_SRSSA" : "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\RtHDVBg_SRSSA=\"c:\\program files\\realtek\\audio\\hda\\ravbg64.exe\" /srssa",
"RtHDVCpl" : "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\RtHDVCpl=c:\\program files\\realtek\\audio\\hda\\ravcpl64.exe -s"
},
"runningProcess" : {
"RAVBg64.exe" : {
"CompanyName" : "Realtek Semiconductor",
"FileDescription" : "HD Audio Background Process",
"FileVersion" : "1, 0, 0, 203",
"Path" : "c:\\program files\\realtek\\audio\\hda\\ravbg64.exe",
"ProductVersion" : "1, 0, 0, 203",
"md5" : "4D3341C3D5AF1A1B8B93A5A6C08902BD"
},
"RAVCpl64.exe" : {
"CompanyName" : "Realtek Semiconductor",
"FileDescription" : "Realtek HD Audio-Manager",
"FileVersion" : "1, 0, 0, 935",
"Path" : "c:\\program files\\realtek\\audio\\hda\\ravcpl64.exe",
"ProductVersion" : "1, 0, 0, 935",
"md5" : "8F9343E9015DA92CDC455A92FE320AB0"
}
},
"uninstallInfo" : {
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" : {
"DisplayName" : "Realtek High Definition Audio Driver",
"Publisher" : "Realtek Semiconductor Corp.",
"UninstallString" : "c:\\program files\\realtek\\audio\\hda\\rtlupd64.exe -r -m -nrg2709"
}
}
}
Detected a potential browser protector: {
"Services" : {
"WindowsMangerProtect" : {
"Description" : "windowsmangerprotect service",
"DisplayName" : "windowsmangerprotect service",
"FileInfo" : {
"Path" : "c:\\programdata\\windowsmangerprotect\\protectwindowsmanager.exe -service",
"md5" : ""
}
}
}
}
Detected a potential browser protector:8AF70D124AE6E89B486BD1D97E0ECA70CB423316CA9EF44BF51373998CA80645 {
"AppInitDll" : {
"CompanyName" : "Client Connect LTD",
"FileDescription" : "Search Protect",
"FileVersion" : "2.19.30.69",
"Path" : "c:\\progra~2\\searchprotect\\searchprotect\\bin\\vc32loader.dll",
"ProductVersion" : "2.19.30.69",
"md5" : "F56FDE850079E5D7FFAFF38E090485C5"
}
}
Detected a potential browser protector: {
"uninstallInfo" : {
"vi-view uninstall" : {
"DisplayName" : "vi-view uninstall",
"Publisher" : "vi-view",
"UninstallString" : "c:\\users\\nico\\appdata\\roaming\\vi-view\\uninstallmanager.exe -ptid=cor"
}
}
}
Detected a potential browser protector:3DE978B005BF2E88BA858CE37D9E27BD3584642B8412E22C300A1E739743838A {
"Services" : {
"AdobeFlashPlayerUpdateSvc" : {
"Description" : "mit diesem dienst ist ihre flash player-installation immer aktuell und verwendet die neuesten verbesserungen und sicherheits-fixes.",
"DisplayName" : "adobe flash player update service",
"FileInfo" : {
"CompanyName" : "Adobe Systems Incorporated",
"FileDescription" : "Adobe® Flash® Player Update Service 16.0 r0",
"FileVersion" : "16,0,0,296",
"Path" : "c:\\windows\\syswow64\\macromed\\flash\\flashplayerupdateservice.exe",
"ProductVersion" : "16,0,0,296",
"md5" : "A2A9C100FE1BE20A76C0B80D4CA44103"
}
},
"PerfHost" : {
"Description" : "@%systemroot%\\syswow64\\perfhost.exe,-1",
"DisplayName" : "@%systemroot%\\syswow64\\perfhost.exe,-2",
"FileInfo" : {
"CompanyName" : "Microsoft Corporation",
"FileDescription" : "x86-Leistungsindikatorhost",
"FileVersion" : "6.3.9600.16384 (winblue_rtm.130821-1623)",
"Path" : "c:\\windows\\syswow64\\perfhost.exe",
"ProductVersion" : "6.3.9600.16384",
"md5" : "8E3C640FFF5A963F570233AE99C0FFF3"
}
},
"cphs" : {
"Description" : "intel(r) content protection heci service - enables communication with the content protection fw",
"DisplayName" : "intel(r) content protection heci service",
"FileInfo" : {
"CompanyName" : "Intel Corporation",
"FileDescription" : "IntelCpHeciSvc Executable",
"Path" : "c:\\windows\\syswow64\\intelcphecisvc.exe",
"ProductVersion" : "9.0.20.9000",
"md5" : "7459091986F5A926AC807F2C85B49BA8"
}
}
},
"runKeys" : {
"StubPath" : "HKLM\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B So, das sollten zusammen mit dem ersten Beitrag nun alle logfiles sein. :)
Interessant, dass das Problem mit der länge nur an FRST.txt lag.
Grüße Nico |