porter3107 | 23.02.2015 17:36 |
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-02-2015
Ran by Porter (administrator) on PORTER-PC on 23-02-2015 17:33:59
Running from C:\Users\Porter\Downloads
Loaded Profiles: Porter (Available profiles: Porter)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Creative Technology Ltd.) C:\Windows\OEM02Mon.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\LCD Manager\LCDMon.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [OEM02Mon.exe] => C:\Windows\OEM02Mon.exe [36864 2007-05-09] (Creative Technology Ltd.)
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [NVHotkey] => rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
HKLM\...\Run: [Launch LCDMon] => C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe [775952 2007-06-26] (Logitech Inc.)
HKLM\...\Run: [AppleSyncNotifier] => C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-06] (Apple Inc.)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [421776 2012-09-09] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-895179479-2616377941-1130945272-1000\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [1940160 2014-11-18] (Valve Corporation)
HKU\S-1-5-21-895179479-2616377941-1130945272-1000\...\Run: [ICQ] => C:\Program Files\ICQ7.2\ICQ.exe [133432 2010-11-30] (ICQ, LLC.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk
ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
ShortcutTarget: QuickSet.lnk -> C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-895179479-2616377941-1130945272-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:51521;https=127.0.0.1:51521
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-895179479-2616377941-1130945272-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-895179479-2616377941-1130945272-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/?gws_rd=ssl
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKU\S-1-5-21-895179479-2616377941-1130945272-1000 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-895179479-2616377941-1130945272-1000 -> {00DAE8CE-7AEB-41ED-BF70-20BF0D67EBCB} URL = https://www.google.com/search?q={searchTerms}
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Winsock: Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Porter\AppData\Roaming\Mozilla\Firefox\Profiles\mb4jduz5.default-1407169763399
FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=1.6.0_35 -> C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-895179479-2616377941-1130945272-1000: @nsroblox.roblox.com/launcher -> C:\Users\Porter\AppData\Local\Roblox\Versions\version-5ce51d8367464075\\NPRobloxProxy.dll ( Roblox Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Porter\AppData\Roaming\Mozilla\Firefox\Profiles\mb4jduz5.default-1407169763399\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\Porter\AppData\Roaming\Mozilla\Firefox\Profiles\mb4jduz5.default-1407169763399\searchplugins\google-maps.xml
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-02-21]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-05-09]
FF HKU\S-1-5-21-895179479-2616377941-1130945272-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
R2 EvtEng; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [647168 2007-07-25] (Intel Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 nicconfigsvc; C:\Program Files\Dell\QuickSet\NicConfigSvc.exe [390424 2008-02-22] (Dell Inc.)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S2 RegSrvc; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [327680 2007-07-25] (Intel Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 3039e7ea; "C:\Windows\system32\rundll32.exe" "c:\Program Files\BocaProc\BocaProc.dll",serv
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2011-08-27] ()
R1 fanio; C:\Windows\system32\drivers\fanio.sys [14464 2007-02-16] (Christian Diefer) [File not signed]
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2011-08-27] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-02-23] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R0 speedfan; C:\Windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [420920 2011-01-15] (Duplex Secure Ltd.)
R3 USBMULCD; C:\Windows\System32\drivers\CM106.sys [1517056 2010-08-12] (C-Media Electronics Inc)
S3 catchme; \??\C:\Users\Porter\AppData\Local\Temp\catchme.sys [X]
S3 DFUBTUSB; System32\Drivers\frmupgr.sys [X]
S1 netfilter2; system32\drivers\netfilter2.sys [X]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-23 17:33 - 2015-02-23 17:33 - 00000000 ____D () C:\Users\Porter\Downloads\FRST-OlderVersion
2015-02-23 17:23 - 2015-02-23 17:23 - 00001469 _____ () C:\Users\Porter\Desktop\JRT.txt
2015-02-23 17:20 - 2015-02-23 17:12 - 00007165 _____ () C:\Users\Porter\Desktop\AdwCleaner[S0].txt
2015-02-23 17:10 - 2015-02-23 17:10 - 01388274 _____ (Thisisu) C:\Users\Porter\Downloads\JRT.exe
2015-02-23 17:07 - 2015-02-23 17:12 - 00000000 ____D () C:\AdwCleaner
2015-02-23 17:07 - 2015-02-23 17:07 - 02126848 _____ () C:\Users\Porter\Downloads\AdwCleaner_4.111.exe
2015-02-23 17:06 - 2015-02-23 17:06 - 00023827 _____ () C:\Users\Porter\Desktop\mbam.txt
2015-02-23 16:37 - 2015-02-23 17:18 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-23 16:37 - 2015-02-23 16:37 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-23 16:37 - 2015-02-23 16:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-23 16:37 - 2015-02-23 16:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-23 16:37 - 2015-02-23 16:37 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-02-23 16:37 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-23 16:37 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-23 16:37 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-22 20:26 - 2015-02-22 20:33 - 00018448 _____ () C:\Users\Porter\Documents\beste lebensweisheit!!!!!!!!!!!!!!!.odt
2015-02-22 20:07 - 2015-02-22 20:07 - 00009058 _____ () C:\Users\Porter\Documents\test druck englische zeiten.bmp
2015-02-22 19:51 - 2015-02-23 15:04 - 00000410 __RSH () C:\ProgramData\ntuser.pol
2015-02-22 18:29 - 2015-02-22 18:29 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Porter\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-21 22:48 - 2015-02-21 22:48 - 02648994 _____ () C:\Users\Porter\AppData\Local\[j0006]-[p01].bmp
2015-02-21 18:37 - 2015-02-21 18:38 - 00000000 ____D () C:\Users\Porter\Downloads\Mathe GS 15.2.15.odt
2015-02-21 18:33 - 2015-02-21 18:33 - 02031502 _____ () C:\Users\Porter\Documents\Matheprüfung Grundstudium Feb. 2015 incl. Lösungen.zip
2015-02-21 18:27 - 2015-02-21 18:27 - 00010232 _____ () C:\Users\Porter\Documents\Lösungen Mathe 15.02.2015.zip
2015-02-21 17:24 - 2015-02-23 17:14 - 00000374 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-02-21 17:02 - 2015-02-21 17:02 - 00013281 _____ () C:\Users\Porter\Desktop\Combofix.txt
2015-02-21 16:53 - 2015-02-21 16:53 - 00013281 _____ () C:\ComboFix.txt
2015-02-21 16:28 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-21 16:28 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-21 16:28 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-21 16:28 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-21 16:28 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-21 16:28 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-21 16:28 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-21 16:28 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-21 16:27 - 2015-02-21 16:53 - 00000000 ____D () C:\Qoobox
2015-02-21 16:27 - 2015-02-21 16:52 - 00000000 ____D () C:\Windows\erdnt
2015-02-21 16:26 - 2015-02-21 16:26 - 05611903 ____R (Swearware) C:\Users\Porter\Downloads\ComboFix.exe
2015-02-21 15:04 - 2015-02-21 15:04 - 00001222 _____ () C:\Users\Porter\Desktop\Revo Uninstaller.lnk
2015-02-21 15:04 - 2015-02-21 15:04 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-02-21 15:03 - 2015-02-21 15:03 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Porter\Downloads\revosetup95.exe
2015-02-21 13:48 - 2015-02-21 13:48 - 00026948 _____ () C:\Users\Porter\Downloads\Gmer.txt
2015-02-21 13:35 - 2015-02-21 13:35 - 00380416 _____ () C:\Users\Porter\Downloads\Gmer-19357.exe
2015-02-21 10:48 - 2015-02-23 17:34 - 00014891 _____ () C:\Users\Porter\Downloads\FRST.txt
2015-02-21 10:48 - 2015-02-21 10:49 - 00047340 _____ () C:\Users\Porter\Downloads\Addition.txt
2015-02-21 10:47 - 2015-02-21 10:47 - 00380416 _____ () C:\Users\Porter\Downloads\71xg2s44.exe
2015-02-21 10:36 - 2015-02-23 17:34 - 00000000 ____D () C:\FRST
2015-02-21 10:36 - 2015-02-23 17:33 - 01126912 _____ (Farbar) C:\Users\Porter\Downloads\FRST.exe
2015-02-21 09:45 - 2015-02-21 09:46 - 00000634 _____ () C:\Users\Porter\Downloads\defogger_disable.log
2015-02-21 09:45 - 2015-02-21 09:46 - 00000020 _____ () C:\Users\Porter\defogger_reenable
2015-02-21 09:45 - 2015-02-21 09:45 - 00050477 _____ () C:\Users\Porter\Downloads\Defogger.exe
2015-02-21 08:56 - 2015-02-21 08:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-02-21 08:51 - 2015-02-21 08:51 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-02-21 08:51 - 2015-02-21 08:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-02-21 08:50 - 2015-02-21 08:50 - 04515896 _____ (Avira Operations & Co. KG) C:\Users\Porter\Downloads\avira_de_av___ws.exe
2015-02-15 19:14 - 2015-02-15 19:14 - 02848556 _____ () C:\Users\Porter\Documents\Prüfung Mathe 15.02.2015 die fertige.odt
2015-02-15 18:42 - 2015-02-15 18:42 - 00080701 _____ () C:\Users\Porter\Documents\Prüfung Mathe 15.02.2015.odt
2015-02-13 10:13 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-13 10:13 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-11 09:12 - 2015-01-15 08:46 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-11 09:12 - 2015-01-15 08:46 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-11 09:12 - 2015-01-15 08:43 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-11 09:12 - 2015-01-15 08:43 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-11 09:12 - 2015-01-15 08:42 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-11 09:12 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-11 09:12 - 2015-01-15 08:42 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-11 09:12 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-11 09:12 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-11 09:12 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-11 09:12 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-11 09:12 - 2015-01-15 05:21 - 00369968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-11 09:12 - 2015-01-09 02:45 - 02380288 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-11 09:11 - 2015-02-04 03:54 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 09:11 - 2015-02-04 03:53 - 00767488 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-11 09:11 - 2015-02-04 03:53 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-11 09:11 - 2015-02-04 03:53 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-11 09:11 - 2015-02-04 03:53 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-11 09:11 - 2015-02-04 03:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-02-11 09:11 - 2015-02-04 03:49 - 00886784 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-11 09:11 - 2015-01-28 00:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-02-11 09:11 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-02-11 09:11 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-11 09:11 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-11 09:11 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-11 09:11 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-11 09:11 - 2015-01-12 03:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 09:11 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-11 09:11 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-11 09:11 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-11 09:11 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-11 09:11 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-11 09:11 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-11 09:11 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-11 09:11 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-11 09:11 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-11 09:11 - 2015-01-12 02:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-11 09:11 - 2015-01-12 02:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 09:11 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-11 09:11 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 09:11 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-11 09:11 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-11 09:11 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-11 09:11 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-11 09:11 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-11 09:11 - 2015-01-12 02:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-11 09:11 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-11 09:11 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-11 09:11 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-11 09:11 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-11 09:11 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-11 09:11 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-11 09:11 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-11 09:11 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-11 09:11 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-11 09:11 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-11 09:11 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-11 09:11 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-11 09:11 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-11 09:11 - 2014-10-04 02:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-02-11 09:11 - 2014-10-04 02:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-02-11 09:10 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-11 09:10 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-02-11 09:10 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-08 19:22 - 2015-02-08 19:22 - 00000115 ____H () C:\Users\Porter\Downloads\.~lock.Mathe_25-11-2012.doc#
2015-02-08 14:10 - 2015-02-08 14:10 - 00011891 _____ () C:\Users\Porter\Documents\Kündigung SV Fuchstal.odt
2015-01-29 19:16 - 2015-01-29 19:16 - 00000000 ____D () C:\Users\Porter\Documents\Lohnsteuerabrechnung 2015
2015-01-29 19:15 - 2015-01-29 19:15 - 00000000 ____D () C:\Users\Porter\Documents\Neuer Ordner
2015-01-26 17:28 - 2015-01-26 17:28 - 00026624 _____ () C:\Users\Porter\Downloads\Lerngemeinschaft-Vordruck.xls
2015-01-26 17:27 - 2015-01-26 17:27 - 00024576 _____ () C:\Users\Porter\Downloads\Lerngemeinschaft.xls
2015-01-24 18:04 - 2015-01-24 18:04 - 00000000 ____D () C:\Users\Public\Desktop\Microsoft IntelliPoint
2015-01-24 16:30 - 2015-01-24 16:30 - 00131072 ____N () C:\Windows\Minidump\012415-24601-01.dmp
2015-01-24 16:08 - 2015-01-24 16:08 - 01295360 _____ () C:\Users\Porter\Downloads\QM_Besprechung.xls
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-23 17:21 - 2009-07-14 05:34 - 00027904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-23 17:21 - 2009-07-14 05:34 - 00027904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-23 17:18 - 2010-11-09 16:03 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-23 17:17 - 2010-11-09 15:56 - 01227747 _____ () C:\Windows\WindowsUpdate.log
2015-02-23 17:14 - 2010-11-09 16:24 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-02-23 17:13 - 2011-01-26 07:38 - 00076870 _____ () C:\Windows\PFRO.log
2015-02-23 17:13 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-23 17:13 - 2009-07-14 05:39 - 00101388 _____ () C:\Windows\setupact.log
2015-02-23 17:12 - 2011-04-07 04:39 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2015-02-23 17:02 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\twain_32
2015-02-23 17:01 - 2014-07-06 19:15 - 00000000 ____D () C:\Users\Porter\AppData\Local\com
2015-02-23 17:01 - 2010-11-30 18:44 - 00000000 ____D () C:\ProgramData\ICQ
2015-02-23 16:44 - 2012-07-12 14:03 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-22 18:20 - 2015-01-09 03:29 - 00000112 _____ () C:\ProgramData\R865638O.dat
2015-02-21 22:10 - 2015-01-11 18:23 - 00000000 ____D () C:\Users\Porter\Documents\Karte Sony Erricson
2015-02-21 18:50 - 2012-03-03 00:39 - 00178176 ___SH () C:\Users\Porter\Thumbs.db
2015-02-21 18:46 - 2014-05-29 18:49 - 00000000 ___RD () C:\Users\Porter\Desktop\DAA Technikum
2015-02-21 17:29 - 2011-11-24 09:40 - 00007598 _____ () C:\Users\Porter\AppData\Local\resmon.resmoncfg
2015-02-21 16:53 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default
2015-02-21 16:53 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2015-02-21 16:48 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2015-02-21 09:47 - 2012-06-08 16:28 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-02-21 09:45 - 2010-11-09 16:00 - 00000000 ____D () C:\Users\Porter
2015-02-21 08:51 - 2014-10-22 19:56 - 00000000 ____D () C:\ProgramData\Avira
2015-02-21 08:51 - 2014-10-22 19:56 - 00000000 ____D () C:\Program Files\Avira
2015-02-21 08:51 - 2012-09-23 14:05 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-15 14:33 - 2011-01-26 00:41 - 00001912 _____ () C:\Windows\epplauncher.mif
2015-02-13 13:58 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2015-02-12 22:52 - 2009-07-14 05:33 - 00294224 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-12 16:51 - 2014-12-18 13:41 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-12 16:51 - 2014-05-07 22:16 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-12 16:51 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-02-05 18:44 - 2012-06-12 17:54 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-02-05 18:44 - 2011-09-23 18:03 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-01-26 16:40 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-01-24 16:30 - 2010-11-09 20:05 - 00000000 ____D () C:\Windows\Minidump
==================== Files in the root of some directories =======
2011-01-13 20:16 - 2014-12-17 16:50 - 0000060 _____ () C:\Users\Porter\AppData\Roaming\AVSDVDPlayer.m3u
2014-05-03 17:31 - 2014-05-03 17:34 - 0017408 ___SH () C:\Users\Porter\AppData\Roaming\Thumbs.db
2011-10-25 20:21 - 2011-11-22 08:25 - 0251546 _____ () C:\Users\Porter\AppData\Roaming\UserTile.png
2011-11-24 09:40 - 2015-02-21 17:29 - 0007598 _____ () C:\Users\Porter\AppData\Local\resmon.resmoncfg
2015-02-21 22:48 - 2015-02-21 22:48 - 2648994 _____ () C:\Users\Porter\AppData\Local\[j0006]-[p01].bmp
2014-05-09 20:44 - 2014-05-09 20:58 - 0000775 _____ () C:\ProgramData\hpzinstall.log
2015-01-09 03:29 - 2015-02-22 18:20 - 0000112 _____ () C:\ProgramData\R865638O.dat
Files to move or delete:
====================
C:\ProgramData\R865638O.dat
C:\Users\Porter\7tq5ju753a18d5.js
Some content of TEMP:
====================
C:\Users\Porter\AppData\Local\Temp\Quarantine.exe
C:\Users\Porter\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-23 15:21
==================== End Of Log ============================ --- --- --- Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Professional x86
Ran by Porter on 23.02.2015 at 17:21:35,94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68f4dacb-10fa-ca10-ad7d-91b574356f1d}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{68f4dacb-10fa-ca10-ad7d-91b574356f1d}
~~~ Files
Successfully deleted: [File] C:\Windows\System32\Tasks\task112705231
~~~ Folders
Successfully deleted: [Folder] C:\ProgramData\AlawarWrapper
Successfully deleted: [Folder] "C:\Users\Porter\AppData\Roaming\pcdr"
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [Folder] C:\Users\Porter\AppData\Roaming\mozilla\firefox\profiles\mb4jduz5.default-1407169763399\extensions\toolbar@web.de
Emptied folder: C:\Users\Porter\AppData\Roaming\mozilla\firefox\profiles\mb4jduz5.default-1407169763399\minidumps [21 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.02.2015 at 17:23:47,87
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 23.02.2015
Suchlauf-Zeit: 16:38:25
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.02.23.04
Rootkit Datenbank: v2015.02.22.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Porter
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 339819
Verstrichene Zeit: 10 Min, 43 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 3
Trojan.Agent.SVR, C:\Program Files\003\buuoujqmrk32.exe, 1984, Löschen bei Neustart, [ad33d34e4d3d2e081e059501f30eaa56]
PUP.Optional.SupraSavings.A, C:\Program Files\003\buuoujqmrk32.exe, 1984, Löschen bei Neustart, [ad33cd54ddad1422a3ec8d428281619f]
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\ICQ Service.exe, 544, Löschen bei Neustart, [657be73af19971c5a5b1a0f42cd714ec]
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 20
Trojan.Agent.SVR, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\buuoujqmrk32, In Quarantäne, [ad33d34e4d3d2e081e059501f30eaa56],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-895179479-2616377941-1130945272-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [4a96fd24bad0bc7a0c055cef1ee5ef11],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-895179479-2616377941-1130945272-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [49976eb398f2eb4bc28b63ab9271c53b],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [49976eb398f2eb4bc28b63ab9271c53b],
PUP.Optional.SupraSavings.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\buuoujqmrk32, In Quarantäne, [ad33cd54ddad1422a3ec8d428281619f],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\SweetIM, In Quarantäne, [02de9b8693f7c86ea413554b5da6b64a],
PUP.Optional.Booster.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{3039e7ea}, In Quarantäne, [4a96a0811f6b261016724f6f60a318e8],
PUP.Optional.CouponDownloader.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Coupon Downloader, In Quarantäne, [20c00d14f397b77f8beac50723e03dc3],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HDV1.6, In Quarantäne, [6d737aa796f484b20b0f308fd42fb947],
PUP.Optional.SupraSavings.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Supra Savings, In Quarantäne, [914f79a88307b482e6c5def5ec1736ca],
PUP.Optional.Softonic.A, HKU\S-1-5-21-895179479-2616377941-1130945272-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, In Quarantäne, [c020bd641c6e7db97fcab6ec49baa65a],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-895179479-2616377941-1130945272-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SweetIM, In Quarantäne, [b22e4cd55c2e2a0ca214534dcc3720e0],
PUP.Optional.SupraSavings.A, HKU\S-1-5-21-895179479-2616377941-1130945272-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\suprasavings, In Quarantäne, [4e9263be8bffff37d6c95d7763a0fc04],
PUP.Optional.ICQToolbar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ICQ Service, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, HKLM\SOFTWARE\CLASSES\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, HKLM\SOFTWARE\CLASSES\ICQToolBar.IEHook.1, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, HKLM\SOFTWARE\CLASSES\ICQToolBar.IEHook, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, HKU\S-1-5-21-895179479-2616377941-1130945272-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{855F3B16-6D32-4FE6-8A56-BBB695989046}, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, HKU\S-1-5-21-895179479-2616377941-1130945272-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{855F3B16-6D32-4FE6-8A56-BBB695989046}, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ICQToolbar, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
Registrierungswerte: 3
PUP.Optional.ICQToolbar.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{855F3B16-6D32-4FE6-8A56-BBB695989046}, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{855F3B16-6D32-4FE6-8A56-BBB695989046}, ICQToolBar, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec]
PUP.Optional.ICQToolbar.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{855F3B16-6D32-4FE6-8A56-BBB695989046}, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
Registrierungsdaten: 3
PUP.Optional.HelperBar.A, HKU\S-1-5-21-895179479-2616377941-1130945272-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=1924cd8b-2d00-d8d1-3813-8e3a2391a04a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=1924cd8b-2d00-d8d1-3813-8e3a2391a04a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000),Ersetzt,[d30d0819d0ba2214ac8615ad4fb6a060]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-895179479-2616377941-1130945272-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=1924cd8b-2d00-d8d1-3813-8e3a2391a04a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=1924cd8b-2d00-d8d1-3813-8e3a2391a04a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000),Ersetzt,[5d8346db9cee01354fe4368c867fd12f]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-895179479-2616377941-1130945272-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=1924cd8b-2d00-d8d1-3813-8e3a2391a04a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=1924cd8b-2d00-d8d1-3813-8e3a2391a04a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000),Ersetzt,[07d95dc4fc8ea1953bf3b40e63a211ef]
Ordner: 25
PUP.Optional.BocaProc.A, C:\Program Files\BocaProc, In Quarantäne, [19c7c55c24663ef82294fd9827dce31d],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\locales, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\locales, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.SupraSavings.A, C:\Program Files\suprasavings, In Quarantäne, [97492ef318720f27bf36d48e04ffc23e],
PUP.Optional.SupraSavings.A, C:\Program Files\suprasavings\SSL, In Quarantäne, [97492ef318720f27bf36d48e04ffc23e],
PUP.Optional.GenesisOffers, C:\Users\Porter\AppData\Local\Genesis_07061811, In Quarantäne, [2ab61d04becc71c529ea29530bf8cf31],
PUP.Optional.NewPlayer.A, C:\Users\Porter\AppData\Local\com\NewPlayer.exe_Url_wmgtxqntq5fklrr4bpxvxljadclrhvq0, In Quarantäne, [2ab6a77a3c4ef145954ea9e5d132be42],
PUP.Optional.NewPlayer.A, C:\Users\Porter\AppData\Local\com\NewPlayer.exe_Url_wmgtxqntq5fklrr4bpxvxljadclrhvq0\2.1.1.9, In Quarantäne, [2ab6a77a3c4ef145954ea9e5d132be42],
PUP.Optional.IEBho.A, C:\Users\Porter\AppData\LocalLow\IE-BHO, In Quarantäne, [50908c95860467cf50f48906857ede22],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\DE, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar, Löschen bei Neustart, [657be73af19971c5a5b1a0f42cd714ec],
Dateien: 92
Trojan.Agent.SVR, C:\Program Files\003\buuoujqmrk32.exe, Löschen bei Neustart, [ad33d34e4d3d2e081e059501f30eaa56],
PUP.Optional.Downloader, C:\Users\Porter\Downloads\Setup.exe, In Quarantäne, [a23e2af7e6a4df57f28a930991743cc4],
PUP.Optional.DownloadSponsor, C:\Users\Porter\Downloads\Tor Browser Paket - CHIP-Installer.exe, In Quarantäne, [cf112df4a1e9b68088fbbe6539c9ae52],
PUP.Optional.DownloadeGuide, C:\Users\Porter\Downloads\windows-movie-maker.exe, In Quarantäne, [38a879a83852082ef16ed9289969d12f],
PUP.Optional.BocaProc.A, C:\Program Files\BocaProc\BocaProc.dll, In Quarantäne, [19c7c55c24663ef82294fd9827dce31d],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\cef.pak, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\cef_100_percent.pak, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\cef_200_percent.pak, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\debug.log, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\icudtl.dat, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\libEGL.dll, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\vcredist_x86.exe, In Quarantäne, [2cb4031e24662e08f804f8a554af0df3],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\cef.pak, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\cef_100_percent.pak, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\cef_200_percent.pak, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\debug.log, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\icudtl.dat, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\libEGL.dll, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Porter\AppData\Roaming\Compatibility Verifier\vcredist_x86.exe, In Quarantäne, [28b8dc45a9e1fb3b53a9aaf314effc04],
PUP.Optional.SupraSavings.A, C:\Program Files\003\buuoujqmrk32.exe, Löschen bei Neustart, [ad33cd54ddad1422a3ec8d428281619f],
PUP.Optional.NewPlayer.A, C:\Users\Porter\AppData\Local\com\NewPlayer.exe_Url_wmgtxqntq5fklrr4bpxvxljadclrhvq0\2.1.1.9\user.config, In Quarantäne, [2ab6a77a3c4ef145954ea9e5d132be42],
PUP.Optional.IEBho.A, C:\Users\Porter\AppData\LocalLow\IE-BHO\bho.dll, In Quarantäne, [50908c95860467cf50f48906857ede22],
PUP.Optional.IEBho.A, C:\Users\Porter\AppData\LocalLow\IE-BHO\data.ini, In Quarantäne, [50908c95860467cf50f48906857ede22],
PUP.Optional.IEBho.A, C:\Users\Porter\AppData\LocalLow\IE-BHO\ie.ini, In Quarantäne, [50908c95860467cf50f48906857ede22],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\Configuration.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\OptionDlg.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\RegionalSettings.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\UserInterface.xml, In Quarantäne, [25bb9f8264265bdbbe9732627b8832ce],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\config.xml, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\Icons.bmp, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\ICQ Service.exe, Löschen bei Neustart, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\icq6Toolbar.ico, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\ICQToolBar.dll, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\ICQUnToolbar.exe, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\logo_small.gif, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\ServiceStarter.exe, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\short.wav, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\Version.txt, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\voucher.bmp, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
PUP.Optional.ICQToolbar.A, C:\Program Files\ICQ6Toolbar\voucher2.bmp, In Quarantäne, [657be73af19971c5a5b1a0f42cd714ec],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
# AdwCleaner v4.111 - Bericht erstellt 23/02/2015 um 17:12:28
# Aktualisiert 18/02/2015 von Xplode
# Datenbank : 2015-02-18.3 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x86)
# Benutzername : Porter - PORTER-PC
# Gestarted von : C:\Users\Porter\Downloads\AdwCleaner_4.111.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : netfilter
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\bd25564a000010f5
Ordner Gelöscht : C:\Program Files\003
Ordner Gelöscht : C:\Program Files\globalUpdate
Ordner Gelöscht : C:\Program Files\SoftwareUpdater
Ordner Gelöscht : C:\Program Files\Optimizer Pro 3.13
Ordner Gelöscht : C:\Program Files\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Porter\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Porter\AppData\Local\Software Updater
Ordner Gelöscht : C:\Users\Porter\AppData\LocalLow\Toolbar4
Ordner Gelöscht : C:\Users\Porter\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\Porter\AppData\Roaming\dvdvideosoftiehelpers
Datei Gelöscht : C:\Windows\system32\drivers\netfilter.sys
Datei Gelöscht : C:\Users\Porter\AppData\Roaming\Mozilla\Firefox\Profiles\mb4jduz5.default-1407169763399\user.js
***** [ Geplante Tasks ] *****
Task Gelöscht : Software Updater Ui
Task Gelöscht : Software Updater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [sparpilot@sparpilot.com]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Web-Suche
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ICQ Service.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbTask
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
Schlüssel Gelöscht : HKLM\SOFTWARE\S_KuPeRS - LP4 - Digital AVS Presets
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S_KuPeRS - LP4 - Digital AVS Presets
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{28C02550-6572-401a-A2AE-5BC703C9BBA6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A1CCCE0D-AE21-42A2-BE58-8E6109410995}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{56E2B5C0-BF99-464A-BC44-B2E729E451C2}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
Schlüssel Gelöscht : HKCU\Software\genesis
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17631
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v35.0.1 (x86 de)
[mb4jduz5.default-1407169763399\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml");
*************************
AdwCleaner[R0].txt - [7096 Bytes] - [23/02/2015 17:07:48]
AdwCleaner[R1].txt - [7155 Bytes] - [23/02/2015 17:10:30]
AdwCleaner[S0].txt - [7026 Bytes] - [23/02/2015 17:12:28]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7085 Bytes] ########## |