Andrea123 | 08.03.2015 17:24 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 08.03.2015
Suchlauf-Zeit: 16:37:35
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.03.08.04
Rootkit Datenbank: v2015.02.25.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Andrea
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 323015
Verstrichene Zeit: 20 Min, 22 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1384, Löschen bei Neustart, [e82c51f26e1c7fb7ae48d1af19e8f907]
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\wajam.exe, 2808, Löschen bei Neustart, [cb4979caa0ea5fd775ec96d645bb2ed2]
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\wajam.exe, 2968, Löschen bei Neustart, [cb4979caa0ea5fd775ec96d645bb2ed2]
PUP.Optional.WindowsMangerProtect.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1456, Löschen bei Neustart, [c2521c279deded491d1d694a9172817f]
Module: 2
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\dlls\cloyawzbbjvg.dll, Löschen bei Neustart, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\dlls\cloyawzbbjvg.dll, Löschen bei Neustart, [38dc261d09818aac11d8faa4af54d828],
Registrierungsschlüssel: 21
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [e82c51f26e1c7fb7ae48d1af19e8f907],
PUP.Optional.Wajam.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wajam Web Enhancer, In Quarantäne, [cb4979caa0ea5fd775ec96d645bb2ed2],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [fe168ab9a6e485b15815c8574bb8a45c],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{55685567-4840-4a91-962b-49a412e9485a}w, In Quarantäne, [52c2f0537d0dc86ec9730f1aa0655ba5],
PUP.Optional.Delta.A, HKLM\SOFTWARE\delta-homesSoftware, In Quarantäne, [e62e083bc2c8ae88202a29a19e65c040],
PUP.Optional.RollAround.A, HKLM\SOFTWARE\RollAround, In Quarantäne, [dc3897ac771340f63e95ecbae41fab55],
PUP.Optional.WPM.A, HKLM\SOFTWARE\supWindowsMangerProtect, In Quarantäne, [f222a2a13e4cf541cbb22207ff0630d0],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\supWPM, In Quarantäne, [25ef30139cee65d185c08d38b64d7987],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\sweet-pageSoftware, In Quarantäne, [50c467dc3a501422ad6f3ce2c63f8977],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\Wajam Web Enhancer, In Quarantäne, [36de0f346f1b7fb78fd818a009fab64a],
PUP.Optional.SecurityProtection.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\noajmlkipclmeolfcnflkjhijkigpfjh, In Quarantäne, [55bf0c3793f770c6ec4d5b58ea196997],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\SUPDP, In Quarantäne, [fa1a6ad91f6be650fe1507be2ed55da3],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\SUPTAB, In Quarantäne, [0f05291aed9d77bf2024d8edde259c64],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [957f4ff4d9b1989ee9479e31e51e8779],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [c2521c279deded491d1d694a9172817f],
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, In Quarantäne, [759f3013038750e6542abcfe6a998d73],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [21f381c22862e0560b7478427291eb15],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-771618654-3341757510-301361698-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [4bc9b291c7c3f6404d94be353bc8dd23],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-771618654-3341757510-301361698-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [9d77b78ca0eaea4c1ca2729762a3926e],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-771618654-3341757510-301361698-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [858f53f01377f73f82ad933cc53ea25e],
PUP.Optional.Wajam.A, HKU\S-1-5-21-771618654-3341757510-301361698-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM, In Quarantäne, [070d63e0dfab261001063dd0f80da35d],
Registrierungswerte: 4
PUP.Optional.SupTab.A, HKLM\SOFTWARE\SUPDP|dir, C:\Program Files\SupTab, In Quarantäne, [fa1a6ad91f6be650fe1507be2ed55da3]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\SUPTAB|ptid, cor, In Quarantäne, [0f05291aed9d77bf2024d8edde259c64]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-771618654-3341757510-301361698-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, In Quarantäne, [9d77b78ca0eaea4c1ca2729762a3926e]
PUP.Optional.Wajam.A, HKU\S-1-5-21-771618654-3341757510-301361698-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM|affiliate_id, 9860, In Quarantäne, [070d63e0dfab261001063dd0f80da35d]
Registrierungsdaten: 3
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.delta-homes.com/?type=hp&ts=1420138434&from=wpm12311&uid=TOSHIBAXMK5055GSX_X96RT0BSTXXX96RT0BST, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1420138434&from=wpm12311&uid=TOSHIBAXMK5055GSX_X96RT0BSTXXX96RT0BST),Ersetzt,[aa6acc77c0cac670a67bb32e23e240c0]
PUP.Optional.Delta.A, HKU\S-1-5-21-771618654-3341757510-301361698-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.delta-homes.com/?type=hp&ts=1420138434&from=wpm12311&uid=TOSHIBAXMK5055GSX_X96RT0BSTXXX96RT0BST, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1420138434&from=wpm12311&uid=TOSHIBAXMK5055GSX_X96RT0BSTXXX96RT0BST),Ersetzt,[8391380bb8d29e980a18d809a4618779]
PUP.Optional.Delta.A, HKU\S-1-5-21-771618654-3341757510-301361698-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://search.delta-homes.com/web/?type=ds&ts=1420138434&from=wpm12311&uid=TOSHIBAXMK5055GSX_X96RT0BSTXXX96RT0BST&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://search.delta-homes.com/web/?type=ds&ts=1420138434&from=wpm12311&uid=TOSHIBAXMK5055GSX_X96RT0BSTXXX96RT0BST&q={searchTerms}),Ersetzt,[fe1644ff1674c373dd436b760302d42c]
Ordner: 17
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, Löschen bei Neustart, [7b995fe483070e28ff796914f01320e0],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [7b995fe483070e28ff796914f01320e0],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [ab696fd4b2d8a78fb7e66a150bf8cb35],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [ab696fd4b2d8a78fb7e66a150bf8cb35],
PUP.Optional.SystemSpeedup, C:\Users\Andrea\AppData\Roaming\Systweak\ssd, In Quarantäne, [40d46ad91b6fd462a595f48cd82bd927],
PUP.Optional.SupTab.A, C:\Program Files\SupTab, In Quarantäne, [d53ffd46385269cd5c95d1b308fb09f7],
PUP.Optional.SweetPage.A, C:\Users\Andrea\AppData\Roaming\sweet-page, In Quarantäne, [3ada1f24771372c48d2ae1ac3ac960a0],
PUP.Optional.SweetPage.A, C:\Users\Andrea\AppData\Roaming\sweet-page\images, In Quarantäne, [3ada1f24771372c48d2ae1ac3ac960a0],
PUP.Optional.SweetPage.A, C:\Users\Andrea\AppData\Roaming\sweet-page\images\code, In Quarantäne, [3ada1f24771372c48d2ae1ac3ac960a0],
PUP.Optional.SweetPage.A, C:\Users\Andrea\AppData\Roaming\sweet-page\log, In Quarantäne, [3ada1f24771372c48d2ae1ac3ac960a0],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Search, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Uninstall Wajam, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer, Löschen bei Neustart, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\dlls, Löschen bei Neustart, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
Dateien: 79
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [e82c51f26e1c7fb7ae48d1af19e8f907],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\wajam.exe, Löschen bei Neustart, [cb4979caa0ea5fd775ec96d645bb2ed2],
PUP.Optional.InstallCore, C:\Users\Andrea\AppData\Roaming\1H1Q\Open Office Packages\uninstaller.exe, In Quarantäne, [2aea70d30f7b76c0660cba7c1fe324dc],
PUP.Optional.RollAround.C, C:\Users\Andrea\AppData\Roaming\RHEng\7176CB8E43CC446788D02C55F0518530\setup0213.exe, In Quarantäne, [83912a1992f837ff53ec8c9fe51d06fa],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\RHEng\D90BD5478C234E3DAA4FA62BC4FEF946\WWE_1.2.0.53.exe, In Quarantäne, [ea2a71d26d1dc96d41207bf1bd43e61a],
PUP.Optional.Adload, C:\Users\Andrea\AppData\Roaming\WinZipper\update\zip_update_v1.5.83.exe, In Quarantäne, [987ce0634c3e270f08bb34ed2bd7aa56],
PUP.Optional.Skytech.A, C:\Program Files\SupTab\DpInterface32.dll, In Quarantäne, [ec286bd8d5b58caa8e63466a3cc5d030],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SupTab.dll, In Quarantäne, [ff15c97a6228ea4ce7e490a5c13ffa06],
PUP.Optional.BoostSaves.A, C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage, Löschen bei Neustart, [b55f3c07c8c2ee48e050298a37ccea16],
PUP.Optional.BoostSaves.A, C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal, Löschen bei Neustart, [c15341025337b2840828d6dd5da6fa06],
PUP.Optional.SecurityProtection.A, C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx, In Quarantäne, [15ffef54ed9d6bcbc6726c47c63d20e0],
PUP.Optional.Boost.A, C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage, Löschen bei Neustart, [3fd52f14e5a5bd79d91ca02c3fc4e31d],
PUP.Optional.Boost.A, C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal, In Quarantäne, [a470a99a56342511fbfa567655aea55b],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{55685567-4840-4a91-962b-49a412e9485a}w.sys, In Quarantäne, [52c2f0537d0dc86ec9730f1aa0655ba5],
PUP.Optional.WindowsMangerProtect.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [c2521c279deded491d1d694a9172817f],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [7b995fe483070e28ff796914f01320e0],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [ab696fd4b2d8a78fb7e66a150bf8cb35],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Settings.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\SignIn with Facebook.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\SignIn with Twitter.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Wajam Website.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Search\Ask.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Search\Google.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Search\IMDb.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Search\Shopping.com.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Search\TripAdvisor.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Search\Wikipedia.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Search\Yahoo!.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Amazon.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Argos.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Ebay.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Etsy.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\HomeDepot.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Ikea.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Lowe's.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Mercadolivre.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\MyShopping.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Sears.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Target.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Tesco.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Walmart.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Explore Social Shopping\Zalando.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer\Uninstall Wajam\uninstall.lnk, In Quarantäne, [4cc8e0633d4d34026f32d2c20df6a759],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\snotlings, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\waaaghs, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\wajam.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\wajam_goblin.dll, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\WWE_uninstall.exe, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\dlls\cloyawzbbjvg.dll, Löschen bei Neustart, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\amazon.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\argos.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\ask.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\bestbuy.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\ebay.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\etsy.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\facebook.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\favicon.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\google.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\homedepot.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\ikea.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\imdb.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\lowes.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\mercado.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\mysearchweb.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\myshopping.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\searchresult.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\sears.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\setting.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\settings.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\shopping.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\target.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\tesco.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\tripadvisor.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\twitter.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\wajam.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\walmart.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\wiki.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\yahoo.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\logos\zalando.ico, In Quarantäne, [38dc261d09818aac11d8faa4af54d828],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
# AdwCleaner v4.111 - Bericht erstellt 08/03/2015 um 17:09:03
# Aktualisiert 18/02/2015 von Xplode
# Datenbank : 2015-03-05.1 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86)
# Benutzername : Andrea - ANDREA-PC
# Gestarted von : C:\Users\Andrea\Desktop\AdwCleaner_4.111.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : iSafeKrnlMon
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Program Files\webget
Ordner Gelöscht : C:\Program Files\WinZipper
Ordner Gelöscht : C:\Users\Andrea\AppData\Roaming\1H1Q
Ordner Gelöscht : C:\Users\Andrea\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Andrea\AppData\Roaming\WinZipper
Ordner Gelöscht : C:\Users\Andrea\AppData\Roaming\RHEng
Datei Gelöscht : C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage
Datei Gelöscht : C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage
Datei Gelöscht : C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_searches.globososo.com_0.localstorage-journal
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Andrea\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\V9
Schlüssel Gelöscht : HKLM\SOFTWARE\hdcode
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\V9
Schlüssel Gelöscht : HKLM\SOFTWARE\winzipersvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Wpm
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Open Office Packages
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\delta-homes.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.delta-homes.com
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17631
-\\ Google Chrome v40.0.2214.115
*************************
AdwCleaner[R0].txt - [4418 Bytes] - [08/03/2015 17:06:27]
AdwCleaner[S0].txt - [4939 Bytes] - [08/03/2015 17:09:03]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4998 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.3 (03.01.2015:1)
OS: Windows 7 Home Premium x86
Ran by Andrea on 08.03.2015 at 17:13:54,84
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}
~~~ Files
Successfully deleted: [File] "C:\Users\Andrea\appdata\local\google\chrome\user data\default\local storage\http_static.boostsaves.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Andrea\appdata\local\google\chrome\user data\default\local storage\http_static.boostsaves.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\Andrea\appdata\local\google\chrome\user data\default\local storage\https_static.boostsaves.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Andrea\appdata\local\google\chrome\user data\default\local storage\https_static.boostsaves.com_0.localstorage-journal"
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08.03.2015 at 17:16:11,55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-03-2015 03
Ran by Andrea (administrator) on ANDREA-PC on 08-03-2015 17:19:56
Running from C:\Users\Andrea\Desktop\Neuer Ordner
Loaded Profiles: Andrea (Available profiles: Andrea)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
(SEC) C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Spotify Ltd) C:\Users\Andrea\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Dropbox, Inc.) C:\Users\Andrea\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7711264 2009-08-19] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1541416 2009-07-15] (Synaptics Incorporated)
HKLM\...\Run: [UCam_Menu] => C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [978520 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-01-27] (Apple Inc.)
HKU\S-1-5-21-771618654-3341757510-301361698-1001\...\Run: [Spotify Web Helper] => C:\Users\Andrea\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-09] (Spotify Ltd)
HKU\S-1-5-21-771618654-3341757510-301361698-1001\...\Run: [GoogleChromeAutoLaunch_233139F6EC4DEC81E5C5F2F1CB87FB15] => C:\Program Files\Google\Chrome\Application\chrome.exe [843592 2015-02-17] (Google Inc.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [280576 2014-05-11] (Microsoft Corporation)
Startup: C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Andrea\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andrea\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andrea\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andrea\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andrea\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andrea\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andrea\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andrea\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andrea\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-771618654-3341757510-301361698-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-771618654-3341757510-301361698-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> {1934886D-51ED-4EDF-94B2-B5598425A755} URL = hxxp://www.startseite24.net/?q={searchTerms}
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-771618654-3341757510-301361698-1001 -> {1934886D-51ED-4EDF-94B2-B5598425A755} URL = hxxp://www.startseite24.net/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-771618654-3341757510-301361698-1001 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_deDE587
BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-771618654-3341757510-301361698-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-07] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> https://www.google.de/
CHR StartupUrls: Default -> "hxxp://google.de/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-05]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-12]
CHR Extension: (YouTube) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-05]
CHR Extension: (Google Search) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-05]
CHR Extension: (Google Wallet) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-05]
CHR Extension: (Gmail) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-05]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1910128 2015-01-27] (Electronic Arts)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-03-08] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Andrea\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-08 17:16 - 2015-03-08 17:16 - 00001537 _____ () C:\Users\Andrea\Desktop\JRT.txt
2015-03-08 17:13 - 2015-03-08 17:13 - 01388333 _____ (Thisisu) C:\Users\Andrea\Desktop\JRT.exe
2015-03-08 17:12 - 2015-03-08 17:12 - 00005078 _____ () C:\Users\Andrea\Desktop\AdwCleaner[S0].txt
2015-03-08 17:06 - 2015-03-08 17:09 - 00000000 ____D () C:\AdwCleaner
2015-03-08 17:05 - 2015-03-08 17:05 - 02126848 _____ () C:\Users\Andrea\Desktop\AdwCleaner_4.111.exe
2015-03-08 17:04 - 2015-03-08 17:04 - 00021493 _____ () C:\Users\Andrea\Desktop\mbam.txt
2015-03-08 16:36 - 2015-03-08 17:10 - 00114904 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-08 16:36 - 2015-03-08 16:36 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-08 16:36 - 2015-03-08 16:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-08 16:36 - 2015-03-08 16:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-08 16:36 - 2015-03-08 16:36 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-03-08 16:36 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-03-08 16:36 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-03-08 16:36 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-03-08 16:35 - 2015-03-08 16:35 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Andrea\Desktop\mbam-setup-2.0.4.1028.exe
2015-03-04 19:30 - 2015-03-04 19:30 - 00016643 _____ () C:\ComboFix.txt
2015-03-04 19:12 - 2015-03-04 19:31 - 00000000 ____D () C:\Qoobox
2015-03-04 19:12 - 2011-06-26 07:45 - 00256000 _____ () C:\windows\PEV.exe
2015-03-04 19:12 - 2010-11-07 18:20 - 00208896 _____ () C:\windows\MBR.exe
2015-03-04 19:12 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-03-04 19:12 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-03-04 19:12 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-03-04 19:12 - 2000-08-31 01:00 - 00098816 _____ () C:\windows\sed.exe
2015-03-04 19:12 - 2000-08-31 01:00 - 00080412 _____ () C:\windows\grep.exe
2015-03-04 19:12 - 2000-08-31 01:00 - 00068096 _____ () C:\windows\zip.exe
2015-03-04 19:11 - 2015-03-04 19:28 - 00000000 ____D () C:\windows\erdnt
2015-03-04 19:10 - 2015-03-04 19:11 - 05612482 _____ (Swearware) C:\Users\Andrea\Desktop\ComboFix (1).exe
2015-03-04 19:09 - 2015-03-04 19:11 - 05612482 ____R (Swearware) C:\Users\Andrea\Desktop\ComboFix.exe
2015-03-04 19:01 - 2015-03-04 19:01 - 00001222 _____ () C:\Users\Andrea\Desktop\Revo Uninstaller.lnk
2015-03-04 19:01 - 2015-03-04 19:01 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-03-04 19:00 - 2015-03-04 19:01 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Andrea\Desktop\revosetup95.exe
2015-03-03 16:58 - 2015-03-03 16:58 - 00380416 _____ () C:\Users\Andrea\Desktop\2d351p23.exe
2015-03-03 16:54 - 2015-03-08 17:19 - 00000000 ____D () C:\FRST
2015-03-03 16:51 - 2015-03-08 17:19 - 00000000 ____D () C:\Users\Andrea\Desktop\Neuer Ordner
2015-03-03 16:51 - 2015-03-03 16:51 - 00000000 _____ () C:\Users\Andrea\defogger_reenable
2015-03-01 21:49 - 2015-03-01 21:50 - 00000000 ____D () C:\Users\Andrea\Desktop\blabla
2015-02-26 20:54 - 2015-02-26 20:57 - 00000000 ____D () C:\Users\Andrea\Desktop\traurig
2015-02-26 18:17 - 2015-02-26 18:17 - 00000000 __SHD () C:\Users\Andrea\AppData\Local\EmieUserList
2015-02-26 18:17 - 2015-02-26 18:17 - 00000000 __SHD () C:\Users\Andrea\AppData\Local\EmieSiteList
2015-02-26 18:17 - 2015-02-26 18:17 - 00000000 __SHD () C:\Users\Andrea\AppData\Local\EmieBrowserModeList
2015-02-25 22:15 - 2015-01-09 00:44 - 00419936 _____ () C:\windows\system32\locale.nls
2015-02-25 21:55 - 2015-01-09 03:48 - 00635904 _____ (Microsoft Corporation) C:\windows\system32\perftrack.dll
2015-02-25 21:55 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\wdi.dll
2015-02-25 21:55 - 2015-01-09 03:48 - 00027136 _____ (Microsoft Corporation) C:\windows\system32\powertracker.dll
2015-02-20 21:57 - 2015-02-20 21:57 - 00000079 _____ () C:\Users\Andrea\Downloads\Download
2015-02-20 20:55 - 2015-02-20 20:55 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-02-20 20:55 - 2015-02-20 20:55 - 00000000 ____D () C:\Program Files\Free Codec Pack
2015-02-20 20:50 - 2015-02-20 21:03 - 00001199 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2015-02-20 20:50 - 2015-02-20 21:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2015-02-20 20:50 - 2015-02-20 20:50 - 00002138 _____ () C:\Users\Public\Desktop\Free Audio Editor.lnk
2015-02-20 20:49 - 2015-02-20 21:03 - 00000000 ____D () C:\Program Files\DVDVideoSoft
2015-02-20 20:49 - 2015-02-20 21:03 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2015-02-20 20:48 - 2015-02-26 20:28 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\DVDVideoSoft
2015-02-20 20:48 - 2015-02-20 20:48 - 03313168 _____ (DVDVideoSoft Ltd. ) C:\Users\Andrea\Downloads\FreeYouTube55ToMP3Converter.exe
2015-02-20 20:47 - 2015-02-20 20:47 - 03305384 _____ (DVDVideoSoft Ltd. ) C:\Users\Andrea\Downloads\FreeAudio09Editor.exe
2015-02-20 20:32 - 2015-02-20 20:32 - 00001047 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-02-20 20:27 - 2015-02-20 20:31 - 00000000 ____D () C:\Program Files\GIMP 2
2015-02-20 20:22 - 2015-02-20 20:24 - 91670064 _____ (The GIMP Team ) C:\Users\Andrea\Downloads\gimp-2.8.14-setup.exe
2015-02-20 20:06 - 2015-02-20 22:23 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Skype
2015-02-20 20:06 - 2015-02-20 20:06 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-02-20 20:06 - 2015-02-20 20:06 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Skype
2015-02-20 20:06 - 2015-02-20 20:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-02-20 20:06 - 2015-02-20 20:06 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-02-20 20:05 - 2015-02-20 20:06 - 00000000 ___RD () C:\Program Files\Skype
2015-02-20 20:05 - 2015-02-20 20:06 - 00000000 ____D () C:\ProgramData\Skype
2015-02-20 20:04 - 2015-02-20 20:04 - 01548384 _____ (Skype Technologies S.A.) C:\Users\Andrea\Downloads\SkypeSetup.exe
2015-02-20 19:43 - 2015-02-22 17:30 - 00048882 _____ () C:\Users\Andrea\Desktop\Chemie Säure und Basen.odt
2015-02-20 18:34 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-02-20 18:34 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-02-13 12:47 - 2015-02-13 12:47 - 04575232 _____ (Google Inc.) C:\windows\system32\GPhotos.scr
2015-02-11 22:26 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-02-11 22:26 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-02-11 22:26 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-02-11 22:26 - 2015-01-12 02:55 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-02-11 22:26 - 2015-01-12 02:48 - 00667648 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-02-11 22:26 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 22:26 - 2015-01-12 02:23 - 00684544 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-02-11 22:26 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-02-11 22:25 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-02-11 22:25 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-02-11 22:25 - 2015-01-12 03:21 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-02-11 22:25 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-02-11 22:25 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-02-11 22:25 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-02-11 22:25 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-02-11 22:25 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-02-11 22:25 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-02-11 22:25 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-02-11 22:25 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-02-11 22:25 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-02-11 22:25 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-02-11 22:25 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-02-11 22:25 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-02-11 22:25 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-02-11 22:25 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-02-11 22:25 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-02-11 22:25 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-02-11 22:25 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-02-11 20:42 - 2015-02-04 03:54 - 00482304 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-02-11 20:42 - 2015-02-04 03:53 - 00767488 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-02-11 20:42 - 2015-02-04 03:53 - 00621056 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-02-11 20:42 - 2015-02-04 03:53 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-02-11 20:42 - 2015-02-04 03:53 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-02-11 20:42 - 2015-02-04 03:53 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-02-11 20:42 - 2015-02-04 03:49 - 00886784 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-02-11 20:42 - 2015-01-28 00:36 - 01167520 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2015-02-11 20:13 - 2015-01-15 08:46 - 00136640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-02-11 20:13 - 2015-01-15 08:46 - 00067520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-02-11 20:13 - 2015-01-15 08:43 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-02-11 20:13 - 2015-01-15 08:43 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-02-11 20:13 - 2015-01-15 08:42 - 01061376 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-02-11 20:13 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-02-11 20:13 - 2015-01-15 08:42 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-02-11 20:13 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-02-11 20:13 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-02-11 20:13 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-02-11 20:13 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-02-11 20:13 - 2015-01-15 05:21 - 00369968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-02-11 20:13 - 2015-01-09 02:45 - 02380288 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-02-11 20:11 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2015-02-11 20:11 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-02-11 20:11 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-02-11 20:11 - 2014-10-04 02:42 - 03221504 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-02-11 20:11 - 2014-10-04 02:42 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\aaclient.dll
2015-02-11 20:09 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-02-11 20:09 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-02-11 20:09 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-02-11 20:09 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-02-11 20:09 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-02-11 20:09 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-02-11 20:09 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-02-11 20:03 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-02-11 20:03 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-02-11 20:03 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
2015-02-11 19:38 - 2015-02-11 19:38 - 00016822 _____ () C:\Users\Andrea\Downloads\englisch.odt
2015-02-07 19:01 - 2015-02-07 19:01 - 05070512 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerInstaller.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-08 17:17 - 2014-05-05 21:31 - 00001098 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-08 17:17 - 2009-07-14 05:34 - 00023328 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-08 17:17 - 2009-07-14 05:34 - 00023328 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-08 17:11 - 2014-10-30 19:44 - 00000000 ___RD () C:\Users\Andrea\Dropbox
2015-03-08 17:11 - 2014-10-30 19:42 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Dropbox
2015-03-08 17:10 - 2014-05-05 21:31 - 00001094 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-08 17:10 - 2009-09-22 06:48 - 00746046 _____ () C:\windows\PFRO.log
2015-03-08 17:10 - 2009-07-14 05:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-08 17:10 - 2009-07-14 05:39 - 00058078 _____ () C:\windows\setupact.log
2015-03-08 17:09 - 2014-05-05 21:31 - 00001236 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-08 17:09 - 2014-05-05 21:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-03-08 17:09 - 2010-06-25 18:58 - 00001150 _____ () C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-03-08 17:09 - 2009-09-22 06:23 - 01438344 _____ () C:\windows\WindowsUpdate.log
2015-03-08 16:59 - 2015-01-16 15:54 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-03-04 19:43 - 2009-07-26 21:06 - 01619284 _____ () C:\windows\system32\PerfStringBackup.INI
2015-03-04 19:31 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default
2015-03-04 19:31 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2015-03-04 19:24 - 2009-07-14 03:04 - 00000215 _____ () C:\windows\system.ini
2015-03-03 16:51 - 2010-06-25 18:40 - 00000000 ____D () C:\Users\Andrea
2015-03-03 14:16 - 2014-05-05 21:40 - 00246920 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2015-02-26 20:59 - 2014-05-29 12:22 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Spotify
2015-02-26 20:26 - 2014-05-29 12:23 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Spotify
2015-02-26 17:49 - 2014-07-29 21:14 - 00000000 ____D () C:\ProgramData\Origin
2015-02-26 17:45 - 2014-07-29 21:13 - 00000000 ____D () C:\Program Files\Origin
2015-02-26 17:30 - 2009-07-14 03:37 - 00000000 ____D () C:\windows\tracing
2015-02-22 13:27 - 2009-07-14 03:37 - 00000000 ____D () C:\windows\rescache
2015-02-12 22:23 - 2009-07-14 03:37 - 00000000 ____D () C:\windows\system32\de-DE
2015-02-12 22:00 - 2014-10-30 19:44 - 00001021 _____ () C:\Users\Andrea\Desktop\Dropbox.lnk
2015-02-12 22:00 - 2014-10-30 19:43 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-12 21:57 - 2009-07-14 05:33 - 00433376 _____ () C:\windows\system32\FNTCACHE.DAT
2015-02-12 21:55 - 2014-12-14 19:59 - 00000000 ____D () C:\windows\system32\appraiser
2015-02-12 21:55 - 2014-05-14 18:40 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-02-11 22:34 - 2014-06-03 19:28 - 00000000 ____D () C:\windows\system32\MRT
2015-02-11 22:27 - 2014-06-03 19:28 - 113756392 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-02-11 22:25 - 2014-05-05 21:49 - 00001912 _____ () C:\windows\epplauncher.mif
2015-02-11 22:25 - 2014-05-05 21:32 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-02-11 22:25 - 2014-05-05 21:32 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-02-07 19:01 - 2015-01-16 15:54 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2015-02-07 19:01 - 2015-01-16 15:54 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2014-10-21 21:17 - 2014-10-21 21:17 - 0004608 _____ () C:\Users\Andrea\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-06-25 18:42 - 2009-08-17 05:54 - 0131368 _____ () C:\ProgramData\FullRemove.exe
Some content of TEMP:
====================
C:\Users\Andrea\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpg7qt8i.dll
C:\Users\Andrea\AppData\Local\Temp\Quarantine.exe
C:\Users\Andrea\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-23 20:39
==================== End Of Log ============================ --- --- ---
Liebe Grüße |