Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.03.2015
Suchlauf-Zeit: 22:36:27
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.03.29.07
Rootkit Datenbank: v2015.03.26.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x86
Dateisystem: NTFS
Benutzer: Mat
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 353275
Verstrichene Zeit: 10 Min, 57 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 10
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [2625c3889ded4ceabae0f372fd069769],
PUP.Optional.Babylon.A, HKU\S-1-5-21-710196107-3409319025-2758534254-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [29228ebd0b7f51e5ee42909cf01360a0],
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}, In Quarantäne, [f556b79499f1a492deb04421758e17e9],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\DataMngr, In Quarantäne, [4efd2229eb9f70c672c911dcea199070],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-710196107-3409319025-2758534254-1001\SOFTWARE\DataMngr, In Quarantäne, [242752f994f63cfa0bf1db43fb0aa957],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-710196107-3409319025-2758534254-1001\SOFTWARE\DataMngr_Toolbar, In Quarantäne, [a4a773d868225ed8a95246d8a95cbb45],
PUP.Optional.Delta.A, HKU\S-1-5-21-710196107-3409319025-2758534254-1001\SOFTWARE\delta LTD, In Quarantäne, [ac9fb49733574aec9b0cf62a59ac4db3],
PUP.Optional.Babylon.A, HKU\S-1-5-21-710196107-3409319025-2758534254-1001\SOFTWARE\BABSOLUTION\Redir, In Quarantäne, [4803bc8f701af83ee11dba65a85d9967],
PUP.Optional.Babylon.A, HKU\S-1-5-21-710196107-3409319025-2758534254-1001\SOFTWARE\BABSOLUTION\Updater, In Quarantäne, [39121f2c8a0089ad946b7ca310f5bd43],
PUP.Optional.BProtector.A, HKU\S-1-5-21-710196107-3409319025-2758534254-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, In Quarantäne, [cc7f96b50783b77fa9995ac863a249b7],
Registrierungswerte: 4
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [8ebddb7031598ea89bff1f45ec1718e8],
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{82E1477C-B154-48D3-9891-33D83C26BCD3}, Delta Toolbar, In Quarantäne, [8ebddb7031598ea89bff1f45ec1718e8]
PUP.BProtector, HKU\S-1-5-21-710196107-3409319025-2758534254-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, hxxp://isearch.babylon.com/?babsrc=HP_ss_Btisdt4&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977, In Quarantäne, [4803ea612466f145926b0e10ed1847b9]
PUP.BProtector, HKU\S-1-5-21-710196107-3409319025-2758534254-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [9ab1e962365439fd32ccf9257d88b947]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 6
PUP.Optional.BabSolution.A, C:\Users\Mat\AppData\Roaming\BabSolution\CR, In Quarantäne, [7ecde368e1a9b87ea5d2127e7f847a86],
PUP.Optional.OnlySearch, C:\Users\Mat\AppData\Local\onlysearch, In Quarantäne, [28232922ee9c64d284a109932fd408f8],
PUP.Optional.OnlySearch, C:\Users\Mat\AppData\Local\onlysearch\onlysearch, In Quarantäne, [28232922ee9c64d284a109932fd408f8],
PUP.Optional.OnlySearch, C:\Users\Mat\AppData\Local\onlysearch\onlysearch\1.3.12.9, In Quarantäne, [28232922ee9c64d284a109932fd408f8],
PUP.Optional.Delta.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde, In Quarantäne, [4506262557339c9abb9ed7c640c3728e],
PUP.Optional.Delta.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.5.1_0, In Quarantäne, [4506262557339c9abb9ed7c640c3728e],
Dateien: 17
PUP.Optional.PayByAds.A, C:\Users\Mat\AppData\Local\Temp\dlsetup.exe, In Quarantäne, [ed5eeb600a80ed495108e44946c0619f],
PUP.Optional.PayByAds.A, C:\Users\Mat\AppData\Local\Temp\res.dll, In Quarantäne, [4dfe08437e0c68ce73e6af7e83836b95],
PUP.Optional.Babylon.A, C:\Windows\System32\Tasks\EPUPDATER, In Quarantäne, [56f5e467d2b80a2c462a767149ba6e92],
PUP.Optional.BitGuard.A, C:\Windows\System32\Tasks\BitGuard, In Quarantäne, [b596af9c7b0f2e08fc7b7770cf34817f],
PUP.Optional.BProtector.A, C:\Users\Mat\AppData\Roaming\Mozilla\Firefox\Profiles\amje54hq.default\bProtector_extensions.sqlite, In Quarantäne, [59f2f15a800aaa8c4966f60809fa4fb1],
PUP.Optional.BProtector.A, C:\Users\Mat\AppData\Roaming\Mozilla\Firefox\Profiles\amje54hq.default\bprotector_prefs.js, In Quarantäne, [f457301b2f5bd75f525eae505aa9ae52],
PUP.Optional.BProtector.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data, In Quarantäne, [0a4118336921be7898abb1718a7bbc44],
PUP.Optional.BProtector.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences, In Quarantäne, [3615f6552961fc3a81c364bea263ec14],
PUP.Optional.BrowserDefender.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage, In Quarantäne, [0c3f37141a70e3532f182df508fd7b85],
PUP.Optional.Delta.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.5.1_0\background.js, In Quarantäne, [4506262557339c9abb9ed7c640c3728e],
PUP.Optional.Delta.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.5.1_0\delta128.png, In Quarantäne, [4506262557339c9abb9ed7c640c3728e],
PUP.Optional.Delta.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.5.1_0\delta48.png, In Quarantäne, [4506262557339c9abb9ed7c640c3728e],
PUP.Optional.Delta.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.5.1_0\manifest.json, In Quarantäne, [4506262557339c9abb9ed7c640c3728e],
PUP.Optional.Delta.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.5.1_0\redirect.html, In Quarantäne, [4506262557339c9abb9ed7c640c3728e],
PUP.Optional.Delta.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.5.1_0\redirect.js, In Quarantäne, [4506262557339c9abb9ed7c640c3728e],
PUP.Optional.Delta.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences, Gut: (), Schlecht: ( "homepage": "hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977",), Ersetzt,[83c861ea1476af87ffd9db5c55b1827e]
PUP.Optional.Babylon.A, C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\chromepreferences, Gut: (), Schlecht: ( "homepage": "hxxp://isearch.babylon.com/?babsrc=HP_ss_Btisdt4&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977",), Ersetzt,[c883fc4f7a10f93d7262e65125e1946c]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
# AdwCleaner v4.113 - Bericht erstellt 30/03/2015 um 06:23:36
# Aktualisiert 22/03/2015 von Xplode
# Datenbank : 2015-03-29.1 [Server]
# Betriebssystem : Windows 8.1 Pro (x86)
# Benutzername : Mat - MAT-PC
# Gestarted von : C:\Users\Mat\Desktop\AdwCleaner_4.113.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\Program Files\Delta
Ordner Gelöscht : C:\Program Files\WinZip Registry Optimizer
Ordner Gelöscht : C:\Users\Mat\AppData\Local\Delta
Ordner Gelöscht : C:\Users\Mat\AppData\Local\DownloadManager
Ordner Gelöscht : C:\Users\Mat\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\Mat\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Mat\AppData\Roaming\Delta
Ordner Gelöscht : C:\Users\Mat\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Mat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Datei Gelöscht : C:\END
Datei Gelöscht : C:\WINDOWS\system32\roboot.exe
Datei Gelöscht : C:\Users\Mat\AppData\Roaming\Mozilla\Firefox\Profiles\amje54hq.default\user.js
***** [ Geplante Tasks ] *****
Task Gelöscht : BitGuard
Task Gelöscht : EPUpdater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{9309FA47-1B48-4768-AFA4-9E0556F5DC81}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pnbbffeddnekkhjmokkhdebbfbibbflc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\5a53d6d9b53bb8
Schlüssel Gelöscht : HKCU\Software\5a53d6d9b53bb813
Schlüssel Gelöscht : HKLM\SOFTWARE\5a53d6d9b53bb813
Schlüssel Gelöscht : HKCU\Software\BABSOLUTION
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\filescout
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.l
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v36.0.4 (x86 de)
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.admin", false);
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.aflt", "babsst");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.autoRvrt", "false");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.dfltLng", "de");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.excTlbr", false);
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.id", "1e8017db000000000000a0f3c114ccc9");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.instlDay", "15934");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.instlRef", "sst");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.newTab", false);
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.prdct", "delta");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.prtnrId", "delta");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.rvrt", "false");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.smplGrp", "none");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.tlbrId", "base");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.5");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.517:03:56");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.5");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta_i.babExt", "");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta_i.babTrack", "affID=124019&tsp=4977");
[amje54hq.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
-\\ Google Chrome v41.0.2272.101
[C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977
[C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977
[C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977
[C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977
[C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977
[C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977
[C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977
*************************
AdwCleaner[R0].txt - [6055 Bytes] - [30/03/2015 06:19:27]
AdwCleaner[S0].txt - [6096 Bytes] - [30/03/2015 06:23:36]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6155 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.7 (03.28.2015:1)
OS: Windows 8.1 Pro x86
Ran by Mat on 30.03.2015 at 6:48:01,28
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-710196107-3409319025-2758534254-1001
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Mat\AppData\Roaming\mozilla\firefox\profiles\amje54hq.default\minidumps [173 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.03.2015 at 6:50:14,51
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by Mat (administrator) on MAT-PC on 30-03-2015 06:50:48
Running from C:\Users\Mat\Desktop
Loaded Profiles: Mat (Available profiles: Mat)
Platform: Microsoft Windows 8.1 Pro (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
() C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(REINER SCT) C:\Windows\System32\cjpcsc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
() C:\Program Files\Hardcopy\hcdll2_ex_Win32.exe
(Cloanto Corporation) C:\Program Files\Common Files\Cloanto\Software Director\softdir.exe
() C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\redirector.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Dropbox, Inc.) C:\Users\Mat\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_134.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_134.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM\...\Run: [CloantoSoftwareDirector] => C:\Program Files\Common Files\Cloanto\Software Director\softdir.exe [370512 2013-02-01] (Cloanto Corporation)
HKLM\...\Run: [AgentMonitor] => C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [KeePass 2 PreLoad] => C:\Program Files\KeePass Password Safe 2\KeePass.exe [2109952 2014-10-07] (Dominik Reichl)
HKLM\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [703888 2013-07-19] (Cisco Systems, Inc.)
HKLM\...\Run: [ConnectionCenter] => C:\Program Files\Citrix\ICA Client\concentr.exe [407904 2014-11-27] (Citrix Systems, Inc.)
HKLM\...\Run: [Redirector] => C:\Program Files\Citrix\ICA Client\redirector.exe [153952 2014-11-27] (Citrix Systems, Inc.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AMD AVT] => C:\Program Files\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKU\S-1-5-21-710196107-3409319025-2758534254-1001\...\Run: [Sony PC Companion] => C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [449248 2013-05-29] (Sony)
HKU\S-1-5-21-710196107-3409319025-2758534254-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5529880 2015-03-13] (Piriform Ltd)
HKU\S-1-5-21-710196107-3409319025-2758534254-1001\...\Run: [DellSystemDetect] => C:\Users\Mat\AppData\Local\Apps\2.0\GX3YODKM.HB3\48G613HX.4B5\dell..tion_e30b47f5d4a30e9e_0005.000e_4ab3a7332dd76702\DellSystemDetect.exe [283432 2015-02-27] (Dell)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Mat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Mat\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mat\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mat\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mat\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-710196107-3409319025-2758534254-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-710196107-3409319025-2758534254-1001 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-27] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-27] (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Mat\AppData\Roaming\Mozilla\Firefox\Profiles\amje54hq.default
FF NewTab:
FF Homepage: about:home
FF Keyword.URL:
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-20] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin: @Citrix.com/npican -> C:\Program Files\Citrix\ICA Client\npicaN.dll [2014-11-27] (Citrix Systems, Inc.)
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-02-25] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-27] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-08] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-08] (Google Inc.)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-02-25] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin HKU\S-1-5-21-710196107-3409319025-2758534254-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-02-25] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2013-02-25] (Tracker Software Products (Canada) Ltd.)
FF Extension: Adblock Plus - C:\Users\Mat\AppData\Roaming\Mozilla\Firefox\Profiles\amje54hq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-07-29]
FF Extension: No Name - C:\Users\Mat\AppData\Roaming\Mozilla\Firefox\Profiles\v2wcdrsa.Job\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-02-19]
FF Extension: Adblock Plus - C:\Users\Mat\AppData\Roaming\Mozilla\Firefox\Profiles\v2wcdrsa.Job\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-19]
Chrome:
=======
CHR DefaultSearchKeyword: Default -> babylon.com
CHR DefaultSearchURL: Default -> hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=1E80A0F3C114CCC9&affID=124019&tsp=4977
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2013-05-09]
CHR Extension: (Google Wallet) - C:\Users\Mat\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-19]
CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - C:\Program Files\LastPass\lpchrome.crx [2013-05-09]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S3 BthHFSrv; C:\WINDOWS\System32\BthHFSrv.dll [250880 2014-11-21] (Microsoft Corporation)
R2 cjpcsc; C:\Windows\system32\cjpcsc.exe [522288 2015-01-21] (REINER SCT)
S2 Garmin Core Update Service; C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [451416 2014-12-31] (Garmin Ltd or its subsidiaries)
R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [696320 2011-08-18] (Hewlett-Packard Co.) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S3 ScDeviceEnum; C:\WINDOWS\System32\ScDeviceEnum.dll [103936 2014-11-21] (Microsoft Corporation)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [557968 2013-07-19] (Cisco Systems, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [284488 2015-02-04] (Microsoft Corporation)
S3 WEPHOSTSVC; C:\WINDOWS\system32\wephostsvc.dll [20992 2014-11-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22200 2015-02-04] (Microsoft Corporation)
S3 workfolderssvc; C:\WINDOWS\system32\workfolderssvc.dll [1269248 2014-11-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 acsock; C:\WINDOWS\system32\DRIVERS\acsock.sys [92112 2013-07-19] (Cisco Systems, Inc.)
R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [25600 2014-11-21] (Microsoft Corporation)
R3 cjusb; C:\WINDOWS\system32\DRIVERS\cjusb.sys [28704 2012-08-29] (REINER SCT)
S3 GPIO; C:\WINDOWS\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
R1 MpKslf5eb356b; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DF83DAB3-7E4D-4708-86F2-99613F15B20B}\MpKslf5eb356b.sys [39464 2015-03-30] (Microsoft Corporation)
R3 RtlWlanu; C:\WINDOWS\system32\DRIVERS\rtwlanu.sys [1698520 2013-07-31] (Realtek Semiconductor Corporation )
S3 vpnva; C:\WINDOWS\system32\DRIVERS\vpnva-6.sys [43120 2013-07-19] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [84800 2015-02-04] (Microsoft Corporation)
R0 Wof; C:\WINDOWS\system32\Drivers\Wof.sys [138584 2014-11-21] (Microsoft Corporation)
R3 WUDFSensorLP; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [190976 2014-11-21] (Microsoft Corporation)
R3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [190976 2014-11-21] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-30 06:50 - 2015-03-30 06:50 - 00000883 _____ () C:\Users\Mat\Desktop\JRT.txt
2015-03-30 06:45 - 2015-03-30 06:45 - 01389240 _____ (Thisisu) C:\Users\Mat\Desktop\JRT.exe
2015-03-30 06:44 - 2015-03-30 06:44 - 00006235 _____ () C:\Users\Mat\Desktop\AdwCleaner[S0].txt
2015-03-30 06:24 - 2015-03-30 06:24 - 00008348 _____ () C:\WINDOWS\PFRO.log
2015-03-30 06:24 - 2015-03-30 06:24 - 00000077 _____ () C:\WINDOWS\setupact.log
2015-03-30 06:24 - 2015-03-30 06:24 - 00000000 _____ () C:\WINDOWS\setuperr.log
2015-03-30 06:19 - 2015-03-30 06:19 - 00000269 _____ () C:\Users\Mat\Desktop\Windows 8.1 Adware eingefangen (Delta) - Trojaner-Board.URL
2015-03-30 06:18 - 2015-03-30 06:23 - 00000000 ____D () C:\AdwCleaner
2015-03-30 06:18 - 2015-03-30 06:18 - 00007500 _____ () C:\Users\Mat\Desktop\mbam.txt
2015-03-29 22:35 - 2015-03-30 06:17 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-03-29 22:35 - 2015-03-29 22:35 - 00001072 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-29 22:35 - 2015-03-29 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-29 22:35 - 2015-03-29 22:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-29 22:35 - 2015-03-29 22:35 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-03-29 22:35 - 2015-03-17 06:15 - 00092888 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-03-29 22:35 - 2015-03-17 06:15 - 00051928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-03-29 22:35 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-03-29 22:34 - 2015-03-29 22:34 - 00000000 __SHD () C:\Users\Mat\AppData\Local\EmieUserList
2015-03-29 22:34 - 2015-03-29 22:34 - 00000000 __SHD () C:\Users\Mat\AppData\Local\EmieSiteList
2015-03-29 22:34 - 2015-03-29 22:34 - 00000000 __SHD () C:\Users\Mat\AppData\Local\EmieBrowserModeList
2015-03-29 22:30 - 2015-03-29 22:30 - 00001238 _____ () C:\Users\Mat\Desktop\Revo Uninstaller.lnk
2015-03-29 22:30 - 2015-03-29 22:30 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-03-29 15:49 - 2015-03-29 15:50 - 00036925 _____ () C:\Users\Mat\Desktop\Addition.txt
2015-03-29 15:49 - 2015-03-24 00:56 - 00003913 _____ () C:\Users\Mat\Desktop\Scan-Ergebnis-20150324-0056.html
2015-03-29 15:48 - 2015-03-30 06:50 - 00017463 _____ () C:\Users\Mat\Desktop\FRST.txt
2015-03-29 15:48 - 2015-03-30 06:50 - 00000000 ____D () C:\FRST
2015-03-29 15:47 - 2015-03-29 15:47 - 00000468 _____ () C:\Users\Mat\Desktop\defogger_disable.log
2015-03-29 15:47 - 2015-03-29 15:47 - 00000239 _____ () C:\Users\Mat\Desktop\Trojaner-Board - Neues Thema erstellen.URL
2015-03-29 15:47 - 2015-03-29 15:47 - 00000000 _____ () C:\Users\Mat\defogger_reenable
2015-03-29 15:45 - 2015-03-29 15:45 - 00380416 _____ () C:\Users\Mat\Desktop\Gmer-19357.exe
2015-03-29 15:43 - 2015-03-29 15:43 - 00000266 _____ () C:\Users\Mat\Desktop\Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten - Trojaner-Board.URL
2015-03-29 15:40 - 2015-03-29 15:40 - 01135104 _____ (Farbar) C:\Users\Mat\Desktop\FRST.exe
2015-03-29 15:40 - 2015-03-29 15:40 - 00050477 _____ () C:\Users\Mat\Desktop\Defogger.exe
2015-03-29 15:33 - 2015-03-29 15:33 - 02168320 _____ () C:\Users\Mat\Desktop\AdwCleaner_4.113.exe
2015-03-24 23:41 - 2015-03-30 06:14 - 00037888 ___SH () C:\Users\Mat\Desktop\Thumbs.db
2015-03-22 18:47 - 2014-04-16 01:35 - 00028352 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll
2015-03-22 10:28 - 2015-03-22 10:28 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-12 13:22 - 2015-03-12 13:22 - 00000000 ____D () C:\Users\Mat\Desktop\107_FUJI
2015-03-11 00:15 - 2015-02-08 01:49 - 00791040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-03-11 00:15 - 2015-02-06 03:08 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-03-11 00:15 - 2015-01-31 01:29 - 02484224 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-03-11 00:15 - 2015-01-31 01:20 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2015-03-11 00:15 - 2015-01-29 20:34 - 01488040 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-03-11 00:15 - 2015-01-29 03:00 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 00:15 - 2015-01-29 02:50 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-03-11 00:15 - 2015-01-23 07:02 - 00560392 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2015-03-11 00:15 - 2015-01-21 07:15 - 01123848 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-03-11 00:14 - 2015-03-06 04:33 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-03-11 00:14 - 2015-02-26 01:27 - 03543552 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-03-11 00:14 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-03-11 00:14 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-03-11 00:14 - 2015-02-21 02:27 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-03-11 00:14 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-03-11 00:14 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-03-11 00:14 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-03-11 00:14 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-03-11 00:14 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-03-11 00:14 - 2015-02-20 03:56 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-03-11 00:14 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-03-11 00:14 - 2015-02-20 03:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-03-11 00:14 - 2015-02-20 03:26 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-03-11 00:14 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-03-11 00:14 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-03-11 00:14 - 2015-02-20 03:24 - 00684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-03-11 00:14 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-03-11 00:14 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-03-11 00:14 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-03-11 00:14 - 2015-02-12 19:34 - 19731824 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-03-11 00:14 - 2015-02-07 01:09 - 00396419 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-03-11 00:14 - 2015-02-03 02:03 - 03551744 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2015-03-11 00:14 - 2015-01-30 04:25 - 00083456 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys
2015-03-11 00:14 - 2015-01-30 03:44 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42u.dll
2015-03-11 00:14 - 2015-01-30 03:42 - 01204224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42.dll
2015-03-11 00:14 - 2015-01-29 03:29 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\photowiz.dll
2015-03-11 00:14 - 2015-01-29 02:56 - 00602624 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2015-03-11 00:14 - 2015-01-29 02:55 - 00873984 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2015-03-11 00:14 - 2015-01-28 01:41 - 02207488 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-03-11 00:14 - 2015-01-24 03:51 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-03-11 00:14 - 2014-12-11 07:40 - 00041296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContentServer.exe
2015-03-11 00:13 - 2015-02-20 04:20 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-03-11 00:13 - 2015-02-20 04:15 - 00035840 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-03-11 00:13 - 2015-02-05 22:17 - 00869696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-03-11 00:13 - 2015-02-04 01:51 - 00227136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-03-11 00:13 - 2015-02-04 01:51 - 00084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2015-03-11 00:13 - 2015-02-04 01:51 - 00038392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-03-11 00:13 - 2015-02-03 01:53 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
2015-03-11 00:13 - 2015-01-30 03:40 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2015-03-11 00:13 - 2015-01-30 03:24 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2015-03-11 00:13 - 2015-01-30 03:16 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2015-03-11 00:13 - 2015-01-30 03:06 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2015-03-11 00:13 - 2015-01-29 02:49 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-03-11 00:13 - 2015-01-28 17:35 - 05769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-03-11 00:13 - 2015-01-28 17:35 - 01468408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-03-11 00:13 - 2015-01-28 03:47 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageContextHandler.dll
2015-03-11 00:13 - 2015-01-28 03:11 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2015-03-11 00:13 - 2015-01-24 04:20 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2015-03-11 00:13 - 2015-01-24 02:48 - 02975744 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2015-02-28 09:52 - 2015-02-28 09:52 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2015-02-28 00:49 - 2014-06-10 00:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-30 06:44 - 2013-05-09 21:37 - 00001120 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-30 06:41 - 2015-02-27 18:11 - 02034939 _____ () C:\WINDOWS\WindowsUpdate.log
2015-03-30 06:41 - 2013-06-18 20:18 - 00000000 ___RD () C:\Users\Mat\Documents\Dropbox
2015-03-30 06:41 - 2013-06-18 20:15 - 00000000 ____D () C:\Users\Mat\AppData\Roaming\Dropbox
2015-03-30 06:40 - 2013-05-09 21:38 - 00002141 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-30 06:40 - 2013-05-09 21:37 - 00001116 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-30 06:35 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2015-03-30 06:31 - 2014-11-21 00:48 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-30 06:30 - 2013-07-29 19:14 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-03-30 06:24 - 2013-08-22 09:23 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-03-30 06:24 - 2013-08-22 08:13 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-03-30 06:11 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-03-29 22:47 - 2012-07-26 10:41 - 00000000 ____D () C:\WINDOWS\DigitalLocker
2015-03-29 17:04 - 2015-01-21 21:25 - 00000000 ____D () C:\Users\Mat\AppData\Roaming\KeePass
2015-03-29 15:47 - 2015-02-27 17:59 - 00000000 ____D () C:\Users\Mat
2015-03-29 14:20 - 2013-05-09 21:40 - 00000977 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-03-29 14:20 - 2013-05-09 21:39 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-26 22:36 - 2014-10-29 20:04 - 00000000 ____D () C:\Profi cash
2015-03-24 23:29 - 2013-05-09 21:39 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-23 22:41 - 2015-02-27 17:51 - 00000000 ___DC () C:\WINDOWS\Panther
2015-03-22 18:48 - 2012-07-26 08:43 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-03-20 20:35 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\rescache
2015-03-20 19:35 - 2014-10-20 17:27 - 00000000 ____D () C:\Users\Mat\AppData\Local\Adobe
2015-03-19 08:21 - 2013-08-22 09:22 - 00402400 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-03-19 08:19 - 2013-08-22 10:17 - 00000000 ___RD () C:\WINDOWS\ToastData
2015-03-19 08:19 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-19 08:19 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-19 08:19 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\WinStore
2015-03-19 08:19 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\de-DE
2015-03-19 08:19 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Windows Defender
2015-03-19 08:06 - 2013-08-15 08:53 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-03-19 08:01 - 2013-05-09 22:30 - 119837696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-03-19 08:00 - 2013-08-22 10:17 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-16 21:36 - 2013-05-16 19:12 - 00000000 ____D () C:\Users\Mat\AppData\Roaming\XnView
2015-03-14 11:00 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-03-11 08:45 - 2013-06-18 20:19 - 00001059 _____ () C:\Users\Mat\Desktop\Dropbox.lnk
2015-03-11 08:45 - 2013-06-18 20:17 - 00000000 ____D () C:\Users\Mat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-03-04 23:24 - 2014-11-21 02:36 - 00792032 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-03-04 23:24 - 2014-11-21 02:36 - 00178144 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-03-03 15:16 - 2013-05-09 22:37 - 00246920 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2015-02-28 09:54 - 2014-12-14 14:28 - 00000000 ____D () C:\WINDOWS\system32\AutoUpdateLicense
2015-02-28 09:52 - 2014-11-21 02:33 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-02-28 09:00 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-RS
2015-02-28 09:00 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-CS
2015-02-28 08:58 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\restore
==================== Files in the root of some directories =======
2014-05-14 22:08 - 2014-05-14 22:19 - 0000791 _____ () C:\Users\Mat\AppData\Local\cookies.ini
2013-11-06 21:42 - 2014-12-17 22:44 - 0007867 _____ () C:\ProgramData\hpzinstall.log
Some content of TEMP:
====================
C:\Users\Mat\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpz16mra.dll
C:\Users\Mat\AppData\Local\Temp\Quarantine.exe
C:\Users\Mat\AppData\Local\Temp\sqlite3.dll
C:\Users\Mat\AppData\Local\Temp\uninst1.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-30 06:35
==================== End Of Log ============================ --- --- --- |