Nach massiven Hardware-Problemen Win32:GenMaliciousA entdeckt Hallo!
Ich hatte massive Hardware-Probleme, der Rechner piepste ständig laut und stürzte ab. Avira hat nichts angezeigt, verhielt sich aber irgendwie "störrisch". Nach Behebung der Hardware-Probleme habe ich Avast installiert und erhielt die Virusmeldung Win32:GenMaliciousA. Der Virus wurde in einem zweiten Scan in Quarantäne geschoben, außerdem zeigte der zweite Scan noch Conduit sowie Win64Adware. Malwarebites hat dann Win32:GenMaliciousA nicht mehr gefunden, meldete dann aber noch ConduitTB.Gen. Danach hab ich mich an eure Anleitung gehalten.
Danke schonmal für Eure Hilfe.
Beim ersten Avira-Suchlauf war das Log nicht aktiviert, beim zweiten Suchlauf wurde nichts gefunden; eine schnelle letzte Überprüfung brachte folgendes Log: Code:
*
* Avast Protokolldatei
* Diese Protokolldatei wurde automatisch erstellt
*
* Prüfungsname: Schnelle Überprüfung
* Start: Donnerstag, 2. Juli 2015 23:57:34
* VPS: 150702-2, 02.07.2015
*
C:\hiberfil.sys [E] Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird (32)
C:\pagefile.sys [E] Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird (32)
Infizierte Dateien: 0
Dateien gesamt: 52007
Ordner gesamt: 36633
Gesamtgröße: 30,3 GB
*
* Prüfung beendet: Freitag, 3. Juli 2015 00:06:56
* Laufzeit war 9 Minute(n), 9 Sekunde(n)
* Malwarebites ergab folgendes Log: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 02.07.2015
Suchlaufzeit: 21:57
Protokolldatei: MalwarebitesLog.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.07.02.04
Rootkit-Datenbank: v2015.07.01.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: VEnte
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 509708
Abgelaufene Zeit: 32 Min., 45 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 6
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\HKOAHCAOBJBIHEHLDFIMHBLMHGALCIPM, In Quarantäne, [0eee34a8ed9dca6c27d8f805cb3807f9],
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\nmhostct3297265, In Quarantäne, [e913f7e5ec9e72c4e53f7b80758ef709],
PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\HKOAHCAOBJBIHEHLDFIMHBLMHGALCIPM, In Quarantäne, [e7158d4fccbeb5815fa12ad457ac3cc4],
PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\nmhostct3297265, In Quarantäne, [bb41a33979112c0a2bf49764ef14fc04],
PUP.Optional.Conduit.A, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{B2D48FF5-2FA7-4E7D-9484-C86C8B853E7C}, In Quarantäne, [ad4f479501891d19218e669aac58fd03],
PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CHCT3297265, In Quarantäne, [d527f4e8553541f5a11ad9bed23323dd],
Registrierungswerte: 5
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\hkoahcaobjbihehldfimhblmhgalcipm|path, C:\Users\VEnte\AppData\Local\CRE\hkoahcaobjbihehldfimhblmhgalcipm.crx, In Quarantäne, [0eee34a8ed9dca6c27d8f805cb3807f9]
PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\hkoahcaobjbihehldfimhblmhgalcipm|path, C:\Users\VEnte\AppData\Local\CRE\hkoahcaobjbihehldfimhblmhgalcipm.crx, In Quarantäne, [e7158d4fccbeb5815fa12ad457ac3cc4]
PUP.Optional.Conduit.A, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{B2D48FF5-2FA7-4E7D-9484-C86C8B853E7C}|URL, hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3297265&CUI=UN38280467413594276&UM=2&UP=SP512ACDB4-C746-44D0-B1B2-8977DBEB0144&SSPV=, In Quarantäne, [ad4f479501891d19218e669aac58fd03]
PUP.Optional.Conduit.A, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{B2D48FF5-2FA7-4E7D-9484-C86C8B853E7C}|SuggestionsURL_JSON, hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}, In Quarantäne, [609c36a6e0aa10267639d42cd4302cd4]
PUP.Optional.Conduit.A, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{B2D48FF5-2FA7-4E7D-9484-C86C8B853E7C}|FaviconURL, hxxp://search.conduit.com/favicon.ico, In Quarantäne, [7b81af2d7f0bd660456a8c742adae020]
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Dateien: 0
(keine bösartigen Elemente erkannt)
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Defogger Log Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 22:57 on 02/07/2015 (VEnte)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- Die beiden FRST Logs:
FRST Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:28-06-2015 01
Ran by Kueken1 (ATTENTION: The logged in user is not administrator) on VEnte on 02-07-2015 22:58:42
Running from C:\Users\Kueken1\Downloads
Loaded Profiles: VEnte & Kueken1 (Available Profiles: VEnte & Kueken2 & Kueken1)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> winlogon.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> lsm.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> AvastSvc.exe
Failed to access process -> wlanext.exe
Failed to access process -> conhost.exe
Failed to access process -> spoolsv.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
Failed to access process -> svchost.exe
() C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
Failed to access process -> armsvc.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
Failed to access process -> svchost.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
Failed to access process -> EvtEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
Failed to access process -> HeciServer.exe
Failed to access process -> Jhi_service.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
Failed to access process -> PowerBiosServer.exe
Failed to access process -> RegSrvc.exe
Failed to access process -> sqlwriter.exe
Failed to access process -> svchost.exe
Failed to access process -> ViakaraokeSrv.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> wmpnetwk.exe
Failed to access process -> svchost.exe
Failed to access process -> unsecapp.exe
Failed to access process -> WmiPrvSE.exe
Failed to access process -> WmiPrvSE.exe
Failed to access process -> svchost.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
Failed to access process -> BTHSAmpPalService.exe
Failed to access process -> BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
Failed to access process -> IAStorDataMgrSvc.exe
Failed to access process -> LMS.exe
Failed to access process -> UNS.exe
Failed to access process -> NASvc.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> TrustedInstaller.exe
Failed to access process -> mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Failed to access process -> mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Failed to access process -> SearchProtocolHost.exe
Failed to access process -> SearchFilterHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [LMADLmon] => C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe [952496 2012-09-07] ()
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-05-15] (Intel Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5119600 2012-05-10] (VIA)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [LMADLmon] => C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe [952496 2012-09-07] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-02] (Avast Software s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_190_ActiveX.exe [623792 2015-07-02] (Adobe Systems Incorporated)
HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\MountPoints2: {cdf7f1ca-c50f-11e2-b414-0090f5e4f3c3} - H:\ting.exe
HKU\S-1-5-18\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
Startup: C:\Users\Kueken1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-05-24]
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-02] (Avast Software s.r.o.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-350991608-221412360-2685823185-1005\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
URLSearchHook: [S-1-5-21-350991608-221412360-2685823185-1001] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope {9CFAA595-7137-4432-9E2C-275AE0F3709D} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {9CFAA595-7137-4432-9E2C-275AE0F3709D} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-02] (Avast Software s.r.o.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-02] (Avast Software s.r.o.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{652752FE-12A3-4B90-A2C1-77BE17A56678}: [DhcpNameServer] 192.168.192.2 192.168.192.3
Tcpip\..\Interfaces\{67345BC8-D4B0-45A5-BA1E-50A1D4D13CFC}: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Kueken1\AppData\Roaming\Mozilla\Firefox\Profiles\ilPrvwwf.default
FF Homepage: www.ixquick.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-07-02] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-07-02] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-02] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-350991608-221412360-2685823185-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kueken1\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-03-19] (Unity Technologies ApS)
FF Extension: Avira Browser Safety - C:\Users\Kueken1\AppData\Roaming\Mozilla\Firefox\Profiles\ilPrvwwf.default\Extensions\abs@avira.com [2015-05-28]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-07-02]
Chrome:
=======
CHR Profile: C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avira Browser Safety) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-07-02]
CHR Extension: (Avast Online Security) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-07-02]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-02]
CHR Extension: (Google Wallet) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-02]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-02]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-02] (Avast Software s.r.o.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-15] (Intel Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] ()
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2011-02-18] () [File not signed]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-03] (VIA Technologies, Inc.)
S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-02] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-02] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-02] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-02] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-02] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-02] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-02] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-02] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-02] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
U3 kwryikog; \??\C:\Users\VEnte~1\AppData\Local\Temp\kwryikog.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-02 22:58 - 2015-07-02 22:59 - 00015707 _____ C:\Users\Kueken1\Downloads\FRST.txt
2015-07-02 22:58 - 2015-07-02 22:58 - 02112512 _____ (Farbar) C:\Users\Kueken1\Downloads\FRST64.exe
2015-07-02 22:58 - 2015-07-02 22:58 - 00000000 ____D C:\FRST
2015-07-02 22:57 - 2015-07-02 22:57 - 00000490 _____ C:\Users\Kueken1\Downloads\defogger_disable.log
2015-07-02 22:57 - 2015-07-02 22:57 - 00000000 _____ C:\Users\VEnte\defogger_reenable
2015-07-02 22:56 - 2015-07-02 22:56 - 00050477 _____ C:\Users\Kueken1\Downloads\Defogger.exe
2015-07-02 22:34 - 2015-07-02 22:34 - 00380416 _____ C:\Users\Kueken1\Downloads\gc87s56g.exe
2015-07-02 22:18 - 2015-07-02 22:18 - 01636352 _____ (Farbar) C:\Users\Kueken1\Downloads\FRST.exe
2015-07-02 21:56 - 2015-07-02 21:57 - 02244096 _____ C:\Users\Kueken1\Downloads\AdwCleaner_4.207.exe
2015-07-02 19:43 - 2015-07-02 21:42 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Kueken1\Downloads\mbam-setup-2.1.6.1022.exe
2015-07-02 16:49 - 2015-07-02 16:49 - 18174128 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-07-02 16:46 - 2015-07-02 22:51 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-02 15:41 - 2015-07-02 19:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-02 15:18 - 2015-07-02 15:18 - 00000000 ____D C:\Users\Kueken1\AppData\Roaming\AVAST Software
2015-07-02 15:14 - 2015-07-02 15:14 - 00001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-07-02 15:14 - 2015-07-02 15:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-07-02 15:13 - 2015-07-02 15:13 - 00002247 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-02 15:13 - 2015-07-02 15:13 - 00000350 ____H C:\Windows\Tasks\avast! Emergency Update.job
2015-07-02 15:13 - 2015-07-02 15:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-07-02 15:07 - 2015-07-02 19:30 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-02 15:07 - 2015-07-02 15:14 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-07-02 15:07 - 2015-07-02 15:07 - 00272248 _____ C:\Windows\system32\Drivers\aswVmm.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00065736 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-07-02 15:07 - 2015-07-02 15:07 - 00029168 _____ C:\Windows\system32\Drivers\aswHwid.sys
2015-07-02 14:51 - 2015-07-02 14:51 - 00000000 ____D C:\Program Files\AVAST Software
2015-07-01 13:33 - 2015-07-01 13:33 - 00000000 ____D C:\Users\VEnte\AppData\Roaming\JAM Software
2015-06-23 21:28 - 2015-06-23 21:28 - 00003224 ____N C:\bootsqm.dat
2015-06-22 19:24 - 2015-07-02 14:46 - 00000000 ____D C:\ProgramData\AVAST Software
2015-06-22 19:23 - 2015-06-22 19:24 - 05481344 _____ (Avast Software s.r.o.) C:\Users\Kueken1\Downloads\avast_free_antivirus_setup.exe
2015-06-22 19:23 - 2015-06-22 19:24 - 05481344 _____ (Avast Software s.r.o.) C:\Users\Public\Desktop\avast_free_antivirus_setup.exe
2015-06-22 19:11 - 2015-06-22 19:12 - 04718584 _____ (Avira Operations GmbH & Co. KG) C:\Users\Kueken1\Downloads\avira_de_av_5588320a39453__ws.exe
2015-06-22 18:01 - 2015-06-22 18:03 - 00000000 ____D C:\OETemp
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-02 22:57 - 2013-05-23 22:06 - 00000000 ____D C:\Users\VEnte
2015-07-02 22:47 - 2014-01-04 20:04 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-02 22:43 - 2009-07-14 06:45 - 00031792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-02 22:43 - 2009-07-14 06:45 - 00031792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-02 21:56 - 2014-06-10 16:40 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-02 21:52 - 2014-06-10 16:40 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-02 21:52 - 2014-06-10 16:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-02 21:52 - 2014-06-10 16:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-02 21:00 - 2013-05-16 12:15 - 01880411 _____ C:\Windows\WindowsUpdate.log
2015-07-02 19:46 - 2013-05-23 23:11 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-02 19:46 - 2013-05-23 23:11 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-02 19:36 - 2010-11-21 08:50 - 00698926 _____ C:\Windows\system32\perfh007.dat
2015-07-02 19:36 - 2010-11-21 08:50 - 00149034 _____ C:\Windows\system32\perfc007.dat
2015-07-02 19:36 - 2009-07-14 07:13 - 01618320 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-02 19:34 - 2015-04-26 21:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-02 19:29 - 2015-04-10 13:24 - 00003093 _____ C:\Windows\setupact.log
2015-07-02 19:29 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-02 18:29 - 2014-05-13 19:48 - 00000000 ____D C:\temp
2015-07-02 15:15 - 2015-04-10 13:24 - 00229700 _____ C:\Windows\PFRO.log
2015-07-02 15:13 - 2013-05-23 23:11 - 00000000 ____D C:\Program Files (x86)\Google
2015-06-23 15:47 - 2014-04-08 22:44 - 00000000 _____ C:\Users\Kueken1\AppData\Roaming\FoxitReaderUpdateInfo.txt
2015-06-22 19:20 - 2014-10-09 21:12 - 00000000 ____D C:\ProgramData\Package Cache
2015-06-22 19:14 - 2013-05-23 22:57 - 00000000 ____D C:\ProgramData\Avira
2015-06-22 19:14 - 2013-05-23 22:57 - 00000000 ____D C:\Program Files (x86)\Avira
2015-06-18 08:41 - 2014-06-10 16:40 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-18 08:41 - 2014-06-10 16:40 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-18 08:41 - 2014-06-10 16:40 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
==================== Files in the root of some directories =======
2014-04-08 22:44 - 2015-06-23 15:47 - 0000000 _____ () C:\Users\Kueken1\AppData\Roaming\FoxitReaderUpdateInfo.txt
2013-05-27 22:36 - 2015-01-23 21:57 - 0000600 _____ () C:\Users\Kueken1\AppData\Roaming\winscp.rnd
2013-12-02 15:23 - 2014-05-13 19:48 - 0007168 _____ () C:\Users\Kueken1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
C:\Users\Kueken1\AppData\Local\Temp\Foxit Reader Updater.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================ FRST Addition Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:28-06-2015 01
Ran by Kueken1 (ATTENTION: The logged in user is not administrator) on VEnte on 02-07-2015 22:58:42
Running from C:\Users\Kueken1\Downloads
Loaded Profiles: VEnte & Kueken1 (Available Profiles: VEnte & Kueken2 & Kueken1)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> winlogon.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> lsm.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> AvastSvc.exe
Failed to access process -> wlanext.exe
Failed to access process -> conhost.exe
Failed to access process -> spoolsv.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
Failed to access process -> svchost.exe
() C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
Failed to access process -> armsvc.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
Failed to access process -> svchost.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
Failed to access process -> EvtEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
Failed to access process -> HeciServer.exe
Failed to access process -> Jhi_service.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
Failed to access process -> PowerBiosServer.exe
Failed to access process -> RegSrvc.exe
Failed to access process -> sqlwriter.exe
Failed to access process -> svchost.exe
Failed to access process -> ViakaraokeSrv.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> wmpnetwk.exe
Failed to access process -> svchost.exe
Failed to access process -> unsecapp.exe
Failed to access process -> WmiPrvSE.exe
Failed to access process -> WmiPrvSE.exe
Failed to access process -> svchost.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
Failed to access process -> BTHSAmpPalService.exe
Failed to access process -> BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
Failed to access process -> IAStorDataMgrSvc.exe
Failed to access process -> LMS.exe
Failed to access process -> UNS.exe
Failed to access process -> NASvc.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> TrustedInstaller.exe
Failed to access process -> mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Failed to access process -> mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Failed to access process -> SearchProtocolHost.exe
Failed to access process -> SearchFilterHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [LMADLmon] => C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe [952496 2012-09-07] ()
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-05-15] (Intel Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5119600 2012-05-10] (VIA)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [LMADLmon] => C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe [952496 2012-09-07] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-02] (Avast Software s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_190_ActiveX.exe [623792 2015-07-02] (Adobe Systems Incorporated)
HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\MountPoints2: {cdf7f1ca-c50f-11e2-b414-0090f5e4f3c3} - H:\ting.exe
HKU\S-1-5-18\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
Startup: C:\Users\Kueken1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-05-24]
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-02] (Avast Software s.r.o.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-350991608-221412360-2685823185-1005\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
URLSearchHook: [S-1-5-21-350991608-221412360-2685823185-1001] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope {9CFAA595-7137-4432-9E2C-275AE0F3709D} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {9CFAA595-7137-4432-9E2C-275AE0F3709D} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-02] (Avast Software s.r.o.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-02] (Avast Software s.r.o.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{652752FE-12A3-4B90-A2C1-77BE17A56678}: [DhcpNameServer] 192.168.192.2 192.168.192.3
Tcpip\..\Interfaces\{67345BC8-D4B0-45A5-BA1E-50A1D4D13CFC}: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Kueken1\AppData\Roaming\Mozilla\Firefox\Profiles\ilPrvwwf.default
FF Homepage: www.ixquick.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-07-02] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-07-02] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-02] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-350991608-221412360-2685823185-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kueken1\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-03-19] (Unity Technologies ApS)
FF Extension: Avira Browser Safety - C:\Users\Kueken1\AppData\Roaming\Mozilla\Firefox\Profiles\ilPrvwwf.default\Extensions\abs@avira.com [2015-05-28]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-07-02]
Chrome:
=======
CHR Profile: C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avira Browser Safety) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-07-02]
CHR Extension: (Avast Online Security) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-07-02]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-02]
CHR Extension: (Google Wallet) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-02]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-02]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-02] (Avast Software s.r.o.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-15] (Intel Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] ()
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2011-02-18] () [File not signed]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-03] (VIA Technologies, Inc.)
S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-02] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-02] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-02] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-02] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-02] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-02] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-02] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-02] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-02] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
U3 kwryikog; \??\C:\Users\VEnte~1\AppData\Local\Temp\kwryikog.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-02 22:58 - 2015-07-02 22:59 - 00015707 _____ C:\Users\Kueken1\Downloads\FRST.txt
2015-07-02 22:58 - 2015-07-02 22:58 - 02112512 _____ (Farbar) C:\Users\Kueken1\Downloads\FRST64.exe
2015-07-02 22:58 - 2015-07-02 22:58 - 00000000 ____D C:\FRST
2015-07-02 22:57 - 2015-07-02 22:57 - 00000490 _____ C:\Users\Kueken1\Downloads\defogger_disable.log
2015-07-02 22:57 - 2015-07-02 22:57 - 00000000 _____ C:\Users\VEnte\defogger_reenable
2015-07-02 22:56 - 2015-07-02 22:56 - 00050477 _____ C:\Users\Kueken1\Downloads\Defogger.exe
2015-07-02 22:34 - 2015-07-02 22:34 - 00380416 _____ C:\Users\Kueken1\Downloads\gc87s56g.exe
2015-07-02 22:18 - 2015-07-02 22:18 - 01636352 _____ (Farbar) C:\Users\Kueken1\Downloads\FRST.exe
2015-07-02 21:56 - 2015-07-02 21:57 - 02244096 _____ C:\Users\Kueken1\Downloads\AdwCleaner_4.207.exe
2015-07-02 19:43 - 2015-07-02 21:42 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Kueken1\Downloads\mbam-setup-2.1.6.1022.exe
2015-07-02 16:49 - 2015-07-02 16:49 - 18174128 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-07-02 16:46 - 2015-07-02 22:51 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-02 15:41 - 2015-07-02 19:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-02 15:18 - 2015-07-02 15:18 - 00000000 ____D C:\Users\Kueken1\AppData\Roaming\AVAST Software
2015-07-02 15:14 - 2015-07-02 15:14 - 00001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-07-02 15:14 - 2015-07-02 15:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-07-02 15:13 - 2015-07-02 15:13 - 00002247 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-02 15:13 - 2015-07-02 15:13 - 00000350 ____H C:\Windows\Tasks\avast! Emergency Update.job
2015-07-02 15:13 - 2015-07-02 15:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-07-02 15:07 - 2015-07-02 19:30 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-02 15:07 - 2015-07-02 15:14 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-07-02 15:07 - 2015-07-02 15:07 - 00272248 _____ C:\Windows\system32\Drivers\aswVmm.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00065736 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2015-07-02 15:07 - 2015-07-02 15:07 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-07-02 15:07 - 2015-07-02 15:07 - 00029168 _____ C:\Windows\system32\Drivers\aswHwid.sys
2015-07-02 14:51 - 2015-07-02 14:51 - 00000000 ____D C:\Program Files\AVAST Software
2015-07-01 13:33 - 2015-07-01 13:33 - 00000000 ____D C:\Users\VEnte\AppData\Roaming\JAM Software
2015-06-23 21:28 - 2015-06-23 21:28 - 00003224 ____N C:\bootsqm.dat
2015-06-22 19:24 - 2015-07-02 14:46 - 00000000 ____D C:\ProgramData\AVAST Software
2015-06-22 19:23 - 2015-06-22 19:24 - 05481344 _____ (Avast Software s.r.o.) C:\Users\Kueken1\Downloads\avast_free_antivirus_setup.exe
2015-06-22 19:23 - 2015-06-22 19:24 - 05481344 _____ (Avast Software s.r.o.) C:\Users\Public\Desktop\avast_free_antivirus_setup.exe
2015-06-22 19:11 - 2015-06-22 19:12 - 04718584 _____ (Avira Operations GmbH & Co. KG) C:\Users\Kueken1\Downloads\avira_de_av_5588320a39453__ws.exe
2015-06-22 18:01 - 2015-06-22 18:03 - 00000000 ____D C:\OETemp
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-02 22:57 - 2013-05-23 22:06 - 00000000 ____D C:\Users\VEnte
2015-07-02 22:47 - 2014-01-04 20:04 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-02 22:43 - 2009-07-14 06:45 - 00031792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-02 22:43 - 2009-07-14 06:45 - 00031792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-02 21:56 - 2014-06-10 16:40 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-02 21:52 - 2014-06-10 16:40 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-02 21:52 - 2014-06-10 16:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-02 21:52 - 2014-06-10 16:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-02 21:00 - 2013-05-16 12:15 - 01880411 _____ C:\Windows\WindowsUpdate.log
2015-07-02 19:46 - 2013-05-23 23:11 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-02 19:46 - 2013-05-23 23:11 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-02 19:36 - 2010-11-21 08:50 - 00698926 _____ C:\Windows\system32\perfh007.dat
2015-07-02 19:36 - 2010-11-21 08:50 - 00149034 _____ C:\Windows\system32\perfc007.dat
2015-07-02 19:36 - 2009-07-14 07:13 - 01618320 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-02 19:34 - 2015-04-26 21:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-02 19:29 - 2015-04-10 13:24 - 00003093 _____ C:\Windows\setupact.log
2015-07-02 19:29 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-02 18:29 - 2014-05-13 19:48 - 00000000 ____D C:\temp
2015-07-02 15:15 - 2015-04-10 13:24 - 00229700 _____ C:\Windows\PFRO.log
2015-07-02 15:13 - 2013-05-23 23:11 - 00000000 ____D C:\Program Files (x86)\Google
2015-06-23 15:47 - 2014-04-08 22:44 - 00000000 _____ C:\Users\Kueken1\AppData\Roaming\FoxitReaderUpdateInfo.txt
2015-06-22 19:20 - 2014-10-09 21:12 - 00000000 ____D C:\ProgramData\Package Cache
2015-06-22 19:14 - 2013-05-23 22:57 - 00000000 ____D C:\ProgramData\Avira
2015-06-22 19:14 - 2013-05-23 22:57 - 00000000 ____D C:\Program Files (x86)\Avira
2015-06-18 08:41 - 2014-06-10 16:40 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-18 08:41 - 2014-06-10 16:40 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-18 08:41 - 2014-06-10 16:40 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
==================== Files in the root of some directories =======
2014-04-08 22:44 - 2015-06-23 15:47 - 0000000 _____ () C:\Users\Kueken1\AppData\Roaming\FoxitReaderUpdateInfo.txt
2013-05-27 22:36 - 2015-01-23 21:57 - 0000600 _____ () C:\Users\Kueken1\AppData\Roaming\winscp.rnd
2013-12-02 15:23 - 2014-05-13 19:48 - 0007168 _____ () C:\Users\Kueken1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
C:\Users\Kueken1\AppData\Local\Temp\Foxit Reader Updater.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================ GMER-Log Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-07-02 23:14:49
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PB4O 465,76GB
Running: gc87s56g.exe; Driver: C:\Users\VEnte~1\AppData\Local\Temp\kwryikog.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0cd292472f33
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0cd292472f33 (not active ControlSet)
---- EOF - GMER 2.1 ---- |