![]() |
Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung Hallo zusammen, seit geraumer Zeit kämpfe ich mit echt nervigen Werbeformen. Zum einen Pop-Ups, obwohl ich diese blockiert eingestellt habe. Zum anderen legt sich die Werbung wie ein Schleier über die Seite, die ich eigentlich sehen will. Oft wird der Mauszeiger in dieser Werbung als Instrument zum Zielen für Interaktion dargestellt (Shooting, Ausziehen von Kleidungsstücken, ...). Die Fa. Star Games ist mir jetzt wiederholt als Werbetreibender aufgefallen. Irgendwelche wiederkehrende Muster bezüglich des Auftretens sind mir leider noch nicht aufgefallen... (doch...der genervte User...:-) ) Als permanenten PC-Schutz habe ich Kaspersky, ergänzt um CC-Cleaner, Ad Aware, Malwarebytes und adwcleaner. Habe schon einmal auf eigene Faust mit diesen Programmen mein Glück versucht, konnte das Phänomen bisher mit keinem der Programme stoppen... (den Hinweis in den Regeln habe ich erst danach gelesen... :-( ) Die Logdatei von Malwarebytes habe ich unten kopiert. In der Checkliste habe ich den Hinweis bzgl. der geschäftlichen Rechner gelesen. Wir haben ein kleines Einzelhandelsgeschäft, mein Laptop ist zwar dort als Gast auf den Server (Warenwirtschaft) eingebunden, aber eigentlich mein privater Laptop. IT-Abteilung habe ich nicht, nur einen Ein-Mann-Betrieb, der mir den Server für die Warenwirtschaft und rudimentäre Aufteilungen aufgesetzt hat. Falls das ein Ausschlusskriterium ist, schreibt es mir einfach, wäre zwar schade, aber nun mal Bestandteil der Regeln. Mag mir jemand helfen??? lg André Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.10.23.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 8.0.7601.17514 Andre.Gunkel :: LAPTOP-ANG [Administrator] 23.10.2013 10:21:14 MBAM-log-2013-10-23 (10-40-08).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 303989 Laufzeit: 11 Minute(n), 41 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|OMESupervisor (PUP.Optional.OfferMosquito.A) -> Daten: C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe (PUP.Optional.OfferMosquito.A) -> Keine Aktion durchgeführt. (Ende) |
hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
FRST Additions Logfile: FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-10-2013 can result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-10-2013 Ran by Andre.Gunkel (administrator) on LAPTOP-ANG on 23-10-2013 13:25:14 Running from C:\Users\Andre.Gunkel\Desktop Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareService.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe (Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files\StarMoney 9.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Google Inc.) C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe (Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe () C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareTray.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Microsoft Corporation) C:\Windows\system32\UI0Detect.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab) HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1136648 2009-09-04] (Dritek System Inc.) HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-06] (Apple Inc.) HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [PMBVolumeWatcher] - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [688128 2011-07-06] () HKLM\...\Run: [CLX3180_Scan2Pc] - C:\Windows\Twain_32\Samsung\CLX3180\Scan2pc.exe [1990144 2011-04-29] () HKLM\...\Run: [3180 Scan2PC] - C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe [1990144 2011-04-29] () HKLM\...\Run: [Cm108Sound] - RunDll32 cm108.cpl,CMICtrlWnd HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.) HKLM\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft) HKLM\...\Run: [] - [x] HKLM\...\Run: [AdAwareTray] - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareTray.exe [2176856 2013-10-08] () HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoDriveTypeAutoRun_KL_notset] 1 HKCU\...\Run: [MobileDocuments] - C:\Program Files\Common Files\Apple\Internet Services\ubd.exe HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-09-15] (Apple Inc.) HKCU\...\Run: [Snoozer] - C:\Users\Andre.Gunkel\AppData\Roaming\Snz\Snz.exe [1226843 2013-10-10] () HKCU\...\Run: [OMESupervisor] - C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe [2220366 2013-10-10] () AppInit_DLLs: c:\progra~1\kasper~1\kasper~1.0fo\adialhk.dll c:\progra~1\kasper~1\kasper~1.0fo\kloehk.dll [ 2011-03-17] (Kaspersky Lab ZAO) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Bing HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://companyweb HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://companyweb URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {4844E65C-D8A7-4FB4-B02A-435280E846B1} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {5504FFE2-37B5-4C89-907F-238B50B79008} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=FA93766D-5B92-4310-B9E9-E8099E190F8F&apn_sauid=593BB89A-F072-41D2-996C-4F756EDC1106 SearchScopes: HKCU - {C967B79E-297A-41C2-938D-FABDB4BC8E4C} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.70.200 FireFox: ======== FF ProfilePath: C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default FF DefaultSearchEngine: Search FF SelectedSearchEngine: Search FF Homepage: hxxp://www.lederweis.de/ FF Keyword.URL: hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_5&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ad-Aware Security Add-on - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} FF Extension: lazarus - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\lazarus@interclue.com.xpi FF Extension: om - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\om@offermosquito.com.xpi FF Extension: No Name - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi FF Extension: No Name - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ ========================== Services (Whitelisted) ================= R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-09-07] (Freemake) R2 klnagent; C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe [141688 2010-10-20] (Kaspersky Lab ZAO) R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareService.exe [497744 2013-10-08] () R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe [175104 2011-04-28] (Samsung Electronics Co., Ltd.) R2 StarMoney 8.0 OnlineUpdate; C:\Program Files\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files\StarMoney 9.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH) ==================== Drivers (Whitelisted) ==================== R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2009-07-13] (Samsung Electronics Co., Ltd.) R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [126480 2009-11-12] (Kaspersky Lab) R3 KLFLTDEV; C:\Windows\System32\DRIVERS\klfltdev.sys [24848 2009-09-03] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [233560 2011-03-17] (Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [22104 2011-03-17] (Kaspersky Lab ZAO) S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC) R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-12] (Samsung Electronics) S3 TridVid; C:\Windows\System32\DRIVERS\tridvid6010.sys [339712 2011-01-21] (10Moons Technologies Co.,Ltd) R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [340624 2013-07-17] (BitDefender S.R.L.) S3 USBPNPA; C:\Windows\System32\drivers\CM108.sys [1515520 2009-11-18] (C-Media Electronics Inc) R3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex) S1 DritekPortIO; \??\C:\Program Files\Launch Manager\DPortIO.sys [x] S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-23 13:24 - 2013-10-23 13:24 - 00000000 ____D C:\FRST 2013-10-23 13:23 - 2013-10-23 13:23 - 01087503 _____ (Farbar) C:\Users\Andre.Gunkel\Desktop\FRST.exe 2013-10-23 13:20 - 2013-10-23 13:20 - 00014983 _____ C:\Users\Andre.Gunkel\Desktop\X+WWqGKT.htm 2013-10-21 11:34 - 2013-10-21 11:34 - 00342115 _____ C:\Users\Andre.Gunkel\Desktop\kunden.txt 2013-10-20 15:04 - 2013-10-20 15:04 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 13:36 - 2013-10-20 13:36 - 00000000 ____D C:\Program Files\Common Files\Java 2013-10-20 13:36 - 2013-10-08 07:50 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-10-20 13:36 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-20 13:36 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-20 13:36 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-20 13:35 - 2013-10-20 13:36 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-16 12:12 - 2013-10-16 12:12 - 00010090 _____ C:\Users\Andre.Gunkel\Desktop\AdwCleaner[S0].txt 2013-10-16 12:01 - 2013-10-16 12:07 - 00000000 ____D C:\AdwCleaner 2013-10-16 12:00 - 2013-10-16 12:00 - 01048960 _____ C:\Users\Andre.Gunkel\Desktop\adwcleaner.exe 2013-10-14 20:14 - 2013-10-14 20:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Snz 2013-10-12 17:37 - 2013-10-12 17:37 - 00000000 ____D C:\Users\Andre.Gunkel\.MCReferenceSdk 2013-10-11 23:17 - 2013-10-11 23:17 - 00001943 _____ C:\Users\Public\Desktop\Lightworks (11.1).lnk 2013-10-11 23:17 - 2013-10-11 23:17 - 00000000 ____D C:\ProgramData\Geevs 2013-10-11 23:14 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2013-10-11 23:14 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2013-10-11 23:14 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2013-10-11 23:14 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2013-10-11 18:53 - 2013-10-11 18:59 - 72720560 _____ (Lightworks) C:\Users\Andre.Gunkel\Downloads\setup_11.1_full_32bit.exe 2013-10-11 15:52 - 2013-10-11 15:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\LavasoftStatistics 2013-10-11 15:34 - 2013-10-11 15:34 - 00001327 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk 2013-10-11 15:33 - 2013-10-11 15:33 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\adawarebp 2013-10-11 15:33 - 2013-10-11 15:33 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-10-11 15:32 - 2013-10-11 15:33 - 00000000 ____D C:\Program Files\Lavasoft 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS\andre.gunkel 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Program Files\Toolbar Cleaner 2013-10-11 15:31 - 2013-10-11 15:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Lavasoft 2013-10-11 15:30 - 2013-10-11 15:30 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-10-11 15:28 - 2013-10-11 15:28 - 01724552 _____ C:\Users\Andre.Gunkel\Downloads\Adaware_Installer.exe 2013-10-11 15:28 - 2013-10-11 15:28 - 00000000 ____D C:\ProgramData\Lavasoft 2013-10-10 18:23 - 2013-10-10 18:23 - 02220366 _____ C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe 2013-10-10 13:03 - 2013-10-10 13:03 - 00000000 ____D C:\Windows\de 2013-10-10 13:02 - 2013-10-10 13:02 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-10-10 13:01 - 2013-10-10 13:02 - 00000000 ____D C:\Program Files\Windows Live 2013-10-10 13:00 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2013-10-10 13:00 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2013-10-10 13:00 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2013-10-10 13:00 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2013-10-10 12:54 - 2013-10-10 12:54 - 01245184 _____ (Microsoft Corporation) C:\Users\Andre.Gunkel\Downloads\wlsetup-webde_16.4.3505.0912.exe 2013-10-10 08:50 - 2013-10-10 08:50 - 00000961 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-10 08:50 - 2013-10-10 08:50 - 00000000 ____D C:\Program Files\CCleaner 2013-10-10 08:49 - 2013-10-10 08:49 - 03294168 _____ (Piriform Ltd) C:\Users\Andre.Gunkel\Downloads\ccsetup406_slim.exe 2013-10-10 00:32 - 2013-10-10 00:32 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{D1F696EE-4AC9-4180-8E0D-677BD145C7A1} 2013-10-09 23:58 - 2013-10-09 23:58 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00001063 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-09 23:57 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-09 23:56 - 2013-10-09 23:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andre.Gunkel\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-08 11:06 - 2013-10-08 11:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{B57CBA9D-F1F3-4583-A41D-3E8DF3CD4622} 2013-10-07 23:06 - 2013-10-07 23:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{42389A2C-4AAE-47CA-92F1-D3A7275C5B96} 2013-10-07 22:07 - 2013-10-07 22:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{D1B65288-BDD6-4533-9305-A106904ADFC8} 2013-10-07 10:13 - 2013-10-07 10:13 - 00179984 _____ (Kaspersky Lab) C:\Users\Andre.Gunkel\Downloads\kss12.0.1.117mlg_en-de_ru-de_fr-de_de-de.exe 2013-10-06 19:23 - 2013-10-06 19:23 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{7944CC22-787E-4E2C-8787-93A3B58A6EA2} 2013-10-06 18:54 - 2013-10-06 18:54 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{E9426538-02C3-4EA7-BE7C-579ED4672789} 2013-10-06 18:24 - 2013-10-06 18:24 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{018A0A36-EDDC-4421-AB0F-00B05245D690} 2013-10-06 14:08 - 2013-10-06 14:08 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{C190DAF3-E8F7-474F-AE1A-72D1637BF9CD} 2013-10-06 13:05 - 2013-10-06 13:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6A33A4EB-12CD-4EC9-BD70-8C5475A1BFF0} 2013-10-06 12:52 - 2013-10-06 12:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{9E3940BB-4CC4-4D45-A54C-4A538D13ABCC} 2013-10-06 12:44 - 2013-10-06 12:44 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{9379E1D0-A35A-4693-9F37-B3EF43F6180D} 2013-10-06 10:29 - 2013-10-06 10:29 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{DF129DA7-356D-497B-9C9D-FCBB52063BF5} 2013-10-05 22:28 - 2013-10-05 22:29 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{B88B4DFA-2E5C-4C50-8CC1-AA8530A7A817} 2013-10-05 10:28 - 2013-10-05 10:28 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{40EF02A3-9067-4DA6-968D-9820B66A7272} 2013-10-04 14:06 - 2013-10-04 14:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{0AB0F183-F11D-4881-B4A0-7A6AB26B268E} 2013-10-04 13:44 - 2013-10-04 13:44 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6227F893-E306-4126-8CA7-F54F63A4D44A} 2013-10-04 13:07 - 2013-10-04 13:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FEF9A27D-71F7-44A6-BEA1-3FA4E4DBF000} 2013-10-04 12:32 - 2013-10-04 12:32 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6AF6AB4D-5F8D-4BDB-9B15-5119993BB247} 2013-10-04 12:04 - 2013-10-04 12:04 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FADF4FB0-A6A2-42DC-B37A-241A47BA8E70} 2013-10-03 21:03 - 2013-10-03 21:03 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{8940AB10-9868-411A-89E8-47F67C9A6AD6} 2013-10-03 09:02 - 2013-10-03 09:03 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{1AE41AD6-7CD9-4DC1-A579-7B397950F822} 2013-10-03 06:38 - 2013-10-03 06:38 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{A44D5D36-7209-48C4-8A58-647AC69A8027} 2013-10-02 16:08 - 2013-10-02 16:08 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{217FCBD5-F54F-454C-B87B-7D9E079B00FE} 2013-10-02 03:05 - 2013-10-02 03:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{27A753EB-A852-4674-BFCC-31025EFD0992} 2013-10-01 09:49 - 2013-10-01 09:49 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{F9BFA550-9F80-4418-9A3F-112ABD409B6D} 2013-10-01 09:16 - 2013-10-01 09:17 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-30 21:49 - 2013-09-30 21:49 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FA26DF71-65CA-443D-BFFB-2EEF4A7D3556} 2013-09-30 09:48 - 2013-09-30 09:49 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{699EDC2C-4558-4C12-86BF-827059FB7172} 2013-09-29 21:48 - 2013-09-29 21:48 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{85973ECA-D48D-4FE1-A0B1-10C6F96DCFC4} 2013-09-26 21:32 - 2013-09-26 21:32 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-09-26 21:31 - 2013-09-26 21:32 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-09-26 21:31 - 2013-09-26 21:32 - 00000000 ____D C:\Program Files\iTunes 2013-09-26 21:31 - 2013-09-26 21:31 - 00000000 ____D C:\Program Files\iPod 2013-09-24 22:40 - 2013-09-24 22:41 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{926AAC78-B42B-4724-9F70-DC386D54C906} ==================== One Month Modified Files and Folders ======= 2013-10-23 13:24 - 2013-10-23 13:24 - 00000000 ____D C:\FRST 2013-10-23 13:23 - 2013-10-23 13:23 - 01087503 _____ (Farbar) C:\Users\Andre.Gunkel\Desktop\FRST.exe 2013-10-23 13:20 - 2013-10-23 13:20 - 00014983 _____ C:\Users\Andre.Gunkel\Desktop\X+WWqGKT.htm 2013-10-23 13:01 - 2011-03-25 00:42 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-23 13:00 - 2012-04-19 17:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-23 12:58 - 2011-03-17 13:13 - 00000112 _____ C:\Windows\system32\config\netlogon.ftl 2013-10-23 12:37 - 2010-12-02 11:09 - 01581070 _____ C:\Windows\WindowsUpdate.log 2013-10-23 11:21 - 2011-03-17 13:23 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-10-23 08:11 - 2009-07-14 06:34 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-23 08:11 - 2009-07-14 06:34 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-23 08:08 - 2011-07-19 23:01 - 00000000 ____D C:\Program Files\StarMoney 8.0 S-Edition 2013-10-23 08:04 - 2011-03-25 00:42 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-23 08:03 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-23 08:03 - 2009-07-14 06:39 - 00144511 _____ C:\Windows\setupact.log 2013-10-22 20:07 - 2013-05-17 11:44 - 00000000 ____D C:\Program Files\StarMoney 9.0 S-Edition 2013-10-22 08:02 - 2011-03-31 09:28 - 00000000 ____D C:\_André Gunkel 2013-10-21 11:34 - 2013-10-21 11:34 - 00342115 _____ C:\Users\Andre.Gunkel\Desktop\kunden.txt 2013-10-21 07:52 - 2011-03-17 13:16 - 00000836 __RSH C:\Users\Andre.Gunkel\ntuser.pol 2013-10-21 07:52 - 2011-03-17 13:16 - 00000000 ____D C:\Users\Andre.Gunkel 2013-10-20 15:04 - 2013-10-20 15:04 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 13:36 - 2013-10-20 13:36 - 00000000 ____D C:\Program Files\Common Files\Java 2013-10-20 13:36 - 2013-10-20 13:35 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-20 13:36 - 2011-03-16 15:09 - 00000000 ____D C:\Program Files\Java 2013-10-20 01:37 - 2011-03-27 00:10 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Apple Computer 2013-10-19 10:18 - 2010-12-02 11:18 - 01507106 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-18 23:32 - 2011-12-30 00:53 - 00000000 ____D C:\Material 2013-10-18 07:19 - 2011-12-30 00:53 - 00000000 ____D C:\Sound 2013-10-16 12:12 - 2013-10-16 12:12 - 00010090 _____ C:\Users\Andre.Gunkel\Desktop\AdwCleaner[S0].txt 2013-10-16 12:07 - 2013-10-16 12:01 - 00000000 ____D C:\AdwCleaner 2013-10-16 12:07 - 2013-03-06 14:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Common 2013-10-16 12:00 - 2013-10-16 12:00 - 01048960 _____ C:\Users\Andre.Gunkel\Desktop\adwcleaner.exe 2013-10-15 09:04 - 2012-03-20 21:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\TeamSpeak 3 Client 2013-10-14 20:14 - 2013-10-14 20:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Snz 2013-10-14 20:07 - 2011-03-16 15:04 - 00060924 _____ C:\Windows\PFRO.log 2013-10-12 17:44 - 2011-12-30 00:41 - 00000000 ____D C:\Users\Public\Documents\Lightworks 2013-10-12 17:37 - 2013-10-12 17:37 - 00000000 ____D C:\Users\Andre.Gunkel\.MCReferenceSdk 2013-10-11 23:17 - 2013-10-11 23:17 - 00001943 _____ C:\Users\Public\Desktop\Lightworks (11.1).lnk 2013-10-11 23:17 - 2013-10-11 23:17 - 00000000 ____D C:\ProgramData\Geevs 2013-10-11 23:17 - 2011-12-30 00:40 - 00000000 ____D C:\Program Files\Lightworks 2013-10-11 18:59 - 2013-10-11 18:53 - 72720560 _____ (Lightworks) C:\Users\Andre.Gunkel\Downloads\setup_11.1_full_32bit.exe 2013-10-11 18:43 - 2011-03-17 13:16 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\VirtualStore 2013-10-11 16:06 - 2011-03-17 19:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla 2013-10-11 15:58 - 2011-07-19 23:01 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-10-11 15:52 - 2013-10-11 15:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\LavasoftStatistics 2013-10-11 15:34 - 2013-10-11 15:34 - 00001327 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk 2013-10-11 15:33 - 2013-10-11 15:33 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\adawarebp 2013-10-11 15:33 - 2013-10-11 15:33 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-10-11 15:33 - 2013-10-11 15:32 - 00000000 ____D C:\Program Files\Lavasoft 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS\andre.gunkel 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Program Files\Toolbar Cleaner 2013-10-11 15:31 - 2013-10-11 15:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Lavasoft 2013-10-11 15:30 - 2013-10-11 15:30 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-10-11 15:28 - 2013-10-11 15:28 - 01724552 _____ C:\Users\Andre.Gunkel\Downloads\Adaware_Installer.exe 2013-10-11 15:28 - 2013-10-11 15:28 - 00000000 ____D C:\ProgramData\Lavasoft 2013-10-10 22:54 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-10-10 18:23 - 2013-10-10 18:23 - 02220366 _____ C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe 2013-10-10 13:04 - 2012-01-01 14:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\Windows Live 2013-10-10 13:03 - 2013-10-10 13:03 - 00000000 ____D C:\Windows\de 2013-10-10 13:02 - 2013-10-10 13:02 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-10-10 13:02 - 2013-10-10 13:01 - 00000000 ____D C:\Program Files\Windows Live 2013-10-10 13:00 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-10-10 12:54 - 2013-10-10 12:54 - 01245184 _____ (Microsoft Corporation) C:\Users\Andre.Gunkel\Downloads\wlsetup-webde_16.4.3505.0912.exe 2013-10-10 09:44 - 2011-03-31 09:28 - 00000000 ____D C:\_Leder Weis 2013-10-10 09:02 - 2011-05-19 11:22 - 00000000 ____D C:\Program Files\PDFCreator 2013-10-10 09:02 - 2011-04-05 08:29 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Skype 2013-10-10 08:54 - 2011-12-03 14:45 - 00000000 ____D C:\Windows\Minidump 2013-10-10 08:50 - 2013-10-10 08:50 - 00000961 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-10 08:50 - 2013-10-10 08:50 - 00000000 ____D C:\Program Files\CCleaner 2013-10-10 08:49 - 2013-10-10 08:49 - 03294168 _____ (Piriform Ltd) C:\Users\Andre.Gunkel\Downloads\ccsetup406_slim.exe 2013-10-10 00:32 - 2013-10-10 00:32 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{D1F696EE-4AC9-4180-8E0D-677BD145C7A1} 2013-10-10 00:27 - 2011-03-16 12:23 - 00000000 ____D C:\Windows\PCHEALTH 2013-10-09 23:58 - 2013-10-09 23:58 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00001063 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-09 23:56 - 2013-10-09 23:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andre.Gunkel\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-08 22:00 - 2012-04-19 17:11 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-08 22:00 - 2011-05-14 23:15 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-08 11:06 - 2013-10-08 11:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{B57CBA9D-F1F3-4583-A41D-3E8DF3CD4622} 2013-10-08 07:50 - 2013-10-20 13:36 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-10-08 07:46 - 2013-10-20 13:36 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-08 07:46 - 2013-10-20 13:36 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-08 07:46 - 2013-10-20 13:36 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-07 23:06 - 2013-10-07 23:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{42389A2C-4AAE-47CA-92F1-D3A7275C5B96} 2013-10-07 22:07 - 2013-10-07 22:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{D1B65288-BDD6-4533-9305-A106904ADFC8} 2013-10-07 10:13 - 2013-10-07 10:13 - 00179984 _____ (Kaspersky Lab) C:\Users\Andre.Gunkel\Downloads\kss12.0.1.117mlg_en-de_ru-de_fr-de_de-de.exe 2013-10-06 19:23 - 2013-10-06 19:23 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{7944CC22-787E-4E2C-8787-93A3B58A6EA2} 2013-10-06 18:54 - 2013-10-06 18:54 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{E9426538-02C3-4EA7-BE7C-579ED4672789} 2013-10-06 18:24 - 2013-10-06 18:24 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{018A0A36-EDDC-4421-AB0F-00B05245D690} 2013-10-06 14:08 - 2013-10-06 14:08 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{C190DAF3-E8F7-474F-AE1A-72D1637BF9CD} 2013-10-06 13:05 - 2013-10-06 13:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6A33A4EB-12CD-4EC9-BD70-8C5475A1BFF0} 2013-10-06 12:52 - 2013-10-06 12:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{9E3940BB-4CC4-4D45-A54C-4A538D13ABCC} 2013-10-06 12:44 - 2013-10-06 12:44 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{9379E1D0-A35A-4693-9F37-B3EF43F6180D} 2013-10-06 10:29 - 2013-10-06 10:29 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{DF129DA7-356D-497B-9C9D-FCBB52063BF5} 2013-10-05 22:29 - 2013-10-05 22:28 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{B88B4DFA-2E5C-4C50-8CC1-AA8530A7A817} 2013-10-05 10:28 - 2013-10-05 10:28 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{40EF02A3-9067-4DA6-968D-9820B66A7272} 2013-10-04 14:06 - 2013-10-04 14:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{0AB0F183-F11D-4881-B4A0-7A6AB26B268E} 2013-10-04 13:44 - 2013-10-04 13:44 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6227F893-E306-4126-8CA7-F54F63A4D44A} 2013-10-04 13:07 - 2013-10-04 13:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FEF9A27D-71F7-44A6-BEA1-3FA4E4DBF000} 2013-10-04 12:32 - 2013-10-04 12:32 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6AF6AB4D-5F8D-4BDB-9B15-5119993BB247} 2013-10-04 12:04 - 2013-10-04 12:04 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FADF4FB0-A6A2-42DC-B37A-241A47BA8E70} 2013-10-03 21:03 - 2013-10-03 21:03 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{8940AB10-9868-411A-89E8-47F67C9A6AD6} 2013-10-03 09:03 - 2013-10-03 09:02 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{1AE41AD6-7CD9-4DC1-A579-7B397950F822} 2013-10-03 06:38 - 2013-10-03 06:38 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{A44D5D36-7209-48C4-8A58-647AC69A8027} 2013-10-02 16:08 - 2013-10-02 16:08 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{217FCBD5-F54F-454C-B87B-7D9E079B00FE} 2013-10-02 03:05 - 2013-10-02 03:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{27A753EB-A852-4674-BFCC-31025EFD0992} 2013-10-02 02:56 - 2012-04-28 05:42 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-10-01 11:10 - 2011-03-17 19:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\Mozilla 2013-10-01 09:49 - 2013-10-01 09:49 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{F9BFA550-9F80-4418-9A3F-112ABD409B6D} 2013-10-01 09:17 - 2013-10-01 09:16 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-30 21:49 - 2013-09-30 21:49 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FA26DF71-65CA-443D-BFFB-2EEF4A7D3556} 2013-09-30 09:49 - 2013-09-30 09:48 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{699EDC2C-4558-4C12-86BF-827059FB7172} 2013-09-29 21:48 - 2013-09-29 21:48 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{85973ECA-D48D-4FE1-A0B1-10C6F96DCFC4} 2013-09-26 21:40 - 2011-03-27 00:10 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\Apple Computer 2013-09-26 21:32 - 2013-09-26 21:32 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-09-26 21:32 - 2013-09-26 21:31 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-09-26 21:32 - 2013-09-26 21:31 - 00000000 ____D C:\Program Files\iTunes 2013-09-26 21:31 - 2013-09-26 21:31 - 00000000 ____D C:\Program Files\iPod 2013-09-26 21:31 - 2011-03-27 00:08 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-09-24 22:41 - 2013-09-24 22:40 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{926AAC78-B42B-4724-9F70-DC386D54C906} Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\ose00000.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\0d7181b6-ef47-402e-bc75-af9e3e97c026.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\18e5ab1b-2558-43bc-aab9-119b7cb6fefa.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-21 09:34 ==================== End Of Log ============================[/CODE] --- --- --- Danke für die Antwort und Bereitschaft! Hoffe richtig so...?! lg André |
![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Code: # AdwCleaner v3.010 - Bericht erstellt am 23/10/2013 um 17:31:03 Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-10-2013 --- --- --- --- --- --- --- --- --- --- --- --- :-) In der Form besser so??? Schon mal ein Zwischen - Danke an Dich "Schrauber" :-) |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
Code: ESETSmartInstaller@High as downloader log: Code: Results of screen317's Security Check version 0.99.74 Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Anti-Virus Ad-Aware Antivirus Antivirus out of date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Ad-Aware Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 45 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox (24.0) ````````Process Check: objlist.exe by Laurent```````` Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareService.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareTray.exe StarMoney 8.0 S-Edition ouservice StarMoneyOnlineUpdate.exe StarMoney 9.0 S-Edition ouservice StarMoneyOnlineUpdate.exe Kaspersky Lab NetworkAgent 8 klnagent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Results of screen317's Security Check version 0.99.74 Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Anti-Virus Ad-Aware Antivirus Antivirus out of date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Ad-Aware Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 45 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox (24.0) ````````Process Check: objlist.exe by Laurent```````` Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareService.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareTray.exe StarMoney 8.0 S-Edition ouservice StarMoneyOnlineUpdate.exe StarMoney 9.0 S-Edition ouservice StarMoneyOnlineUpdate.exe Kaspersky Lab NetworkAgent 8 klnagent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Results of screen317's Security Check version 0.99.74 Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Anti-Virus Ad-Aware Antivirus Antivirus out of date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Ad-Aware Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 45 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox (24.0) ````````Process Check: objlist.exe by Laurent```````` Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareService.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareTray.exe StarMoney 8.0 S-Edition ouservice StarMoneyOnlineUpdate.exe StarMoney 9.0 S-Edition ouservice StarMoneyOnlineUpdate.exe Kaspersky Lab NetworkAgent 8 klnagent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 --- --- --- |
Fertig :) Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Liste der Anhänge anzeigen (Anzahl: 1) Also so weit läuft es rund, nur den Fall hier hatte ich auf meiner eigenen Homepage und da ist nicht mal Werbung geschwweige denn irgendwelche Sondersachen... ? |
Firefox mal neu installieren :) |
Ok, habe Firefox neu installiert. Sieht nach 10 Tagen jetzt störungfrei aus. supi! Dir Schrauber vielen herzlichen Dank, Deine Hinweise und Tipps habe ich gespeichert, um ab und zu mal wieder drauf zu schauen. Liebe Grüße André |
Gern Geschehen :) |
Alle Zeitangaben in WEZ +1. Es ist jetzt 13:30 Uhr. |
Copyright ©2000-2025, Trojaner-Board