Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 12-02-2014
Ran by 1 at 2014-02-13 20:32:27 Run:1
Running from C:\Users\1\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.web.de/home
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.web.de/runonce
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://go.web.de/tab2
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NIS&chn=retail&geo=DE&ver=20&locale=de_DE&gct=sb&qsrc=2869
SearchScopes: HKCU - {BBB3829B-6ADC-4B83-8464-BBC45634CE94} URL = hxxp://search.1und1.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {D4607F03-416A-4727-9CCC-CCC0952AE5B8} URL = hxxp://suche.gmx.net/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
S4 serviceIEConfig; C:\Windows\System32\ieconfig_1und1_svc.exe [662416 2009-11-07] (mquadr.at softwareengineering und consulting gmbh)
R3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
2014-02-03 22:30 - 2014-02-03 22:30 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-02-03 22:29 - 2014-02-03 22:29 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\1\Downloads\SpyHunter-Installer.exe
2014-02-03 22:06 - 2014-02-03 22:06 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Aniol\Downloads\SpyHunter-Installer.exe
2014-02-03 22:13 - 2014-02-10 21:36 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP
AlternateDataStreams: C:\ProgramData\TEMP:834DD57E
AlternateDataStreams: C:\ProgramData\TEMP:C980DA7D
C:\Users\Aniol\AppData\Roaming\skype.ini
*****************
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\First Home Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBB3829B-6ADC-4B83-8464-BBC45634CE94} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{BBB3829B-6ADC-4B83-8464-BBC45634CE94} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D4607F03-416A-4727-9CCC-CCC0952AE5B8} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{D4607F03-416A-4727-9CCC-CCC0952AE5B8} => Key not found.
serviceIEConfig => Service deleted successfully.
esgiguard => Service deleted successfully.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\Users\1\Downloads\SpyHunter-Installer.exe => Moved successfully.
C:\Users\Aniol\Downloads\SpyHunter-Installer.exe => Moved successfully.
C:\Windows\455F074C814E4520B69B5584BD90400C.TMP => Moved successfully.
C:\ProgramData\TEMP => ":834DD57E" ADS removed successfully.
C:\ProgramData\TEMP => ":C980DA7D" ADS removed successfully.
C:\Users\Aniol\AppData\Roaming\skype.ini => Moved successfully.
==== End of Fixlog ====
sorry für die späte antwort war beruflich unterwegs der eset scan läuft gerade poste ich gleich zusammen mit dem frst scan
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=e0dd1ee12cc6c146bc41b38922df1006
# engine=17063
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-13 10:09:04
# local_time=2014-02-13 11:09:04 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=3591 16777213 100 93 606174 154925929 0 0
# compatibility_mode=5892 16776574 100 100 21368214 229862072 0 0
# scanned=192658
# found=3
# cleaned=0
# scan_time=9150
sh=7E2CD664CDB0CF9E06DB0EABE6143E3EF3591824 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Aniol\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\f59fdb-3bd6fb39"
sh=66446326F6A774D9BBF64561E42A623684F237EF ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Aniol\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\2a7c4fbb-5e4c7937"
sh=B626424CD4CF8F8A6E802F4AA475DE60D5E356CB ft=1 fh=c71c0011bc02fdfc vn="a variant of Win32/Injector.AMXL trojan" ac=I fn="D:\FILME\CCleaner 4 00 4064 (Final) + Crack\CCleaner.4.00.4064.(Final).+.Crack.exe"
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-02-2014
Ran by 1 (administrator) on ANIOL-PC on 13-02-2014 23:18:34
Running from C:\Users\1\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(ESET) C:\Program Files\ESET\ESET Online Scanner\OnlineScannerApp.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [] - [X]
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdSync.exe [215552 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [747264 2013-08-30] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [iTunesHelper] - D:\Itunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4435968 2007-04-23] (Realtek Semiconductor)
HKU\.DEFAULT\...\Run: [InfoCockpit] - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE [268800 2009-04-29] (Deutsche Telekom AG, T-Com)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-19\...\Run: [InfoCockpit] - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE [268800 2009-04-29] (Deutsche Telekom AG, T-Com)
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [InfoCockpit] - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE [268800 2009-04-29] (Deutsche Telekom AG, T-Com)
Startup: C:\Users\Aniol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk
ShortcutTarget: Product Registration.lnk -> C:\Users\1\AppData\Local\Temp\is-IMSSM.tmp\ATR1.exe (No File)
==================== Internet (Whitelisted) ====================
HKLM\Software\Microsoft\Internet Explorer\Main,Update_Check_Page = Download Internet Explorer - Browser
BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: WEB.DE Browser Configuration by mquadr.at - {D48FF4B4-E68F-47D1-8E25-81A0F0EEB341} - C:\Windows\System32\ieconfig_1und1.dll (mquadr.at softwareengineering und consulting gmbh)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} MSN Games - Free Online Games
DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\hpdt8sej.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - D:\Itunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @sony.com/ReaderDesktop - D:\Reader for pc\npreaderdetectmoz.dll (Sony Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.8 - D:\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - D:\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - D:\VLC\npvlc.dll (VideoLAN)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-05-24]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\coFFPlgn\ []
FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\IPSFF [2013-10-09]
========================== Services (Whitelisted) =================
S4 InCDsrv; C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe [1550896 2007-05-15] (Nero AG)
R2 NIS; C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
S4 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [66872 2008-06-05] ()
S4 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [107832 2008-06-05] ()
S4 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
==================== Drivers (Whitelisted) ====================
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdLH3.sys [83984 2012-02-23] (Advanced Micro Devices)
S3 AVMUNET; C:\Windows\System32\DRIVERS\avmunet.sys [15104 2005-03-02] (AVM GmbH)
R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\BASHDefs\20140121.001\BHDrvx86.sys [1098968 2013-12-18] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-11-21] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-11-21] (Symantec Corporation)
S3 FlashUSB; C:\Windows\System32\DRIVERS\FlashUSB.sys [16896 2009-05-12] (Danish Wireless Design A/S)
S3 gdrv; C:\Windows\gdrv.sys [15600 2007-11-04] (Windows (R) 2000 DDK provider)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\IPSDefs\20140212.001\IDSvix86.sys [394456 2014-01-22] (Symantec Corporation)
R4 InCDfs; C:\Windows\System32\drivers\InCDFs.sys [118576 2007-05-15] (Nero AG)
R1 InCDPass; C:\Windows\System32\drivers\InCDPass.sys [37040 2007-05-15] (Nero AG)
U1 InCDrec; C:\Windows\system32\Drivers\InCDrec.sys [16304 2007-05-15] (Nero AG)
S1 incdrm; C:\Windows\System32\drivers\InCDRm.sys [38576 2007-05-15] (Nero AG)
R0 JGOGO; C:\Windows\System32\DRIVERS\JGOGO.sys [6912 2006-02-07] (JMicron )
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [44928 2007-02-16] (JMicron Technology Corp.)
R3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtport.sys [12160 2009-09-29] (LG Electronics Inc.)
R3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbus.sys [10496 2009-09-29] (LG Electronics Inc.)
R3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmodem.sys [12928 2009-09-29] (LG Electronics Inc.)
S3 MTOnlPktAlyX; C:\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys [17536 2006-10-09] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20140213.002\NAVENG.SYS [93272 2013-08-29] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20140213.002\NAVEX15.SYS [1612376 2013-08-29] (Symantec Corporation)
R3 ovt530; C:\Windows\System32\Drivers\ov530vid.sys [161792 2005-03-15] (OmniVision Technologies, Inc.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-11-11] ()
R3 SRTSP; C:\Windows\System32\Drivers\NIS\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NIS\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
S3 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2010-06-17] (Avira GmbH)
R1 StarOpen; C:\Windows\system32\Drivers\StarOpen.sys [5632 2009-10-21] ()
R0 SymDS; C:\Windows\System32\drivers\NIS\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NIS\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-20] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NIS\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-19] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-19] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-19] (LG Electronics Inc.)
U3 ag379csh; C:\Windows\system32\Drivers\ag379csh.sys [0 ] (Microsoft Corporation)
S3 Afc; system32\drivers\Afc.sys [X]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 dtwmnic5; system32\DRIVERS\dtwmnic5.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U5 UnlockerDriver5; D:\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-13 23:18 - 2014-02-13 23:18 - 00014968 _____ () C:\Users\1\Desktop\FRST.txt
2014-02-13 21:56 - 2014-02-13 21:56 - 00000000 ____D () C:\Users\1\AppData\Roaming\WinRAR
2014-02-13 20:34 - 2014-02-13 20:34 - 00000000 ____D () C:\Program Files\ESET
2014-02-13 20:33 - 2014-02-13 20:33 - 02347384 _____ (ESET) C:\Users\1\Downloads\esetsmartinstaller_enu.exe
2014-02-13 20:29 - 2014-02-13 20:29 - 00000000 ____D () C:\Users\1\Downloads\FRST-OlderVersion
2014-02-10 22:19 - 2014-02-10 22:20 - 00035186 _____ () C:\Users\1\Downloads\Addition.txt
2014-02-10 22:18 - 2014-02-13 23:18 - 00000000 ____D () C:\FRST
2014-02-10 22:18 - 2014-02-13 20:29 - 01141248 _____ (Farbar) C:\Users\1\Desktop\FRST.exe
2014-02-10 22:18 - 2014-02-10 22:20 - 00028584 _____ () C:\Users\1\Downloads\FRST.txt
2014-02-06 23:09 - 2014-02-13 21:41 - 00000000 ____D () C:\Users\1\AppData\Roaming\Skype
2014-02-06 21:41 - 2014-02-10 21:22 - 00000000 ____D () C:\AdwCleaner
2014-02-06 21:33 - 2014-02-06 21:33 - 01166132 _____ () C:\Users\1\Downloads\adwcleaner.exe
2014-02-06 21:14 - 2014-02-06 21:15 - 00000000 ____D () C:\Users\1\AppData\Roaming\Firstload
2014-02-06 21:14 - 2014-02-06 21:14 - 00000000 ____D () C:\Users\1\Documents\Firstload
2014-02-03 22:52 - 2014-02-13 23:03 - 00000000 ____D () C:\Users\1\AppData\Roaming\vlc
2014-02-03 22:51 - 2014-02-13 22:56 - 00028160 _____ () C:\Users\1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-03 22:51 - 2014-02-03 22:51 - 00000000 ____D () C:\Users\1\AppData\Roaming\T-Online
2014-02-03 22:29 - 2014-02-03 22:29 - 00000680 _____ () C:\Users\1\AppData\Local\d3d9caps.dat
2014-02-03 22:08 - 2014-02-03 22:08 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-02-03 21:56 - 2014-02-03 21:56 - 00033288 _____ () C:\{1CC20377-3E0C-4A61-9315-7DCAABADF80E}
2014-02-03 21:37 - 2014-02-06 22:46 - 00001952 _____ () C:\Windows\PFRO.log
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Roaming\Macromedia
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Roaming\Adobe
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Local\Macromedia
2014-02-03 21:23 - 2014-02-03 21:23 - 00000000 ____D () C:\Users\1\AppData\Roaming\Mozilla
2014-02-03 21:23 - 2014-02-03 21:23 - 00000000 ____D () C:\Users\1\AppData\Local\Mozilla
2014-02-03 19:44 - 2014-02-03 19:44 - 00000000 ____D () C:\Users\1\AppData\Roaming\ATI
2014-02-03 19:44 - 2014-02-03 19:44 - 00000000 ____D () C:\Users\1\AppData\Local\ATI
2014-01-30 23:26 - 2014-01-30 23:26 - 00002608 _____ () C:\{B6EF3CC7-B2D2-4504-BE4F-71B12B1FE8C4}
2014-01-30 21:41 - 2014-01-30 21:41 - 00002088 _____ () C:\{06124B29-E47E-4E24-97E3-A6A106514E09}
2014-01-30 21:05 - 2014-01-30 21:05 - 107690016 _____ () C:\Windows\MEMORY.DMP
2014-01-30 21:05 - 2014-01-30 21:05 - 00137248 _____ () C:\Windows\Minidump\Mini013014-01.dmp
2014-01-20 19:20 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-01-20 19:20 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-20 19:20 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-20 19:20 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-20 19:19 - 2014-01-20 19:20 - 00005384 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
==================== One Month Modified Files and Folders =======
2014-02-13 23:18 - 2014-02-13 23:18 - 00014968 _____ () C:\Users\1\Desktop\FRST.txt
2014-02-13 23:18 - 2014-02-10 22:18 - 00000000 ____D () C:\FRST
2014-02-13 23:14 - 2007-11-05 19:19 - 00000418 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{06FDA24E-180F-4B01-AAFC-6F667AFEE44A}.job
2014-02-13 23:03 - 2014-02-03 22:52 - 00000000 ____D () C:\Users\1\AppData\Roaming\vlc
2014-02-13 22:57 - 2013-11-04 15:17 - 01058944 _____ () C:\Windows\WindowsUpdate.log
2014-02-13 22:56 - 2014-02-03 22:51 - 00028160 _____ () C:\Users\1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-13 22:37 - 2012-04-12 13:59 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-13 22:08 - 2006-11-02 13:47 - 00004176 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-13 22:08 - 2006-11-02 13:47 - 00004176 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-13 22:00 - 2009-07-26 19:28 - 00000000 ____D () C:\ProgramData\Skype
2014-02-13 21:56 - 2014-02-13 21:56 - 00000000 ____D () C:\Users\1\AppData\Roaming\WinRAR
2014-02-13 21:41 - 2014-02-06 23:09 - 00000000 ____D () C:\Users\1\AppData\Roaming\Skype
2014-02-13 20:34 - 2014-02-13 20:34 - 00000000 ____D () C:\Program Files\ESET
2014-02-13 20:33 - 2014-02-13 20:33 - 02347384 _____ (ESET) C:\Users\1\Downloads\esetsmartinstaller_enu.exe
2014-02-13 20:29 - 2014-02-13 20:29 - 00000000 ____D () C:\Users\1\Downloads\FRST-OlderVersion
2014-02-13 20:29 - 2014-02-10 22:18 - 01141248 _____ (Farbar) C:\Users\1\Desktop\FRST.exe
2014-02-13 20:08 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-11 06:53 - 2006-11-02 14:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-10 22:20 - 2014-02-10 22:19 - 00035186 _____ () C:\Users\1\Downloads\Addition.txt
2014-02-10 22:20 - 2014-02-10 22:18 - 00028584 _____ () C:\Users\1\Downloads\FRST.txt
2014-02-10 21:24 - 2012-05-03 14:52 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-10 21:22 - 2014-02-06 21:41 - 00000000 ____D () C:\AdwCleaner
2014-02-10 21:17 - 2013-05-24 14:02 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-06 23:16 - 2010-08-01 12:08 - 00000000 ____D () C:\Users\Aniol\AppData\Roaming\Skype
2014-02-06 23:09 - 2012-04-29 08:29 - 00002489 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-02-06 22:46 - 2014-02-03 21:37 - 00001952 _____ () C:\Windows\PFRO.log
2014-02-06 21:33 - 2014-02-06 21:33 - 01166132 _____ () C:\Users\1\Downloads\adwcleaner.exe
2014-02-06 21:15 - 2014-02-06 21:14 - 00000000 ____D () C:\Users\1\AppData\Roaming\Firstload
2014-02-06 21:14 - 2014-02-06 21:14 - 00000000 ____D () C:\Users\1\Documents\Firstload
2014-02-03 22:51 - 2014-02-03 22:51 - 00000000 ____D () C:\Users\1\AppData\Roaming\T-Online
2014-02-03 22:51 - 2013-06-11 14:17 - 00000000 ____D () C:\Users\1\AppData\Local\VirtualStore
2014-02-03 22:29 - 2014-02-03 22:29 - 00000680 _____ () C:\Users\1\AppData\Local\d3d9caps.dat
2014-02-03 22:08 - 2014-02-03 22:08 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-02-03 21:56 - 2014-02-03 21:56 - 00033288 _____ () C:\{1CC20377-3E0C-4A61-9315-7DCAABADF80E}
2014-02-03 21:47 - 2013-07-05 17:56 - 00000000 ____D () C:\Users\Aniol\AppData\Local\CrashDumps
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Roaming\Macromedia
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Roaming\Adobe
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Local\Macromedia
2014-02-03 21:23 - 2014-02-03 21:23 - 00000000 ____D () C:\Users\1\AppData\Roaming\Mozilla
2014-02-03 21:23 - 2014-02-03 21:23 - 00000000 ____D () C:\Users\1\AppData\Local\Mozilla
2014-02-03 19:45 - 2013-06-11 14:18 - 00058384 _____ () C:\Users\1\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-03 19:44 - 2014-02-03 19:44 - 00000000 ____D () C:\Users\1\AppData\Roaming\ATI
2014-02-03 19:44 - 2014-02-03 19:44 - 00000000 ____D () C:\Users\1\AppData\Local\ATI
2014-01-30 23:26 - 2014-01-30 23:26 - 00002608 _____ () C:\{B6EF3CC7-B2D2-4504-BE4F-71B12B1FE8C4}
2014-01-30 22:34 - 2012-06-05 18:54 - 00000000 ____D () C:\Users\Aniol\AppData\Roaming\vlc
2014-01-30 22:32 - 2007-11-04 21:35 - 00157184 _____ () C:\Users\Aniol\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-30 21:41 - 2014-01-30 21:41 - 00002088 _____ () C:\{06124B29-E47E-4E24-97E3-A6A106514E09}
2014-01-30 21:05 - 2014-01-30 21:05 - 107690016 _____ () C:\Windows\MEMORY.DMP
2014-01-30 21:05 - 2014-01-30 21:05 - 00137248 _____ () C:\Windows\Minidump\Mini013014-01.dmp
2014-01-30 21:05 - 2009-02-12 15:47 - 00000000 ____D () C:\Windows\Minidump
2014-01-27 20:29 - 2012-06-05 18:22 - 00000000 ____D () C:\Users\Aniol\AppData\Roaming\Firstload
2014-01-27 20:15 - 2007-11-03 21:35 - 00008944 _____ () C:\Users\Aniol\AppData\Local\d3d9caps.dat
2014-01-20 19:20 - 2014-01-20 19:19 - 00005384 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-01-20 19:20 - 2008-08-03 20:10 - 00000000 ____D () C:\Program Files\Java
2014-01-16 23:36 - 2013-08-15 20:54 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-16 23:34 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-01-14 22:20 - 2006-11-02 11:33 - 01597068 _____ () C:\Windows\system32\PerfStringBackup.INI
Some content of TEMP:
====================
C:\Users\1\AppData\Local\Temp\AskSLib.dll
C:\Users\1\AppData\Local\Temp\Quarantine.exe
C:\Users\1\AppData\Local\Temp\SHSetup.exe
C:\Users\Aniol\AppData\Local\Temp\icqsetup.exe
C:\Users\Aniol\AppData\Local\Temp\SHSetup.exe
C:\Users\Aniol\AppData\Local\Temp\uu-s5x8y.dll
C:\Users\Aniol\AppData\Local\Temp\v080qlmg.dll
C:\Users\Aniol\AppData\Local\Temp\z4rd43a6.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-13 20:14
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 12-02-2014
Ran by 1 at 2014-02-13 20:32:27 Run:1
Running from C:\Users\1\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.web.de/home
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.web.de/runonce
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://go.web.de/tab2
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NIS&chn=retail&geo=DE&ver=20&locale=de_DE&gct=sb&qsrc=2869
SearchScopes: HKCU - {BBB3829B-6ADC-4B83-8464-BBC45634CE94} URL = hxxp://search.1und1.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {D4607F03-416A-4727-9CCC-CCC0952AE5B8} URL = hxxp://suche.gmx.net/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
S4 serviceIEConfig; C:\Windows\System32\ieconfig_1und1_svc.exe [662416 2009-11-07] (mquadr.at softwareengineering und consulting gmbh)
R3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
2014-02-03 22:30 - 2014-02-03 22:30 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-02-03 22:29 - 2014-02-03 22:29 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\1\Downloads\SpyHunter-Installer.exe
2014-02-03 22:06 - 2014-02-03 22:06 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Aniol\Downloads\SpyHunter-Installer.exe
2014-02-03 22:13 - 2014-02-10 21:36 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP
AlternateDataStreams: C:\ProgramData\TEMP:834DD57E
AlternateDataStreams: C:\ProgramData\TEMP:C980DA7D
C:\Users\Aniol\AppData\Roaming\skype.ini
*****************
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\First Home Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBB3829B-6ADC-4B83-8464-BBC45634CE94} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{BBB3829B-6ADC-4B83-8464-BBC45634CE94} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D4607F03-416A-4727-9CCC-CCC0952AE5B8} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{D4607F03-416A-4727-9CCC-CCC0952AE5B8} => Key not found.
serviceIEConfig => Service deleted successfully.
esgiguard => Service deleted successfully.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\Users\1\Downloads\SpyHunter-Installer.exe => Moved successfully.
C:\Users\Aniol\Downloads\SpyHunter-Installer.exe => Moved successfully.
C:\Windows\455F074C814E4520B69B5584BD90400C.TMP => Moved successfully.
C:\ProgramData\TEMP => ":834DD57E" ADS removed successfully.
C:\ProgramData\TEMP => ":C980DA7D" ADS removed successfully.
C:\Users\Aniol\AppData\Roaming\skype.ini => Moved successfully.
==== End of Fixlog ====
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=e0dd1ee12cc6c146bc41b38922df1006
# engine=17063
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-13 10:09:04
# local_time=2014-02-13 11:09:04 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=3591 16777213 100 93 606174 154925929 0 0
# compatibility_mode=5892 16776574 100 100 21368214 229862072 0 0
# scanned=192658
# found=3
# cleaned=0
# scan_time=9150
sh=7E2CD664CDB0CF9E06DB0EABE6143E3EF3591824 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Aniol\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\f59fdb-3bd6fb39"
sh=66446326F6A774D9BBF64561E42A623684F237EF ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Aniol\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\2a7c4fbb-5e4c7937"
sh=B626424CD4CF8F8A6E802F4AA475DE60D5E356CB ft=1 fh=c71c0011bc02fdfc vn="a variant of Win32/Injector.AMXL trojan" ac=I fn="D:\FILME\CCleaner 4 00 4064 (Final) + Crack\CCleaner.4.00.4064.(Final).+.Crack.exe"
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-02-2014
Ran by 1 (administrator) on ANIOL-PC on 13-02-2014 23:18:34
Running from C:\Users\1\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(ESET) C:\Program Files\ESET\ESET Online Scanner\OnlineScannerApp.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [] - [X]
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdSync.exe [215552 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [747264 2013-08-30] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [iTunesHelper] - D:\Itunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4435968 2007-04-23] (Realtek Semiconductor)
HKU\.DEFAULT\...\Run: [InfoCockpit] - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE [268800 2009-04-29] (Deutsche Telekom AG, T-Com)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-19\...\Run: [InfoCockpit] - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE [268800 2009-04-29] (Deutsche Telekom AG, T-Com)
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [InfoCockpit] - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE [268800 2009-04-29] (Deutsche Telekom AG, T-Com)
Startup: C:\Users\Aniol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk
ShortcutTarget: Product Registration.lnk -> C:\Users\1\AppData\Local\Temp\is-IMSSM.tmp\ATR1.exe (No File)
==================== Internet (Whitelisted) ====================
HKLM\Software\Microsoft\Internet Explorer\Main,Update_Check_Page = Download Internet Explorer - Browser
BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: WEB.DE Browser Configuration by mquadr.at - {D48FF4B4-E68F-47D1-8E25-81A0F0EEB341} - C:\Windows\System32\ieconfig_1und1.dll (mquadr.at softwareengineering und consulting gmbh)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} MSN Games - Free Online Games
DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\hpdt8sej.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - D:\Itunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @sony.com/ReaderDesktop - D:\Reader for pc\npreaderdetectmoz.dll (Sony Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.8 - D:\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - D:\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - D:\VLC\npvlc.dll (VideoLAN)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-05-24]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\coFFPlgn\ []
FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\IPSFF [2013-10-09]
========================== Services (Whitelisted) =================
S4 InCDsrv; C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe [1550896 2007-05-15] (Nero AG)
R2 NIS; C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
S4 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [66872 2008-06-05] ()
S4 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [107832 2008-06-05] ()
S4 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
==================== Drivers (Whitelisted) ====================
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdLH3.sys [83984 2012-02-23] (Advanced Micro Devices)
S3 AVMUNET; C:\Windows\System32\DRIVERS\avmunet.sys [15104 2005-03-02] (AVM GmbH)
R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\BASHDefs\20140121.001\BHDrvx86.sys [1098968 2013-12-18] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-11-21] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-11-21] (Symantec Corporation)
S3 FlashUSB; C:\Windows\System32\DRIVERS\FlashUSB.sys [16896 2009-05-12] (Danish Wireless Design A/S)
S3 gdrv; C:\Windows\gdrv.sys [15600 2007-11-04] (Windows (R) 2000 DDK provider)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\IPSDefs\20140212.001\IDSvix86.sys [394456 2014-01-22] (Symantec Corporation)
R4 InCDfs; C:\Windows\System32\drivers\InCDFs.sys [118576 2007-05-15] (Nero AG)
R1 InCDPass; C:\Windows\System32\drivers\InCDPass.sys [37040 2007-05-15] (Nero AG)
U1 InCDrec; C:\Windows\system32\Drivers\InCDrec.sys [16304 2007-05-15] (Nero AG)
S1 incdrm; C:\Windows\System32\drivers\InCDRm.sys [38576 2007-05-15] (Nero AG)
R0 JGOGO; C:\Windows\System32\DRIVERS\JGOGO.sys [6912 2006-02-07] (JMicron )
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [44928 2007-02-16] (JMicron Technology Corp.)
R3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtport.sys [12160 2009-09-29] (LG Electronics Inc.)
R3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbus.sys [10496 2009-09-29] (LG Electronics Inc.)
R3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmodem.sys [12928 2009-09-29] (LG Electronics Inc.)
S3 MTOnlPktAlyX; C:\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys [17536 2006-10-09] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20140213.002\NAVENG.SYS [93272 2013-08-29] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20140213.002\NAVEX15.SYS [1612376 2013-08-29] (Symantec Corporation)
R3 ovt530; C:\Windows\System32\Drivers\ov530vid.sys [161792 2005-03-15] (OmniVision Technologies, Inc.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-11-11] ()
R3 SRTSP; C:\Windows\System32\Drivers\NIS\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NIS\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
S3 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2010-06-17] (Avira GmbH)
R1 StarOpen; C:\Windows\system32\Drivers\StarOpen.sys [5632 2009-10-21] ()
R0 SymDS; C:\Windows\System32\drivers\NIS\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NIS\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-20] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NIS\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-19] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-19] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-19] (LG Electronics Inc.)
U3 ag379csh; C:\Windows\system32\Drivers\ag379csh.sys [0 ] (Microsoft Corporation)
S3 Afc; system32\drivers\Afc.sys [X]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 dtwmnic5; system32\DRIVERS\dtwmnic5.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U5 UnlockerDriver5; D:\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-13 23:18 - 2014-02-13 23:18 - 00014968 _____ () C:\Users\1\Desktop\FRST.txt
2014-02-13 21:56 - 2014-02-13 21:56 - 00000000 ____D () C:\Users\1\AppData\Roaming\WinRAR
2014-02-13 20:34 - 2014-02-13 20:34 - 00000000 ____D () C:\Program Files\ESET
2014-02-13 20:33 - 2014-02-13 20:33 - 02347384 _____ (ESET) C:\Users\1\Downloads\esetsmartinstaller_enu.exe
2014-02-13 20:29 - 2014-02-13 20:29 - 00000000 ____D () C:\Users\1\Downloads\FRST-OlderVersion
2014-02-10 22:19 - 2014-02-10 22:20 - 00035186 _____ () C:\Users\1\Downloads\Addition.txt
2014-02-10 22:18 - 2014-02-13 23:18 - 00000000 ____D () C:\FRST
2014-02-10 22:18 - 2014-02-13 20:29 - 01141248 _____ (Farbar) C:\Users\1\Desktop\FRST.exe
2014-02-10 22:18 - 2014-02-10 22:20 - 00028584 _____ () C:\Users\1\Downloads\FRST.txt
2014-02-06 23:09 - 2014-02-13 21:41 - 00000000 ____D () C:\Users\1\AppData\Roaming\Skype
2014-02-06 21:41 - 2014-02-10 21:22 - 00000000 ____D () C:\AdwCleaner
2014-02-06 21:33 - 2014-02-06 21:33 - 01166132 _____ () C:\Users\1\Downloads\adwcleaner.exe
2014-02-06 21:14 - 2014-02-06 21:15 - 00000000 ____D () C:\Users\1\AppData\Roaming\Firstload
2014-02-06 21:14 - 2014-02-06 21:14 - 00000000 ____D () C:\Users\1\Documents\Firstload
2014-02-03 22:52 - 2014-02-13 23:03 - 00000000 ____D () C:\Users\1\AppData\Roaming\vlc
2014-02-03 22:51 - 2014-02-13 22:56 - 00028160 _____ () C:\Users\1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-03 22:51 - 2014-02-03 22:51 - 00000000 ____D () C:\Users\1\AppData\Roaming\T-Online
2014-02-03 22:29 - 2014-02-03 22:29 - 00000680 _____ () C:\Users\1\AppData\Local\d3d9caps.dat
2014-02-03 22:08 - 2014-02-03 22:08 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-02-03 21:56 - 2014-02-03 21:56 - 00033288 _____ () C:\{1CC20377-3E0C-4A61-9315-7DCAABADF80E}
2014-02-03 21:37 - 2014-02-06 22:46 - 00001952 _____ () C:\Windows\PFRO.log
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Roaming\Macromedia
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Roaming\Adobe
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Local\Macromedia
2014-02-03 21:23 - 2014-02-03 21:23 - 00000000 ____D () C:\Users\1\AppData\Roaming\Mozilla
2014-02-03 21:23 - 2014-02-03 21:23 - 00000000 ____D () C:\Users\1\AppData\Local\Mozilla
2014-02-03 19:44 - 2014-02-03 19:44 - 00000000 ____D () C:\Users\1\AppData\Roaming\ATI
2014-02-03 19:44 - 2014-02-03 19:44 - 00000000 ____D () C:\Users\1\AppData\Local\ATI
2014-01-30 23:26 - 2014-01-30 23:26 - 00002608 _____ () C:\{B6EF3CC7-B2D2-4504-BE4F-71B12B1FE8C4}
2014-01-30 21:41 - 2014-01-30 21:41 - 00002088 _____ () C:\{06124B29-E47E-4E24-97E3-A6A106514E09}
2014-01-30 21:05 - 2014-01-30 21:05 - 107690016 _____ () C:\Windows\MEMORY.DMP
2014-01-30 21:05 - 2014-01-30 21:05 - 00137248 _____ () C:\Windows\Minidump\Mini013014-01.dmp
2014-01-20 19:20 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-01-20 19:20 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-20 19:20 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-20 19:20 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-20 19:19 - 2014-01-20 19:20 - 00005384 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
==================== One Month Modified Files and Folders =======
2014-02-13 23:18 - 2014-02-13 23:18 - 00014968 _____ () C:\Users\1\Desktop\FRST.txt
2014-02-13 23:18 - 2014-02-10 22:18 - 00000000 ____D () C:\FRST
2014-02-13 23:14 - 2007-11-05 19:19 - 00000418 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{06FDA24E-180F-4B01-AAFC-6F667AFEE44A}.job
2014-02-13 23:03 - 2014-02-03 22:52 - 00000000 ____D () C:\Users\1\AppData\Roaming\vlc
2014-02-13 22:57 - 2013-11-04 15:17 - 01058944 _____ () C:\Windows\WindowsUpdate.log
2014-02-13 22:56 - 2014-02-03 22:51 - 00028160 _____ () C:\Users\1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-13 22:37 - 2012-04-12 13:59 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-13 22:08 - 2006-11-02 13:47 - 00004176 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-13 22:08 - 2006-11-02 13:47 - 00004176 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-13 22:00 - 2009-07-26 19:28 - 00000000 ____D () C:\ProgramData\Skype
2014-02-13 21:56 - 2014-02-13 21:56 - 00000000 ____D () C:\Users\1\AppData\Roaming\WinRAR
2014-02-13 21:41 - 2014-02-06 23:09 - 00000000 ____D () C:\Users\1\AppData\Roaming\Skype
2014-02-13 20:34 - 2014-02-13 20:34 - 00000000 ____D () C:\Program Files\ESET
2014-02-13 20:33 - 2014-02-13 20:33 - 02347384 _____ (ESET) C:\Users\1\Downloads\esetsmartinstaller_enu.exe
2014-02-13 20:29 - 2014-02-13 20:29 - 00000000 ____D () C:\Users\1\Downloads\FRST-OlderVersion
2014-02-13 20:29 - 2014-02-10 22:18 - 01141248 _____ (Farbar) C:\Users\1\Desktop\FRST.exe
2014-02-13 20:08 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-11 06:53 - 2006-11-02 14:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-10 22:20 - 2014-02-10 22:19 - 00035186 _____ () C:\Users\1\Downloads\Addition.txt
2014-02-10 22:20 - 2014-02-10 22:18 - 00028584 _____ () C:\Users\1\Downloads\FRST.txt
2014-02-10 21:24 - 2012-05-03 14:52 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-10 21:22 - 2014-02-06 21:41 - 00000000 ____D () C:\AdwCleaner
2014-02-10 21:17 - 2013-05-24 14:02 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-06 23:16 - 2010-08-01 12:08 - 00000000 ____D () C:\Users\Aniol\AppData\Roaming\Skype
2014-02-06 23:09 - 2012-04-29 08:29 - 00002489 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-02-06 22:46 - 2014-02-03 21:37 - 00001952 _____ () C:\Windows\PFRO.log
2014-02-06 21:33 - 2014-02-06 21:33 - 01166132 _____ () C:\Users\1\Downloads\adwcleaner.exe
2014-02-06 21:15 - 2014-02-06 21:14 - 00000000 ____D () C:\Users\1\AppData\Roaming\Firstload
2014-02-06 21:14 - 2014-02-06 21:14 - 00000000 ____D () C:\Users\1\Documents\Firstload
2014-02-03 22:51 - 2014-02-03 22:51 - 00000000 ____D () C:\Users\1\AppData\Roaming\T-Online
2014-02-03 22:51 - 2013-06-11 14:17 - 00000000 ____D () C:\Users\1\AppData\Local\VirtualStore
2014-02-03 22:29 - 2014-02-03 22:29 - 00000680 _____ () C:\Users\1\AppData\Local\d3d9caps.dat
2014-02-03 22:08 - 2014-02-03 22:08 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-02-03 21:56 - 2014-02-03 21:56 - 00033288 _____ () C:\{1CC20377-3E0C-4A61-9315-7DCAABADF80E}
2014-02-03 21:47 - 2013-07-05 17:56 - 00000000 ____D () C:\Users\Aniol\AppData\Local\CrashDumps
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Roaming\Macromedia
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Roaming\Adobe
2014-02-03 21:25 - 2014-02-03 21:25 - 00000000 ____D () C:\Users\1\AppData\Local\Macromedia
2014-02-03 21:23 - 2014-02-03 21:23 - 00000000 ____D () C:\Users\1\AppData\Roaming\Mozilla
2014-02-03 21:23 - 2014-02-03 21:23 - 00000000 ____D () C:\Users\1\AppData\Local\Mozilla
2014-02-03 19:45 - 2013-06-11 14:18 - 00058384 _____ () C:\Users\1\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-03 19:44 - 2014-02-03 19:44 - 00000000 ____D () C:\Users\1\AppData\Roaming\ATI
2014-02-03 19:44 - 2014-02-03 19:44 - 00000000 ____D () C:\Users\1\AppData\Local\ATI
2014-01-30 23:26 - 2014-01-30 23:26 - 00002608 _____ () C:\{B6EF3CC7-B2D2-4504-BE4F-71B12B1FE8C4}
2014-01-30 22:34 - 2012-06-05 18:54 - 00000000 ____D () C:\Users\Aniol\AppData\Roaming\vlc
2014-01-30 22:32 - 2007-11-04 21:35 - 00157184 _____ () C:\Users\Aniol\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-30 21:41 - 2014-01-30 21:41 - 00002088 _____ () C:\{06124B29-E47E-4E24-97E3-A6A106514E09}
2014-01-30 21:05 - 2014-01-30 21:05 - 107690016 _____ () C:\Windows\MEMORY.DMP
2014-01-30 21:05 - 2014-01-30 21:05 - 00137248 _____ () C:\Windows\Minidump\Mini013014-01.dmp
2014-01-30 21:05 - 2009-02-12 15:47 - 00000000 ____D () C:\Windows\Minidump
2014-01-27 20:29 - 2012-06-05 18:22 - 00000000 ____D () C:\Users\Aniol\AppData\Roaming\Firstload
2014-01-27 20:15 - 2007-11-03 21:35 - 00008944 _____ () C:\Users\Aniol\AppData\Local\d3d9caps.dat
2014-01-20 19:20 - 2014-01-20 19:19 - 00005384 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-01-20 19:20 - 2008-08-03 20:10 - 00000000 ____D () C:\Program Files\Java
2014-01-16 23:36 - 2013-08-15 20:54 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-16 23:34 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-01-14 22:20 - 2006-11-02 11:33 - 01597068 _____ () C:\Windows\system32\PerfStringBackup.INI
Some content of TEMP:
====================
C:\Users\1\AppData\Local\Temp\AskSLib.dll
C:\Users\1\AppData\Local\Temp\Quarantine.exe
C:\Users\1\AppData\Local\Temp\SHSetup.exe
C:\Users\Aniol\AppData\Local\Temp\icqsetup.exe
C:\Users\Aniol\AppData\Local\Temp\SHSetup.exe
C:\Users\Aniol\AppData\Local\Temp\uu-s5x8y.dll
C:\Users\Aniol\AppData\Local\Temp\v080qlmg.dll
C:\Users\Aniol\AppData\Local\Temp\z4rd43a6.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-13 20:14
==================== End Of Log ============================
--- --- ---
--- --- ---
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 12-02-2014
Ran by 1 at 2014-02-13 20:32:27 Run:1
Running from C:\Users\1\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.web.de/home
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.web.de/runonce
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://go.web.de/tab2
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NIS&chn=retail&geo=DE&ver=20&locale=de_DE&gct=sb&qsrc=2869
SearchScopes: HKCU - {BBB3829B-6ADC-4B83-8464-BBC45634CE94} URL = hxxp://search.1und1.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {D4607F03-416A-4727-9CCC-CCC0952AE5B8} URL = hxxp://suche.gmx.net/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
S4 serviceIEConfig; C:\Windows\System32\ieconfig_1und1_svc.exe [662416 2009-11-07] (mquadr.at softwareengineering und consulting gmbh)
R3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
2014-02-03 22:30 - 2014-02-03 22:30 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-02-03 22:29 - 2014-02-03 22:29 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\1\Downloads\SpyHunter-Installer.exe
2014-02-03 22:06 - 2014-02-03 22:06 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Aniol\Downloads\SpyHunter-Installer.exe
2014-02-03 22:13 - 2014-02-10 21:36 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP
AlternateDataStreams: C:\ProgramData\TEMP:834DD57E
AlternateDataStreams: C:\ProgramData\TEMP:C980DA7D
C:\Users\Aniol\AppData\Roaming\skype.ini
*****************
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\First Home Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{1AA803F4-CD29-4604-B1A5-1A1D7ECA7015} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBB3829B-6ADC-4B83-8464-BBC45634CE94} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{BBB3829B-6ADC-4B83-8464-BBC45634CE94} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D4607F03-416A-4727-9CCC-CCC0952AE5B8} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{D4607F03-416A-4727-9CCC-CCC0952AE5B8} => Key not found.
serviceIEConfig => Service deleted successfully.
esgiguard => Service deleted successfully.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\Users\1\Downloads\SpyHunter-Installer.exe => Moved successfully.
C:\Users\Aniol\Downloads\SpyHunter-Installer.exe => Moved successfully.
C:\Windows\455F074C814E4520B69B5584BD90400C.TMP => Moved successfully.
C:\ProgramData\TEMP => ":834DD57E" ADS removed successfully.
C:\ProgramData\TEMP => ":C980DA7D" ADS removed successfully.
C:\Users\Aniol\AppData\Roaming\skype.ini => Moved successfully.
==== End of Fixlog ====