hier das mbam.txt Log
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.04.2014
Suchlauf-Zeit: 19:20:39
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.18.07
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7
CPU: x86
Dateisystem: NTFS
Benutzer: User
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 274171
Verstrichene Zeit: 21 Min, 2 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 1
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [58a85ea2e51b9b65ea5ea4c7a2605ca4],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 0
(No malicious items detected)
Physische Sektoren: 0
(No malicious items detected)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.023 - Bericht erstellt am 18/04/2014 um 20:35:37
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium (32 bits)
# Benutzername : User - USER-PC
# Gestartet von : C:\Users\User\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\User\AppData\Local\CrashRpt
Ordner Gelöscht : C:\Users\User\AppData\LocalLow\PutLockerDownloader V6.0
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16533
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\wsjwaufh.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [20457 octets] - [17/02/2014 22:02:41]
AdwCleaner[R1].txt - [19232 octets] - [17/02/2014 22:07:31]
AdwCleaner[R2].txt - [1438 octets] - [04/03/2014 21:50:21]
AdwCleaner[R3].txt - [1275 octets] - [18/04/2014 19:36:53]
AdwCleaner[S0].txt - [1616 octets] - [17/02/2014 22:04:39]
AdwCleaner[S1].txt - [16872 octets] - [17/02/2014 22:08:07]
AdwCleaner[S2].txt - [1499 octets] - [04/03/2014 21:57:25]
AdwCleaner[S3].txt - [1201 octets] - [18/04/2014 20:35:37]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1261 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x86
Ran by User on 18.04.2014 at 20:46:28,07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\wsjwaufh.default\minidumps [8 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.04.2014 at 20:49:46,50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
und FRST Log kommt auch noch gleich
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-04-2014 01
Ran by User (administrator) on USER-PC on 18-04-2014 21:10:35
Running from C:\Users\User\Desktop
Microsoft Windows 7 Home Premium (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(brother Industries Ltd) C:\Windows\system32\brsvc01a.exe
(brother Industries Ltd) C:\Windows\system32\brss01a.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Microsoft) C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nitro PDF Software) C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
() C:\Program Files\CyberLink\Shared files\RichVideo.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(X10) C:\Program Files\Common Files\X10\Common\X10nets.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Wistron) C:\Program Files\Launch Manager\HotkeyApp.exe
(Wistron Corp.) C:\Program Files\Launch Manager\OSD.exe
(Wistron Corp.) C:\Program Files\Launch Manager\WButton.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Wistron Corp.) C:\Program Files\Launch Manager\WisLMSvc.exe
(CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\Brother\BrStMonW.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCtrlCntr.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\BrYNSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCcUxSys.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9177632 2010-04-23] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [1423904 2010-04-23] (Realtek Semiconductor)
HKLM\...\Run: [HotkeyApp] => C:\Program Files\Launch Manager\HotkeyApp.exe [200704 2009-12-14] (Wistron)
HKLM\...\Run: [LMgrVolOSD] => C:\Program Files\Launch Manager\OSD.exe [348960 2009-12-12] (Wistron Corp.)
HKLM\...\Run: [Wbutton] => C:\Program Files\Launch Manager\Wbutton.exe [413696 2010-01-13] (Wistron Corp.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1594664 2009-12-11] (Synaptics Incorporated)
HKLM\...\Run: [CLMLServer] => C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-02] (CyberLink)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM\...\Run: [IndexSearch] => C:\Program Files\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PaperPort PTD] => C:\Program Files\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PDFHook] => C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] => C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [ControlCenter4] => C:\Program Files\ControlCenter4\BrCcBoot.exe [139264 2011-04-20] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] => C:\Program Files\Browny02\Brother\BrStMonW.exe [2629632 2011-05-19] (Brother Industries, Ltd.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-03-04] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-2424951300-607356146-3166250846-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-2424951300-607356146-3166250846-1000\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-2424951300-607356146-3166250846-1000\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-2424951300-607356146-3166250846-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-2424951300-607356146-3166250846-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
HKU\S-1-5-21-2424951300-607356146-3166250846-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2424951300-607356146-3166250846-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Welcome to ALDI
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Welcome to ALDI
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\wsjwaufh.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @nitropdf.com/NitroPDF - C:\Program Files\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
========================== Services (Whitelisted) =================
R2 AntiVirFirewallService; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [1012280 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [896592 2014-03-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-03-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-03-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-03-04] (Avira Operations GmbH & Co. KG)
R2 Brother XP spl Service; C:\Windows\system32\brsvc01a.exe [57344 2002-04-12] (brother Industries Ltd)
R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [96768 2012-06-18] (Freemake)
R2 FreemakeVideoCapture; C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [8704 2012-02-10] (Microsoft)
S2 KMService; C:\Windows\system32\srvany.exe [8192 2003-04-18] ()
R2 NitroReaderDriverReadSpool3; C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [196624 2013-03-26] (Nitro PDF Software)
R2 PDFProFiltSrvPP; C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [244904 2010-02-10] ()
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118560 2009-10-23] (Wistron Corp.)
R2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10)
==================== Drivers (Whitelisted) ====================
R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [92448 2013-06-13] (Avira GmbH)
R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [113024 2013-06-13] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-28] (Avira Operations GmbH & Co. KG)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [107736 2014-04-18] (Malwarebytes Corporation)
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-06-13] (Avira GmbH)
R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13720 2009-05-13] (X10 Wireless Technology, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27160 2009-05-13] (X10 Wireless Technology, Inc.)
S1 HWiNFO32; \??\C:\Users\User\AppData\Local\Temp\HWiNFO32.SYS [X]
S3 uxddrv; \??\F:\uxddrv86.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-18 21:10 - 2014-04-18 21:10 - 00000000 ____D () C:\Users\User\Desktop\FRST-OlderVersion
2014-04-18 20:49 - 2014-04-18 20:49 - 00000754 _____ () C:\Users\User\Desktop\JRT.txt
2014-04-18 20:45 - 2014-04-18 20:45 - 01016261 _____ (Thisisu) C:\Users\User\Downloads\JRT.exe
2014-04-18 20:45 - 2014-04-18 20:45 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe
2014-04-18 19:34 - 2014-04-18 19:34 - 01426178 _____ () C:\Users\User\Desktop\adwcleaner.exe
2014-04-18 19:28 - 2014-04-18 19:28 - 00001266 _____ () C:\Users\User\Desktop\mbam.txt
2014-04-18 19:24 - 2014-04-18 20:37 - 00000112 _____ () C:\Windows\setupact.log
2014-04-18 19:24 - 2014-04-18 19:24 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-18 18:56 - 2014-04-18 18:56 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\User\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-18 07:34 - 2014-04-18 07:34 - 00538210 _____ () C:\Users\User\Documents\Kopie von Dienstplan KW 17.xlsx
2014-04-14 17:55 - 2014-04-14 17:55 - 00000000 ____D () C:\Users\Web\AppData\Local\Apple
2014-04-12 17:27 - 2014-04-12 17:27 - 00000000 ____D () C:\Users\Web\AppData\Roaming\Avira
2014-04-12 17:24 - 2014-04-12 17:24 - 00000000 ____D () C:\Users\Web\AppData\Local\Google
2014-04-12 17:22 - 2014-04-12 17:24 - 00002197 _____ () C:\Users\Web\Desktop\Google Chrome.lnk
2014-04-12 17:22 - 2014-04-12 17:22 - 00001413 _____ () C:\Users\Web\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-12 17:22 - 2014-04-12 17:22 - 00000000 ____D () C:\Users\Web\AppData\Roaming\ControlCenter4
2014-04-12 17:22 - 2014-04-12 17:22 - 00000000 ____D () C:\Users\Web\AppData\Roaming\Apple Computer
2014-04-12 17:22 - 2014-04-12 17:22 - 00000000 ____D () C:\Users\Web\AppData\Local\Power2Go
2014-04-12 17:21 - 2014-04-12 17:22 - 00000000 ____D () C:\Users\Web
2014-04-12 17:21 - 2014-04-12 17:21 - 00000680 __RSH () C:\Users\Web\ntuser.pol
2014-04-12 17:21 - 2014-04-12 17:21 - 00000020 ___SH () C:\Users\Web\ntuser.ini
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\Startmenü
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\Netzwerkumgebung
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\Druckumgebung
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\Documents\Eigene Musik
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\Documents\Eigene Bilder
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\AppData\Local\Verlauf
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 ____D () C:\Users\Web\AppData\Local\VirtualStore
2014-04-12 17:21 - 2013-09-09 17:04 - 00000000 ____D () C:\Users\Web\AppData\Roaming\Macromedia
2014-04-12 17:21 - 2012-02-01 18:18 - 00000000 ____D () C:\Users\Web\AppData\Local\Microsoft Help
2014-04-12 17:21 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Web\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-04-12 17:21 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Web\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-04-09 12:20 - 2014-04-09 12:20 - 00363730 _____ () C:\Users\User\Documents\Kopie von Dienstplan KW 16.xlsx
2014-04-07 17:03 - 2014-04-18 18:54 - 00000000 ____D () C:\Users\User\Desktop\Kochkurs Fotos
2014-04-07 15:38 - 2014-04-07 15:39 - 00041159 _____ () C:\Users\User\Desktop\Addition.txt
2014-04-05 20:19 - 2014-04-18 21:10 - 00016933 _____ () C:\Users\User\Desktop\FRST.txt
2014-04-05 20:18 - 2014-04-18 21:10 - 01146880 _____ (Farbar) C:\Users\User\Desktop\FRST.exe
2014-04-05 20:15 - 2014-04-05 20:15 - 02157056 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2014-03-27 21:41 - 2014-04-18 19:27 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-27 21:41 - 2014-04-18 18:57 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-27 21:40 - 2014-04-18 18:57 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-03-27 21:40 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-27 21:40 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-27 21:40 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-27 21:34 - 2014-03-27 21:34 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-27 21:29 - 2014-03-27 21:29 - 00001041 _____ () C:\Users\Public\Desktop\SpywareBlaster.lnk
2014-03-27 21:29 - 2014-03-27 21:29 - 00000000 ____D () C:\ProgramData\Licenses
2014-03-27 21:29 - 2014-03-27 21:29 - 00000000 ____D () C:\Program Files\SpywareBlaster
2014-03-27 21:29 - 2009-03-24 13:52 - 00129872 _____ (Microsoft Corporation) C:\Windows\system32\MSSTDFMT.DLL
2014-03-27 21:28 - 2014-03-27 21:28 - 04095448 _____ (BrightFort LLC ) C:\Users\User\Downloads\spywareblastersetup50.exe
2014-03-21 08:06 - 2014-03-21 08:06 - 00361906 _____ () C:\Users\User\Documents\Kopie von KW 13 MD.xlsx
2014-03-21 08:06 - 2014-03-21 08:06 - 00358241 _____ () C:\Users\User\Documents\Kopie von KW 14 GN.xlsx
==================== One Month Modified Files and Folders =======
2014-04-18 21:11 - 2014-04-05 20:19 - 00016933 _____ () C:\Users\User\Desktop\FRST.txt
2014-04-18 21:10 - 2014-04-18 21:10 - 00000000 ____D () C:\Users\User\Desktop\FRST-OlderVersion
2014-04-18 21:10 - 2014-04-05 20:18 - 01146880 _____ (Farbar) C:\Users\User\Desktop\FRST.exe
2014-04-18 21:10 - 2014-03-04 11:47 - 00000000 ____D () C:\FRST
2014-04-18 20:49 - 2014-04-18 20:49 - 00000754 _____ () C:\Users\User\Desktop\JRT.txt
2014-04-18 20:45 - 2014-04-18 20:45 - 01016261 _____ (Thisisu) C:\Users\User\Downloads\JRT.exe
2014-04-18 20:45 - 2014-04-18 20:45 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe
2014-04-18 20:44 - 2013-07-06 13:05 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-18 20:43 - 2009-07-14 06:34 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-18 20:43 - 2009-07-14 06:34 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-18 20:39 - 2013-07-06 13:05 - 00001090 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-18 20:38 - 2012-06-23 09:29 - 00000000 _____ () C:\sniffer.log
2014-04-18 20:37 - 2014-04-18 19:24 - 00000112 _____ () C:\Windows\setupact.log
2014-04-18 20:37 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-18 20:35 - 2014-02-17 22:02 - 00000000 ____D () C:\AdwCleaner
2014-04-18 20:35 - 2012-01-26 14:10 - 01146318 _____ () C:\Windows\WindowsUpdate.log
2014-04-18 19:37 - 2012-07-30 10:05 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-18 19:34 - 2014-04-18 19:34 - 01426178 _____ () C:\Users\User\Desktop\adwcleaner.exe
2014-04-18 19:28 - 2014-04-18 19:28 - 00001266 _____ () C:\Users\User\Desktop\mbam.txt
2014-04-18 19:27 - 2014-03-27 21:41 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-18 19:24 - 2014-04-18 19:24 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-18 18:57 - 2014-03-27 21:41 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-18 18:57 - 2014-03-27 21:40 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-18 18:56 - 2014-04-18 18:56 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\User\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-18 18:54 - 2014-04-07 17:03 - 00000000 ____D () C:\Users\User\Desktop\Kochkurs Fotos
2014-04-18 16:47 - 2013-08-23 16:46 - 00000000 ____D () C:\Users\User\AppData\Roaming\FileAdvisor
2014-04-18 16:35 - 2013-08-21 16:25 - 00000000 ____D () C:\Program Files\File Type Advisor
2014-04-18 13:33 - 2012-12-25 15:28 - 00000000 ____D () C:\Users\User\AppData\Local\3AC385DE-33F9-4019-A4B1-E8352B23A66F.aplzod
2014-04-18 07:34 - 2014-04-18 07:34 - 00538210 _____ () C:\Users\User\Documents\Kopie von Dienstplan KW 17.xlsx
2014-04-14 17:55 - 2014-04-14 17:55 - 00000000 ____D () C:\Users\Web\AppData\Local\Apple
2014-04-12 17:27 - 2014-04-12 17:27 - 00000000 ____D () C:\Users\Web\AppData\Roaming\Avira
2014-04-12 17:24 - 2014-04-12 17:24 - 00000000 ____D () C:\Users\Web\AppData\Local\Google
2014-04-12 17:24 - 2014-04-12 17:22 - 00002197 _____ () C:\Users\Web\Desktop\Google Chrome.lnk
2014-04-12 17:22 - 2014-04-12 17:22 - 00001413 _____ () C:\Users\Web\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-12 17:22 - 2014-04-12 17:22 - 00000000 ____D () C:\Users\Web\AppData\Roaming\ControlCenter4
2014-04-12 17:22 - 2014-04-12 17:22 - 00000000 ____D () C:\Users\Web\AppData\Roaming\Apple Computer
2014-04-12 17:22 - 2014-04-12 17:22 - 00000000 ____D () C:\Users\Web\AppData\Local\Power2Go
2014-04-12 17:22 - 2014-04-12 17:21 - 00000000 ____D () C:\Users\Web
2014-04-12 17:21 - 2014-04-12 17:21 - 00000680 __RSH () C:\Users\Web\ntuser.pol
2014-04-12 17:21 - 2014-04-12 17:21 - 00000020 ___SH () C:\Users\Web\ntuser.ini
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\Startmenü
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\Netzwerkumgebung
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\Druckumgebung
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\Documents\Eigene Musik
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\Documents\Eigene Bilder
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 _SHDL () C:\Users\Web\AppData\Local\Verlauf
2014-04-12 17:21 - 2014-04-12 17:21 - 00000000 ____D () C:\Users\Web\AppData\Local\VirtualStore
2014-04-09 23:34 - 2012-02-01 15:22 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 23:33 - 2013-07-17 10:18 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 23:29 - 2010-06-29 01:06 - 88028728 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-09 13:53 - 2012-11-06 19:20 - 00000000 ____D () C:\CLATRU
2014-04-09 12:20 - 2014-04-09 12:20 - 00363730 _____ () C:\Users\User\Documents\Kopie von Dienstplan KW 16.xlsx
2014-04-09 11:38 - 2010-06-29 00:30 - 01507106 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-08 11:54 - 2014-03-07 22:34 - 00000000 ____D () C:\Users\User\Desktop\doTerra
2014-04-08 11:18 - 2014-03-08 18:35 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-04-07 15:39 - 2014-04-07 15:38 - 00041159 _____ () C:\Users\User\Desktop\Addition.txt
2014-04-07 12:55 - 2014-03-08 18:35 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-05 20:15 - 2014-04-05 20:15 - 02157056 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2014-04-03 09:51 - 2014-03-27 21:40 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-03-27 21:40 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-03-27 21:40 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-27 21:40 - 2014-02-17 20:23 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-27 21:38 - 2013-01-26 17:53 - 00000000 ____D () C:\Users\User\Desktop\e-Books
2014-03-27 21:35 - 2014-01-03 14:43 - 00000000 ____D () C:\Users\User\Desktop\Energie-Workshop
2014-03-27 21:34 - 2014-03-27 21:34 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-27 21:29 - 2014-03-27 21:29 - 00001041 _____ () C:\Users\Public\Desktop\SpywareBlaster.lnk
2014-03-27 21:29 - 2014-03-27 21:29 - 00000000 ____D () C:\ProgramData\Licenses
2014-03-27 21:29 - 2014-03-27 21:29 - 00000000 ____D () C:\Program Files\SpywareBlaster
2014-03-27 21:28 - 2014-03-27 21:28 - 04095448 _____ (BrightFort LLC ) C:\Users\User\Downloads\spywareblastersetup50.exe
2014-03-21 08:06 - 2014-03-21 08:06 - 00361906 _____ () C:\Users\User\Documents\Kopie von KW 13 MD.xlsx
2014-03-21 08:06 - 2014-03-21 08:06 - 00358241 _____ () C:\Users\User\Documents\Kopie von KW 14 GN.xlsx
Some content of TEMP:
====================
C:\Users\User\AppData\Local\Temp\avgnt.exe
C:\Users\User\AppData\Local\Temp\Quarantine.exe
C:\Users\Web\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-09 07:21
==================== End Of Log ============================
--- --- ---
--- --- ---
ich hoffe, ich hab nun nichts vergessen und alles richtig gemacht!
Frohe Ostern und erholsame Feiertage!
:dankeschoen: