dakir2004 | 03.04.2014 08:57 | Hallo, hat leider berufsbedingt etwas länger gedauert. Sorry. Hier nun die Ergebnisse: Malwarebytes Anti-Malware Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 30.03.2014
Suchlauf-Zeit: 16:01:42
Logdatei: Test1.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.03.30.02
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Daniel
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 278087
Verstrichene Zeit: 2 Std, 1 Min, 36 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 12
PUP.Optional.Jotzey.A, HKU\S-1-5-21-420823474-2913344114-3078669060-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{63A20A19-B1E6-4355-AB4C-28553AF40CA2}, Löschen bei Neustart, [b64a956b31cf7987178a3ccbea182dd3],
PUP.Optional.Jotzey.A, HKU\S-1-5-21-420823474-2913344114-3078669060-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{63A20A19-B1E6-4355-AB4C-28553AF40CA2}, Löschen bei Neustart, [b64a956b31cf7987178a3ccbea182dd3],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [e719907060a0b14f63d46bd2857dcc34],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [738d04fccb351ee2231585b87191bc44],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, In Quarantäne, [18e827d9857bb74939932418a2603dc3],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\Iminent, In Quarantäne, [a25ed22eaf511de3eba277f0ca380ff1],
PUP.Optional.SupraSavings.A, HKLM\SOFTWARE\suprasavings, In Quarantäne, [1ce4b24e02fe77892daf20374eb46f91],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent, In Quarantäne, [ae52f40ce21ec23e37f20f83fa0941bf],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [31cf89775ea26a96b2db87e0ba4815eb],
PUP.Optional.SupraSavings.A, HKLM\SOFTWARE\WOW6432NODE\SupraSavings, In Quarantäne, [eb1556aae02039c7b725c5923ac855ab],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent, In Quarantäne, [50b01be5b947d82844e5c0d2ed16dd23],
PUP.Optional.Iminent.A, HKU\S-1-5-21-420823474-2913344114-3078669060-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\IminentToolbar, Löschen bei Neustart, [58a8748c6997a45c8df8dd8bab5732ce],
Registrierungswerte: 2
PUP.Optional.Iminent.A, HKU\S-1-5-21-420823474-2913344114-3078669060-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, Löschen bei Neustart, [18e827d9857bb74939932418a2603dc3],
PUP.Optional.Iminent.A, HKU\S-1-5-21-420823474-2913344114-3078669060-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, In Quarantäne, [37c9f10fb54bb050bc103606976b36ca],
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 3
PUP.Optional.Iminent.A, C:\Program Files (x86)\IminentToolbar, In Quarantäne, [ca3657a906faa957375a410e9b67b34d],
PUP.Optional.DVDVideoSoft.A, C:\Users\Daniel\AppData\Roaming\DVDVideoSoft\FreeYouTubeToMP3Converter, In Quarantäne, [27d9ca36fd0354acf6960b4c7e844fb1],
PUP.Optional.DVDVideoSoft.A, C:\Users\Daniel\AppData\Roaming\DVDVideoSoft\FreeYouTubeToMP3Converter\History, In Quarantäne, [27d9ca36fd0354acf6960b4c7e844fb1],
Dateien: 40
PUP.Optional.SearchProtect.A, C:\Users\Daniel\AppData\Local\Temp\nsr95C5.exe, In Quarantäne, [649c6b9587798e72cd3b22ff25dc5fa1],
PUP.Optional.Rapiddown, C:\Users\Daniel\AppData\Local\Temp\n6692\s6692.exe, In Quarantäne, [1be57f814cb48779ba5155044bb69967],
PUP.Optional.Rapiddown, C:\Users\Daniel\AppData\Local\Temp\n6855\s6855.exe, In Quarantäne, [14ecd32d946c24dc7695cc8d9a672bd5],
PUP.Optional.Iminent.A, C:\Users\Daniel\AppData\Local\Temp\n6921\Iminent_1712-b2fcad5e.exe, In Quarantäne, [fc04fa06d7294cb4d1e8c07b3dc4847c],
PUP.Optional.PricePeep.A, C:\Users\Daniel\AppData\Local\Temp\n6921\pricepeep_EN_0303-a419cb8d.exe, In Quarantäne, [67992dd39d634bb52b7a90a510f1758b],
PUP.Optional.Rapiddown, C:\Users\Daniel\AppData\Local\Temp\n6921\s6921.exe, In Quarantäne, [e51b000002fe0af640cbc990639e40c0],
PUP.Optional.Conduit.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\searchplugins\conduit-search.xml, In Quarantäne, [12ee6c944fb126da1144f16a7092956b],
PUP.Optional.Iminent.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\searchplugins\iminent.xml, In Quarantäne, [ee12c8381ce428d8762094c7a260d729],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [df216c94728e748c69e2421ee31fba46],
PUP.Optional.DVDVideoSoft.A, C:\Users\Daniel\AppData\Roaming\DVDVideoSoft\FreeYouTubeToMP3Converter\History\CC.K - Pinball(1).png, In Quarantäne, [27d9ca36fd0354acf6960b4c7e844fb1],
PUP.Optional.DVDVideoSoft.A, C:\Users\Daniel\AppData\Roaming\DVDVideoSoft\FreeYouTubeToMP3Converter\History\CC.K - Pinball(2).png, In Quarantäne, [27d9ca36fd0354acf6960b4c7e844fb1],
PUP.Optional.DVDVideoSoft.A, C:\Users\Daniel\AppData\Roaming\DVDVideoSoft\FreeYouTubeToMP3Converter\History\Dolly D - Viva Dynamo(1).png, In Quarantäne, [27d9ca36fd0354acf6960b4c7e844fb1],
PUP.Optional.DVDVideoSoft.A, C:\Users\Daniel\AppData\Roaming\DVDVideoSoft\FreeYouTubeToMP3Converter\History\Dolly D - Viva Dynamo(2).png, In Quarantäne, [27d9ca36fd0354acf6960b4c7e844fb1],
PUP.Optional.DVDVideoSoft.A, C:\Users\Daniel\AppData\Roaming\DVDVideoSoft\FreeYouTubeToMP3Converter\History\FuÃ?ball ist das Leben... - Dynamo Dresden (Dolly D.)(1).png, In Quarantäne, [27d9ca36fd0354acf6960b4c7e844fb1],
PUP.Optional.DVDVideoSoft.A, C:\Users\Daniel\AppData\Roaming\DVDVideoSoft\FreeYouTubeToMP3Converter\History\FuÃ?ball ist das Leben... - Dynamo Dresden (Dolly D.)(2).png, In Quarantäne, [27d9ca36fd0354acf6960b4c7e844fb1],
PUP.Optional.DVDVideoSoft.A, C:\Users\Daniel\AppData\Roaming\DVDVideoSoft\FreeYouTubeToMP3Converter\History\History.xml, In Quarantäne, [27d9ca36fd0354acf6960b4c7e844fb1],
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.admin", false);), Ersetzt,[857bf50b8d73a45ca8dbce6740c409f7]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.aflt", "babsst");), Ersetzt,[817fec14de22768ac9ba999c9a6ac63a]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");), Ersetzt,[02fe46ba30d031cfd7acc174e4207789]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.autoRvrt", "false");), Ersetzt,[a9572fd1649cf20ebbc82411e42001ff]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.dfltLng", "en");), Ersetzt,[ed137d83837d4eb2740f58dde0242ed2]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.excTlbr", false);), Ersetzt,[bf4142bec53b6d93463d41f415ef6c94]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.ffxUnstlRst", true);), Ersetzt,[28d8ec148a767e82b7ccbc79c63e21df]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.id", "e8a807ac00000000000018f46aa38616");), Ersetzt,[f50bb64a2ad6f70987fca19417ed8b75]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlDay", "15857");), Ersetzt,[30d0c63a3ec244bc156e71c49e66e41c]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlRef", "sst");), Ersetzt,[1ce445bb53ad0df3681b75c0c63e7d83]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.newTab", false);), Ersetzt,[05fb45bbb14fd7290a79122350b437c9]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prdct", "delta");), Ersetzt,[54ac9c64f60aa25ef48f270e36cec838]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prtnrId", "delta");), Ersetzt,[9e62c838659b07f93350122331d3e41c]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.rvrt", "false");), Ersetzt,[a45c4cb4ca3622debcc741f444c00ff1]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.smplGrp", "none");), Ersetzt,[ca364eb267992bd59ee552e306fe2dd3]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrId", "base");), Ersetzt,[9c644eb2857b837d43405cd9659ff709]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrSrchUrl", "");), Ersetzt,[7a869a661de313edf58ebe7705ff2dd3]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsn", "1.8.21.5");), Ersetzt,[3fc112ee12eeb050681b8ca9dc2806fa]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsnTs", "1.8.21.513:40:46");), Ersetzt,[837def11f40c25db5b289f96f90b768a]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsni", "1.8.21.5");), Ersetzt,[c739f60a946c44bc2261df56ca3a7d83]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.babExt", "");), Ersetzt,[ca36f60ace32b44cbec5e352749057a9]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.babTrack", "affID=121562&tt=gc_");), Ersetzt,[36ca35cbd729d82886fd4de811f3669a]
PUP.Optional.Delta.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.srcExt", "ss");), Ersetzt,[629e2cd433cd14ec711247eecb3903fd]
PUP.Optional.Iminent.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\user.js, Gut: (), Schlecht: (user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q=");), Ersetzt,[49b7a75917e922def0819a9b44c006fa]
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner Code:
# AdwCleaner v3.023 - Bericht erstellt am 02/04/2014 um 16:34:48
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Daniel - DANIEL-PC
# Gestartet von : C:\Users\Daniel\Desktop\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\invalidprefs.js
Datei Gefunden : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\user.js
Datei Gefunden : C:\Windows\System32\Tasks\QtraxPlayer
Ordner Gefunden C:\Program Files (x86)\pc speed up
Ordner Gefunden C:\Program Files (x86)\uniblue
Ordner Gefunden C:\Program Files (x86)\Uniblue\SpeedUpMyPC
Ordner Gefunden C:\ProgramData\boost_interprocess
Ordner Gefunden C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\Allin1Convert_8h
Ordner Gefunden C:\Users\Daniel\AppData\Roaming\Systweak
Ordner Gefunden C:\Users\Daniel\AppData\Roaming\uniblue
Ordner Gefunden C:\Users\Daniel\AppData\Roaming\Uniblue\SpeedUpMyPC
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\ViewPassword
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKCU\Software\systweak
Schlüssel Gefunden : HKCU\Software\YahooPartnerToolbar
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Schlüssel Gefunden : [x64] HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\systweak
Schlüssel Gefunden : [x64] HKCU\Software\YahooPartnerToolbar
Schlüssel Gefunden : HKLM\Software\Babylon
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gefunden : HKLM\Software\DataMngr
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader27335_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader27335_RASMANCS
Schlüssel Gefunden : HKLM\Software\systweak
Schlüssel Gefunden : HKLM\Software\Uniblue
Schlüssel Gefunden : HKLM\Software\Uniblue\DriverScanner
Schlüssel Gefunden : HKLM\Software\Uniblue\SpeedUpMyPC
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default\prefs.js ]
Zeile gefunden : user_pref("CT3309350.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gefunden : user_pref("extensions.delta.admin", false);
Zeile gefunden : user_pref("extensions.delta.aflt", "babsst");
Zeile gefunden : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gefunden : user_pref("extensions.delta.autoRvrt", "false");
Zeile gefunden : user_pref("extensions.delta.dfltLng", "en");
Zeile gefunden : user_pref("extensions.delta.excTlbr", false);
Zeile gefunden : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gefunden : user_pref("extensions.delta.id", "e8a807ac00000000000018f46aa38616");
Zeile gefunden : user_pref("extensions.delta.instlDay", "15857");
Zeile gefunden : user_pref("extensions.delta.instlRef", "sst");
Zeile gefunden : user_pref("extensions.delta.newTab", false);
Zeile gefunden : user_pref("extensions.delta.prdct", "delta");
Zeile gefunden : user_pref("extensions.delta.prtnrId", "delta");
Zeile gefunden : user_pref("extensions.delta.rvrt", "false");
Zeile gefunden : user_pref("extensions.delta.smplGrp", "none");
Zeile gefunden : user_pref("extensions.delta.tlbrId", "base");
Zeile gefunden : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gefunden : user_pref("extensions.delta.vrsn", "1.8.21.5");
Zeile gefunden : user_pref("extensions.delta.vrsnTs", "1.8.21.513:40:46");
Zeile gefunden : user_pref("extensions.delta.vrsni", "1.8.21.5");
Zeile gefunden : user_pref("extensions.delta_i.babExt", "");
Zeile gefunden : user_pref("extensions.delta_i.babTrack", "affID=121562&tt=gc_");
Zeile gefunden : user_pref("extensions.delta_i.srcExt", "ss");
Zeile gefunden : user_pref("extensions.iminent.admin", false);
Zeile gefunden : user_pref("extensions.iminent.aflt", "orgnl");
Zeile gefunden : user_pref("extensions.iminent.appId", "{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}");
Zeile gefunden : user_pref("extensions.iminent.autoRvrt", "false");
Zeile gefunden : user_pref("extensions.iminent.cntry", "DE");
Zeile gefunden : user_pref("extensions.iminent.dfltLng", "");
Zeile gefunden : user_pref("extensions.iminent.excTlbr", false);
Zeile gefunden : user_pref("extensions.iminent.ffxUnstlRst", false);
Zeile gefunden : user_pref("extensions.iminent.hdrMd5", "6A43F6FB42CF0AF3946403376F851EDA");
Zeile gefunden : user_pref("extensions.iminent.id", "e8a807ac00000000000018f46aa38616");
Zeile gefunden : user_pref("extensions.iminent.instlDay", "16158");
Zeile gefunden : user_pref("extensions.iminent.instlRef", "");
Zeile gefunden : user_pref("extensions.iminent.lastVrsnTs", "1.8.28.315:20:24");
Zeile gefunden : user_pref("extensions.iminent.newTab", false);
Zeile gefunden : user_pref("extensions.iminent.prdct", "iminent");
Zeile gefunden : user_pref("extensions.iminent.prtnrId", "iminent");
Zeile gefunden : user_pref("extensions.iminent.rvrt", "false");
Zeile gefunden : user_pref("extensions.iminent.sg", "none");
Zeile gefunden : user_pref("extensions.iminent.smplGrp", "none");
Zeile gefunden : user_pref("extensions.iminent.tlbrId", "YBCPCSTIPO");
Zeile gefunden : user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q=");
Zeile gefunden : user_pref("extensions.iminent.vrsn", "1.8.28.3");
Zeile gefunden : user_pref("extensions.iminent.vrsnTs", "1.8.28.315:20:24");
Zeile gefunden : user_pref("extensions.iminent.vrsni", "1.8.28.3");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.BUTTON_STRUCTURE", "[{\"b\":221360012,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":221360013,\"c\":\"mindspark.entersearchterms\",\"p\":\"L.0.0[...]
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.firstKnownVersion", "6.33.3.42841");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=085CF34E-2B28-4948-AA07-DA4DED21145E&n=780bb3a8&p2=^AYY^xdm070^YYA^de&si=flvrunner");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.initialized", true);
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.installKeysSource", "LocalStorage");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.installType", "XPI");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.installation.contextKey", "");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.installation.installDate", "2014032808");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.installation.partnerId", "^AYY^xdm070^YYA^de");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.installation.partnerSubId", "flvrunner");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.installation.pixelUrl", "hxxp://allin1convert.dl.tb.ask.com/install_pixels.jhtml?partner=^AYY^xdm070^YYA^de&coId=3b459a63ff6641d1a0d22775a2f4d124&ca[...]
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.installation.success", true);
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.installation.toolbarId", "085CF34E-2B28-4948-AA07-DA4DED21145E");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.isCompliantUninstallImplementation", true);
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.lastActivePing", "1396035327198");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.lastKnownVersion", "6.33.3.42841");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.options.defaultSearch", false);
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.options.homePageEnabled", false);
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.options.keywordEnabled", false);
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.options.tabEnabled", false);
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.partnerPixelFired", true);
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.successUrl", "hxxp://flvrunner.com/thankyou.php");
Zeile gefunden : user_pref("extensions.toolbar.mindspark._8hMembers_.toolbarCollapsed", false);
Zeile gefunden : user_pref("extensions.toolbar.mindspark.lastInstalled", "allin1convert@mindspark.com");
Zeile gefunden : user_pref("iminent.adapters", "{\"iminent\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"Status\":1,\"AdapterKey\":\"iminent\",\"v\":true,\"p\":0,\"t\":1,\"th\":0.275,\"expireTime\":\"139610283435286400\[...]
Zeile gefunden : user_pref("iminent.externalScripts", "{\"value\":[{\"addonUid\":\"10bb6277-6b2b-413e-8d82-ad9398543254\",\"name\":\"Dealply\",\"addonId\":1,\"url\":\"//i.iminentjs.info/imitin/javascript.js\",\"queryS[...]
Zeile gefunden : user_pref("iminent.registerToolbarEvent102", "1396106648921");
Zeile gefunden : user_pref("iminent.trackingInfo", "{\"state\":0,\"samplingRate\":0}");
*************************
AdwCleaner[R0].txt - [11309 octets] - [30/03/2014 14:11:44]
AdwCleaner[R1].txt - [10252 octets] - [30/03/2014 19:49:44]
AdwCleaner[R2].txt - [10287 octets] - [30/03/2014 20:08:18]
AdwCleaner[R3].txt - [10259 octets] - [02/04/2014 16:34:48]
########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [10320 octets] ########## Junkware Removal Tool Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x64
Ran by Daniel on 02.04.2014 at 18:10:55,03
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-420823474-2913344114-3078669060-1001\Software\sweetim
~~~ Files
Successfully deleted: [File] "C:\Users\Daniel\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"
Successfully deleted: [File] C:\Windows\syswow64\sho137B.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho9A8F.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoA130.tmp
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Daniel\AppData\Roaming\mozilla\firefox\profiles\4v5g8c1n.default\minidumps [451 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02.04.2014 at 18:17:05,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Hab ich doch glatt das frische FRST vergessen. FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Daniel (administrator) on DANIEL-PC on 03-04-2014 09:54:47
Running from C:\Users\Daniel\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Seiko Epson Corporation) C:\Windows\system32\EscSvc64.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
() C:\Program Files (x86)\Join Air\AssistantServices.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
() C:\Program Files\003\xmkysecqun64.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATILFE.EXE
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Apple Inc.) C:\Users\Daniel\Documents\Software\iTunes - Apple\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Microsoft Corporation) C:\Windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-29] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Users\Daniel\Documents\Software\iTunes - Apple\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-420823474-2913344114-3078669060-1001\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.)
HKU\S-1-5-21-420823474-2913344114-3078669060-1001\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILFE.EXE [297024 2013-01-24] (SEIKO EPSON CORPORATION)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [111720 2010-10-28] (NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\4v5g8c1n.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Users\Daniel\Documents\Software\iTunes - Apple\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Daniel\Documents\Music\Amazon Music\npAmazonMP3DownloaderPlugin1017319.dll (Amazon.com, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
R2 MyEPSON Connect Service; C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe [703616 2012-10-01] (SEIKO EPSON CORPORATION)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1223704 2013-02-07] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660504 2013-02-07] (Secunia)
R2 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [247152 2010-04-27] ()
R2 xmkysecqun64; C:\Program Files\003\xmkysecqun64.exe [706560 2014-03-29] ()
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-02-07] (Secunia)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] ()
R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61112 2014-03-29] (StdLib)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-03 09:54 - 2014-04-03 09:54 - 02157056 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2014-04-03 09:54 - 2014-04-03 09:54 - 00012435 _____ () C:\Users\Daniel\Desktop\FRST.txt
2014-04-03 09:50 - 2014-04-03 09:50 - 00000056 _____ () C:\Windows\setupact.log
2014-04-03 09:50 - 2014-04-03 09:50 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-02 18:10 - 2014-04-02 18:10 - 00000000 ____D () C:\Windows\ERUNT
2014-03-30 14:11 - 2014-04-02 18:04 - 00000000 ____D () C:\AdwCleaner
2014-03-30 13:57 - 2014-03-30 19:41 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-30 13:57 - 2014-03-30 13:57 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-30 13:57 - 2014-03-30 13:57 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-30 13:57 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-30 13:57 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-30 13:57 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-30 13:56 - 2014-04-02 20:43 - 00095158 _____ () C:\Windows\WindowsUpdate.log
2014-03-30 13:41 - 2014-03-30 13:41 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-03-29 20:10 - 2014-04-03 09:54 - 00000000 ____D () C:\FRST
2014-03-29 16:22 - 2014-03-12 17:00 - 00338120 _____ (SecureAssist) C:\Windows\system32\SecureAssist64.dll
2014-03-29 16:22 - 2014-03-12 17:00 - 00295080 _____ (SecureAssist) C:\Windows\SysWOW64\SecureAssist.dll
2014-03-29 16:20 - 2014-03-29 18:23 - 00000000 ____D () C:\Program Files (x86)\BestPractice
2014-03-29 16:20 - 2014-03-29 16:20 - 00000000 ____D () C:\Program Files\003
2014-03-29 15:25 - 2014-03-29 15:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 11:51 - 2014-03-29 11:51 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\wStLibG64.sys
2014-03-28 22:56 - 2014-03-28 23:40 - 00000000 ____D () C:\Program Files (x86)\Listen N Write Free
2014-03-21 12:46 - 2014-03-21 12:46 - 00152848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2014-03-16 21:27 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-16 21:27 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-16 21:27 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-16 21:27 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-16 21:27 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-16 21:27 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-16 21:27 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-16 21:27 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-16 21:27 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-16 21:27 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-16 21:27 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-16 21:27 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-16 21:27 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-16 21:27 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-16 21:27 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-16 21:27 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-16 21:27 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-16 21:27 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-16 21:27 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-16 21:27 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-16 21:27 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-16 21:27 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-16 21:27 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-16 21:27 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-16 21:27 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-16 21:27 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-16 21:26 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-16 21:26 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-16 21:26 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-16 21:26 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-16 21:26 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-16 21:26 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-16 21:26 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-16 21:26 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-16 21:26 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-16 21:26 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-16 21:26 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-16 21:26 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-16 21:26 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-16 21:26 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-16 21:26 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-16 21:26 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-16 21:26 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-16 21:26 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-16 21:26 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-16 21:26 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-16 21:26 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-16 21:26 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-05 10:33 - 2014-03-05 10:33 - 00002148 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-03-05 10:32 - 2014-03-05 10:33 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-03-05 10:32 - 2014-03-05 10:33 - 00000000 ____D () C:\Program Files\iTunes
2014-03-05 10:32 - 2014-03-05 10:32 - 00000000 ____D () C:\Program Files\iPod
==================== One Month Modified Files and Folders =======
2014-04-03 09:54 - 2014-04-03 09:54 - 02157056 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2014-04-03 09:54 - 2014-04-03 09:54 - 00012435 _____ () C:\Users\Daniel\Desktop\FRST.txt
2014-04-03 09:54 - 2014-03-30 13:56 - 00095158 _____ () C:\Windows\WindowsUpdate.log
2014-04-03 09:54 - 2014-03-29 20:10 - 00000000 ____D () C:\FRST
2014-04-03 09:50 - 2014-04-03 09:50 - 00000056 _____ () C:\Windows\setupact.log
2014-04-03 09:50 - 2014-04-03 09:50 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-03 09:50 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-02 20:09 - 2014-01-04 15:09 - 00000911 _____ () C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {F92AE547-3EBC-4541-8880-B84F8B95060D}.job
2014-04-02 20:09 - 2014-01-04 15:09 - 00000725 _____ () C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {F92AE547-3EBC-4541-8880-B84F8B95060D}.job
2014-04-02 20:05 - 2012-07-31 13:50 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-02 18:21 - 2011-03-12 22:25 - 00000000 ____D () C:\Users\Daniel\Documents\Software
2014-04-02 18:12 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-02 18:12 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-02 18:11 - 2010-11-25 06:04 - 00703644 _____ () C:\Windows\system32\perfh007.dat
2014-04-02 18:11 - 2010-11-25 06:04 - 00150994 _____ () C:\Windows\system32\perfc007.dat
2014-04-02 18:11 - 2009-07-14 07:13 - 01630836 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-02 18:10 - 2014-04-02 18:10 - 00000000 ____D () C:\Windows\ERUNT
2014-04-02 18:04 - 2014-03-30 14:11 - 00000000 ____D () C:\AdwCleaner
2014-04-02 17:10 - 2011-03-12 21:57 - 00000000 ____D () C:\Users\Daniel\Documents\Excel
2014-04-02 08:30 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-30 19:41 - 2014-03-30 13:57 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-30 16:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system
2014-03-30 16:02 - 2012-10-04 17:55 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\DVDVideoSoft
2014-03-30 13:57 - 2014-03-30 13:57 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-30 13:57 - 2014-03-30 13:57 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-30 13:57 - 2012-07-31 12:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-30 13:41 - 2014-03-30 13:41 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-03-29 18:41 - 2013-03-28 17:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-29 18:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-03-29 18:35 - 2011-03-12 21:30 - 00000000 ___RD () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-29 18:23 - 2014-03-29 16:20 - 00000000 ____D () C:\Program Files (x86)\BestPractice
2014-03-29 16:20 - 2014-03-29 16:20 - 00000000 ____D () C:\Program Files\003
2014-03-29 15:25 - 2014-03-29 15:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 11:51 - 2014-03-29 11:51 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\wStLibG64.sys
2014-03-28 23:40 - 2014-03-28 22:56 - 00000000 ____D () C:\Program Files (x86)\Listen N Write Free
2014-03-21 12:46 - 2014-03-21 12:46 - 00152848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2014-03-17 16:52 - 2013-08-15 23:45 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-17 16:49 - 2012-04-06 11:05 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-17 10:45 - 2009-07-14 06:45 - 00416312 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-17 10:43 - 2013-03-13 16:20 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-17 10:43 - 2013-03-13 16:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-16 22:45 - 2012-03-16 14:19 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-16 22:05 - 2012-07-31 13:50 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-16 22:05 - 2012-07-31 13:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-16 22:05 - 2012-07-31 13:50 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-12 17:00 - 2014-03-29 16:22 - 00338120 _____ (SecureAssist) C:\Windows\system32\SecureAssist64.dll
2014-03-12 17:00 - 2014-03-29 16:22 - 00295080 _____ (SecureAssist) C:\Windows\SysWOW64\SecureAssist.dll
2014-03-05 11:52 - 2011-03-12 22:23 - 01605116 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-05 10:33 - 2014-03-05 10:33 - 00002148 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-03-05 10:33 - 2014-03-05 10:32 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-03-05 10:33 - 2014-03-05 10:32 - 00000000 ____D () C:\Program Files\iTunes
2014-03-05 10:32 - 2014-03-05 10:32 - 00000000 ____D () C:\Program Files\iPod
2014-03-05 09:26 - 2014-03-30 13:57 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-03-30 13:57 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-03-30 13:57 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
Some content of TEMP:
====================
C:\Users\Daniel\AppData\Local\Temp\avgnt.exe
C:\Users\Daniel\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 14:56
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- |