Roeroe19 | 03.04.2014 21:52 | Schönen guten Abend,
also nach der Reihe:
1. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.04.2014
Suchlauf-Zeit: 22:21:12
Logdatei: MAB.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.04.03.08
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Maximilian
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 376739
Verstrichene Zeit: 29 Min, 5 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 3
PUP.Optional.VShareRedir, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}, In Quarantäne, [d82801ffd22e8779d7b5d14d1fe3f808],
PUP.Optional.VShareRedir, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}, In Quarantäne, [1ae67a861ae648b8c2c9978780823fc1],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-1473888687-1214762889-3515708772-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [936da06046baf20ea69cca9d3bc7db25],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 2
PUP.Optional.OpenCandy, C:\Users\Maximilian\AppData\Roaming\OpenCandy, In Quarantäne, [bd431ee2ee12e7197520e1727b872dd3],
PUP.Optional.OpenCandy, C:\Users\Maximilian\AppData\Roaming\OpenCandy\51750E1109A043D388B600286AF56EB9, In Quarantäne, [bd431ee2ee12e7197520e1727b872dd3],
Dateien: 1
PUP.Optional.OpenCandy, C:\Users\Maximilian\AppData\Roaming\OpenCandy\51750E1109A043D388B600286AF56EB9\DivXInstaller.exe, In Quarantäne, [bd431ee2ee12e7197520e1727b872dd3],
Physische Sektoren: 0
(No malicious items detected)
(end) 2. Code:
# AdwCleaner v3.023 - Bericht erstellt am 03/04/2014 um 22:30:23
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 8.1 Pro (64 bits)
# Benutzername : Maximilian - MAXIMILIAN-PC
# Gestartet von : C:\Users\Maximilian\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\boost_interprocess
Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar
Ordner Gelöscht : C:\Users\Maximilian\AppData\Local\TempDir
Ordner Gelöscht : C:\Users\Maximilian\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Maximilian\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Maximilian\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\ii97laq6.default\Smartbar
Ordner Gelöscht : C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\ii97laq6.default\CT2736476
Ordner Gelöscht : C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\ii97laq6.default\Extensions\{7e111a5c-3d11-4f56-9463-5310c3c69025}
Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\S
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2736476
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\StartSearch
Schlüssel Gelöscht : HKCU\Software\vShare.tv
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\Software\Uniblue
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16518
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v14.0.1 (de)
[ Datei : C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\ii97laq6.default\prefs.js ]
Zeile gelöscht : user_pref("CT2736476.1000082.currentList", "[{\"stationId\":\"21930450\",\"url\":\"hxxp://www.feedlive.net/california.asx\",\"description\":\"California Rock - Rock\",\"text\":\"Californi...\",\"type\[...]
Zeile gelöscht : user_pref("CT2736476.1000082.isPlayDisplay", "true");
Zeile gelöscht : user_pref("CT2736476.1000082.localStations", "[{\"stationId\":\"8546\",\"url\":\"hxxp://stream.radio8.de:8000/live.m3u\",\"description\":\"Radio 8\",\"text\":\"Radio 8\",\"type\":\"STREAM\"},{\"statio[...]
Zeile gelöscht : user_pref("CT2736476.1000082.nowPlaying", "{\"stationId\":\"21930450\",\"url\":\"hxxp://www.feedlive.net/california.asx\",\"description\":\"California Rock - Rock\",\"text\":\"Californi...\",\"type\":[...]
Zeile gelöscht : user_pref("CT2736476.1000082.publisherStations", "[{\"stationId\":\"21930450\",\"url\":\"hxxp://www.feedlive.net/california.asx\",\"description\":\"California Rock - Rock\",\"text\":\"Californi...\",\[...]
Zeile gelöscht : user_pref("CT2736476.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description\":\"California Rock - Rock\",\"url\":\"hxxp://www.feedlive.net/california.asx\"}");
Zeile gelöscht : user_pref("CT2736476.2736476a129652188678262596000000paramsGK1", "{\"updateReqTime\":1334227286852,\"updateRespTime\":1334227290710,\"data\":{\"settings\":{\"icon\":\"hxxp://storage.conduit.com/bankim[...]
Zeile gelöscht : user_pref("CT2736476.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2736476.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2736476.FirstTime", "true");
Zeile gelöscht : user_pref("CT2736476.FirstTimeFF3", "true");
Zeile gelöscht : user_pref("CT2736476.UserID", "UN46018148743056646");
Zeile gelöscht : user_pref("CT2736476.autoDisableScopes", -1);
Zeile gelöscht : user_pref("CT2736476.browser.search.defaultthis.engineName", true);
Zeile gelöscht : user_pref("CT2736476.defaultSearch", "true");
Zeile gelöscht : user_pref("CT2736476.embeddedsData", "[{\"appId\":\"129257551953665476\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
Zeile gelöscht : user_pref("CT2736476.enableAlerts", "false");
Zeile gelöscht : user_pref("CT2736476.enableFix404", "true");
Zeile gelöscht : user_pref("CT2736476.enableSearchFromAddressBar", "true");
Zeile gelöscht : user_pref("CT2736476.firstTimeDialogOpened", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2736476.installId", "ConduitNSISIntegration");
Zeile gelöscht : user_pref("CT2736476.installType", "ConduitXPEIntegration");
Zeile gelöscht : user_pref("CT2736476.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2736476.isPerformedSmartBarTransition", "true");
Zeile gelöscht : user_pref("CT2736476.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gelöscht : user_pref("CT2736476.keyword", true);
Zeile gelöscht : user_pref("CT2736476.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Ftransfermarkt.de%2F\",\"EB_MAIN_FRAME_TITLE\":\"Das%20Fu%C3%9Fball%20Portal%20%C3%BCber%20di[...]
Zeile gelöscht : user_pref("CT2736476.openThankYouPage", "false");
Zeile gelöscht : user_pref("CT2736476.openUninstallPage", "true");
Zeile gelöscht : user_pref("CT2736476.search.searchAppId", "129257551953665476");
Zeile gelöscht : user_pref("CT2736476.search.searchCount", "0");
Zeile gelöscht : user_pref("CT2736476.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2736476\"}");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://FreewaredeToolbar.OurToolbar.com//xpi\"}");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Freeware.de\"}");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1334227281910");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_appTracking_lastUpdate", "1334227286823");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_appsMetadata_lastUpdate", "1334227273937");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1334227276592");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_login_10.7.7.9_lastUpdate", "1334227283443");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1334227277343");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_searchAPI_lastUpdate", "1334227269957");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_serviceMap_lastUpdate", "1334227268025");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_toolbarContextMenu_lastUpdate", "1334227277252");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_toolbarSettings_lastUpdate", "1334227269563");
Zeile gelöscht : user_pref("CT2736476.serviceLayer_services_translation_lastUpdate", "1334227275906");
Zeile gelöscht : user_pref("CT2736476.settingsINI", true);
Zeile gelöscht : user_pref("CT2736476.shouldFirstTimeDialog", "false");
Zeile gelöscht : user_pref("CT2736476.smartbar.CTID", "CT2736476");
Zeile gelöscht : user_pref("CT2736476.smartbar.Uninstall", "0");
Zeile gelöscht : user_pref("CT2736476.smartbar.homepage", true);
Zeile gelöscht : user_pref("CT2736476.smartbar.isHidden", false);
Zeile gelöscht : user_pref("CT2736476.smartbar.toolbarName", "Freeware.de ");
Zeile gelöscht : user_pref("CT2736476.toolbarBornServerTime", "12-4-2012");
Zeile gelöscht : user_pref("CT2736476.toolbarCurrentServerTime", "12-4-2012");
Zeile gelöscht : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?SSPV=FFSB6&ctid=CT2736476&SearchSource=13");
Zeile gelöscht : user_pref("Smartbar.ConduitSearchEngineList", "Freeware.de Customized Web Search");
Zeile gelöscht : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?SSPV=FFSB6&ctid=CT2736476&SearchSource=2&q=");
Zeile gelöscht : user_pref("browser.search.defaultengine", "Web Search");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
Zeile gelöscht : user_pref("browser.search.order.1", "Web Search");
Zeile gelöscht : user_pref("tfp.CT2736476", true);
Zeile gelöscht : user_pref("vshare.install.date", "1315755460");
Zeile gelöscht : user_pref("vshare.install.finished", "1.0.0");
Zeile gelöscht : user_pref("vshare.install.fresh", "false");
Zeile gelöscht : user_pref("vshare.install.guid", "{1b5cd0ff-58a6-4966-8586-ad8845ac8d08}");
Zeile gelöscht : user_pref("vshare.install.newtab", false);
-\\ Google Chrome v33.0.1750.154
[ Datei : C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [11336 octets] - [03/04/2014 22:29:09]
AdwCleaner[S0].txt - [10944 octets] - [03/04/2014 22:30:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11005 octets] ########## 3. Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 8.1 Pro x64
Ran by Maximilian on 03.04.2014 at 22:35:30,09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{63FA094E-A311-47C6-8100-26411FBEEDE4}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{64FAAB83-CB2F-4D04-B631-ACB3CA6F535B}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{63FA094E-A311-47C6-8100-26411FBEEDE4}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{63FA094E-A311-47C6-8100-26411FBEEDE4}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{63FA094E-A311-47C6-8100-26411FBEEDE4}
~~~ Files
Failed to delete: [File] C:\WINDOWS\syswow64\sho15D5.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\sho2ABB.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\sho3E4F.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\sho3FBF.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\sho57C6.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\sho6A6.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\sho8E8D.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\sho9388.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoA6C.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoA7C7.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoB379.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoB828.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoBB8F.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoC090.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoD9EA.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoE4A4.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoE5B5.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoE683.tmp
Failed to delete: [File] C:\WINDOWS\syswow64\shoFE61.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Empty Folder] C:\Users\Maximilian\appdata\local\{28F58D5B-A4A2-46F8-8662-5684A04E8ECA}
Successfully deleted: [Empty Folder] C:\Users\Maximilian\appdata\local\{38855497-2001-411C-999A-6EBC153AABD9}
Successfully deleted: [Empty Folder] C:\Users\Maximilian\appdata\local\{44E91DEF-1F4A-4098-9444-4F4F89BBEE94}
Successfully deleted: [Empty Folder] C:\Users\Maximilian\appdata\local\{4C55F8B0-5A31-4E0E-B2CA-15A3EB0CD884}
Successfully deleted: [Empty Folder] C:\Users\Maximilian\appdata\local\{74B8A4FA-924D-4302-9997-1D481E817567}
Successfully deleted: [Empty Folder] C:\Users\Maximilian\appdata\local\{D356BDB7-D31A-4319-93D8-D33539DB9D67}
Successfully deleted: [Empty Folder] C:\Users\Maximilian\appdata\local\{E5EF8BC9-85B8-4523-A93A-497180414D01}
~~~ FireFox
Successfully deleted: [File] C:\Users\Maximilian\AppData\Roaming\mozilla\firefox\profiles\ii97laq6.default\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi
Emptied folder: C:\Users\Maximilian\AppData\Roaming\mozilla\firefox\profiles\ii97laq6.default\minidumps [156 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.04.2014 at 22:45:55,84
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und 4.
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Maximilian (administrator) on MAXIMILIAN-PC on 03-04-2014 22:49:27
Running from C:\Users\Maximilian\Downloads
Windows 8.1 Pro (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\wmi64.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11725928 2010-12-23] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2186856 2010-12-10] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2280232 2010-07-29] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860040 2011-01-06] (Acer Incorporated)
HKLM\...\Run: [IntelTBRunOnce] - wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296984 2012-01-05] (NTI Corporation)
HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2012-11-13] ()
HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263512 2012-11-30] ()
HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-09-18] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-09-18] (Egis Technology Inc.)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-14] (Intel Corporation)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1078352 2011-02-24] (Dritek System Inc.)
HKLM-x32\...\Run: [MDS_Menu] - C:\Program Files (x86)\Acer\clear.fi\MediaEspresso\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340336 2010-09-28] (Egis Technology Inc.)
HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe [24504 2012-10-25] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-06] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1473888687-1214762889-3515708772-1001\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
HKU\S-1-5-21-1473888687-1214762889-3515708772-1001\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-1473888687-1214762889-3515708772-1001\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.)
HKU\S-1-5-21-1473888687-1214762889-3515708772-1006\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516608 2013-08-22] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation)
AppInit_DLLs: , C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM-x32 - {63FA094E-A311-47C6-8100-26411FBEEDE4} URL = hxxp://startsear.ch/?aff=1&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {6ABB146C-28B3-4FF9-B3E0-A111A07E3551} URL = hxxp://www.google.de/search?q={searchTerms}
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
DPF: HKLM-x32 {99FE5072-78AA-4FEE-89BA-69A5FA55343F} hxxp://download.microsoft.com/download/B/3/A/B3A2EA73-793D-4ABE-992D-C81140384044/igdtoolx.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\ii97laq6.default
FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml
FF Homepage: hxxp://www.volkswagen-karriere.de/de/jobs/initiativbewerbungsmoeglichkeiten/ferienjobs.html
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: DownloadHelper - C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\ii97laq6.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-04-03]
FF Extension: WEB.DE MailCheck - C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\ii97laq6.default\Extensions\toolbar@web.de.xpi [2011-12-21]
FF Extension: Anti-Banner - C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2 [2011-07-03]
FF Extension: Modul zur Link-Untersuchung - C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2 [2011-07-03]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-10-15]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-02-11]
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-02-12]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-02-12]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-02-12]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-02-12]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-02-12]
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-03]
CHR Extension: (Google Drive) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-03]
CHR Extension: (YouTube) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-03]
CHR Extension: (Google-Suche) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-03]
CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-04-03]
CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-04-03]
CHR Extension: (Modul für das Blockieren gefährlicher Webseiten) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-04-03]
CHR Extension: (Virtuelle Tastatur) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-04-03]
CHR Extension: (Google Wallet) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-03]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2014-04-03]
CHR Extension: (Google Mail) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-03]
CHR Extension: (Anti-Banner) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-04-03]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-10-25]
==================== Services (Whitelisted) =================
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2169016 2014-03-01] (Microsoft Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [25600 2014-01-08] (Microsoft Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256536 2012-01-05] (NTI Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-01-08] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2014-01-08] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R3 athr; C:\Windows\system32\DRIVERS\athwnx.sys [3680256 2013-06-18] (Qualcomm Atheros Communications, Inc.)
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [303616 2013-12-06] ()
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-01-08] (Microsoft Corporation)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-11-14] (Microsoft Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-12] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625760 2013-10-10] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-12-12] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-05-06] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-05-06] (Kaspersky Lab ZAO)
S3 libusb0; C:\Windows\system32\DRIVERS\libusb0.sys [44480 2011-05-17] (hxxp://libusb-win32.sourceforge.net)
S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [35328 2013-12-06] ()
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [173568 2014-01-08] (Microsoft Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-01-08] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation)
U3 idsvc;
S3 vpnva; \SystemRoot\system32\DRIVERS\vpnva64-6.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-03 22:45 - 2014-04-03 22:45 - 00003614 _____ () C:\Users\Maximilian\Desktop\JRT.txt
2014-04-03 22:35 - 2014-04-03 22:35 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-04-03 22:29 - 2014-04-03 22:30 - 00000000 ____D () C:\AdwCleaner
2014-04-03 22:22 - 2014-04-03 22:31 - 00001524 _____ () C:\WINDOWS\PFRO.log
2014-04-03 21:48 - 2014-04-03 21:48 - 01426178 _____ () C:\Users\Maximilian\Downloads\adwcleaner.exe
2014-04-03 21:40 - 2014-04-03 22:25 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-03 21:40 - 2014-04-03 21:40 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-03 21:40 - 2014-04-03 21:40 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-03 21:40 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-03 21:40 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-04-03 21:40 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-04-03 21:38 - 2014-04-03 21:39 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Maximilian\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-03 21:34 - 2014-04-03 21:37 - 00003970 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2B3F4DBD-A5DA-40CF-8380-FA40CD844C51}
2014-04-03 21:31 - 2014-04-03 21:31 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Maximilian\Downloads\revosetup95.exe
2014-04-03 21:31 - 2014-04-03 21:31 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-01 23:51 - 2014-04-01 23:51 - 00541592 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-04-01 23:46 - 2014-02-22 14:16 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2014-04-01 23:46 - 2014-02-22 13:24 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2014-04-01 21:54 - 2014-04-03 22:16 - 00240949 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-01 16:53 - 2014-04-01 16:54 - 00042174 _____ () C:\Users\Maximilian\Downloads\Addition.txt
2014-04-01 16:52 - 2014-04-03 22:49 - 00027163 _____ () C:\Users\Maximilian\Downloads\FRST.txt
2014-04-01 16:52 - 2014-04-03 22:49 - 00000000 ____D () C:\FRST
2014-04-01 16:51 - 2014-04-01 16:51 - 02157056 _____ (Farbar) C:\Users\Maximilian\Downloads\FRST64.exe
2014-03-24 23:04 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-03-24 23:04 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-03-24 23:04 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-03-24 23:04 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-03-24 23:04 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-03-24 23:04 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-03-24 23:04 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-03-24 23:04 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-03-24 23:04 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-03-24 23:04 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-03-24 23:04 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-03-24 23:04 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-03-24 23:04 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-03-24 23:04 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-03-24 23:04 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-03-24 23:04 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-03-24 23:04 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-03-24 23:04 - 2014-01-31 18:15 - 00311640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2014-03-24 23:04 - 2014-01-31 18:07 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2014-03-24 23:04 - 2014-01-31 18:06 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-03-24 23:04 - 2014-01-31 15:47 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2014-03-24 23:04 - 2014-01-31 11:06 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2014-03-24 23:04 - 2014-01-29 11:55 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2014-03-24 23:04 - 2014-01-29 10:53 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2014-03-24 23:04 - 2014-01-29 10:53 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2014-03-24 23:04 - 2014-01-29 10:49 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2014-03-24 23:04 - 2014-01-29 10:47 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-03-24 23:04 - 2014-01-29 09:44 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2014-03-24 23:04 - 2014-01-29 09:44 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2014-03-24 23:04 - 2014-01-29 09:44 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2014-03-24 23:04 - 2014-01-29 08:41 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2014-03-24 23:04 - 2014-01-29 02:36 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2014-03-24 23:04 - 2014-01-27 21:07 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2014-03-24 23:04 - 2014-01-27 21:06 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2014-03-24 23:04 - 2014-01-27 21:04 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2014-03-24 23:04 - 2014-01-27 20:52 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2014-03-24 23:04 - 2014-01-27 20:23 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2014-03-24 23:04 - 2014-01-27 20:21 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2014-03-24 23:04 - 2014-01-27 20:20 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2014-03-24 23:04 - 2014-01-27 20:15 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2014-03-24 23:04 - 2014-01-27 19:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2014-03-24 23:04 - 2014-01-27 19:18 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2014-03-24 23:04 - 2014-01-27 19:00 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2014-03-24 23:04 - 2014-01-27 17:58 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-03-24 23:04 - 2014-01-27 17:50 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-03-24 23:04 - 2014-01-27 13:45 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-03-24 23:04 - 2014-01-18 01:04 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-03-24 23:04 - 2014-01-17 23:54 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2014-03-24 23:04 - 2013-12-21 16:51 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2014-03-24 23:04 - 2013-12-21 10:54 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2014-03-24 23:04 - 2013-12-20 12:18 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2014-03-24 23:04 - 2013-12-20 12:18 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2014-03-24 23:03 - 2014-02-11 05:04 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-03-24 23:03 - 2014-02-11 04:43 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2014-03-24 23:03 - 2014-02-11 04:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2014-03-24 23:03 - 2013-10-31 02:29 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-03-24 23:03 - 2013-10-31 02:29 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-03-24 23:03 - 2013-10-31 02:28 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-03-24 21:16 - 2014-03-24 21:16 - 00000000 _____ () C:\Users\Administrator\.uc-64d2b2abcc792cfb4d4e4c0b0708b488.administrator.maximilian-pc.tmp
2014-03-24 21:12 - 2014-03-24 21:12 - 00002360 _____ () C:\Users\Administrator\Desktop\Sicherer Zahlungsverkehr.lnk
2014-03-24 21:12 - 2014-03-24 21:12 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Intel Corporation
2014-03-24 21:12 - 2014-03-24 21:12 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Apple Computer
2014-03-24 21:11 - 2014-03-24 21:16 - 00000000 ____D () C:\Users\Administrator
2014-03-24 21:11 - 2014-03-24 21:11 - 00002271 _____ () C:\Users\Administrator\Desktop\Google Chrome.lnk
2014-03-24 21:11 - 2014-03-24 21:11 - 00001454 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-24 21:11 - 2014-03-24 21:11 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Startmenü
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-03-24 21:11 - 2014-01-08 14:36 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-24 21:11 - 2014-01-08 14:36 - 00000000 ____D () C:\Users\Administrator\AppData\LocalGoogle
2014-03-24 21:11 - 2014-01-08 14:36 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-03-24 21:11 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-03-24 21:11 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-03-24 21:11 - 2013-08-22 17:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
==================== One Month Modified Files and Folders =======
2014-04-03 22:49 - 2014-04-01 16:52 - 00027163 _____ () C:\Users\Maximilian\Downloads\FRST.txt
2014-04-03 22:49 - 2014-04-01 16:52 - 00000000 ____D () C:\FRST
2014-04-03 22:45 - 2014-04-03 22:45 - 00003614 _____ () C:\Users\Maximilian\Desktop\JRT.txt
2014-04-03 22:43 - 2013-02-12 01:20 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1473888687-1214762889-3515708772-1001
2014-04-03 22:38 - 2013-11-14 09:26 - 02063920 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-04-03 22:38 - 2013-11-14 09:11 - 00876824 _____ () C:\WINDOWS\system32\perfh007.dat
2014-04-03 22:38 - 2013-11-14 09:11 - 00200914 _____ () C:\WINDOWS\system32\perfc007.dat
2014-04-03 22:35 - 2014-04-03 22:35 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-04-03 22:35 - 2014-01-30 16:55 - 00000584 _____ () C:\WINDOWS\Tasks\MATLAB R2013b Startup Accelerator.job
2014-04-03 22:33 - 2013-02-12 01:38 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-04-03 22:32 - 2011-07-26 20:22 - 00001114 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-03 22:31 - 2014-04-03 22:22 - 00001524 _____ () C:\WINDOWS\PFRO.log
2014-04-03 22:31 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-04-03 22:30 - 2014-04-03 22:29 - 00000000 ____D () C:\AdwCleaner
2014-04-03 22:27 - 2012-04-04 10:56 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-04-03 22:25 - 2014-04-03 21:40 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-03 22:25 - 2011-07-26 20:22 - 00001118 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-03 22:22 - 2013-08-22 15:25 - 01048576 ___SH () C:\WINDOWS\system32\config\BBI
2014-04-03 22:16 - 2014-04-01 21:54 - 00240949 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-03 22:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-04-03 21:57 - 2011-07-26 20:22 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Google
2014-04-03 21:56 - 2011-07-26 20:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-04-03 21:48 - 2014-04-03 21:48 - 01426178 _____ () C:\Users\Maximilian\Downloads\adwcleaner.exe
2014-04-03 21:42 - 2011-10-13 12:30 - 00001158 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1473888687-1214762889-3515708772-1001UA.job
2014-04-03 21:40 - 2014-04-03 21:40 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-03 21:40 - 2014-04-03 21:40 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-03 21:39 - 2014-04-03 21:38 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Maximilian\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-03 21:37 - 2014-04-03 21:34 - 00003970 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2B3F4DBD-A5DA-40CF-8380-FA40CD844C51}
2014-04-03 21:31 - 2014-04-03 21:31 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Maximilian\Downloads\revosetup95.exe
2014-04-03 21:31 - 2014-04-03 21:31 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-02 21:41 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-04-02 21:34 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-04-02 18:13 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-04-01 23:51 - 2014-04-01 23:51 - 00541592 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-04-01 23:50 - 2013-03-20 10:28 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-04-01 23:50 - 2013-03-20 10:28 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-04-01 23:49 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-04-01 23:49 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-04-01 23:49 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-04-01 23:49 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-04-01 23:48 - 2013-08-08 13:28 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-04-01 23:46 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-04-01 23:46 - 2011-07-03 21:25 - 90015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-04-01 16:54 - 2014-04-01 16:53 - 00042174 _____ () C:\Users\Maximilian\Downloads\Addition.txt
2014-04-01 16:51 - 2014-04-01 16:51 - 02157056 _____ (Farbar) C:\Users\Maximilian\Downloads\FRST64.exe
2014-03-30 12:42 - 2011-10-13 12:30 - 00001136 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1473888687-1214762889-3515708772-1001Core.job
2014-03-30 11:20 - 2011-07-26 20:22 - 00004090 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-30 11:20 - 2011-07-26 20:22 - 00003854 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-24 23:33 - 2014-01-06 16:19 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-03-24 23:20 - 2013-02-12 01:13 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Packages
2014-03-24 23:17 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-03-24 23:17 - 2011-07-03 11:16 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Apple Computer
2014-03-24 23:17 - 2011-07-03 11:14 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-03-24 23:17 - 2011-07-02 21:36 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\SoftGrid Client
2014-03-24 23:17 - 2011-03-12 17:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-03-24 23:16 - 2013-10-22 14:31 - 00000000 ____D () C:\Program Files (x86)\Cisco
2014-03-24 23:11 - 2013-12-17 17:32 - 00000000 ____D () C:\Program Files\Recuva
2014-03-24 23:10 - 2013-07-16 18:21 - 00000000 ____D () C:\Users\Maximilian\Fotosoftware_Rossmann
2014-03-24 23:10 - 2011-07-03 11:00 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-03-24 23:08 - 2014-01-08 14:27 - 00000000 ____D () C:\Users\Maximilian
2014-03-24 23:07 - 2011-10-03 18:30 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-03-24 21:16 - 2014-03-24 21:16 - 00000000 _____ () C:\Users\Administrator\.uc-64d2b2abcc792cfb4d4e4c0b0708b488.administrator.maximilian-pc.tmp
2014-03-24 21:16 - 2014-03-24 21:11 - 00000000 ____D () C:\Users\Administrator
2014-03-24 21:12 - 2014-03-24 21:12 - 00002360 _____ () C:\Users\Administrator\Desktop\Sicherer Zahlungsverkehr.lnk
2014-03-24 21:12 - 2014-03-24 21:12 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Intel Corporation
2014-03-24 21:12 - 2014-03-24 21:12 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Apple Computer
2014-03-24 21:12 - 2009-07-14 07:09 - 00000000 ____D () C:\WINDOWS\System32\Tasks\WPD
2014-03-24 21:11 - 2014-03-24 21:11 - 00002271 _____ () C:\Users\Administrator\Desktop\Google Chrome.lnk
2014-03-24 21:11 - 2014-03-24 21:11 - 00001454 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-24 21:11 - 2014-03-24 21:11 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Startmenü
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-24 21:11 - 2014-03-24 21:11 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-03-24 21:07 - 2014-01-08 14:16 - 00000000 ___DC () C:\WINDOWS\Panther
2014-03-16 21:16 - 2014-01-19 19:04 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-03-12 12:27 - 2012-04-04 10:56 - 00003796 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-03-10 19:07 - 2014-01-08 14:27 - 00000000 ____D () C:\Users\UpdatusUser.Maximilian-PC
2014-03-05 09:26 - 2014-04-03 21:40 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-04-03 21:40 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-04-03 21:40 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-03-05 00:53 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-03-05 00:53 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-04 12:26 - 2011-07-04 15:25 - 00000000 ____D () C:\Users\Maximilian\Documents\Uni
2014-03-04 11:21 - 2011-11-03 16:58 - 00000000 ____D () C:\ProgramData\Cisco
Files to move or delete:
====================
C:\Users\Maximilian\license.dat
Some content of TEMP:
====================
C:\Users\Maximilian\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2014-03-24 23:04] - [2014-01-31 18:15] - 0311640 ____A (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02
LastRegBack: 2014-04-03 22:43
==================== End Of Log ============================ --- --- ---
5. Google Chrome wurde deeinstalliert und neu installiert. Leider keine Veränderung. Wenn Kaspersky´s Schutz angehalten ist, funktioniert dieses jedoch. Liegt das an den Kaspersky Einstellungen? Sonst tritt folgender Fehler auf: "Es kann keine sichere Verbindung zum Server hergestellt werden. Möglicherweise liegt ein Problem mit dem Server vor oder es ist ein Client-Authentifizierungszertifikat erforderlich, das Sie nicht haben.
Fehlercode: ERR_SSL_PROTOCOL_ERROR".
Kann bereits gesagt werden, ob ich mir einen Schädling bei der ursprünglich geschilderten Situation zugezogen habe?
Vielen vielen Dank für die Anstrengungen und Mühe! |