Chris979 | 22.04.2014 13:55 | Liste der Anhänge anzeigen (Anzahl: 1) Hallo Schrauber,
vielen Dank für die schnelle Reaktion.
Hier die Ergebnisse. AdwCleaner funktioniert nicht. Screenshot der Fehlermeldung anbei.
mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.04.2014
Suchlauf-Zeit: 14:36:15
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.22.03
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Christian
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 256071
Verstrichene Zeit: 8 Min, 45 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\UpdaterService.exe, 2592, Löschen bei Neustart, [2bd54ab625db6d935910aaa73ac78a76]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 65
PUP.Optional.UniversalUpdater.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UniversalUpdater, In Quarantäne, [2bd54ab625db6d935910aaa73ac78a76],
PUP.Optional.SpeedAnalysis3.A, HKLM\SOFTWARE\CLASSES\APPID\{562B9316-C08A-444A-9482-62080DD851AE}, In Quarantäne, [fe02f40c24dc5da3a5082726c83ada26],
PUP.Optional.SpeedAnalysis3.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{562B9316-C08A-444A-9482-62080DD851AE}, In Quarantäne, [fe02f40c24dc5da3a5082726c83ada26],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\CLSID\{E6062A33-016E-4BDA-A6F1-890D989F8656}, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\CLSID\{CACBAC2D-FDC3-4608-A289-6F281F471B83}, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CACBAC2D-FDC3-4608-A289-6F281F471B83}, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\TYPELIB\{73BB74C6-8886-4245-BCDA-448137D75D42}, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{73BB74C6-8886-4245-BCDA-448137D75D42}, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.Tool.1, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.Tool, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.Tool, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.Tool.1, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E6062A33-016E-4BDA-A6F1-890D989F8656}, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.ScriptHostObject.1, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.ScriptHostObject, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.ScriptHostObject, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E6062A33-016E-4BDA-A6F1-890D989F8656}, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E6062A33-016E-4BDA-A6F1-890D989F8656}, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.ScriptHostObject.1, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKU\S-1-5-21-714063657-1659228072-2378222278-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{E6062A33-016E-4BDA-A6F1-890D989F8656}, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKU\S-1-5-21-714063657-1659228072-2378222278-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{E6062A33-016E-4BDA-A6F1-890D989F8656}, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\CLSID\{E6062A33-016E-4BDA-A6F1-890D989F8656}\INPROCSERVER32, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3868E0C2-3E75-445F-B748-C97BB82300AC}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\TYPELIB\{6D697641-4C65-49F0-8CED-FE8180B5E37E}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6D697641-4C65-49F0-8CED-FE8180B5E37E}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.Navbar.1, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.Navbar, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.Navbar, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.Navbar.1, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\CLSID\{3868E0C2-3E75-445F-B748-C97BB82300AC}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\TYPELIB\{E7ABCD91-74F6-45AD-968B-A45EB265072C}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{045F91B3-695F-423A-98C7-8DE3C47AA020}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{A1440EC3-F0FA-407A-B811-DE6668C06D29}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{C815E3DA-0823-49B0-9270-D1771D58B317}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{E4A994B0-5550-4680-A4C6-B9470B888069}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{F9EB11AB-9384-4736-9B33-993940F88895}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{045F91B3-695F-423A-98C7-8DE3C47AA020}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A1440EC3-F0FA-407A-B811-DE6668C06D29}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C815E3DA-0823-49B0-9270-D1771D58B317}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E4A994B0-5550-4680-A4C6-B9470B888069}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F9EB11AB-9384-4736-9B33-993940F88895}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E7ABCD91-74F6-45AD-968B-A45EB265072C}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\TYPELIB\{5375FB9F-DF09-444B-9DC0-C6ED079C2577}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{5375FB9F-DF09-444B-9DC0-C6ED079C2577}, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HD Streamer, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
Registrierungswerte: 1
PUP.Optional.UniversalUpdater.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UNIVERSALUPDATER|ImagePath, C:\Program Files (x86)\Universal Updater\UpdaterService.exe, In Quarantäne, [2dd3659b926eb9479e79b4c96c9626da]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 2
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater, Löschen bei Neustart, [dd2310f0000003fdbe58e39abd459c64],
Dateien: 36
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\UpdaterService.exe, Löschen bei Neustart, [2bd54ab625db6d935910aaa73ac78a76],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\ScriptHost64.dll, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\ScriptHost.dll, In Quarantäne, [9868827e59a7a25eb37d6fa9a06218e8],
PUP.Optional.Somoto, C:\Users\Christian\AppData\Local\Temp\nsf44C7.tmp, In Quarantäne, [f010e8180df306fab0eb18a71de652ae],
PUP.Optional.SearchProtect.A, C:\Users\Christian\AppData\Local\Temp\nsp4207.exe, In Quarantäne, [c63a1ae630d0f30d1a7876ae0ef3ba46],
PUP.Optional.SearchProtect.A, C:\Users\Christian\AppData\Local\Temp\nsq75B6.exe, In Quarantäne, [f50b52aead53f907cbc7e83c7889af51],
PUP.Optional.SearchProtect.A, C:\Users\Christian\AppData\Local\Temp\nsq8F1B.exe, In Quarantäne, [3ec246baee12fe02a1f184a0e61b45bb],
PUP.Optional.Somoto, C:\Users\Christian\AppData\Local\Temp\bitool.dll, In Quarantäne, [837d6f911fe106fae9d85da0b74a639d],
PUP.Optional.BesttoolBars, C:\Users\Christian\AppData\Local\Temp\hd_streamer_install_new.exe, In Quarantäne, [956ba55b56aa778976dde94b936de61a],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\background.html, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\ButtonSite.dll, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\ButtonSite64.dll, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\128.png, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\16.ico, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\16.png, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\18.png, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\32.ico, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\32.png, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\48.png, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\AddonsFramework.Typelib.dll, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\AddonsFramework.Typelib64.dll, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\BackgroundHost.exe, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\BackgroundHost64.exe, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\bg.js, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\config.xml, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\content.js, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\jquery-1.9.1.min.js, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\json2.min.js, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\options.htm, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\settings.html, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\settings.js, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\settings_128.png, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\uninstall.exe, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\updater.js, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\updaterWrapper.js, In Quarantäne, [c43cac54fa0669979184116c55ad817f],
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\settings.json, In Quarantäne, [dd2310f0000003fdbe58e39abd459c64],
Physische Sektoren: 0
(No malicious items detected)
(end) JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Christian on 22.04.2014 at 14:44:31,51
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{19975B78-1907-4DD6-A437-4C48120F46A4}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{562B9317-C08A-444A-9482-62080DD851AE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\addonsframework.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\buttonsite.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\scripthost.dll
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\speedypc software
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\speedypc software
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
~~~ Files
Successfully deleted: [File] "C:\end"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\speedypc software"
Successfully deleted: [Folder] "C:\Users\Christian\AppData\Roaming\drivercure"
Successfully deleted: [Folder] "C:\Users\Christian\AppData\Roaming\speedypc software"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.04.2014 at 14:47:16,65
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST.txt
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014
Ran by Christian (administrator) on AIO_BÜRO on 22-04-2014 14:49:01
Running from C:\Users\Christian\Desktop
Windows 8.1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
() C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
(ASUSTeK) C:\Program Files (x86)\ASUS\ASUS Manager\Power Manager\Power Manager_background.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK Computer Inc.) C:\Program Files\ASUS\P1801 System Behavior\P1801Ctrl.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\AsHKService.exe
() C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Trans AiO\AsRunASUSTransAiO.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Trans AiO\TaichiHome.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Connection Builder\ConBuilder.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Key Suite\AsKeySuite.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Windows\SysWOW64\UMonit.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe
(Dropbox, Inc.) C:\Users\Christian\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(ASUSTek Computer Inc.) C:\Program Files (x86)\asus\ASUS Ai Charger\AiChargerAP.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17031_none_fa50b3979b1bcb4a\TiWorker.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6844560 2012-11-10] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1234064 2012-10-29] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [765056 2012-09-30] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-09-30] (Atheros Communications)
HKLM\...\Run: [UMonit] => C:\Windows\SysWOW64\UMonit.exe [40960 2013-01-31] ()
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1575192 2013-09-27] (Bitdefender)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-02] (Intel Corporation)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-06-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUS Ai Charger] => C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe [547984 2012-08-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-19] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2013-10-10] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Agent] => "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe"
HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse] => "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard
HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe"
Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Christian\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar466.lnk
ShortcutTarget: Sidebar466.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2014-02-01]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2014-02-01]
Chrome:
=======
CHR StartupUrls: "hxxp://www.google.de/"
CHR Extension: (Google Docs) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-09]
CHR Extension: (Google Drive) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-09]
CHR Extension: (YouTube) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-09]
CHR Extension: (GMX MailCheck) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\camnampocfohlcgbajligmemmabnljcm [2014-04-13]
CHR Extension: (Google-Suche) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-09]
CHR Extension: (Google Wallet) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-09]
CHR Extension: (Google Mail) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-09]
==================== Services (Whitelisted) =================
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] ()
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [220288 2012-09-30] (Qualcomm Atheros Commnucations)
S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [69392 2013-08-07] (Bitdefender)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [95184 2012-06-25] (Bitdefender)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2013-08-07] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2013-09-30] (Bitdefender)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [0 2013-10-31] ()
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-09-30] (Atheros)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R3 AiCharger; C:\Windows\SysWow64\drivers\AiCharger.sys [14848 2012-03-23] (ASUSTek Computer Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2011-04-12] ()
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2013-07-19] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261056 2014-02-01] (BitDefender)
S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2013-07-19] (BitDefender)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-07-24] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC)
S3 BDSandBox; C:\WINDOWS\system32\drivers\bdsandbox.sys [82824 2013-07-23] (BitDefender SRL)
S1 BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [0 2013-07-30] ()
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-09-30] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
R3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [60928 2012-07-06] (GenesysLogic)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-01-07] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 PVUSB; C:\Windows\System32\drivers\CESG64.sys [63808 2007-02-19] (CASIO COMPUTER CO.,LTD.)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-01-07] (Microsoft Corporation)
R3 sthid; C:\Windows\System32\drivers\sthid.sys [21216 2013-04-01] (Splashtop Inc.)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-08-07] (BitDefender S.R.L.)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-22 14:49 - 2014-04-22 14:49 - 00018372 _____ () C:\Users\Christian\Desktop\FRST.txt
2014-04-22 14:48 - 2014-04-22 14:48 - 00000000 ____D () C:\Users\Christian\Desktop\1st_answer
2014-04-22 14:43 - 2014-04-22 14:43 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-04-22 14:40 - 2014-04-22 14:48 - 00000000 ____D () C:\Users\Christian\Desktop\Anfragestep
2014-04-22 14:40 - 2014-04-22 14:40 - 00000000 ____D () C:\AdwCleaner
2014-04-22 14:25 - 2014-04-22 14:38 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-22 14:25 - 2014-04-22 14:25 - 00001121 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-22 14:25 - 2014-04-22 14:25 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-22 14:25 - 2014-04-22 14:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-22 14:25 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-22 14:25 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-04-22 14:25 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-04-22 14:24 - 2014-04-22 14:21 - 01016261 _____ (Thisisu) C:\Users\Christian\Desktop\JRT.exe
2014-04-22 14:24 - 2014-04-22 14:19 - 01335637 _____ () C:\Users\Christian\Desktop\adwcleaner.exe
2014-04-22 14:24 - 2014-04-22 14:18 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Christian\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-22 14:18 - 2014-04-22 14:18 - 00000000 __SHD () C:\found.000
2014-04-22 12:58 - 2014-04-22 14:49 - 00000000 ____D () C:\FRST
2014-04-22 12:56 - 2014-04-22 12:56 - 02061312 _____ (Farbar) C:\Users\Christian\Desktop\FRST64.exe
2014-04-22 12:55 - 2014-04-22 12:55 - 00000000 _____ () C:\Users\Christian\defogger_reenable
2014-04-13 20:54 - 2014-04-13 20:54 - 00000000 ___SD () C:\Users\Christian\Documents\Meine Shapes
2014-04-13 20:44 - 2014-04-13 20:44 - 00471112 _____ (1&1 Mail & Media GmbH) C:\Users\Christian\Downloads\GMX_MailCheck_chrome_setup.exe
2014-04-13 20:37 - 2014-04-13 20:37 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Autodesk
2014-04-13 20:37 - 2014-04-13 20:37 - 00000000 ____D () C:\ProgramData\Autodesk
2014-04-13 10:31 - 2014-04-22 10:20 - 00000039 _____ () C:\WINDOWS\vbaddin.ini
2014-04-12 20:11 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-04-12 20:11 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-04-12 20:11 - 2014-03-10 12:35 - 02008408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2014-04-12 20:11 - 2014-03-10 12:35 - 00377176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2014-04-12 20:11 - 2014-03-06 11:19 - 01287576 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2014-04-12 20:11 - 2014-03-06 11:02 - 01109424 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-04-12 20:11 - 2014-03-06 08:17 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-04-12 20:11 - 2014-03-06 08:10 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2014-03-30 13:48 - 2014-03-30 13:48 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\DropboxMaster
2014-03-30 12:21 - 2014-02-22 14:16 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2014-03-30 12:21 - 2014-02-22 13:24 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
==================== One Month Modified Files and Folders =======
2014-04-22 14:49 - 2014-04-22 14:49 - 00018372 _____ () C:\Users\Christian\Desktop\FRST.txt
2014-04-22 14:49 - 2014-04-22 12:58 - 00000000 ____D () C:\FRST
2014-04-22 14:48 - 2014-04-22 14:48 - 00000000 ____D () C:\Users\Christian\Desktop\1st_answer
2014-04-22 14:48 - 2014-04-22 14:40 - 00000000 ____D () C:\Users\Christian\Desktop\Anfragestep
2014-04-22 14:44 - 2014-01-03 14:43 - 00101212 _____ () C:\WINDOWS\system32\lvcoinst.log
2014-04-22 14:44 - 2013-11-14 09:27 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-04-22 14:44 - 2013-11-14 09:11 - 00765378 _____ () C:\WINDOWS\system32\perfh007.dat
2014-04-22 14:44 - 2013-11-14 09:11 - 00159696 _____ () C:\WINDOWS\system32\perfc007.dat
2014-04-22 14:43 - 2014-04-22 14:43 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-04-22 14:43 - 2014-02-23 19:15 - 00003586 _____ () C:\WINDOWS\System32\Tasks\Bitdefender Auto-Scan
2014-04-22 14:43 - 2014-01-02 22:40 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-714063657-1659228072-2378222278-1001
2014-04-22 14:40 - 2014-04-22 14:40 - 00000000 ____D () C:\AdwCleaner
2014-04-22 14:39 - 2014-02-09 11:46 - 00002202 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-22 14:39 - 2014-01-02 22:32 - 00000062 _____ () C:\Users\Christian\AppData\Roaming\sp_data.sys
2014-04-22 14:38 - 2014-04-22 14:25 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-22 14:38 - 2014-01-08 17:05 - 00000000 __RDO () C:\Users\Christian\SkyDrive
2014-04-22 14:38 - 2014-01-05 19:51 - 00000000 ____D () C:\Users\Christian\AppData\Local\FreePDF_XP
2014-04-22 14:38 - 2014-01-02 23:13 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Dropbox
2014-04-22 14:38 - 2014-01-02 22:33 - 00000000 ___RD () C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-22 14:37 - 2014-01-07 22:06 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-04-22 14:37 - 2013-11-14 00:18 - 00030046 _____ () C:\WINDOWS\PFRO.log
2014-04-22 14:37 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-04-22 14:36 - 2014-01-07 22:05 - 01675040 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-22 14:36 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppCompat
2014-04-22 14:36 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-04-22 14:25 - 2014-04-22 14:25 - 00001121 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-22 14:25 - 2014-04-22 14:25 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-22 14:25 - 2014-04-22 14:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-22 14:21 - 2014-04-22 14:24 - 01016261 _____ (Thisisu) C:\Users\Christian\Desktop\JRT.exe
2014-04-22 14:19 - 2014-04-22 14:24 - 01335637 _____ () C:\Users\Christian\Desktop\adwcleaner.exe
2014-04-22 14:18 - 2014-04-22 14:24 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Christian\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-22 14:18 - 2014-04-22 14:18 - 00000000 __SHD () C:\found.000
2014-04-22 14:01 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-04-22 13:56 - 2014-02-09 11:45 - 00001134 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-22 13:11 - 2014-02-09 11:45 - 00000000 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-22 13:08 - 2014-01-02 23:15 - 00000000 ___RD () C:\Users\Christian\Dropbox
2014-04-22 12:56 - 2014-04-22 12:56 - 02061312 _____ (Farbar) C:\Users\Christian\Desktop\FRST64.exe
2014-04-22 12:55 - 2014-04-22 12:55 - 00000000 _____ () C:\Users\Christian\defogger_reenable
2014-04-22 12:55 - 2014-01-07 22:09 - 00000000 ____D () C:\Users\Christian
2014-04-22 12:11 - 2014-01-12 16:10 - 00000000 ____D () C:\Users\Christian\Documents\My Digital Editions
2014-04-22 11:21 - 2014-01-02 22:31 - 00000000 ____D () C:\Users\Christian\AppData\Local\VirtualStore
2014-04-22 10:25 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-04-22 10:22 - 2014-01-03 00:43 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-22 10:20 - 2014-04-13 10:31 - 00000039 _____ () C:\WINDOWS\vbaddin.ini
2014-04-18 21:30 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-04-13 21:51 - 2014-02-09 11:45 - 00004106 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-13 21:51 - 2014-02-09 11:45 - 00003870 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-13 21:47 - 2013-08-22 16:44 - 00555936 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-04-13 21:46 - 2014-01-04 10:44 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-04-13 21:45 - 2014-01-04 10:44 - 90655440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-04-13 20:54 - 2014-04-13 20:54 - 00000000 ___SD () C:\Users\Christian\Documents\Meine Shapes
2014-04-13 20:54 - 2014-01-03 01:16 - 00000000 ____D () C:\Users\Christian\Documents\Outlook-Dateien
2014-04-13 20:44 - 2014-04-13 20:44 - 00471112 _____ (1&1 Mail & Media GmbH) C:\Users\Christian\Downloads\GMX_MailCheck_chrome_setup.exe
2014-04-13 20:37 - 2014-04-13 20:37 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Autodesk
2014-04-13 20:37 - 2014-04-13 20:37 - 00000000 ____D () C:\ProgramData\Autodesk
2014-04-13 10:09 - 2013-11-14 09:13 - 00000000 ____D () C:\WINDOWS\ShellNew
2014-04-03 09:51 - 2014-04-22 14:25 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-22 14:25 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-22 14:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-03-31 23:23 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-03-31 23:23 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-31 03:16 - 2014-04-12 20:11 - 23134208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-03-31 01:57 - 2014-04-12 20:11 - 17073152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-03-30 21:16 - 2014-03-15 21:30 - 00000401 _____ () C:\WINDOWS\system32\checkdnsid.xml
2014-03-30 13:48 - 2014-03-30 13:48 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\DropboxMaster
2014-03-30 13:48 - 2014-01-02 23:15 - 00001087 _____ () C:\Users\Christian\Desktop\Dropbox.lnk
2014-03-30 13:48 - 2014-01-02 23:14 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
Some content of TEMP:
====================
C:\Users\Christian\AppData\Local\Temp\AcDeltree.exe
C:\Users\Christian\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp7p2lbg.dll
C:\Users\Christian\AppData\Local\Temp\Quarantine.exe
C:\Users\Christian\AppData\Local\Temp\SSStub_Somo_SpeedyPC.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-18 15:04
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
PS: Was ist das für eine Thematik von M-K-D-B. Nur Werbung? |