Weit über 100 PUPs etc. bei Malwarebytes Hallo liebes Team von Trojaner-Board,
ein Freund empfahl mir einen Durchlauf von Malwarebytes. Ich fiel fast vom Stuhl als ich die weit über 100 Funde entdeckte. Ich fürchte mein Rechner ist total verseucht... :wtf:
Ich wäre Euch sehr dankbar wenn ihr mir helft meinen Laptop zu reinigen!
Vielen Dank und Gruß :abklatsch:
Fuat
Hier alle logs:
Malware Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 23.04.2014
Suchlauf-Zeit: 21:33:21
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.23.07
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: ***
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 296746
Verstrichene Zeit: 40 Min, 49 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 45
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, , [5ea202febb45c53bc957be908a7847b9],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, , [5ea202febb45c53bc957be908a7847b9],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, , [e818fb05de22ca3602c861b6da28f30d],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.dskBnd.1, , [e818fb05de22ca3602c861b6da28f30d],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.dskBnd, , [e818fb05de22ca3602c861b6da28f30d],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.dskBnd, , [e818fb05de22ca3602c861b6da28f30d],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.dskBnd.1, , [e818fb05de22ca3602c861b6da28f30d],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane.1, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane.1, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.SoftonicHlpr.1, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.SoftonicHlpr, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.SoftonicHlpr, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.SoftonicHlpr.1, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Delta.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, , [7a86946c2cd49d63e9370a435fa309f7],
PUP.Optional.Delta.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, , [7a86946c2cd49d63e9370a435fa309f7],
PUP.Optional.Delta.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, , [47b9f40c6997cf312bf453fafe04fa06],
PUP.Optional.Delta.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, , [47b9f40c6997cf312bf453fafe04fa06],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc, , [3ec24ab614ec619f20c6cea5936f1ce4],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc.1, , [d828c7391ce4a858e6004e25e81a916f],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc, , [1ee27c8448b8629e33b3f38054ae46ba],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc.1, , [8977b14fcc343fc1974ffd768c76fe02],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\elchiiiejkobdbblfejjkbphbddgmljf, , [4ab6eb1567994bb5edfca8cba062e020],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\SOFTONIC\Softonic, , [2ed2fa06d42ccf31da100d667191936d],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, , [bf416d937e825ca4a5d836623ac97789],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, , [01ff8779f50b1ce45a224058dc27e31d],
PUP.Optional.Babylon.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Redir, , [ab5522de7789f30de99ceaafac5752ae],
PUP.Optional.Babylon.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, , [ca363bc558a835cbd3b38b0ee0237987],
PUP.Optional.Softonic.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Softonic, , [956b0af62bd524dc1ec92b4822e048b8],
PUP.Optional.Softonic.A, HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [c33d25db58a8fd03b0ee0d63857d916f],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore.1, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore.1, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\S, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\S, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Softonic, , [aa56827e7789ad538267cb9d18ea3ac6],
Registrierungswerte: 2
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, Softonic Toolbar, , [e818fb05de22ca3602c861b6da28f30d]
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, , [a35ddb2501ff23dd567445d2758dc739],
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 14
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\225724A56DC14C7E9F829212E2AD9957, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\358ADAE8E67541ECB69F8A04F0102DE7, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\8DE5407FF51A4831A9321DD709F20985, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AAF0B8FFDA8048F7B06085E02F90D512, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\bh, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Temp\mt_ffx\Softonic, , [43bd9e627a86ee12f2f8e97fa75b44bc],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Temp\mt_ffx\Softonic\Softonic, , [43bd9e627a86ee12f2f8e97fa75b44bc],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Temp\mt_ffx\Softonic\Softonic\1.8.21.14, , [43bd9e627a86ee12f2f8e97fa75b44bc],
Dateien: 95
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicTlbr.dll, , [e818fb05de22ca3602c861b6da28f30d],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\bh\Softonic.dll, , [35cbce32867ade2233982becec1660a0],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Roaming\OpenCandy\358ADAE8E67541ECB69F8A04F0102DE7\DeltaTB.exe, , [8b759d63ac540cf4f65d30d1a55c6799],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Roaming\OpenCandy\8DE5407FF51A4831A9321DD709F20985\DeltaTB.exe, , [5ca4c23e3dc32ed20d46ea1749b8ca36],
PUP.Optional.OpenCandy.A, C:\Users\***\AppData\Roaming\OpenCandy\AAF0B8FFDA8048F7B06085E02F90D512\Setupsft_chr_p1v7.exe, , [08f8b24efc04ec14ad5953cdc63ea35d],
PUP.Optional.Babylon.A, C:\Program Files (x86)\Mozilla Firefox\ccp.bao, , [af51926e9868b54b3ae6ff1f6e9246ba],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\BExternal.dll, , [04fc11efa858ef1126b8cd5513ed60a0],
PUP.Optional.BabSolution.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\BUSolution.dll, , [32ce40c0a15fb44c27a14fb859a823dd],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\CrxInstaller.dll, , [817f34cc08f84fb19eded1437889de22],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\MntrDLLInstall.dll, , [639d33cd02fef30d2a53ec2838c954ac],
PUP.Optional.Delta.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\MyDeltaTB.exe, , [7c8442be35cbb44c0b11dd8e13eefe02],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\F8828C7C-BAB0-7891-BCA3-5CBBA0982DA2\Latest\Setup.exe, , [659b788810f09d6334edf6287c8413ed],
PUP.Optional.BabSolution.A, C:\Users\***\AppData\Local\Temp\bus8390\BUSolution.dll, , [fa06fe026a966c9425a30bfc09f804fc],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\9818B6B5-BAB0-7891-AD0F-046BAF01DD80\Latest\BExternal.dll, , [f01013ed54acfe0226b85bc710f052ae],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\9818B6B5-BAB0-7891-AD0F-046BAF01DD80\Latest\CrxInstaller.dll, , [808057a9fc046d93fb818b89699854ac],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\9818B6B5-BAB0-7891-AD0F-046BAF01DD80\Latest\MntrDLLInstall.dll, , [27d9bc4441bf46ba3845858f699816ea],
PUP.Optional.Delta.A, C:\Users\***\AppData\Local\Temp\9818B6B5-BAB0-7891-AD0F-046BAF01DD80\Latest\MyDeltaTB.exe, , [47b9b24e39c702fefc20175425dcc43c],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Local\Temp\9818B6B5-BAB0-7891-AD0F-046BAF01DD80\Latest\Setup.exe, , [cd3334cc45bb02feb66bf628ca36be42],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\searchplugins\softonic.xml, , [8779718fd92730d074705a19867c6a96],
PUP.Optional.Babylon.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\searchplugins\babylon.xml, , [55abee12f010847c1dfa2c4b3ac8c937],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\225724A56DC14C7E9F829212E2AD9957\HSS-2.83-install-plain-452-silent.exe, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB\2877.ico, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB\avg.exe, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB\AVG923_p1v3.exe, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB\EBB77268-338F-4C6A-8590-AD88FED26F4A, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.OpenCandy, C:\Users\***\AppData\Roaming\OpenCandy\AB7C5FE5D93140A69793308EDD92F8DB\OCBrowserHelper_1.0.3.85.dll, , [8c74dc24ff0108f8e12ed38e15ed867a],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\appCntrl.js, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\bg.html, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\bg.js, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\chMntz.dll, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\CrmAdpt.dll, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\ct.js, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\CTB.dll, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\dpk.js, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\hprtkMsg.htm, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\hprtkMsg.js, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\json2.min.js, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\logo.png, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\manifest.json, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\pref.json, , [7789be4270908f712bbde97f70925ea2],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\softonic.crx, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicApp.dll, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicEng.dll, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\Softonicsrv.exe, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\uninstall.exe, , [aa56827e7789ad538267cb9d18ea3ac6],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Local\Temp\mt_ffx\Softonic\Softonic\1.8.21.14\softonic.xpi, , [43bd9e627a86ee12f2f8e97fa75b44bc],
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.admin", false);), ,[5ca4728eb14fb0504620c692d72dd729]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.aflt", "OC");), ,[b749de2254acea167beb154345bf22de]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");), ,[34ccdf21fe0210f0c0a685d36c980af6]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.autoRvrt", "false");), ,[f20e1ae6f907ec14a9bde0780ff59e62]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dfltLng", "de");), ,[f80806fad0309a663a2ca9af36ce40c0]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dfltSrch", true);), ,[728e817f14ec966a2541c8903cc8d32d]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dnsErr", true);), ,[e818b050fc048c742c3aacace61e47b9]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.excTlbr", false);), ,[52ae8a76cf31ba462f37134521e304fc]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.ffxUnstlRst", false);), ,[1de358a8788888785115a4b4af5548b8]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpg", true);), ,[c937837d1ce44cb471f52830768e6898]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=20ca48d400000000000074de2beaeff9");), ,[2bd557a917e94ab6046281d72dd738c8]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.id", "20ca48d400000000000074de2beaeff9");), ,[b14f1fe18c741fe15d0993c5fb09916f]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.instlDay", "16026");), ,[12eec23e29d741bffd696aee55af10f0]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.instlRef", "MOY00621");), ,[7090867abd43af51b4b2ed6bb25243bd]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.newTab", true);), ,[9e6228d8926e738d69fd85d390744bb5]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=20ca48d400000000000074de2beaeff9");), ,[7987f20eb8486d93ed79fb5ddb299769]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.prdct", "Softonic");), ,[c43c36ca14ec7e8213536eeaad570000]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.prtnrId", "softonic");), ,[0af630d0f70968982d39a1b76c988878]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.rvrt", "false");), ,[2fd110f0659bec14a7bf4414996bfb05]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.smplGrp", "none");), ,[659bee12c53b70906df9bb9d34d0a45c]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");), ,[c33dd03029d76b9567ffa3b5b64ea858]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.tlbrId", "opencandy2013");), ,[a858b64a03fd6b95b4b26cece3213cc4]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=20ca48d400000000000074de2beaeff9&q=");), ,[6898a85815eb6997fb6baaae53b1ea16]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsn", "1.8.21.14");), ,[5da30000f60afb055e0818407a8a19e7]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsnTs", "1.8.21.1414:03:01");), ,[8b75c73937c97789ec7ac197c242669a]
PUP.Optional.Softonic.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsni", "1.8.21.14");), ,[ba465ca41ee20df33e2869efcc388977]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.admin", false);), ,[629ef50ba060a65a2844b1a762a2f40c]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.aflt", "babsst");), ,[aa56619f9769ef11d59721377292ea16]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");), ,[649c02fe8d7347b995d735239d671be5]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.autoRvrt", "false");), ,[42bea759f50bab55680450084fb5df21]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.dfltLng", "de");), ,[31cf37c91ee29b65bab262f618ecd729]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.excTlbr", false);), ,[8c7422de9d6334cc36363b1d3bc9aa56]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.ffxUnstlRst", true);), ,[d32d8a7602fe5ea23c304414b252738d]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.id", "20ca48d400000000000000ffbb10c4d0");), ,[5da31ce4de22cf31343882d6f3115fa1]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlDay", "15941");), ,[4eb2946cb44cbd431c50292f3dc7b44c]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlRef", "sst");), ,[1fe1c63a9f617c847def64f4a95b3bc5]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.newTab", false);), ,[ab55cc343ac62cd409630553a460669a]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prdct", "delta");), ,[758b3cc40cf451afb7b5f95fe222cc34]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prtnrId", "delta");), ,[b947c43cab55956b1557193f37cd42be]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.rvrt", "false");), ,[2ad62cd4b9474cb4b7b5d286659f40c0]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.smplGrp", "none");), ,[a95722deb749e91764089bbd3dc7718f]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrId", "base");), ,[8a76bc44639d45bbbab282d6788c37c9]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrSrchUrl", "");), ,[fb05e31df709b7497bf180d837cd46ba]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsn", "1.8.24.6");), ,[6e92f90790709e62016b8dcbcc3810f0]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsnTs", "1.8.24.69:59:04");), ,[bc445fa10af6639d8ae22e2a7a8a7888]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsni", "1.8.24.6");), ,[8c74db25bd4360a058146deb16eed030]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.babExt", "");), ,[cc34b64af40cfc04c4a863f5758f43bd]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.babTrack", "affID=121564&tsp=4984");), ,[718f9f61f01023ddf37970e88b79c23e]
PUP.Optional.Delta.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.srcExt", "ss");), ,[4ab6eb1541bf1ae668041246b74d847c]
Physische Sektoren: 0
(No malicious items detected)
(end)
defogfger Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 21:33 on 23/04/2014 (Fuat)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
Frst Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-04-2014
Ran by *** (administrator) on ***-PC on 23-04-2014 21:34:41
Running from C:\Users\***\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(AMD) C:\windows\system32\atiesrxx.exe
(AMD) C:\windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Marvell Semiconductor, Inc.) C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
() C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\ipmGui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-11-24] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2011-11-24] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-11-24] (Lenovo(beijing) Limited)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1238528 2007-08-29] (Marvell Semiconductor, Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2011-11-24] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-807794254-139005778-1418515836-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-807794254-139005778-1418515836-1000\...\Run: [Amazon Cloud Player] => C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3140608 2014-01-14] ()
HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-807794254-139005778-1418515836-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Amazon Cloud Player] => C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3140608 2014-01-14] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=10&cc=&mi=20ca48d400000000000074de2beaeff9
HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
SearchScopes: HKCU - DefaultScope {1D6289B1-98DF-40A3-A61C-E9F912C40B47} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=20ca48d400000000000074de2beaeff9&r=412
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=20CA00FFBB10C4D0&affID=121564&tsp=4984
SearchScopes: HKCU - {1D6289B1-98DF-40A3-A61C-E9F912C40B47} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=20ca48d400000000000074de2beaeff9&r=412
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://isearch.avg.com/search?cid={7B80D188-C6D3-4804-831B-94DAA4A1BCDC}&mid=36fa2a3dc6fa47d0a5400d47e788938e-2407c80f4ea851e8267460b2327656fcd5111031&lang=de&ds=od011&pr=sa&d=2012-07-18 16:51:35&v=12.1.0.20&sap=dsp&q={searchTerms}
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll No File
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\bh\Softonic.dll (Softonic.com)
Toolbar: HKLM-x32 - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicTlbr.dll (Softonic.com)
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default
FF user.js: detected! => C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101753.dll (Amazon.com, Inc.)
FF SearchPlugin: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\searchplugins\softonic.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Add to Amazon Wish List Button - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\Extensions\amznUWL2@amazon.com.xpi [2012-12-31]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zn8jndgw.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-21]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Softonic Chrome Toolbar) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf [2013-11-17]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\***\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-11-01]
CHR HKLM-x32\...\Chrome\Extension: [elchiiiejkobdbblfejjkbphbddgmljf] - C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\Softonic.crx [2013-06-11]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG)
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-02] (Avira Operations GmbH & Co. KG)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-23] (Malwarebytes Corporation)
R3 SPUVCbv; C:\Windows\System32\Drivers\usbvideo.sys [185344 2013-07-12] (Microsoft Corporation)
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-01-10] (Anchorfree Inc.)
U3 BcmSqlStartupSvc;
U2 CLKMSVC10_3A60B698;
U2 CLKMSVC10_C3B3B687;
U2 DriverService;
U2 iATAgentService;
U2 idealife Update Service;
U3 IGRS;
U2 IviRegMgr;
U2 nvUpdatusService;
U2 Oasis2Service;
U2 PCCarerService;
U2 ReadyComm.DirectRouter;
U2 RichVideo;
U2 RtLedService;
U2 SeaPort;
U2 SoftwareService;
U3 SQLWriter;
U2 Stereo Service;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-23 21:34 - 2014-04-23 21:34 - 00014988 _____ () C:\Users\***\Desktop\FRST.txt
2014-04-23 21:34 - 2014-04-23 21:34 - 00000000 ____D () C:\FRST
2014-04-23 21:33 - 2014-04-23 21:33 - 00027969 _____ () C:\Users\***\Desktop\mbam.txt
2014-04-23 21:33 - 2014-04-23 21:33 - 00000470 _____ () C:\Users\***\Desktop\defogger_disable.log
2014-04-23 21:33 - 2014-04-23 21:33 - 00000000 _____ () C:\Users\***\defogger_reenable
2014-04-23 21:13 - 2014-04-23 21:13 - 00380416 _____ () C:\Users\***\Desktop\Gmer-19357.exe
2014-04-23 21:12 - 2014-04-23 21:13 - 02061312 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe
2014-04-23 21:12 - 2014-04-23 21:12 - 00050477 _____ () C:\Users\***\Desktop\Defogger.exe
2014-04-23 20:51 - 2014-04-23 20:52 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-23 20:51 - 2014-04-23 20:51 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-23 20:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-23 20:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-23 20:50 - 2014-04-23 20:51 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\***\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-17 19:53 - 2014-04-17 19:53 - 00000000 ____D () C:\Users\***\AppData\Local\{C55381F5-CA4A-4FD6-8D4B-17A6191F056B}
2014-04-10 06:13 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-04-10 06:13 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-04-10 06:13 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-04-10 06:13 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-04-10 06:12 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2014-04-10 06:12 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2014-04-10 06:12 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2014-04-10 06:12 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2014-04-10 06:12 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2014-04-10 06:12 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2014-04-10 06:12 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2014-04-10 06:12 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2014-04-10 06:12 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2014-04-10 06:12 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2014-04-10 06:12 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2014-04-10 06:12 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2014-04-10 06:12 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2014-04-10 06:12 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2014-04-10 06:12 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2014-04-10 06:12 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll
2014-04-10 06:12 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2014-04-09 19:01 - 2014-04-09 19:01 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_deu(1).exe
2014-04-01 18:09 - 2014-04-01 18:10 - 00006011 _____ () C:\Users\***\Desktop\Themenvorschläge zur Fortbildungsprüfung.odt
2014-03-29 13:19 - 2014-03-29 13:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2014-04-23 21:34 - 2014-04-23 21:34 - 00014988 _____ () C:\Users\***\Desktop\FRST.txt
2014-04-23 21:34 - 2014-04-23 21:34 - 00000000 ____D () C:\FRST
2014-04-23 21:33 - 2014-04-23 21:33 - 00027969 _____ () C:\Users\***\Desktop\mbam.txt
2014-04-23 21:33 - 2014-04-23 21:33 - 00000470 _____ () C:\Users\***\Desktop\defogger_disable.log
2014-04-23 21:33 - 2014-04-23 21:33 - 00000000 _____ () C:\Users\***\defogger_reenable
2014-04-23 21:33 - 2012-02-17 18:35 - 00000000 ____D () C:\Users\***
2014-04-23 21:30 - 2012-04-09 09:23 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-23 21:17 - 2009-07-14 06:45 - 00021072 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-23 21:17 - 2009-07-14 06:45 - 00021072 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-23 21:13 - 2014-04-23 21:13 - 00380416 _____ () C:\Users\***\Desktop\Gmer-19357.exe
2014-04-23 21:13 - 2014-04-23 21:12 - 02061312 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe
2014-04-23 21:12 - 2014-04-23 21:12 - 00050477 _____ () C:\Users\***\Desktop\Defogger.exe
2014-04-23 20:56 - 2011-11-24 15:23 - 01424365 _____ () C:\windows\WindowsUpdate.log
2014-04-23 20:52 - 2014-04-23 20:51 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-23 20:51 - 2014-04-23 20:51 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-23 20:51 - 2014-04-23 20:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-23 20:51 - 2014-04-23 20:50 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\***\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-23 20:51 - 2012-10-08 09:25 - 00000000 ____D () C:\Users\***\AppData\Roaming\Malwarebytes
2014-04-23 20:51 - 2012-10-08 09:25 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-23 20:51 - 2012-10-08 09:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-04-23 20:51 - 2011-11-24 07:09 - 00700134 _____ () C:\windows\system32\perfh007.dat
2014-04-23 20:51 - 2011-11-24 07:09 - 00149984 _____ () C:\windows\system32\perfc007.dat
2014-04-23 20:51 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-23 20:47 - 2011-11-24 16:11 - 00138091 _____ () C:\windows\system32\fastboot.set
2014-04-23 20:47 - 2011-11-24 16:04 - 03384033 _____ () C:\FaceProv.log
2014-04-23 20:47 - 2011-11-24 16:04 - 00000000 ____D () C:\ProgramData\VeriFace
2014-04-23 20:47 - 2011-11-24 15:56 - 00001120 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-23 20:47 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-23 20:47 - 2009-07-14 06:51 - 00115591 _____ () C:\windows\setupact.log
2014-04-21 19:53 - 2013-12-27 12:33 - 00000000 ____D () C:\Users\***\Desktop\Handy
2014-04-21 19:43 - 2011-11-24 15:57 - 00001124 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-18 13:14 - 2009-07-14 07:08 - 00032632 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-04-17 19:53 - 2014-04-17 19:53 - 00000000 ____D () C:\Users\***\AppData\Local\{C55381F5-CA4A-4FD6-8D4B-17A6191F056B}
2014-04-10 06:16 - 2013-08-13 19:37 - 00000000 ____D () C:\windows\system32\MRT
2014-04-10 06:14 - 2012-08-06 16:30 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-09 19:09 - 2012-05-22 21:46 - 00000000 ____D () C:\Users\***\AppData\Local\Adobe
2014-04-09 19:04 - 2012-04-09 09:23 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-04-09 19:04 - 2012-04-09 09:23 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-04-09 19:04 - 2012-02-17 18:52 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-09 19:01 - 2014-04-09 19:01 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_deu(1).exe
2014-04-03 19:58 - 2013-08-07 17:54 - 00000000 ____D () C:\Users\***\Desktop\Bilder130807
2014-04-03 09:51 - 2014-04-23 20:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-23 20:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2012-10-08 09:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-04-01 18:13 - 2012-07-18 11:33 - 00000000 ____D () C:\Users\***\AppData\Roaming\SoftGrid Client
2014-04-01 18:10 - 2014-04-01 18:09 - 00006011 _____ () C:\Users\***\Desktop\Themenvorschläge zur Fortbildungsprüfung.odt
2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-03-31 03:16 - 2014-04-10 06:13 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-10 06:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-10 06:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-10 06:13 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-30 10:01 - 2012-10-08 09:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-29 13:19 - 2014-03-29 13:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 12:38 - 2011-11-24 15:57 - 00004120 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-29 12:38 - 2011-11-24 15:57 - 00003868 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-27 16:55 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\NDF
Some content of TEMP:
====================
C:\Users\***\AppData\Local\Temp\AskSLib.dll
C:\Users\***\AppData\Local\Temp\avgnt.exe
C:\Users\***\AppData\Local\Temp\avguidx.dll
C:\Users\***\AppData\Local\Temp\CommonInstaller.exe
C:\Users\***\AppData\Local\Temp\contentDATs.exe
C:\Users\***\AppData\Local\Temp\MachineIdCreator.exe
C:\Users\***\AppData\Local\Temp\oi_{292C31A9-1BA2-4016-8710-0657D1C588A7}.exe
C:\Users\***\AppData\Local\Temp\pdf24-creator-update.exe
C:\Users\***\AppData\Local\Temp\SecurityScan_Release.exe
C:\Users\***\AppData\Local\Temp\ToolbarInstaller.exe
C:\Users\***\AppData\Local\Temp\uninst1.exe
C:\Users\***\AppData\Local\Temp\UNINSTALL.exe
C:\Users\Gastkonto\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-24 16:22
==================== End Of Log ============================
Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-04-2014
Ran by *** at 2014-04-23 21:35:17
Running from C:\Users\***\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.182 - Adobe Systems Incorporated)
Adobe Reader X (10.1.9) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.9 - Adobe Systems Incorporated)
Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.3.0.422 - Amazon Services LLC)
Amazon MP3-Downloader 1.0.17 (HKLM-x32\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Client Installation Program (HKLM-x32\...\{D3694B69-6F8C-42D3-8A0A-EB2AB528C02C}) (Version: 7.0 - Atheros)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.36 - Atheros Communications Inc.)
ATI Catalyst Install Manager (HKLM\...\{C3E6E2B5-DEB5-235A-4999-4D424C11788B}) (Version: 3.0.808.0 - ATI Technologies, Inc.)
ATI Uninstaller (HKLM\...\ATI Uninstaller) (Version: 8.813.3.2-110324a-116588C-Lenovo - ATI Technologies, Inc.)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
Benutzerhandbuch (x32 Version: 1.0.0.6 - Lenovo) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0324.2228.38483 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2011.0324.2228.38483 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2011.0324.2228.38483 - ATI) Hidden
Catalyst Control Center Profiles Mobile (x32 Version: 2011.0324.2228.38483 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Czech (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Danish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Dutch (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help English (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Finnish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help French (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help German (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Greek (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Italian (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Japanese (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Korean (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Polish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Russian (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Spanish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Swedish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Thai (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
CCC Help Turkish (x32 Version: 2011.0324.2227.38483 - ATI) Hidden
ccc-core-static (x32 Version: 2011.0324.2228.38483 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2011.0324.2228.38483 - ATI) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.15 - Piriform)
ClipGrab 3.2.0.10 (HKLM-x32\...\{8A1033B0-EF33-4FB5-97A1-C47A7DCDD7E6}_is1) (Version: - Philipp Schmieder Medien)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.1.0 - Conexant)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
ElsterFormular (HKLM-x32\...\ElsterFormular 13.0.0.8086p) (Version: 13.0.0.8086p - Landesfinanzdirektion Thüringen)
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.0 - Lenovo)
Energy Management (x32 Version: 6.0.2.0 - Lenovo) Hidden
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Free YouTube to MP3 Converter version 3.12.20.1230 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.20.1230 - DVDVideoSoft Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 7.0.517.43 - Google Inc.)
Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3074 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.10.1209.1 - Lenovo EasyCamera)
Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.6 - Lenovo)
Lenovo Games Console (HKLM-x32\...\Lenovo Games Console) (Version: 1.2.6.436 - Oberon Media Inc.)
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 7.0.1628 - CyberLink Corp.) Hidden
Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3728 - CyberLink Corp.)
Lenovo YouCam (x32 Version: 3.1.3728 - CyberLink Corp.) Hidden
Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft IntelliPoint 8.2 (HKLM\...\Microsoft IntelliPoint 8.2) (Version: 8.20.468.0 - Microsoft Corporation)
Microsoft IntelliPoint 8.2 (Version: 8.20.468.0 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
Nur Entfernen der CopyTrans Suite möglich (HKCU\...\CopyTrans Suite) (Version: 2.34 - WindSolutions)
OpenOffice.org 3.4 (HKLM-x32\...\{4C552FD3-2CCD-4E00-AC64-0681DBB3F8B5}) (Version: 3.4.9590 - OpenOffice.org)
PDF24 Creator 5.2.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.4.2 - Frank Heindörfer, Philip Chinery)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.7303 - CyberLink Corp.)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10003 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
SopCast 3.4.8 (HKLM-x32\...\SopCast) (Version: 3.4.8 - www.sopcast.com)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.0.0 - Synaptics Incorporated)
UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.6 - Lenovo)
VeriFace (HKLM-x32\...\VeriFace) (Version: 4.0.0.1224 - Lenovo)
VLC media player 2.0.1 (HKLM-x32\...\VLC media player) (Version: 2.0.1 - VideoLAN)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows-Treiberpaket - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)
WMV9/VC-1 Video Playback (Version: 1.00.0000 - ATI Technologies Inc.) Hidden
==================== Restore Points =========================
22-03-2014 09:32:39 Windows Update
22-03-2014 10:47:27 Windows Update
28-03-2014 15:00:17 Windows Update
01-04-2014 07:12:29 Windows Update
10-04-2014 04:08:02 Windows Update
10-04-2014 04:13:51 Windows Update
15-04-2014 16:59:09 Windows Update
19-04-2014 07:32:50 Windows Update
23-04-2014 18:54:27 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {27CD145D-A9C2-4754-B9BF-29F8A6DACD79} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-29] (CyberLink)
Task: {30A5F4A5-D235-4BC0-B96F-D36708FD05F8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-24] (Google Inc.)
Task: {3D8A5982-1B07-4CD9-B3BA-C9B0054D4A68} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-08-01] (Microsoft Corporation)
Task: {6D124FF4-D929-4CDB-8719-57BD45F62B50} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {FB8C0B16-D800-4FAB-9818-E3CEB9F4A6D4} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-09] (Adobe Systems Incorporated)
Task: {FFF66D4A-54F8-4060-B237-6FD9E9D92358} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-24] (Google Inc.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2011-11-24 16:04 - 2011-11-24 16:03 - 01508192 _____ () C:\windows\system32\IcnOvrly.dll
2011-11-24 16:04 - 2011-11-24 16:03 - 00628064 _____ () C:\windows\system32\SimpleExt.dll
2011-11-24 15:35 - 2011-03-25 11:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2008-12-20 05:20 - 2011-11-24 16:14 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2008-12-20 05:20 - 2011-11-24 16:14 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2014-02-13 22:46 - 2014-01-14 21:46 - 03140608 _____ () C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
2013-05-04 20:09 - 2013-05-04 20:05 - 00397704 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-11-24 16:03 - 2011-11-24 16:03 - 00013664 _____ () C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll
2014-02-19 19:59 - 2014-02-19 19:59 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\aeb07412ad41bff851002a4cd8ed97d1\IsdiInterop.ni.dll
2011-11-24 15:34 - 2011-02-18 10:16 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2014-03-29 13:19 - 2014-03-29 13:19 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/23/2014 09:35:45 PM) (Source: Application Hang) (User: )
Description: Programm mbam.exe, Version 1.0.0.500 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 13c8
Startzeit: 01cf5f251826bba0
Endzeit: 15
Anwendungspfad: C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Berichts-ID: 6fe2b746-cb1e-11e3-98e9-dc0ea16c7a7d
Error: (04/23/2014 09:04:12 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (04/23/2014 09:04:12 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (04/23/2014 09:04:11 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (04/23/2014 08:48:51 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC
Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC
Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC
Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC
Error: (04/21/2014 07:10:04 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (04/23/2014 08:47:15 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/21/2014 07:08:29 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/21/2014 02:05:22 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/21/2014 11:51:18 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/21/2014 09:01:50 AM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005
Error: (04/21/2014 08:59:00 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/20/2014 06:24:09 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/20/2014 08:13:05 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/19/2014 01:31:17 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/19/2014 11:24:37 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Client Virtualization Handler" ist vom Dienst "Application Virtualization Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1053
Microsoft Office Sessions:
=========================
Error: (04/23/2014 09:35:45 PM) (Source: Application Hang)(User: )
Description: mbam.exe1.0.0.50013c801cf5f251826bba015C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe6fe2b746-cb1e-11e3-98e9-dc0ea16c7a7d
Error: (04/23/2014 09:04:12 PM) (Source: SideBySide)(User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\***\Downloads\esetsmartinstaller_deu(1).exe
Error: (04/23/2014 09:04:12 PM) (Source: SideBySide)(User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\***\Downloads\esetsmartinstaller_deu(1).exe
Error: (04/23/2014 09:04:11 PM) (Source: SideBySide)(User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\***\Downloads\esetsmartinstaller_deu.exe
Error: (04/23/2014 08:48:51 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord)(User: )
Description:
Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord)(User: )
Description:
Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord)(User: )
Description:
Error: (04/21/2014 08:02:53 PM) (Source: ATIeRecord)(User: )
Description:
Error: (04/21/2014 07:10:04 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Percentage of memory in use: 41%
Total physical RAM: 4039.86 MB
Available physical RAM: 2375.67 MB
Total Pagefile: 8077.9 MB
Available Pagefile: 6161.13 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:421.81 GB) (Free:332.37 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:26.59 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 1ADBAB2B)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=422 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=15 GB) - (Type=12)
==================== End Of Log ============================
Gmer Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-04-23 22:07:57
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0011 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\***\AppData\Local\Temp\kxldypow.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2616] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2616] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77]
.text ... * 2
.text C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe[2980] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77]
.text C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe[2980] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77]
.text ... * 2
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[3252] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77]
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[3252] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77]
.text ... * 2
---- Processes - GMER 2.1 ----
Process C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe (*** suspicious ***) @ C:\Users\***\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [2980](2014-02-13 20:46:39) 0000000000f10000
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076fc1a13
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076fc1a13 (not active ControlSet)
---- EOF - GMER 2.1 ----
|