BuckWheat | 17.05.2014 12:19 | Hi,
mit den Logs ist etwas schiefgegangen.
Die Logs hatte ich mir in einen Ordner abgelegt.
Nach dem Ausführen von JRT wurde dieser Ordner gelöscht.
Deshalb fehlen die Logs von Malware, Adv cleaner, nur das von JRT ist noch da.
Die Programme sind auch bis auf Malware und Revo wieder entfernt worden.
Sieht nach einer Systemrückstellung aus.
Hir das JRT Log: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by admin on 17.05.2014 at 1:35:52,47
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\user pinned\taskbar\startfenster.lnk"
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\d9stfx7p.default\minidumps [3 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17.05.2014 at 1:42:08,16
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRT wieder runtergeladen und Log erstellt:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-05-2014
Ran by admin (administrator) on JOERN-PC on 17-05-2014 02:04:16
Running from C:\Users\admin\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Hauppauge Computer Works) D:\Programme\WinTV\TVServer\HauppaugeTVServer.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Kinetic Jump Software, LLC) C:\Program Files (x86)\Common Files\AppLifeUpdateService2\kjsausvc.exe
(Hauppauge Computer Works) D:\Programme\WinTV\TVServer\CaptureGenPCI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TomTom) C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe
(Hauppauge Computer Works) D:\Programme\WinTV\Ir.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Hauppauge Computer Works, Inc.) D:\Programme\WinTV\WinTV7\WinTVTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor)
HKLM\...\Run: [THXCfg64] => C:\Windows\system32\THXCfg64.dll [26624 2011-05-13] (Creative Technology Ltd.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-02-07] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation)
HKLM-x32\...\Run: [XFastUSB] => C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5019360 2013-01-12] (FNet Co., Ltd.)
HKLM-x32\...\Run: [THX TruStudio NB Settings] => C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM\...\RunOnce: [*WerKernelReporting] - %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq [415232 2009-07-14] (Microsoft Corporation)
HKLM-x32\...\Runonce: [SpUninstallCleanUp] - REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect /f [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\Run: [ASRockXTU] => [X]
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\Run: [MyTomTomSA.exe] => C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [458680 2013-08-01] (TomTom)
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\MountPoints2: G - "G:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\MountPoints2: {1eafcd0e-5c46-11e2-8641-bc5ff43d783c} - "G:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-1196304418-2561846535-3657677396-1001\...\Run: [MyTomTomSA.exe] => C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [458680 2013-08-01] (TomTom)
HKU\S-1-5-21-1196304418-2561846535-3657677396-1001\...\Run: [Hudl Mercury] => C:\Program Files (x86)\Hudl Mercury\HudlMercury.exe [3396760 2013-12-04] (Agile Sports Technologies)
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
ShortcutTarget: Logitech . Produktregistrierung.lnk -> C:\Program Files (x86)\Logitech\Ereg\eReg.exe (Leader Technologies/Logitech)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoStart IR.lnk
ShortcutTarget: AutoStart IR.lnk -> D:\Programme\WinTV\Ir.exe (Hauppauge Computer Works)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinTV Recording Status.lnk
ShortcutTarget: WinTV Recording Status.lnk -> D:\Programme\WinTV\WinTV7\WinTVTray.exe (Hauppauge Computer Works, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hattrick.org/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=protegere
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\d9stfx7p.default
FF Homepage: hxxp://www.hattrick.org
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Protegere - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\d9stfx7p.default\Extensions\security@protegere.org [2014-04-09]
FF HKCU\...\Firefox\Extensions: [{07e403c0-41ac-420d-8d82-3a4d196059a8}] - C:\Program Files (x86)\best-markit Corp\158.xpi
FF Extension: No Name - C:\Program Files (x86)\best-markit Corp\158.xpi [2014-04-09]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-22] (Avira Operations GmbH & Co. KG)
R2 HauppaugeTVServer; D:\Programme\WinTV\TVServer\HauppaugeTVServer.exe [577536 2013-01-25] (Hauppauge Computer Works)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-07] ()
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
R2 KjsUpdateService2; C:\Program Files (x86)\Common Files\AppLifeUpdateService2\kjsausvc.exe [12800 2011-08-02] (Kinetic Jump Software, LLC)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [31016 2012-01-13] (ASRock Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
R3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2014-04-10] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-01-12] (FNet Co., Ltd.)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-05-17] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-17 02:04 - 2014-05-17 02:04 - 00014436 _____ () C:\Users\admin\Desktop\FRST.txt
2014-05-17 02:00 - 2014-05-17 02:00 - 02067456 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2014-05-17 01:53 - 2014-05-17 01:53 - 00001146 _____ () C:\Users\joern\Desktop\mbam.txt
2014-05-17 01:42 - 2014-05-17 01:42 - 00000899 _____ () C:\Users\admin\Desktop\JRT.txt
2014-05-17 01:35 - 2014-05-17 01:35 - 00000000 ____D () C:\Windows\ERUNT
2014-05-17 01:32 - 2014-05-17 01:32 - 01016261 _____ (Thisisu) C:\Users\joern\Desktop\JRT.exe
2014-05-16 19:59 - 2014-05-17 01:34 - 00000000 ____D () C:\AdwCleaner
2014-05-16 19:58 - 2014-05-16 19:58 - 01325827 _____ () C:\Users\joern\Desktop\adwcleaner_3.208.exe
2014-05-16 19:56 - 2014-05-16 19:56 - 00004830 _____ () C:\Users\joern\Desktop\malware.txt
2014-05-16 19:33 - 2014-05-16 19:33 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-16 19:32 - 2014-05-16 19:32 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-16 19:32 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-16 19:32 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-16 19:32 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-16 19:31 - 2014-05-16 19:31 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\joern\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 19:54 - 2014-05-15 19:54 - 00026672 _____ () C:\ComboFix.txt
2014-05-15 19:44 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-15 19:44 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-15 19:44 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-15 19:43 - 2014-05-15 19:54 - 00000000 ____D () C:\Qoobox
2014-05-15 19:43 - 2014-05-15 19:42 - 05200050 ____R (Swearware) C:\Users\joern\Desktop\ComboFix.exe
2014-05-15 19:42 - 2014-05-15 19:53 - 00000000 ____D () C:\Windows\erdnt
2014-05-15 19:41 - 2014-05-15 19:42 - 05200050 ____R (Swearware) C:\Users\joern\Downloads\ComboFix.exe
2014-05-15 19:35 - 2014-05-15 19:35 - 00001268 _____ () C:\Users\admin\Desktop\Revo Uninstaller.lnk
2014-05-15 19:35 - 2014-05-15 19:35 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-15 19:32 - 2014-05-15 19:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\joern\Downloads\revosetup95.exe
2014-05-14 18:55 - 2014-05-15 19:39 - 00017478 _____ () C:\Users\joern\Desktop\Addition.txt
2014-05-14 18:53 - 2014-05-17 02:04 - 00000000 ____D () C:\FRST
2014-05-14 18:53 - 2014-05-14 19:07 - 00019061 _____ () C:\Users\joern\Desktop\FRST.txt
2014-05-14 18:52 - 2014-05-14 18:52 - 02066944 _____ (Farbar) C:\Users\joern\Desktop\FRST64.exe
2014-05-14 18:50 - 2014-05-14 18:50 - 00000000 ____D () C:\Users\joern\AppData\Roaming\DropboxMaster
2014-05-13 20:48 - 2014-05-13 20:48 - 00283144 _____ (Mozilla) C:\Users\joern\Downloads\Firefox Setup Stub 29.0.1.exe
2014-05-08 21:15 - 2014-05-17 01:26 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
==================== One Month Modified Files and Folders =======
2014-05-17 02:04 - 2014-05-17 02:04 - 00014436 _____ () C:\Users\admin\Desktop\FRST.txt
2014-05-17 02:04 - 2014-05-14 18:53 - 00000000 ____D () C:\FRST
2014-05-17 02:00 - 2014-05-17 02:00 - 02067456 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2014-05-17 01:53 - 2014-05-17 01:53 - 00001146 _____ () C:\Users\joern\Desktop\mbam.txt
2014-05-17 01:51 - 2014-02-06 12:30 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-17 01:42 - 2014-05-17 01:42 - 00000899 _____ () C:\Users\admin\Desktop\JRT.txt
2014-05-17 01:35 - 2014-05-17 01:35 - 00000000 ____D () C:\Windows\ERUNT
2014-05-17 01:34 - 2014-05-16 19:59 - 00000000 ____D () C:\AdwCleaner
2014-05-17 01:34 - 2009-07-14 06:45 - 00026720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-17 01:34 - 2009-07-14 06:45 - 00026720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-17 01:32 - 2014-05-17 01:32 - 01016261 _____ (Thisisu) C:\Users\joern\Desktop\JRT.exe
2014-05-17 01:32 - 2013-01-09 07:02 - 00696132 _____ () C:\Windows\system32\perfh007.dat
2014-05-17 01:32 - 2013-01-09 07:02 - 00147428 _____ () C:\Windows\system32\perfc007.dat
2014-05-17 01:32 - 2009-07-14 07:13 - 01611160 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-17 01:27 - 2013-01-12 00:12 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-05-17 01:26 - 2014-05-08 21:15 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2014-05-17 01:26 - 2014-04-09 21:26 - 00000402 _____ () C:\Windows\Tasks\best-markit_wd.job
2014-05-17 01:26 - 2014-04-09 21:26 - 00000400 _____ () C:\Windows\Tasks\best-markit Update.job
2014-05-17 01:26 - 2013-09-09 21:14 - 00000000 ____D () C:\Users\joern\AppData\Local\FreePDF_XP
2014-05-17 01:26 - 2013-01-12 00:17 - 00034752 _____ () C:\Windows\system32\Drivers\WPRO_41_2001.sys
2014-05-17 01:26 - 2010-11-21 05:47 - 00228734 _____ () C:\Windows\PFRO.log
2014-05-17 01:26 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-17 01:26 - 2009-07-14 06:51 - 00062659 _____ () C:\Windows\setupact.log
2014-05-17 01:25 - 2013-01-08 22:10 - 01469765 _____ () C:\Windows\WindowsUpdate.log
2014-05-16 19:58 - 2014-05-16 19:58 - 01325827 _____ () C:\Users\joern\Desktop\adwcleaner_3.208.exe
2014-05-16 19:56 - 2014-05-16 19:56 - 00004830 _____ () C:\Users\joern\Desktop\malware.txt
2014-05-16 19:56 - 2014-04-09 21:26 - 00000000 ____D () C:\Program Files (x86)\best-markit Corp
2014-05-16 19:48 - 2013-02-23 01:02 - 00000000 ____D () C:\Users\joern\AppData\Local\TSVNCache
2014-05-16 19:33 - 2014-05-16 19:33 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-16 19:33 - 2013-02-23 02:42 - 00000000 ____D () C:\Users\admin\AppData\Local\TSVNCache
2014-05-16 19:32 - 2014-05-16 19:32 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-16 19:31 - 2014-05-16 19:31 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\joern\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 20:03 - 2013-02-23 01:10 - 00000000 ___RD () C:\Users\joern\Dropbox
2014-05-15 19:55 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-05-15 19:54 - 2014-05-15 19:54 - 00026672 _____ () C:\ComboFix.txt
2014-05-15 19:54 - 2014-05-15 19:43 - 00000000 ____D () C:\Qoobox
2014-05-15 19:53 - 2014-05-15 19:42 - 00000000 ____D () C:\Windows\erdnt
2014-05-15 19:53 - 2013-01-08 22:10 - 00000000 ___RD () C:\Users\joern\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 19:53 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-15 19:42 - 2014-05-15 19:43 - 05200050 ____R (Swearware) C:\Users\joern\Desktop\ComboFix.exe
2014-05-15 19:42 - 2014-05-15 19:41 - 05200050 ____R (Swearware) C:\Users\joern\Downloads\ComboFix.exe
2014-05-15 19:39 - 2014-05-14 18:55 - 00017478 _____ () C:\Users\joern\Desktop\Addition.txt
2014-05-15 19:35 - 2014-05-15 19:35 - 00001268 _____ () C:\Users\admin\Desktop\Revo Uninstaller.lnk
2014-05-15 19:35 - 2014-05-15 19:35 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-15 19:32 - 2014-05-15 19:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\joern\Downloads\revosetup95.exe
2014-05-15 19:29 - 2013-02-23 01:05 - 00000000 ____D () C:\Users\joern\AppData\Roaming\Dropbox
2014-05-14 19:07 - 2014-05-14 18:53 - 00019061 _____ () C:\Users\joern\Desktop\FRST.txt
2014-05-14 18:52 - 2014-05-14 18:52 - 02066944 _____ (Farbar) C:\Users\joern\Desktop\FRST64.exe
2014-05-14 18:50 - 2014-05-14 18:50 - 00000000 ____D () C:\Users\joern\AppData\Roaming\DropboxMaster
2014-05-14 18:50 - 2013-02-23 01:10 - 00000979 _____ () C:\Users\joern\Desktop\Dropbox.lnk
2014-05-14 18:50 - 2013-02-23 01:07 - 00000000 ____D () C:\Users\joern\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-14 18:48 - 2014-03-30 10:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-14 18:48 - 2013-01-12 00:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-13 21:51 - 2014-02-06 12:30 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-13 21:51 - 2013-01-12 00:48 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-13 21:51 - 2013-01-12 00:48 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-13 20:50 - 2013-01-12 00:47 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-13 20:50 - 2013-01-12 00:47 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-05-13 20:48 - 2014-05-13 20:48 - 00283144 _____ (Mozilla) C:\Users\joern\Downloads\Firefox Setup Stub 29.0.1.exe
2014-05-13 08:42 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-07 22:44 - 2013-02-03 16:43 - 00000000 ____D () C:\Users\joern\AppData\Roaming\Skype
Some content of TEMP:
====================
C:\Users\joern\AppData\Local\temp\avgnt.exe
C:\Users\joern\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpnjoyvp.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-12 21:23
==================== End Of Log ============================ --- --- ---
--- --- ---
FRT Addition:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-05-2014
Ran by admin (administrator) on JOERN-PC on 17-05-2014 02:07:19
Running from C:\Users\admin\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Hauppauge Computer Works) D:\Programme\WinTV\TVServer\HauppaugeTVServer.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Kinetic Jump Software, LLC) C:\Program Files (x86)\Common Files\AppLifeUpdateService2\kjsausvc.exe
(Hauppauge Computer Works) D:\Programme\WinTV\TVServer\CaptureGenPCI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TomTom) C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe
(Hauppauge Computer Works) D:\Programme\WinTV\Ir.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Hauppauge Computer Works, Inc.) D:\Programme\WinTV\WinTV7\WinTVTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor)
HKLM\...\Run: [THXCfg64] => C:\Windows\system32\THXCfg64.dll [26624 2011-05-13] (Creative Technology Ltd.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-02-07] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation)
HKLM-x32\...\Run: [XFastUSB] => C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5019360 2013-01-12] (FNet Co., Ltd.)
HKLM-x32\...\Run: [THX TruStudio NB Settings] => C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM\...\RunOnce: [*WerKernelReporting] - %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq [415232 2009-07-14] (Microsoft Corporation)
HKLM-x32\...\Runonce: [SpUninstallCleanUp] - REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect /f [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\Run: [ASRockXTU] => [X]
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\Run: [MyTomTomSA.exe] => C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [458680 2013-08-01] (TomTom)
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\MountPoints2: G - "G:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\MountPoints2: {1eafcd0e-5c46-11e2-8641-bc5ff43d783c} - "G:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-1196304418-2561846535-3657677396-1001\...\Run: [MyTomTomSA.exe] => C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [458680 2013-08-01] (TomTom)
HKU\S-1-5-21-1196304418-2561846535-3657677396-1001\...\Run: [Hudl Mercury] => C:\Program Files (x86)\Hudl Mercury\HudlMercury.exe [3396760 2013-12-04] (Agile Sports Technologies)
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
ShortcutTarget: Logitech . Produktregistrierung.lnk -> C:\Program Files (x86)\Logitech\Ereg\eReg.exe (Leader Technologies/Logitech)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoStart IR.lnk
ShortcutTarget: AutoStart IR.lnk -> D:\Programme\WinTV\Ir.exe (Hauppauge Computer Works)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinTV Recording Status.lnk
ShortcutTarget: WinTV Recording Status.lnk -> D:\Programme\WinTV\WinTV7\WinTVTray.exe (Hauppauge Computer Works, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hattrick.org/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=protegere
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\d9stfx7p.default
FF Homepage: hxxp://www.hattrick.org
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Protegere - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\d9stfx7p.default\Extensions\security@protegere.org [2014-04-09]
FF HKCU\...\Firefox\Extensions: [{07e403c0-41ac-420d-8d82-3a4d196059a8}] - C:\Program Files (x86)\best-markit Corp\158.xpi
FF Extension: No Name - C:\Program Files (x86)\best-markit Corp\158.xpi [2014-04-09]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-22] (Avira Operations GmbH & Co. KG)
R2 HauppaugeTVServer; D:\Programme\WinTV\TVServer\HauppaugeTVServer.exe [577536 2013-01-25] (Hauppauge Computer Works)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-07] ()
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
R2 KjsUpdateService2; C:\Program Files (x86)\Common Files\AppLifeUpdateService2\kjsausvc.exe [12800 2011-08-02] (Kinetic Jump Software, LLC)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [31016 2012-01-13] (ASRock Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
R3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2014-04-10] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-01-12] (FNet Co., Ltd.)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-05-17] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-17 02:04 - 2014-05-17 02:07 - 00014436 _____ () C:\Users\admin\Desktop\FRST.txt
2014-05-17 02:00 - 2014-05-17 02:00 - 02067456 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2014-05-17 01:53 - 2014-05-17 01:53 - 00001146 _____ () C:\Users\joern\Desktop\mbam.txt
2014-05-17 01:42 - 2014-05-17 01:42 - 00000899 _____ () C:\Users\admin\Desktop\JRT.txt
2014-05-17 01:35 - 2014-05-17 01:35 - 00000000 ____D () C:\Windows\ERUNT
2014-05-17 01:32 - 2014-05-17 01:32 - 01016261 _____ (Thisisu) C:\Users\joern\Desktop\JRT.exe
2014-05-16 19:59 - 2014-05-17 01:34 - 00000000 ____D () C:\AdwCleaner
2014-05-16 19:58 - 2014-05-16 19:58 - 01325827 _____ () C:\Users\joern\Desktop\adwcleaner_3.208.exe
2014-05-16 19:56 - 2014-05-16 19:56 - 00004830 _____ () C:\Users\joern\Desktop\malware.txt
2014-05-16 19:33 - 2014-05-16 19:33 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-16 19:32 - 2014-05-16 19:32 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-16 19:32 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-16 19:32 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-16 19:32 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-16 19:31 - 2014-05-16 19:31 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\joern\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 19:54 - 2014-05-15 19:54 - 00026672 _____ () C:\ComboFix.txt
2014-05-15 19:44 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-15 19:44 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-15 19:44 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-15 19:43 - 2014-05-15 19:54 - 00000000 ____D () C:\Qoobox
2014-05-15 19:43 - 2014-05-15 19:42 - 05200050 ____R (Swearware) C:\Users\joern\Desktop\ComboFix.exe
2014-05-15 19:42 - 2014-05-15 19:53 - 00000000 ____D () C:\Windows\erdnt
2014-05-15 19:41 - 2014-05-15 19:42 - 05200050 ____R (Swearware) C:\Users\joern\Downloads\ComboFix.exe
2014-05-15 19:35 - 2014-05-15 19:35 - 00001268 _____ () C:\Users\admin\Desktop\Revo Uninstaller.lnk
2014-05-15 19:35 - 2014-05-15 19:35 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-15 19:32 - 2014-05-15 19:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\joern\Downloads\revosetup95.exe
2014-05-14 18:55 - 2014-05-15 19:39 - 00017478 _____ () C:\Users\joern\Desktop\Addition.txt
2014-05-14 18:53 - 2014-05-17 02:07 - 00000000 ____D () C:\FRST
2014-05-14 18:53 - 2014-05-14 19:07 - 00019061 _____ () C:\Users\joern\Desktop\FRST.txt
2014-05-14 18:52 - 2014-05-14 18:52 - 02066944 _____ (Farbar) C:\Users\joern\Desktop\FRST64.exe
2014-05-14 18:50 - 2014-05-14 18:50 - 00000000 ____D () C:\Users\joern\AppData\Roaming\DropboxMaster
2014-05-13 20:48 - 2014-05-13 20:48 - 00283144 _____ (Mozilla) C:\Users\joern\Downloads\Firefox Setup Stub 29.0.1.exe
2014-05-08 21:15 - 2014-05-17 01:26 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
==================== One Month Modified Files and Folders =======
2014-05-17 02:07 - 2014-05-17 02:04 - 00014436 _____ () C:\Users\admin\Desktop\FRST.txt
2014-05-17 02:07 - 2014-05-14 18:53 - 00000000 ____D () C:\FRST
2014-05-17 02:00 - 2014-05-17 02:00 - 02067456 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2014-05-17 01:53 - 2014-05-17 01:53 - 00001146 _____ () C:\Users\joern\Desktop\mbam.txt
2014-05-17 01:51 - 2014-02-06 12:30 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-17 01:42 - 2014-05-17 01:42 - 00000899 _____ () C:\Users\admin\Desktop\JRT.txt
2014-05-17 01:35 - 2014-05-17 01:35 - 00000000 ____D () C:\Windows\ERUNT
2014-05-17 01:34 - 2014-05-16 19:59 - 00000000 ____D () C:\AdwCleaner
2014-05-17 01:34 - 2009-07-14 06:45 - 00026720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-17 01:34 - 2009-07-14 06:45 - 00026720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-17 01:32 - 2014-05-17 01:32 - 01016261 _____ (Thisisu) C:\Users\joern\Desktop\JRT.exe
2014-05-17 01:32 - 2013-01-09 07:02 - 00696132 _____ () C:\Windows\system32\perfh007.dat
2014-05-17 01:32 - 2013-01-09 07:02 - 00147428 _____ () C:\Windows\system32\perfc007.dat
2014-05-17 01:32 - 2009-07-14 07:13 - 01611160 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-17 01:31 - 2013-01-08 22:10 - 01469765 _____ () C:\Windows\WindowsUpdate.log
2014-05-17 01:27 - 2013-01-12 00:12 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-05-17 01:26 - 2014-05-08 21:15 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2014-05-17 01:26 - 2014-04-09 21:26 - 00000402 _____ () C:\Windows\Tasks\best-markit_wd.job
2014-05-17 01:26 - 2014-04-09 21:26 - 00000400 _____ () C:\Windows\Tasks\best-markit Update.job
2014-05-17 01:26 - 2013-09-09 21:14 - 00000000 ____D () C:\Users\joern\AppData\Local\FreePDF_XP
2014-05-17 01:26 - 2013-01-12 00:17 - 00034752 _____ () C:\Windows\system32\Drivers\WPRO_41_2001.sys
2014-05-17 01:26 - 2010-11-21 05:47 - 00228734 _____ () C:\Windows\PFRO.log
2014-05-17 01:26 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-17 01:26 - 2009-07-14 06:51 - 00062659 _____ () C:\Windows\setupact.log
2014-05-16 19:58 - 2014-05-16 19:58 - 01325827 _____ () C:\Users\joern\Desktop\adwcleaner_3.208.exe
2014-05-16 19:56 - 2014-05-16 19:56 - 00004830 _____ () C:\Users\joern\Desktop\malware.txt
2014-05-16 19:56 - 2014-04-09 21:26 - 00000000 ____D () C:\Program Files (x86)\best-markit Corp
2014-05-16 19:48 - 2013-02-23 01:02 - 00000000 ____D () C:\Users\joern\AppData\Local\TSVNCache
2014-05-16 19:33 - 2014-05-16 19:33 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-16 19:33 - 2013-02-23 02:42 - 00000000 ____D () C:\Users\admin\AppData\Local\TSVNCache
2014-05-16 19:32 - 2014-05-16 19:32 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-16 19:31 - 2014-05-16 19:31 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\joern\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 20:03 - 2013-02-23 01:10 - 00000000 ___RD () C:\Users\joern\Dropbox
2014-05-15 19:55 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-05-15 19:54 - 2014-05-15 19:54 - 00026672 _____ () C:\ComboFix.txt
2014-05-15 19:54 - 2014-05-15 19:43 - 00000000 ____D () C:\Qoobox
2014-05-15 19:53 - 2014-05-15 19:42 - 00000000 ____D () C:\Windows\erdnt
2014-05-15 19:53 - 2013-01-08 22:10 - 00000000 ___RD () C:\Users\joern\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 19:53 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-15 19:42 - 2014-05-15 19:43 - 05200050 ____R (Swearware) C:\Users\joern\Desktop\ComboFix.exe
2014-05-15 19:42 - 2014-05-15 19:41 - 05200050 ____R (Swearware) C:\Users\joern\Downloads\ComboFix.exe
2014-05-15 19:39 - 2014-05-14 18:55 - 00017478 _____ () C:\Users\joern\Desktop\Addition.txt
2014-05-15 19:35 - 2014-05-15 19:35 - 00001268 _____ () C:\Users\admin\Desktop\Revo Uninstaller.lnk
2014-05-15 19:35 - 2014-05-15 19:35 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-15 19:32 - 2014-05-15 19:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\joern\Downloads\revosetup95.exe
2014-05-15 19:29 - 2013-02-23 01:05 - 00000000 ____D () C:\Users\joern\AppData\Roaming\Dropbox
2014-05-14 19:07 - 2014-05-14 18:53 - 00019061 _____ () C:\Users\joern\Desktop\FRST.txt
2014-05-14 18:52 - 2014-05-14 18:52 - 02066944 _____ (Farbar) C:\Users\joern\Desktop\FRST64.exe
2014-05-14 18:50 - 2014-05-14 18:50 - 00000000 ____D () C:\Users\joern\AppData\Roaming\DropboxMaster
2014-05-14 18:50 - 2013-02-23 01:10 - 00000979 _____ () C:\Users\joern\Desktop\Dropbox.lnk
2014-05-14 18:50 - 2013-02-23 01:07 - 00000000 ____D () C:\Users\joern\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-14 18:48 - 2014-03-30 10:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-14 18:48 - 2013-01-12 00:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-13 21:51 - 2014-02-06 12:30 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-13 21:51 - 2013-01-12 00:48 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-13 21:51 - 2013-01-12 00:48 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-13 20:50 - 2013-01-12 00:47 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-13 20:50 - 2013-01-12 00:47 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-05-13 20:48 - 2014-05-13 20:48 - 00283144 _____ (Mozilla) C:\Users\joern\Downloads\Firefox Setup Stub 29.0.1.exe
2014-05-13 08:42 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-07 22:44 - 2013-02-03 16:43 - 00000000 ____D () C:\Users\joern\AppData\Roaming\Skype
Some content of TEMP:
====================
C:\Users\joern\AppData\Local\temp\avgnt.exe
C:\Users\joern\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpnjoyvp.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-12 21:23
==================== End Of Log ============================ --- --- ---
--- --- ---
Hier gibt es wieder ein Attention:
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
Gruss
Buck
Nachtrag.
Heute nach dem Hochfahren waren der Ordner mit den Logs wieder da.
Auch scheint das System nochmals wiederhergestellt worden zu sein.
Bildschirmauflösung etc sind wieder die alten.
Ich maile mal die fehlenden Logs.
Firefox arbeitet schon wieder wie früher, da gibt es Erfolge zu melden.
Im FRT Log ist noch ein Attention.
Gruss
Buck
AdwCleaner[R0] Code:
# AdwCleaner v3.208 - Bericht erstellt am 16/05/2014 um 19:59:59
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : admin - JOERN-PC
# Gestartet von : C:\Users\joern\Desktop\adwcleaner_3.208.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
Datei Gefunden : C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\d9stfx7p.default\user.js
Ordner Gefunden : C:\Program Files (x86)\RrSavings
Ordner Gefunden : C:\Program Files\002
Ordner Gefunden : C:\Program Files\RrSavings
Ordner Gefunden : C:\Users\admin\AppData\Roaming\BupSystem
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\RrSavings
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\OCS
Schlüssel Gefunden : HKLM\Software\Classes\Installer\Features\07BF6653227E2814286618E5EA689289
Schlüssel Gefunden : HKLM\Software\Classes\Installer\Products\07BF6653227E2814286618E5EA689289
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3566FB70-E722-4182-8266-815EAE862998}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RrSavings
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\RrSavings
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16476
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\d9stfx7p.default\prefs.js ]
[ Datei : C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\prefs.js ]
Zeile gefunden : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?gd=&ctid=CT3322196&octid=EB_ORIGINAL_CTID&ISID=M450BE6AF-FF72-41A4-BDA4-24FE07A633F3&SearchSource=55&CUI=&UM=5&UP=SPFACFADE7-2D05-4DF6[...]
[ Datei : C:\Users\tvuser\AppData\Roaming\Mozilla\Firefox\Profiles\sn4agd5i.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [2418 octets] - [16/05/2014 19:59:59]
########## EOF - \AdwCleaner\AdwCleaner[R0].txt - [2478 octets] ########## AdwCleaner[R0] Code:
# AdwCleaner v3.208 - Bericht erstellt am 17/05/2014 um 01:25:11
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : admin - JOERN-PC
# Gestartet von : C:\Users\joern\Desktop\adwcleaner_3.208.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\RrSavings
Ordner Gelöscht : C:\Program Files\002
Ordner Gelöscht : C:\Program Files\RrSavings
Ordner Gelöscht : C:\Users\admin\AppData\Roaming\BupSystem
Datei Gelöscht : C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
Datei Gelöscht : C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\d9stfx7p.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\RrSavings
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3566FB70-E722-4182-8266-815EAE862998}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\RrSavings
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RrSavings
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\07BF6653227E2814286618E5EA689289
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\07BF6653227E2814286618E5EA689289
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16476
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\d9stfx7p.default\prefs.js ]
[ Datei : C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\prefs.js ]
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?gd=&ctid=CT3322196&octid=EB_ORIGINAL_CTID&ISID=M450BE6AF-FF72-41A4-BDA4-24FE07A633F3&SearchSource=55&CUI=&UM=5&UP=SPFACFADE7-2D05-4DF6[...]
[ Datei : C:\Users\tvuser\AppData\Roaming\Mozilla\Firefox\Profiles\sn4agd5i.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [2572 octets] - [16/05/2014 19:59:59]
AdwCleaner[S0].txt - [2437 octets] - [17/05/2014 01:25:11]
########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [2497 octets] ########## mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 16.05.2014 19:33:06, SYSTEM, JOERN-PC, Protection, Malware Protection, Starting,
Protection, 16.05.2014 19:33:06, SYSTEM, JOERN-PC, Protection, Malware Protection, Started,
Protection, 16.05.2014 19:33:06, SYSTEM, JOERN-PC, Protection, Malicious Website Protection, Starting,
Update, 16.05.2014 19:33:16, SYSTEM, JOERN-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Protection, 16.05.2014 19:33:21, SYSTEM, JOERN-PC, Protection, Malicious Website Protection, Started,
Update, 16.05.2014 19:33:27, SYSTEM, JOERN-PC, Manual, Malware Database, 2014.3.4.9, 2014.5.16.12,
Protection, 16.05.2014 19:33:38, SYSTEM, JOERN-PC, Protection, Refresh, Starting,
Protection, 16.05.2014 19:33:38, SYSTEM, JOERN-PC, Protection, Malicious Website Protection, Stopping,
Protection, 16.05.2014 19:33:38, SYSTEM, JOERN-PC, Protection, Malicious Website Protection, Stopped,
Protection, 16.05.2014 19:33:42, SYSTEM, JOERN-PC, Protection, Refresh, Success,
Protection, 16.05.2014 19:33:42, SYSTEM, JOERN-PC, Protection, Malicious Website Protection, Starting,
Protection, 16.05.2014 19:33:43, SYSTEM, JOERN-PC, Protection, Malicious Website Protection, Started,
Protection, 16.05.2014 19:47:58, SYSTEM, JOERN-PC, Protection, Malware Protection, Starting,
Protection, 16.05.2014 19:47:58, SYSTEM, JOERN-PC, Protection, Malware Protection, Started,
Protection, 16.05.2014 19:47:58, SYSTEM, JOERN-PC, Protection, Malicious Website Protection, Starting,
Protection, 16.05.2014 19:49:17, SYSTEM, JOERN-PC, Protection, Malicious Website Protection, Started,
Detection, 16.05.2014 19:50:58, SYSTEM, JOERN-PC, Protection, Malware Protection, File, PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\2rs3.dll, Quarantine, [bf5d7fd3e79481b5593fbbc1976b8977]
Protection, 16.05.2014 19:50:58, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 5, Failed, C:\Program Files (x86)\RrSavings\2rs3.dll,
Error, 16.05.2014 19:50:58, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 5, Failed, C:\Program Files (x86)\RrSavings\2rs3.dll,
Detection, 16.05.2014 19:54:44, SYSTEM, JOERN-PC, Protection, Malware Protection, File, PUP.Optional.RRSavings.A, c:\program files (x86)\rrsavings\2rs3.dll, Quarantine, [bf5d7fd3e79481b5593fbbc1976b8977]
Protection, 16.05.2014 19:54:44, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\rrsavings\2rs3.dll,
Error, 16.05.2014 19:54:44, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\rrsavings\2rs3.dll,
Detection, 16.05.2014 19:54:47, SYSTEM, JOERN-PC, Protection, Malware Protection, File, PUP.Optional.RRSavings.A, c:\program files (x86)\rrsavings\2rs3.dll, Quarantine, [bf5d7fd3e79481b5593fbbc1976b8977]
Protection, 16.05.2014 19:54:47, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\rrsavings\2rs3.dll,
Error, 16.05.2014 19:54:47, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\rrsavings\2rs3.dll,
Detection, 16.05.2014 19:54:47, SYSTEM, JOERN-PC, Protection, Malware Protection, File, PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\best-markit158.exe, Quarantine, [39e321311c5f2f074ad952257989b14f]
Protection, 16.05.2014 19:54:47, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 5, Failed, C:\Program Files (x86)\best-markit Corp\best-markit158.exe,
Error, 16.05.2014 19:54:47, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 5, Failed, C:\Program Files (x86)\best-markit Corp\best-markit158.exe,
Detection, 16.05.2014 19:54:47, SYSTEM, JOERN-PC, Protection, Malware Protection, File, PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\best-markit158.dll, Quarantine, [d14b262ceb90c76f1e051f587d85847c]
Protection, 16.05.2014 19:54:47, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 5, Failed, C:\Program Files (x86)\best-markit Corp\best-markit158.dll,
Error, 16.05.2014 19:54:47, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 5, Failed, C:\Program Files (x86)\best-markit Corp\best-markit158.dll,
Detection, 16.05.2014 19:55:51, SYSTEM, JOERN-PC, Protection, Malware Protection, File, PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\best-markit158.dll, Quarantine, [d14b262ceb90c76f1e051f587d85847c]
Detection, 16.05.2014 19:55:51, SYSTEM, JOERN-PC, Protection, Malware Protection, File, PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\best-markit158.exe, Quarantine, [39e321311c5f2f074ad952257989b14f]
Protection, 16.05.2014 19:55:51, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 5, Failed, C:\Program Files (x86)\best-markit Corp\best-markit158.exe,
Error, 16.05.2014 19:55:51, SYSTEM, JOERN-PC, Protection, SDKQuarantine, 5, Failed, C:\Program Files (x86)\best-markit Corp\best-markit158.exe,
(end)
mbam2 Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 16.05.2014
Suchlauf-Zeit: 19:46:20
Logdatei: mbam2.txt
Administrator: Nein
Version: 2.00.1.1004
Malware Datenbank: v2014.05.16.12
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: joern
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 193035
Verstrichene Zeit: 12 Min, 13 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 7
Adware.Adpeak, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\bukgmhvrux64, Löschen bei Neustart, [74a830228ceff83edd9507350ff530d0],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3}, Löschen bei Neustart, [41dbd37fccaf75c14f981c0962a02cd4],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{10AD2C61-0898-4348-8600-14A342F22AC3}, Löschen bei Neustart, [41dbd37fccaf75c14f981c0962a02cd4],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\rrsavings, Löschen bei Neustart, [63b9ff53e19ad561c80f0a7e57abf907],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\rrsavings, Löschen bei Neustart, [d349f260106b59ddd2033f4905fd916f],
PUP.Optional.BestMarkIt.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\best-markit, Löschen bei Neustart, [d349232f1c5f64d26adb098eb949ad53],
PUP.Optional.BestMarkIt.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\cec73dbc-cc47-471c-a2e7-288ad572cb41, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 31
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.RRSavings.A, C:\Program Files\rrsavings, Löschen bei Neustart, [36e60b473348b77f9206106cb64c46ba],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\defaults, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\defaults\preferences, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\locale, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\addon-kit, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\addon-kit\data, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\addon-kit\lib, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\data, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\event, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\addon, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\dom, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\events, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\private-browsing, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\system, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\tabs, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\traits, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\utils, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\window, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\windows, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\RrSavings, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\RrSavings\data, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\RrSavings\lib, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\RrSavings\tests, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
Dateien: 121
Adware.Adpeak, C:\Program Files\002\bukgmhvrux64.exe, Löschen bei Neustart, [74a830228ceff83edd9507350ff530d0],
PUP.Optional.CouponDownloader.A, C:\Program Files (x86)\RrSavings\2rs3.dll, Löschen bei Neustart, [41dbd37fccaf75c14f981c0962a02cd4],
PUP.Optional.Breitschopp, C:\Users\joern\Downloads\agsetup183se.exe, In Quarantäne, [9c80f45e3d3e1422452d4eeb699b6799],
PUP.Optional.Trovi.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\searchplugins\trovi-search.xml, In Quarantäne, [23f9df73ef8ce84e37d63c47ad558c74],
PUP.Optional.BestMarkIt.A, C:\Windows\Tasks\best-markit Update.job, Löschen bei Neustart, [e03c8cc6eb90b086bd31a3eb2fd34cb4],
PUP.Optional.BestMarkIt.A, C:\Windows\Tasks\best-markit_wd.job, Löschen bei Neustart, [38e495bd82f90d29f7f7bdd1ef13e917],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\best-markit158.exe, Löschen bei Neustart, [d349232f1c5f64d26adb098eb949ad53],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\158.crx, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\158.dat, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\158.xpi, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\a.db, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\b.db, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\best-markit158.bin, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\best-markit158.dll, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\best-markit158.ini, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\best-markit_wd.exe, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\bestu.exe, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\Sqlite3.dll, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.BestMarkIt.A, C:\Program Files (x86)\best-markit Corp\Uninstall.exe, Löschen bei Neustart, [d04c520083f84ceae241c5b2a2600df3],
PUP.Optional.RRSavings.A, C:\Program Files\rrsavings\uninstaller.exe, Löschen bei Neustart, [36e60b473348b77f9206106cb64c46ba],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\background.js, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\CustomActionInstall, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\CustomActionUninstall, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon128.png, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon16.png, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon32.png, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon48.png, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon64.png, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon8.png, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\iwalyk.js, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\manifest.json, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\marcopolo.js, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\Microsoft.Deployment.WindowsInstaller.dll, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\Microsoft.Deployment.WindowsInstaller.xml, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\SendJson.dll, Löschen bei Neustart, [fc209db5b0cbd85e67315d1fba4851af],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\bootstrap.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\harness-options.json, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\icon.png, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\install.rdf, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\locales.json, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\defaults\preferences\prefs.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\addon-kit\lib\page-mod.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\addon-kit\lib\private-browsing.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\addon-kit\lib\request.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\addon-kit\lib\windows.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\observer-service.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\api-utils.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\base64.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\byte-streams.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\collection.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\cortex.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\cuddlefish.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\deprecate.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\environment.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\errors.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\events.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\file.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\functional.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\globals.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\heritage.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\hidden-frame.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\light-traits.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\list.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\loader.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\match-pattern.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\memory.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\namespace.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\plain-text-console.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\preferences-service.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\promise.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\querystring.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\runtime.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\sandbox.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\self.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\system.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\text-streams.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\timer.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\traceback.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\traits.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\unload.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\url.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\uuid.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\window-utils.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\xhr.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\xpcom.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\xul-app.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\event\core.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\event\target.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\addon\runner.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content\content-proxy.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content\content-worker.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content\loader.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content\symbiont.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content\worker.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\dom\events.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\events\assembler.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n\core.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n\html.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n\loader.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n\locale.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n\prefs.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\private-browsing\utils.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\system\events.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\tabs\events.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\tabs\observer.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\tabs\tab.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\tabs\utils.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\traits\core.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\utils\data.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\utils\object.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\utils\registry.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\utils\thumbnail.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\window\utils.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\windows\dom.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\windows\loader.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\windows\observer.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\api-utils\lib\windows\tabs.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\RrSavings\data\icon64.png, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.RRSavings.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\extensions\RrSavings@jetpack\resources\RrSavings\lib\main.js, In Quarantäne, [28f4de7498e38ea8a9f1c7b5ea188080],
PUP.Optional.Conduit.A, C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?gd=&ctid=CT3322196&octid=EB_ORIGINAL_CTID&ISID=M450BE6AF-FF72-41A4-BDA4-24FE07A633F3&SearchSource=55&CUI=&UM=5&UP=SPFACFADE7-2D05-4DF6-B089-493582693CDC&SSPV=");), Ersetzt,[51cbd0826219181e00d9f186e51fef11]
Physische Sektoren: 0
(No malicious items detected)
(end) aktuelles FRT
Ein Addition von FRT wurde nicht erzeugt.
Ein Attention ist im Log:
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-05-2014
Ran by joern (ATTENTION: The logged in user is not administrator) on JOERN-PC on 17-05-2014 13:11:30
Running from C:\Users\joern\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TomTom) C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe
(Hauppauge Computer Works) D:\Programme\WinTV\Ir.exe
(Hauppauge Computer Works, Inc.) D:\Programme\WinTV\WinTV7\WinTVTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor)
HKLM\...\Run: [THXCfg64] => C:\Windows\system32\THXCfg64.dll [26624 2011-05-13] (Creative Technology Ltd.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-02-07] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation)
HKLM-x32\...\Run: [XFastUSB] => C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5019360 2013-01-12] (FNet Co., Ltd.)
HKLM-x32\...\Run: [THX TruStudio NB Settings] => C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM\...\RunOnce: [*WerKernelReporting] - %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq [415232 2009-07-14] (Microsoft Corporation)
HKLM-x32\...\Runonce: [SpUninstallCleanUp] - REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect /f [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\Run: [ASRockXTU] => [X]
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\Run: [MyTomTomSA.exe] => C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [458680 2013-08-01] (TomTom)
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\MountPoints2: G - "G:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-1196304418-2561846535-3657677396-1000\...\MountPoints2: {1eafcd0e-5c46-11e2-8641-bc5ff43d783c} - "G:\WD SmartWare.exe" autoplay=true
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoStart IR.lnk
ShortcutTarget: AutoStart IR.lnk -> D:\Programme\WinTV\Ir.exe (Hauppauge Computer Works)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinTV Recording Status.lnk
ShortcutTarget: WinTV Recording Status.lnk -> D:\Programme\WinTV\WinTV7\WinTVTray.exe (Hauppauge Computer Works, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:13828
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?gd=&ctid=CT3322196&octid=EB_ORIGINAL_CTID&ISID=M450BE6AF-FF72-41A4-BDA4-24FE07A633F3&SearchSource=55&CUI=&UM=5&UP=SPFACFADE7-2D05-4DF6-B089-493582693CDC&SSPV=
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\joern\AppData\Roaming\Mozilla\Firefox\Profiles\f2475axk.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-22] (Avira Operations GmbH & Co. KG)
R2 HauppaugeTVServer; D:\Programme\WinTV\TVServer\HauppaugeTVServer.exe [577536 2013-01-25] (Hauppauge Computer Works)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-07] ()
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
R2 KjsUpdateService2; C:\Program Files (x86)\Common Files\AppLifeUpdateService2\kjsausvc.exe [12800 2011-08-02] (Kinetic Jump Software, LLC)
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [31016 2012-01-13] (ASRock Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
R3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2014-04-10] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-01-12] (FNet Co., Ltd.)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-05-17] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-17 13:11 - 2014-05-17 13:11 - 00012071 _____ () C:\Users\joern\Desktop\FRST.txt
2014-05-17 01:53 - 2014-05-17 01:53 - 00001146 _____ () C:\Users\joern\Desktop\mbam.txt
2014-05-17 01:35 - 2014-05-17 01:35 - 00000000 ____D () C:\Windows\ERUNT
2014-05-17 01:32 - 2014-05-17 01:32 - 01016261 _____ (Thisisu) C:\Users\joern\Desktop\JRT.exe
2014-05-16 19:59 - 2014-05-17 01:34 - 00000000 ____D () C:\AdwCleaner
2014-05-16 19:58 - 2014-05-16 19:58 - 01325827 _____ () C:\Users\joern\Desktop\adwcleaner_3.208.exe
2014-05-16 19:56 - 2014-05-16 19:56 - 00004830 _____ () C:\Users\joern\Desktop\malware.txt
2014-05-16 19:33 - 2014-05-16 19:33 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-16 19:32 - 2014-05-16 19:32 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-16 19:32 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-16 19:32 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-16 19:32 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-16 19:31 - 2014-05-16 19:31 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\joern\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 19:54 - 2014-05-15 19:54 - 00026672 _____ () C:\ComboFix.txt
2014-05-15 19:44 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-15 19:44 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-15 19:44 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-15 19:44 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-15 19:43 - 2014-05-15 19:54 - 00000000 ____D () C:\Qoobox
2014-05-15 19:43 - 2014-05-15 19:42 - 05200050 ____R (Swearware) C:\Users\joern\Desktop\ComboFix.exe
2014-05-15 19:42 - 2014-05-15 19:53 - 00000000 ____D () C:\Windows\erdnt
2014-05-15 19:41 - 2014-05-15 19:42 - 05200050 ____R (Swearware) C:\Users\joern\Downloads\ComboFix.exe
2014-05-15 19:35 - 2014-05-15 19:35 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-15 19:32 - 2014-05-15 19:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\joern\Downloads\revosetup95.exe
2014-05-14 18:53 - 2014-05-17 13:11 - 00000000 ____D () C:\FRST
2014-05-14 18:52 - 2014-05-14 18:52 - 02066944 _____ (Farbar) C:\Users\joern\Desktop\FRST64.exe
2014-05-14 18:50 - 2014-05-14 18:50 - 00000000 ____D () C:\Users\joern\AppData\Roaming\DropboxMaster
2014-05-13 20:48 - 2014-05-13 20:48 - 00283144 _____ (Mozilla) C:\Users\joern\Downloads\Firefox Setup Stub 29.0.1.exe
2014-05-08 21:15 - 2014-05-17 11:04 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
==================== One Month Modified Files and Folders =======
2014-05-17 13:11 - 2014-05-17 13:11 - 00012071 _____ () C:\Users\joern\Desktop\FRST.txt
2014-05-17 13:11 - 2014-05-14 18:53 - 00000000 ____D () C:\FRST
2014-05-17 13:03 - 2013-01-09 07:02 - 00696132 _____ () C:\Windows\system32\perfh007.dat
2014-05-17 13:03 - 2013-01-09 07:02 - 00147428 _____ () C:\Windows\system32\perfc007.dat
2014-05-17 13:03 - 2009-07-14 07:13 - 01611160 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-17 13:01 - 2014-04-09 21:26 - 00000402 _____ () C:\Windows\Tasks\best-markit_wd.job
2014-05-17 13:01 - 2014-04-09 21:26 - 00000400 _____ () C:\Windows\Tasks\best-markit Update.job
2014-05-17 13:01 - 2013-01-12 00:12 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-05-17 13:01 - 2013-01-08 22:10 - 01499993 _____ () C:\Windows\WindowsUpdate.log
2014-05-17 13:00 - 2013-09-09 21:14 - 00000000 ____D () C:\Users\joern\AppData\Local\FreePDF_XP
2014-05-17 13:00 - 2013-02-23 01:02 - 00000000 ____D () C:\Users\joern\AppData\Local\TSVNCache
2014-05-17 12:51 - 2014-02-06 12:30 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-17 11:12 - 2009-07-14 06:45 - 00026720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-17 11:12 - 2009-07-14 06:45 - 00026720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-17 11:04 - 2014-05-08 21:15 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2014-05-17 11:04 - 2013-01-12 00:17 - 00034752 _____ () C:\Windows\system32\Drivers\WPRO_41_2001.sys
2014-05-17 11:04 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-17 11:04 - 2009-07-14 06:51 - 00062715 _____ () C:\Windows\setupact.log
2014-05-17 11:03 - 2010-11-21 05:47 - 00229064 _____ () C:\Windows\PFRO.log
2014-05-17 01:53 - 2014-05-17 01:53 - 00001146 _____ () C:\Users\joern\Desktop\mbam.txt
2014-05-17 01:35 - 2014-05-17 01:35 - 00000000 ____D () C:\Windows\ERUNT
2014-05-17 01:34 - 2014-05-16 19:59 - 00000000 ____D () C:\AdwCleaner
2014-05-17 01:32 - 2014-05-17 01:32 - 01016261 _____ (Thisisu) C:\Users\joern\Desktop\JRT.exe
2014-05-16 19:58 - 2014-05-16 19:58 - 01325827 _____ () C:\Users\joern\Desktop\adwcleaner_3.208.exe
2014-05-16 19:56 - 2014-05-16 19:56 - 00004830 _____ () C:\Users\joern\Desktop\malware.txt
2014-05-16 19:56 - 2014-04-09 21:26 - 00000000 ____D () C:\Program Files (x86)\best-markit Corp
2014-05-16 19:33 - 2014-05-16 19:33 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-16 19:32 - 2014-05-16 19:32 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-16 19:32 - 2014-05-16 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-16 19:31 - 2014-05-16 19:31 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\joern\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 20:03 - 2013-02-23 01:10 - 00000000 ___RD () C:\Users\joern\Dropbox
2014-05-15 19:54 - 2014-05-15 19:54 - 00026672 _____ () C:\ComboFix.txt
2014-05-15 19:54 - 2014-05-15 19:43 - 00000000 ____D () C:\Qoobox
2014-05-15 19:53 - 2014-05-15 19:42 - 00000000 ____D () C:\Windows\erdnt
2014-05-15 19:53 - 2013-01-08 22:10 - 00000000 ___RD () C:\Users\joern\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 19:53 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-15 19:42 - 2014-05-15 19:43 - 05200050 ____R (Swearware) C:\Users\joern\Desktop\ComboFix.exe
2014-05-15 19:42 - 2014-05-15 19:41 - 05200050 ____R (Swearware) C:\Users\joern\Downloads\ComboFix.exe
2014-05-15 19:35 - 2014-05-15 19:35 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-15 19:32 - 2014-05-15 19:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\joern\Downloads\revosetup95.exe
2014-05-15 19:29 - 2013-02-23 01:05 - 00000000 ____D () C:\Users\joern\AppData\Roaming\Dropbox
2014-05-14 18:52 - 2014-05-14 18:52 - 02066944 _____ (Farbar) C:\Users\joern\Desktop\FRST64.exe
2014-05-14 18:50 - 2014-05-14 18:50 - 00000000 ____D () C:\Users\joern\AppData\Roaming\DropboxMaster
2014-05-14 18:50 - 2013-02-23 01:10 - 00000979 _____ () C:\Users\joern\Desktop\Dropbox.lnk
2014-05-14 18:50 - 2013-02-23 01:07 - 00000000 ____D () C:\Users\joern\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-14 18:48 - 2014-03-30 10:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-14 18:48 - 2013-01-12 00:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-13 21:51 - 2013-01-12 00:48 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-13 21:51 - 2013-01-12 00:48 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-13 20:50 - 2013-01-12 00:47 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-13 20:50 - 2013-01-12 00:47 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-05-13 20:48 - 2014-05-13 20:48 - 00283144 _____ (Mozilla) C:\Users\joern\Downloads\Firefox Setup Stub 29.0.1.exe
2014-05-13 08:42 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-07 22:44 - 2013-02-03 16:43 - 00000000 ____D () C:\Users\joern\AppData\Roaming\Skype
Some content of TEMP:
====================
C:\Users\joern\AppData\Local\Temp\avgnt.exe
C:\Users\joern\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpnjoyvp.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================ --- --- ---
--- --- --- |