Bonnie-jo | 17.07.2014 13:49 | Mbam-Log Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 17.07.2014
Suchlauf-Zeit: 13:39:25
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.17.05
Rootkit Datenbank: v2014.07.14.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Lea
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 271605
Verstrichene Zeit: 17 Min, 29 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\updateToggleMark.exe, 2932, Löschen bei Neustart, [2d6cb4ec3744d561e33675fe20e1c63a]
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\utilToggleMark.exe, 2496, Löschen bei Neustart, [8316a0003d3e9d99c653f57e966b3cc4]
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\ToggleMark.BrowserAdapter.exe, 6200, Löschen bei Neustart, [d7c21a861e5d1c1ade488752ab5711ef]
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\ToggleMark.PurBrowse64.exe, 6032, Löschen bei Neustart, [d7c21a861e5d1c1ade488752ab5711ef]
Module: 1
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}.dll, Löschen bei Neustart, [d7c21a861e5d1c1ade488752ab5711ef],
Registrierungsschlüssel: 23
PUP.Optional.ToggleMark.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update ToggleMark, In Quarantäne, [2d6cb4ec3744d561e33675fe20e1c63a],
PUP.Optional.ToggleMark.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util ToggleMark, In Quarantäne, [8316a0003d3e9d99c653f57e966b3cc4],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [9900cfd14e2d7fb7ec2b622c58aa6e92],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [9900cfd14e2d7fb7ec2b622c58aa6e92],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{dc59a866-959c-4638-a191-c13177d0bd68}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{c3715f93-4241-49f6-ba85-1d8151b277af}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5B79DF26-5A4A-4A88-BFF4-FE188A4F223E}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5B79DF26-5A4A-4A88-BFF4-FE188A4F223E}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{c3715f93-4241-49f6-ba85-1d8151b277af}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{DC59A866-959C-4638-A191-C13177D0BD68}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ToggleMark, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}Gw64, In Quarantäne, [e6b3b7e9abd0201672af24f847bd9967],
Adware.EoRezo, HKLM\SOFTWARE\WOW6432NODE\FREESOFTTODAY, In Quarantäne, [20795947e695ce68d359af533aca56aa],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\ToggleMark, In Quarantäne, [b2e7d5cb6912171fdc4bc0194db5af51],
PUP.Optional.ToggleMark.A, HKU\S-1-5-21-3086842316-3700398337-352134568-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\ToggleMark, In Quarantäne, [0396f3ad28531b1b4eda0bce6999aa56],
PUP.Optional.Softonic.A, HKU\S-1-5-21-3086842316-3700398337-352134568-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [702998081f5ccd6945f1f2e3659daa56],
Registrierungswerte: 1
PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|fst_de_99, In Quarantäne, [dcbd4f511f5c0036dcf56a686c96a55b],
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 4
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark, Löschen bei Neustart, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin, Löschen bei Neustart, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\TEMP, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
Dateien: 30
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\updateToggleMark.exe, Löschen bei Neustart, [2d6cb4ec3744d561e33675fe20e1c63a],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\utilToggleMark.exe, Löschen bei Neustart, [8316a0003d3e9d99c653f57e966b3cc4],
PUP.Optional.BetterDeals.A, C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage, In Quarantäne, [f7a2acf40c6f5cda92412d9b5ca6857b],
PUP.Optional.BetterDeals.A, C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage-journal, In Quarantäne, [1881138dadce85b103d01fa9917125db],
PUP.Optional.Superfish.A, C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [3c5d138dd1aae3531ef0d8f66b97a759],
PUP.Optional.Superfish.A, C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [e3b69f01e09b90a68b833a944ab81ce4],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\ToggleMark.ico, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\0, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\7za.exe, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\ToggleMark.FirstRun.exe, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\ToggleMarkBHO.dll, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\ToggleMarkUninstall.exe, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\updateToggleMark.InstallState, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\7za.exe, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\BrowserAdapterS.7z, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\tmp5CD4.tmp, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\ToggleMark.BrowserAdapter.exe, Löschen bei Neustart, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\ToggleMark.PurBrowse64.exe, Löschen bei Neustart, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\ToggleMark.PurBrowseG.zip, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\ToggleMarkBAApp.dll, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\utilToggleMark.InstallState, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}.dll, Löschen bei Neustart, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.Bromon.dll, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.BroStats.dll, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.BrowserAdapterS.dll, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.CompatibilityChecker.dll, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.FFUpdate.dll, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.IEUpdate.dll, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.PurBrowseG.dll, In Quarantäne, [d7c21a861e5d1c1ade488752ab5711ef],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}Gw64.sys, In Quarantäne, [e6b3b7e9abd0201672af24f847bd9967],
Physische Sektoren: 0
(No malicious items detected)
(end) Adw-Log Code:
# AdwCleaner v3.215 - Bericht erstellt am 17/07/2014 um 14:09:54
# Aktualisiert 09/07/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Lea - LEA
# Gestartet von : C:\Users\Lea\Desktop\Mama\adwcleaner_3.215.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\predm
Ordner Gelöscht : C:\Users\Lea\AppData\Local\Pokki
Ordner Gelöscht : C:\Users\Public\Pokki
Datei Gelöscht : C:\Users\Lea\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.de_0.localstorage
Datei Gelöscht : C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.de_0.localstorage-journal
Datei Gelöscht : C:\Windows\Tasks\APSnotifierPP1.job
Datei Gelöscht : C:\Windows\System32\Tasks\APSnotifierPP1
Datei Gelöscht : C:\Windows\Tasks\APSnotifierPP2.job
Datei Gelöscht : C:\Windows\System32\Tasks\APSnotifierPP2
Datei Gelöscht : C:\Windows\Tasks\APSnotifierPP3.job
Datei Gelöscht : C:\Windows\System32\Tasks\APSnotifierPP3
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\FreeSoftToday
Schlüssel Gelöscht : HKCU\Software\Pokki
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKLM\Software\Tutorials
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [3606 octets] - [17/07/2014 14:06:48]
AdwCleaner[S0].txt - [3135 octets] - [17/07/2014 14:09:54]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3195 octets] ##########
JRT-Log Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Lea on 17.07.2014 at 14:19:43,02
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17.07.2014 at 14:24:54,76
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Frisches FRST Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-07-2014 01
Ran by Lea (administrator) on LEA on 17-07-2014 14:26:44
Running from C:\Users\Lea\Desktop\Mama
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QuickAccess.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2778352 2013-08-28] (Synaptics Incorporated)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [53504 2014-06-26] (Acer Incorporated)
HKLM-x32\...\Run: [AnyProtect Scanner] => "C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe"
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/?gws_rd=ssl
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
SearchScopes: HKLM - DefaultScope {06FF55DB-90D1-4D80-8589-CEF572363C8C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {06FF55DB-90D1-4D80-8589-CEF572363C8C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {06FF55DB-90D1-4D80-8589-CEF572363C8C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKCU - {06FF55DB-90D1-4D80-8589-CEF572363C8C} URL =
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2014-01-08]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-01-08]
Chrome:
=======
CHR HomePage:
CHR StartupUrls: "hxxp://www.google.de/"
CHR Extension: (Google Drive) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-05]
CHR Extension: (YouTube) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-05]
CHR Extension: (Google-Suche) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-05]
CHR Extension: (Google Wallet) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-05]
CHR Extension: (Google Mail) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-05]
==================== Services (Whitelisted) =================
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [3053312 2014-06-26] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed]
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-21] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [457768 2013-08-03] (Acer Incorporate)
R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-25] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-03-18] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-04-03] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-04-03] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4278112 2013-08-01] (Symantec Corporation)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [457768 2013-08-02] (Acer Incorporate)
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [448040 2013-08-02] (Acer Incorporate)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S3 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0405000.009\ccSetx64.sys [150104 2013-07-30] (Symantec Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70592 2014-04-03] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [177544 2014-04-03] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311856 2014-04-03] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69352 2014-04-03] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [522360 2014-04-03] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [784760 2014-04-03] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [441264 2014-03-18] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-03-18] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [346760 2014-04-03] (McAfee, Inc.)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-28] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) |