supi hab gemacht was nun. hat lange genug gedauert Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-06-2014 02
Ran by Laxman at 2014-06-30 19:22:18 Run:2
Running from C:\Users\Laxman\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
AlternateDataStreams: C:\ProgramData\Temp:008586AE
AlternateDataStreams: C:\ProgramData\Temp:021496FB
AlternateDataStreams: C:\ProgramData\Temp:041C0562
AlternateDataStreams: C:\ProgramData\Temp:0474F714
AlternateDataStreams: C:\ProgramData\Temp:063969F8
AlternateDataStreams: C:\ProgramData\Temp:0696EC8E
AlternateDataStreams: C:\ProgramData\Temp:072F1F69
AlternateDataStreams: C:\ProgramData\Temp:0AC0213C
AlternateDataStreams: C:\ProgramData\Temp:0BBF232A
AlternateDataStreams: C:\ProgramData\Temp:0E61938B
AlternateDataStreams: C:\ProgramData\Temp:0EC7A545
AlternateDataStreams: C:\ProgramData\Temp:0ED1C542
AlternateDataStreams: C:\ProgramData\Temp:0FAE191E
AlternateDataStreams: C:\ProgramData\Temp:0FD8569B
AlternateDataStreams: C:\ProgramData\Temp:0FE0A03C
AlternateDataStreams: C:\ProgramData\Temp:104A1C3E
AlternateDataStreams: C:\ProgramData\Temp:10B970A9
AlternateDataStreams: C:\ProgramData\Temp:1181620C
AlternateDataStreams: C:\ProgramData\Temp:128B55C8
AlternateDataStreams: C:\ProgramData\Temp:12D2EB9C
AlternateDataStreams: C:\ProgramData\Temp:1416AAA6
AlternateDataStreams: C:\ProgramData\Temp:14B2E0BD
AlternateDataStreams: C:\ProgramData\Temp:164561C8
AlternateDataStreams: C:\ProgramData\Temp:18B5F839
AlternateDataStreams: C:\ProgramData\Temp:1A15E356
AlternateDataStreams: C:\ProgramData\Temp:1B389835
AlternateDataStreams: C:\ProgramData\Temp:1B7E2022
AlternateDataStreams: C:\ProgramData\Temp:1B96CF22
AlternateDataStreams: C:\ProgramData\Temp:1D5FADCD
AlternateDataStreams: C:\ProgramData\Temp:1DB77A89
AlternateDataStreams: C:\ProgramData\Temp:1E942FB9
AlternateDataStreams: C:\ProgramData\Temp:1ECED34B
AlternateDataStreams: C:\ProgramData\Temp:1FA4C06F
AlternateDataStreams: C:\ProgramData\Temp:206470A5
AlternateDataStreams: C:\ProgramData\Temp:2211E7A0
AlternateDataStreams: C:\ProgramData\Temp:234E9CC5
AlternateDataStreams: C:\ProgramData\Temp:244E4E3A
AlternateDataStreams: C:\ProgramData\Temp:2652902F
AlternateDataStreams: C:\ProgramData\Temp:282CE153
AlternateDataStreams: C:\ProgramData\Temp:2AE74FF9
AlternateDataStreams: C:\ProgramData\Temp:2B1EA607
AlternateDataStreams: C:\ProgramData\Temp:2B9555D8
AlternateDataStreams: C:\ProgramData\Temp:2CB9631F
AlternateDataStreams: C:\ProgramData\Temp:2E3F04BC
AlternateDataStreams: C:\ProgramData\Temp:2E636DD9
AlternateDataStreams: C:\ProgramData\Temp:320208DA
AlternateDataStreams: C:\ProgramData\Temp:32289BE8
AlternateDataStreams: C:\ProgramData\Temp:3241739E
AlternateDataStreams: C:\ProgramData\Temp:329BA65B
AlternateDataStreams: C:\ProgramData\Temp:32A82570
AlternateDataStreams: C:\ProgramData\Temp:32AE8659
AlternateDataStreams: C:\ProgramData\Temp:32FFF2D1
AlternateDataStreams: C:\ProgramData\Temp:331B76C7
AlternateDataStreams: C:\ProgramData\Temp:366EFA1A
AlternateDataStreams: C:\ProgramData\Temp:37C279BE
AlternateDataStreams: C:\ProgramData\Temp:386B39C3
AlternateDataStreams: C:\ProgramData\Temp:3969ACF7
AlternateDataStreams: C:\ProgramData\Temp:398D2775
AlternateDataStreams: C:\ProgramData\Temp:3B454A5C
AlternateDataStreams: C:\ProgramData\Temp:3B71586E
AlternateDataStreams: C:\ProgramData\Temp:3B75B877
AlternateDataStreams: C:\ProgramData\Temp:3B812EE0
AlternateDataStreams: C:\ProgramData\Temp:3C4BD225
AlternateDataStreams: C:\ProgramData\Temp:3E06C78F
AlternateDataStreams: C:\ProgramData\Temp:3EC5BC08
AlternateDataStreams: C:\ProgramData\Temp:4009F120
AlternateDataStreams: C:\ProgramData\Temp:401CAF8F
AlternateDataStreams: C:\ProgramData\Temp:405D842B
AlternateDataStreams: C:\ProgramData\Temp:406E0034
AlternateDataStreams: C:\ProgramData\Temp:45912F61
AlternateDataStreams: C:\ProgramData\Temp:460638C7
AlternateDataStreams: C:\ProgramData\Temp:46283136
AlternateDataStreams: C:\ProgramData\Temp:48081133
AlternateDataStreams: C:\ProgramData\Temp:488F7244
AlternateDataStreams: C:\ProgramData\Temp:49EB69E2
AlternateDataStreams: C:\ProgramData\Temp:4A448DB2
AlternateDataStreams: C:\ProgramData\Temp:4C9782FB
AlternateDataStreams: C:\ProgramData\Temp:4CA05B44
AlternateDataStreams: C:\ProgramData\Temp:4DDE401B
AlternateDataStreams: C:\ProgramData\Temp:4EE323A4
AlternateDataStreams: C:\ProgramData\Temp:4EFA2FC7
AlternateDataStreams: C:\ProgramData\Temp:4F49DA66
AlternateDataStreams: C:\ProgramData\Temp:5008417E
AlternateDataStreams: C:\ProgramData\Temp:50636E35
AlternateDataStreams: C:\ProgramData\Temp:5197985B
AlternateDataStreams: C:\ProgramData\Temp:51A20D23
AlternateDataStreams: C:\ProgramData\Temp:54380FEC
AlternateDataStreams: C:\ProgramData\Temp:54403233
AlternateDataStreams: C:\ProgramData\Temp:5453E5AF
AlternateDataStreams: C:\ProgramData\Temp:5539129F
AlternateDataStreams: C:\ProgramData\Temp:55818279
AlternateDataStreams: C:\ProgramData\Temp:57DFBE4E
AlternateDataStreams: C:\ProgramData\Temp:59465B40
AlternateDataStreams: C:\ProgramData\Temp:5A2E8BBF
AlternateDataStreams: C:\ProgramData\Temp:5A9F1AE5
AlternateDataStreams: C:\ProgramData\Temp:5C353220
AlternateDataStreams: C:\ProgramData\Temp:5D10C56A
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:5E21B96B
AlternateDataStreams: C:\ProgramData\Temp:5E73E1C2
AlternateDataStreams: C:\ProgramData\Temp:5E9B629B
AlternateDataStreams: C:\ProgramData\Temp:607A99D7
AlternateDataStreams: C:\ProgramData\Temp:609CAC7C
AlternateDataStreams: C:\ProgramData\Temp:61AF2B29
AlternateDataStreams: C:\ProgramData\Temp:6247E766
AlternateDataStreams: C:\ProgramData\Temp:6294B369
AlternateDataStreams: C:\ProgramData\Temp:667565EE
AlternateDataStreams: C:\ProgramData\Temp:67E674B0
AlternateDataStreams: C:\ProgramData\Temp:6A9CA6CB
AlternateDataStreams: C:\ProgramData\Temp:6E11933F
AlternateDataStreams: C:\ProgramData\Temp:6E2D80C8
AlternateDataStreams: C:\ProgramData\Temp:6ECE93A8
AlternateDataStreams: C:\ProgramData\Temp:6F0B6A5A
AlternateDataStreams: C:\ProgramData\Temp:6FF14C72
AlternateDataStreams: C:\ProgramData\Temp:71612023
AlternateDataStreams: C:\ProgramData\Temp:7254CF01
AlternateDataStreams: C:\ProgramData\Temp:762408BA
AlternateDataStreams: C:\ProgramData\Temp:769BB147
AlternateDataStreams: C:\ProgramData\Temp:79875988
AlternateDataStreams: C:\ProgramData\Temp:7ADB695A
AlternateDataStreams: C:\ProgramData\Temp:7DC5D762
AlternateDataStreams: C:\ProgramData\Temp:7EC01D6D
AlternateDataStreams: C:\ProgramData\Temp:7FCB9D0D
AlternateDataStreams: C:\ProgramData\Temp:80253E8D
AlternateDataStreams: C:\ProgramData\Temp:8075370B
AlternateDataStreams: C:\ProgramData\Temp:8318A814
AlternateDataStreams: C:\ProgramData\Temp:834DD57E
AlternateDataStreams: C:\ProgramData\Temp:8855A119
AlternateDataStreams: C:\ProgramData\Temp:88A44CC1
AlternateDataStreams: C:\ProgramData\Temp:89CC3B44
AlternateDataStreams: C:\ProgramData\Temp:8A620099
AlternateDataStreams: C:\ProgramData\Temp:8B480195
AlternateDataStreams: C:\ProgramData\Temp:8BE7A048
AlternateDataStreams: C:\ProgramData\Temp:8D565A9B
AlternateDataStreams: C:\ProgramData\Temp:8F6B75BF
AlternateDataStreams: C:\ProgramData\Temp:905BCB57
AlternateDataStreams: C:\ProgramData\Temp:90C320E1
AlternateDataStreams: C:\ProgramData\Temp:927EC486
AlternateDataStreams: C:\ProgramData\Temp:92A815D8
AlternateDataStreams: C:\ProgramData\Temp:92CA7E75
AlternateDataStreams: C:\ProgramData\Temp:943971F5
AlternateDataStreams: C:\ProgramData\Temp:94B46CA2
AlternateDataStreams: C:\ProgramData\Temp:95198126
AlternateDataStreams: C:\ProgramData\Temp:9524D821
AlternateDataStreams: C:\ProgramData\Temp:96372A73
AlternateDataStreams: C:\ProgramData\Temp:968F624D
AlternateDataStreams: C:\ProgramData\Temp:9836B5E4
AlternateDataStreams: C:\ProgramData\Temp:98982C88
AlternateDataStreams: C:\ProgramData\Temp:98CF1A39
AlternateDataStreams: C:\ProgramData\Temp:9A88B65D
AlternateDataStreams: C:\ProgramData\Temp:9F3CEEE6
AlternateDataStreams: C:\ProgramData\Temp:9FD757A9
AlternateDataStreams: C:\ProgramData\Temp:A02025CE
AlternateDataStreams: C:\ProgramData\Temp:A0921B2C
AlternateDataStreams: C:\ProgramData\Temp:A391510C
AlternateDataStreams: C:\ProgramData\Temp:A4AF8D0D
AlternateDataStreams: C:\ProgramData\Temp:A5584049
AlternateDataStreams: C:\ProgramData\Temp:A6D6E537
AlternateDataStreams: C:\ProgramData\Temp:A6D89509
AlternateDataStreams: C:\ProgramData\Temp:A6F30843
AlternateDataStreams: C:\ProgramData\Temp:A819A132
AlternateDataStreams: C:\ProgramData\Temp:A8DFD30C
AlternateDataStreams: C:\ProgramData\Temp:A9056F42
AlternateDataStreams: C:\ProgramData\Temp:A9223B61
AlternateDataStreams: C:\ProgramData\Temp:A9562832
AlternateDataStreams: C:\ProgramData\Temp:AD179392
AlternateDataStreams: C:\ProgramData\Temp:AECF4772
AlternateDataStreams: C:\ProgramData\Temp:AED4A2B7
AlternateDataStreams: C:\ProgramData\Temp:B1381B34
AlternateDataStreams: C:\ProgramData\Temp:B139DDF3
AlternateDataStreams: C:\ProgramData\Temp:B4980368
AlternateDataStreams: C:\ProgramData\Temp:B504E4C2
AlternateDataStreams: C:\ProgramData\Temp:B61767F5
AlternateDataStreams: C:\ProgramData\Temp:B6DD2C7E
AlternateDataStreams: C:\ProgramData\Temp:B6E6C4EA
AlternateDataStreams: C:\ProgramData\Temp:B8791731
AlternateDataStreams: C:\ProgramData\Temp:BCFEA004
AlternateDataStreams: C:\ProgramData\Temp:BD0A043E
AlternateDataStreams: C:\ProgramData\Temp:BE6B5FC3
AlternateDataStreams: C:\ProgramData\Temp:BECA50FF
AlternateDataStreams: C:\ProgramData\Temp:BEE39E9B
AlternateDataStreams: C:\ProgramData\Temp:C07A6A6B
AlternateDataStreams: C:\ProgramData\Temp:C0893153
AlternateDataStreams: C:\ProgramData\Temp:C0A9B815
AlternateDataStreams: C:\ProgramData\Temp:C22674B6
AlternateDataStreams: C:\ProgramData\Temp:C2F24DB5
AlternateDataStreams: C:\ProgramData\Temp:C368C9EA
AlternateDataStreams: C:\ProgramData\Temp:C3A047E3
AlternateDataStreams: C:\ProgramData\Temp:C48905F4
AlternateDataStreams: C:\ProgramData\Temp:C76CFF82
AlternateDataStreams: C:\ProgramData\Temp:C8E3A625
AlternateDataStreams: C:\ProgramData\Temp:C9BC8592
AlternateDataStreams: C:\ProgramData\Temp:CE506F23
AlternateDataStreams: C:\ProgramData\Temp:D02FBAEC
AlternateDataStreams: C:\ProgramData\Temp:D086B88D
AlternateDataStreams: C:\ProgramData\Temp:D1FE35E7
AlternateDataStreams: C:\ProgramData\Temp:D4E62FA9
AlternateDataStreams: C:\ProgramData\Temp:D5BF78B4
AlternateDataStreams: C:\ProgramData\Temp:D61EB62D
AlternateDataStreams: C:\ProgramData\Temp:D6D084A5
AlternateDataStreams: C:\ProgramData\Temp:D7740E2A
AlternateDataStreams: C:\ProgramData\Temp:DBC3D477
AlternateDataStreams: C:\ProgramData\Temp:DC21D414
AlternateDataStreams: C:\ProgramData\Temp:DD04902E
AlternateDataStreams: C:\ProgramData\Temp:DDF112BD
AlternateDataStreams: C:\ProgramData\Temp:DE0BD04E
AlternateDataStreams: C:\ProgramData\Temp:DE47A3DA
AlternateDataStreams: C:\ProgramData\Temp:DE875C30
AlternateDataStreams: C:\ProgramData\Temp:E3C56885
AlternateDataStreams: C:\ProgramData\Temp:E4272706
AlternateDataStreams: C:\ProgramData\Temp:E5496666
AlternateDataStreams: C:\ProgramData\Temp:E6708F08
AlternateDataStreams: C:\ProgramData\Temp:E6C6EB3B
AlternateDataStreams: C:\ProgramData\Temp:E894A3ED
AlternateDataStreams: C:\ProgramData\Temp:E8AEB2BF
AlternateDataStreams: C:\ProgramData\Temp:E8B61305
AlternateDataStreams: C:\ProgramData\Temp:E8C44CB4
AlternateDataStreams: C:\ProgramData\Temp:EA10407C
AlternateDataStreams: C:\ProgramData\Temp:ED2D63E4
AlternateDataStreams: C:\ProgramData\Temp:ED51D3ED
AlternateDataStreams: C:\ProgramData\Temp:EF38B79C
AlternateDataStreams: C:\ProgramData\Temp:F56BE392
AlternateDataStreams: C:\ProgramData\Temp:F5E8CAE0
AlternateDataStreams: C:\ProgramData\Temp:F74EC668
AlternateDataStreams: C:\ProgramData\Temp:F7BF538D
AlternateDataStreams: C:\ProgramData\Temp:F84B8DB5
AlternateDataStreams: C:\ProgramData\Temp:F89F2593
AlternateDataStreams: C:\ProgramData\Temp:F8C2E3B9
AlternateDataStreams: C:\ProgramData\Temp:F8DE80DB
AlternateDataStreams: C:\ProgramData\Temp:F9E46E4C
AlternateDataStreams: C:\ProgramData\Temp:FAB64002
AlternateDataStreams: C:\ProgramData\Temp:FB4262DE
AlternateDataStreams: C:\ProgramData\Temp:FB71A279
AlternateDataStreams: C:\ProgramData\Temp:FC2E567F
AlternateDataStreams: C:\ProgramData\Temp:FCBEDCFD
AlternateDataStreams: C:\ProgramData\Temp:FD4C7AD3
AlternateDataStreams: C:\ProgramData\Temp:FEE00EB9
*****************
C:\ProgramData\Temp => ":008586AE" ADS removed successfully.
C:\ProgramData\Temp => ":021496FB" ADS removed successfully.
C:\ProgramData\Temp => ":041C0562" ADS removed successfully.
C:\ProgramData\Temp => ":0474F714" ADS removed successfully.
C:\ProgramData\Temp => ":063969F8" ADS removed successfully.
C:\ProgramData\Temp => ":0696EC8E" ADS removed successfully.
C:\ProgramData\Temp => ":072F1F69" ADS removed successfully.
C:\ProgramData\Temp => ":0AC0213C" ADS removed successfully.
C:\ProgramData\Temp => ":0BBF232A" ADS removed successfully.
C:\ProgramData\Temp => ":0E61938B" ADS removed successfully.
C:\ProgramData\Temp => ":0EC7A545" ADS removed successfully.
C:\ProgramData\Temp => ":0ED1C542" ADS removed successfully.
C:\ProgramData\Temp => ":0FAE191E" ADS removed successfully.
C:\ProgramData\Temp => ":0FD8569B" ADS removed successfully.
C:\ProgramData\Temp => ":0FE0A03C" ADS removed successfully.
C:\ProgramData\Temp => ":104A1C3E" ADS removed successfully.
C:\ProgramData\Temp => ":10B970A9" ADS removed successfully.
C:\ProgramData\Temp => ":1181620C" ADS removed successfully.
C:\ProgramData\Temp => ":128B55C8" ADS removed successfully.
C:\ProgramData\Temp => ":12D2EB9C" ADS removed successfully.
C:\ProgramData\Temp => ":1416AAA6" ADS removed successfully.
C:\ProgramData\Temp => ":14B2E0BD" ADS removed successfully.
C:\ProgramData\Temp => ":164561C8" ADS removed successfully.
C:\ProgramData\Temp => ":18B5F839" ADS removed successfully.
C:\ProgramData\Temp => ":1A15E356" ADS removed successfully.
C:\ProgramData\Temp => ":1B389835" ADS removed successfully.
C:\ProgramData\Temp => ":1B7E2022" ADS removed successfully.
C:\ProgramData\Temp => ":1B96CF22" ADS removed successfully.
C:\ProgramData\Temp => ":1D5FADCD" ADS removed successfully.
C:\ProgramData\Temp => ":1DB77A89" ADS removed successfully.
C:\ProgramData\Temp => ":1E942FB9" ADS removed successfully.
C:\ProgramData\Temp => ":1ECED34B" ADS removed successfully.
C:\ProgramData\Temp => ":1FA4C06F" ADS removed successfully.
C:\ProgramData\Temp => ":206470A5" ADS removed successfully.
C:\ProgramData\Temp => ":2211E7A0" ADS removed successfully.
C:\ProgramData\Temp => ":234E9CC5" ADS removed successfully.
C:\ProgramData\Temp => ":244E4E3A" ADS removed successfully.
C:\ProgramData\Temp => ":2652902F" ADS removed successfully.
C:\ProgramData\Temp => ":282CE153" ADS removed successfully.
C:\ProgramData\Temp => ":2AE74FF9" ADS removed successfully.
C:\ProgramData\Temp => ":2B1EA607" ADS removed successfully.
C:\ProgramData\Temp => ":2B9555D8" ADS removed successfully.
C:\ProgramData\Temp => ":2CB9631F" ADS removed successfully.
C:\ProgramData\Temp => ":2E3F04BC" ADS removed successfully.
C:\ProgramData\Temp => ":2E636DD9" ADS removed successfully.
C:\ProgramData\Temp => ":320208DA" ADS removed successfully.
C:\ProgramData\Temp => ":32289BE8" ADS removed successfully.
C:\ProgramData\Temp => ":3241739E" ADS removed successfully.
C:\ProgramData\Temp => ":329BA65B" ADS removed successfully.
C:\ProgramData\Temp => ":32A82570" ADS removed successfully.
C:\ProgramData\Temp => ":32AE8659" ADS removed successfully.
C:\ProgramData\Temp => ":32FFF2D1" ADS removed successfully.
C:\ProgramData\Temp => ":331B76C7" ADS removed successfully.
C:\ProgramData\Temp => ":366EFA1A" ADS removed successfully.
C:\ProgramData\Temp => ":37C279BE" ADS removed successfully.
C:\ProgramData\Temp => ":386B39C3" ADS removed successfully.
C:\ProgramData\Temp => ":3969ACF7" ADS removed successfully.
C:\ProgramData\Temp => ":398D2775" ADS removed successfully.
C:\ProgramData\Temp => ":3B454A5C" ADS removed successfully.
C:\ProgramData\Temp => ":3B71586E" ADS removed successfully.
C:\ProgramData\Temp => ":3B75B877" ADS removed successfully.
C:\ProgramData\Temp => ":3B812EE0" ADS removed successfully.
C:\ProgramData\Temp => ":3C4BD225" ADS removed successfully.
C:\ProgramData\Temp => ":3E06C78F" ADS removed successfully.
C:\ProgramData\Temp => ":3EC5BC08" ADS removed successfully.
C:\ProgramData\Temp => ":4009F120" ADS removed successfully.
C:\ProgramData\Temp => ":401CAF8F" ADS removed successfully.
C:\ProgramData\Temp => ":405D842B" ADS removed successfully.
C:\ProgramData\Temp => ":406E0034" ADS removed successfully.
C:\ProgramData\Temp => ":45912F61" ADS removed successfully.
C:\ProgramData\Temp => ":460638C7" ADS removed successfully.
C:\ProgramData\Temp => ":46283136" ADS removed successfully.
C:\ProgramData\Temp => ":48081133" ADS removed successfully.
C:\ProgramData\Temp => ":488F7244" ADS removed successfully.
C:\ProgramData\Temp => ":49EB69E2" ADS removed successfully.
C:\ProgramData\Temp => ":4A448DB2" ADS removed successfully.
C:\ProgramData\Temp => ":4C9782FB" ADS removed successfully.
C:\ProgramData\Temp => ":4CA05B44" ADS removed successfully.
C:\ProgramData\Temp => ":4DDE401B" ADS removed successfully.
C:\ProgramData\Temp => ":4EE323A4" ADS removed successfully.
C:\ProgramData\Temp => ":4EFA2FC7" ADS removed successfully.
C:\ProgramData\Temp => ":4F49DA66" ADS removed successfully.
C:\ProgramData\Temp => ":5008417E" ADS removed successfully.
C:\ProgramData\Temp => ":50636E35" ADS removed successfully.
C:\ProgramData\Temp => ":5197985B" ADS removed successfully.
C:\ProgramData\Temp => ":51A20D23" ADS removed successfully.
C:\ProgramData\Temp => ":54380FEC" ADS removed successfully.
C:\ProgramData\Temp => ":54403233" ADS removed successfully.
C:\ProgramData\Temp => ":5453E5AF" ADS removed successfully.
C:\ProgramData\Temp => ":5539129F" ADS removed successfully.
C:\ProgramData\Temp => ":55818279" ADS removed successfully.
C:\ProgramData\Temp => ":57DFBE4E" ADS removed successfully.
C:\ProgramData\Temp => ":59465B40" ADS removed successfully.
C:\ProgramData\Temp => ":5A2E8BBF" ADS removed successfully.
C:\ProgramData\Temp => ":5A9F1AE5" ADS removed successfully.
C:\ProgramData\Temp => ":5C353220" ADS removed successfully.
C:\ProgramData\Temp => ":5D10C56A" ADS removed successfully.
C:\ProgramData\Temp => ":5D7E5A8F" ADS removed successfully.
C:\ProgramData\Temp => ":5E21B96B" ADS removed successfully.
C:\ProgramData\Temp => ":5E73E1C2" ADS removed successfully.
C:\ProgramData\Temp => ":5E9B629B" ADS removed successfully.
C:\ProgramData\Temp => ":607A99D7" ADS removed successfully.
C:\ProgramData\Temp => ":609CAC7C" ADS removed successfully.
C:\ProgramData\Temp => ":61AF2B29" ADS removed successfully.
C:\ProgramData\Temp => ":6247E766" ADS removed successfully.
C:\ProgramData\Temp => ":6294B369" ADS removed successfully.
C:\ProgramData\Temp => ":667565EE" ADS removed successfully.
C:\ProgramData\Temp => ":67E674B0" ADS removed successfully.
C:\ProgramData\Temp => ":6A9CA6CB" ADS removed successfully.
C:\ProgramData\Temp => ":6E11933F" ADS removed successfully.
C:\ProgramData\Temp => ":6E2D80C8" ADS removed successfully.
C:\ProgramData\Temp => ":6ECE93A8" ADS removed successfully.
C:\ProgramData\Temp => ":6F0B6A5A" ADS removed successfully.
C:\ProgramData\Temp => ":6FF14C72" ADS removed successfully.
C:\ProgramData\Temp => ":71612023" ADS removed successfully.
C:\ProgramData\Temp => ":7254CF01" ADS removed successfully.
C:\ProgramData\Temp => ":762408BA" ADS removed successfully.
C:\ProgramData\Temp => ":769BB147" ADS removed successfully.
C:\ProgramData\Temp => ":79875988" ADS removed successfully.
C:\ProgramData\Temp => ":7ADB695A" ADS removed successfully.
C:\ProgramData\Temp => ":7DC5D762" ADS removed successfully.
C:\ProgramData\Temp => ":7EC01D6D" ADS removed successfully.
C:\ProgramData\Temp => ":7FCB9D0D" ADS removed successfully.
C:\ProgramData\Temp => ":80253E8D" ADS removed successfully.
C:\ProgramData\Temp => ":8075370B" ADS removed successfully.
C:\ProgramData\Temp => ":8318A814" ADS removed successfully.
C:\ProgramData\Temp => ":834DD57E" ADS removed successfully.
C:\ProgramData\Temp => ":8855A119" ADS removed successfully.
C:\ProgramData\Temp => ":88A44CC1" ADS removed successfully.
C:\ProgramData\Temp => ":89CC3B44" ADS removed successfully.
C:\ProgramData\Temp => ":8A620099" ADS removed successfully.
C:\ProgramData\Temp => ":8B480195" ADS removed successfully.
C:\ProgramData\Temp => ":8BE7A048" ADS removed successfully.
C:\ProgramData\Temp => ":8D565A9B" ADS removed successfully.
C:\ProgramData\Temp => ":8F6B75BF" ADS removed successfully.
C:\ProgramData\Temp => ":905BCB57" ADS removed successfully.
C:\ProgramData\Temp => ":90C320E1" ADS removed successfully.
C:\ProgramData\Temp => ":927EC486" ADS removed successfully.
C:\ProgramData\Temp => ":92A815D8" ADS removed successfully.
C:\ProgramData\Temp => ":92CA7E75" ADS removed successfully.
C:\ProgramData\Temp => ":943971F5" ADS removed successfully.
C:\ProgramData\Temp => ":94B46CA2" ADS removed successfully.
C:\ProgramData\Temp => ":95198126" ADS removed successfully.
C:\ProgramData\Temp => ":9524D821" ADS removed successfully.
C:\ProgramData\Temp => ":96372A73" ADS removed successfully.
C:\ProgramData\Temp => ":968F624D" ADS removed successfully.
C:\ProgramData\Temp => ":9836B5E4" ADS removed successfully.
C:\ProgramData\Temp => ":98982C88" ADS removed successfully.
C:\ProgramData\Temp => ":98CF1A39" ADS removed successfully.
C:\ProgramData\Temp => ":9A88B65D" ADS removed successfully.
C:\ProgramData\Temp => ":9F3CEEE6" ADS removed successfully.
C:\ProgramData\Temp => ":9FD757A9" ADS removed successfully.
C:\ProgramData\Temp => ":A02025CE" ADS removed successfully.
C:\ProgramData\Temp => ":A0921B2C" ADS removed successfully.
C:\ProgramData\Temp => ":A391510C" ADS removed successfully.
C:\ProgramData\Temp => ":A4AF8D0D" ADS removed successfully.
C:\ProgramData\Temp => ":A5584049" ADS removed successfully.
C:\ProgramData\Temp => ":A6D6E537" ADS removed successfully.
C:\ProgramData\Temp => ":A6D89509" ADS removed successfully.
C:\ProgramData\Temp => ":A6F30843" ADS removed successfully.
C:\ProgramData\Temp => ":A819A132" ADS removed successfully.
C:\ProgramData\Temp => ":A8DFD30C" ADS removed successfully.
C:\ProgramData\Temp => ":A9056F42" ADS removed successfully.
C:\ProgramData\Temp => ":A9223B61" ADS removed successfully.
C:\ProgramData\Temp => ":A9562832" ADS removed successfully.
C:\ProgramData\Temp => ":AD179392" ADS removed successfully.
C:\ProgramData\Temp => ":AECF4772" ADS removed successfully.
C:\ProgramData\Temp => ":AED4A2B7" ADS removed successfully.
C:\ProgramData\Temp => ":B1381B34" ADS removed successfully.
C:\ProgramData\Temp => ":B139DDF3" ADS removed successfully.
C:\ProgramData\Temp => ":B4980368" ADS removed successfully.
C:\ProgramData\Temp => ":B504E4C2" ADS removed successfully.
C:\ProgramData\Temp => ":B61767F5" ADS removed successfully.
C:\ProgramData\Temp => ":B6DD2C7E" ADS removed successfully.
C:\ProgramData\Temp => ":B6E6C4EA" ADS removed successfully.
C:\ProgramData\Temp => ":B8791731" ADS removed successfully.
C:\ProgramData\Temp => ":BCFEA004" ADS removed successfully.
C:\ProgramData\Temp => ":BD0A043E" ADS removed successfully.
C:\ProgramData\Temp => ":BE6B5FC3" ADS removed successfully.
C:\ProgramData\Temp => ":BECA50FF" ADS removed successfully.
C:\ProgramData\Temp => ":BEE39E9B" ADS removed successfully.
C:\ProgramData\Temp => ":C07A6A6B" ADS removed successfully.
C:\ProgramData\Temp => ":C0893153" ADS removed successfully.
C:\ProgramData\Temp => ":C0A9B815" ADS removed successfully.
C:\ProgramData\Temp => ":C22674B6" ADS removed successfully.
C:\ProgramData\Temp => ":C2F24DB5" ADS removed successfully.
C:\ProgramData\Temp => ":C368C9EA" ADS removed successfully.
C:\ProgramData\Temp => ":C3A047E3" ADS removed successfully.
C:\ProgramData\Temp => ":C48905F4" ADS removed successfully.
C:\ProgramData\Temp => ":C76CFF82" ADS removed successfully.
C:\ProgramData\Temp => ":C8E3A625" ADS removed successfully.
C:\ProgramData\Temp => ":C9BC8592" ADS removed successfully.
C:\ProgramData\Temp => ":CE506F23" ADS removed successfully.
C:\ProgramData\Temp => ":D02FBAEC" ADS removed successfully.
C:\ProgramData\Temp => ":D086B88D" ADS removed successfully.
C:\ProgramData\Temp => ":D1FE35E7" ADS removed successfully.
C:\ProgramData\Temp => ":D4E62FA9" ADS removed successfully.
C:\ProgramData\Temp => ":D5BF78B4" ADS removed successfully.
C:\ProgramData\Temp => ":D61EB62D" ADS removed successfully.
C:\ProgramData\Temp => ":D6D084A5" ADS removed successfully.
C:\ProgramData\Temp => ":D7740E2A" ADS removed successfully.
C:\ProgramData\Temp => ":DBC3D477" ADS removed successfully.
C:\ProgramData\Temp => ":DC21D414" ADS removed successfully.
C:\ProgramData\Temp => ":DD04902E" ADS removed successfully.
C:\ProgramData\Temp => ":DDF112BD" ADS removed successfully.
C:\ProgramData\Temp => ":DE0BD04E" ADS removed successfully.
C:\ProgramData\Temp => ":DE47A3DA" ADS removed successfully.
C:\ProgramData\Temp => ":DE875C30" ADS removed successfully.
C:\ProgramData\Temp => ":E3C56885" ADS removed successfully.
C:\ProgramData\Temp => ":E4272706" ADS removed successfully.
C:\ProgramData\Temp => ":E5496666" ADS removed successfully.
C:\ProgramData\Temp => ":E6708F08" ADS removed successfully.
C:\ProgramData\Temp => ":E6C6EB3B" ADS removed successfully.
C:\ProgramData\Temp => ":E894A3ED" ADS removed successfully.
C:\ProgramData\Temp => ":E8AEB2BF" ADS removed successfully.
C:\ProgramData\Temp => ":E8B61305" ADS removed successfully.
C:\ProgramData\Temp => ":E8C44CB4" ADS removed successfully.
C:\ProgramData\Temp => ":EA10407C" ADS removed successfully.
C:\ProgramData\Temp => ":ED2D63E4" ADS removed successfully.
C:\ProgramData\Temp => ":ED51D3ED" ADS removed successfully.
C:\ProgramData\Temp => ":EF38B79C" ADS removed successfully.
C:\ProgramData\Temp => ":F56BE392" ADS removed successfully.
C:\ProgramData\Temp => ":F5E8CAE0" ADS removed successfully.
C:\ProgramData\Temp => ":F74EC668" ADS removed successfully.
C:\ProgramData\Temp => ":F7BF538D" ADS removed successfully.
C:\ProgramData\Temp => ":F84B8DB5" ADS removed successfully.
C:\ProgramData\Temp => ":F89F2593" ADS removed successfully.
C:\ProgramData\Temp => ":F8C2E3B9" ADS removed successfully.
C:\ProgramData\Temp => ":F8DE80DB" ADS removed successfully.
C:\ProgramData\Temp => ":F9E46E4C" ADS removed successfully.
C:\ProgramData\Temp => ":FAB64002" ADS removed successfully.
C:\ProgramData\Temp => ":FB4262DE" ADS removed successfully.
C:\ProgramData\Temp => ":FB71A279" ADS removed successfully.
C:\ProgramData\Temp => ":FC2E567F" ADS removed successfully.
C:\ProgramData\Temp => ":FCBEDCFD" ADS removed successfully.
C:\ProgramData\Temp => ":FD4C7AD3" ADS removed successfully.
C:\ProgramData\Temp => ":FEE00EB9" ADS removed successfully.
==== End of Fixlog ==== MBAM Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 01.07.2014
Suchlauf-Zeit: 06:29:19
Logdatei: backdoor.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.01.01
Rootkit Datenbank: v2014.06.30.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Laxman
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 2603135
Verstrichene Zeit: 9 Std, 0 Min, 31 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 12
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}),Ersetzt,[dd785f3b4635c1750be31b7108fc35cb]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9heA7HTNRYfuXxYVrVyHSaln_C402ANfojQQeYjSW05_Uu0Ry7B-jKHF-HooOBPS, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9heA7HTNRYfuXxYVrVyHSaln_C402ANfojQQeYjSW05_Uu0Ry7B-jKHF-HooOBPS),Ersetzt,[9bbaadedaccf290d955a513bbe46cc34]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}),Ersetzt,[d283aaf05328d165af3eb9d3b64e4fb1]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}),Ersetzt,[1e374852c3b883b36b85cebe30d401ff]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}),Ersetzt,[4114ecaeb1cace688b6609830afae020]
PUP.Optional.SnapDo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}),Ersetzt,[1243e4b66615d2648cfdbec5b94b9868]
PUP.Optional.Snapdo, HKU\S-1-5-21-3176568229-742132424-851327841-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9heA7HTNRYfuXxYVrVyHSaln_C402ANfojQQeYjSW05_Uu0Ry7B-jKHF-HooOBPS, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9heA7HTNRYfuXxYVrVyHSaln_C402ANfojQQeYjSW05_Uu0Ry7B-jKHF-HooOBPS),Ersetzt,[bd984b4f1e5dcf678966f696cf3502fe]
PUP.Optional.Snapdo, HKU\S-1-5-21-3176568229-742132424-851327841-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}),Ersetzt,[2a2b2b6f25563402ab426c2071933ac6]
PUP.Optional.Snapdo, HKU\S-1-5-21-3176568229-742132424-851327841-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}),Ersetzt,[88cdc4d6ccaf4aecffefdeae52b2dd23]
PUP.Optional.Snapdo, HKU\S-1-5-21-3176568229-742132424-851327841-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}),Ersetzt,[e570bcde68138ea85898dab26a9a53ad]
PUP.Optional.Snapdo, HKU\S-1-5-21-3176568229-742132424-851327841-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}),Ersetzt,[91c48911d1aa39fde809127acc388878]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-3176568229-742132424-851327841-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtlQiitBddEiB8J3_ZbrfuzGVNDJsf1hO6MIk_TBUBEm2s0tY9ARfNH39sr45Gkp9huKxippRLxVebXQ5EErFkFjoTsvz4w6w4fI24Ge2slw82WMLBVHrHtIrHELaWRp&q={searchTerms}),Ersetzt,[7ed7b4e6b9c22016a9e02b58e1232fd1]
Ordner: 0
(No malicious items detected)
Dateien: 30
PUP.Optional.SnapDo.A, C:\Windows\Installer\2cbb96.msi, In Quarantäne, [be97405a423995a16cb7eb9e758ccb35],
Backdoor.ProRat, C:\Windows\temp\pey3jmvf.tmp, In Quarantäne, [c88d52484e2dc670bf3afa329c670000],
Backdoor.ProRat, C:\Windows\temp\pey532zb.tmp, In Quarantäne, [7dd84b4ff685e15587724ae271928b75],
Backdoor.ProRat, C:\Windows\temp\pey56mou.tmp, In Quarantäne, [a4b1e2b89dde76c050a9d25aba49f808],
Backdoor.ProRat, C:\Windows\temp\peyb_0gd.tmp, In Quarantäne, [4e079cfebac10a2c3dbcb17be91a9e62],
Backdoor.ProRat, C:\Windows\temp\peycsmay.tmp, In Quarantäne, [cd882872057695a19e5b4be127dca55b],
Backdoor.ProRat, C:\Windows\temp\peydplkz.tmp, In Quarantäne, [f362a9f14833b284c930c369fc07ab55],
Backdoor.ProRat, C:\Windows\temp\peydwbsl.tmp, In Quarantäne, [81d47921d9a2f93d28d139f3847fd62a],
Backdoor.ProRat, C:\Windows\temp\peyfrzdn.tmp, In Quarantäne, [8acb85154635cc6a4eabe14bfd06ec14],
Backdoor.ProRat, C:\Windows\temp\peyg-l3j.tmp, In Quarantäne, [391cddbd1e5d2e08c73273b98d7639c7],
Backdoor.ProRat, C:\Windows\temp\peyiqhpe.tmp, In Quarantäne, [084d2c6ee19a14229465cd5ffe054fb1],
Backdoor.ProRat, C:\Windows\temp\peyjo2nv.tmp, In Quarantäne, [85d0b8e24f2c2d0983760f1d7e8533cd],
Backdoor.ProRat, C:\Windows\temp\peyktzat.tmp, In Quarantäne, [63f2475391ea8aac956485a731d23dc3],
Backdoor.ProRat, C:\Windows\temp\peyn_7bm.tmp, In Quarantäne, [3d18a8f26d0eac8a45b4111bcd3605fb],
Backdoor.ProRat, C:\Windows\temp\peyq8k3q.tmp, In Quarantäne, [292c297186f587af34c547e5a75cbe42],
Backdoor.ProRat, C:\Windows\temp\peysw6bo.tmp, In Quarantäne, [41149efc92e905316b8e9795e71c9b65],
Backdoor.ProRat, C:\Windows\temp\peyxuoff.tmp, In Quarantäne, [a8ad8f0b1d5ea492c039200c669d5ca4],
Trojan.Vundo, C:\Windows\temp\gos-8w6m.tmp, In Quarantäne, [db7a1e7caad1a0962602da9eac579c64],
Trojan.Vundo, C:\Windows\temp\gos23wcv.tmp, In Quarantäne, [c095e4b63a41bb7b88a0294f25de0cf4],
Trojan.Vundo, C:\Windows\temp\gos28tew.tmp, In Quarantäne, [4d088a10e5961d19e3458bedf60d17e9],
Trojan.Vundo, C:\Windows\temp\gos5uksl.tmp, In Quarantäne, [11448b0f6219a0965cccc6b2877cd729],
Trojan.Vundo, C:\Windows\temp\gosadwft.tmp, In Quarantäne, [95c09a007902c1750523195f659e56aa],
Trojan.Vundo, C:\Windows\temp\gosaeovc.tmp, In Quarantäne, [193c9a00790284b2ce5a2c4c34cf6799],
Trojan.Vundo, C:\Windows\temp\gosfoxdu.tmp, In Quarantäne, [0e47d9c1bdbe62d4b474a8d09b68c33d],
Trojan.Vundo, C:\Windows\temp\gosggml5.tmp, In Quarantäne, [b5a0009a5724c670f632bcbc33d03bc5],
Trojan.Vundo, C:\Windows\temp\gosi9nhi.tmp, In Quarantäne, [c78e4654700b54e2ec3ce29623e08a76],
Trojan.Vundo, C:\Windows\temp\goskwi_x.tmp, In Quarantäne, [ada8aeec9ae1fd3959cf14641ee560a0],
Trojan.Vundo, C:\Windows\temp\gosln7si.tmp, In Quarantäne, [96bf7f1b7dfeb08651d7d0a843c0b14f],
Trojan.Vundo, C:\Windows\temp\gosuevhl.tmp, In Quarantäne, [0154d0ca9ae1d165aa7e81f7867daf51],
Trojan.Vundo, C:\Windows\temp\gosz62cv.tmp, In Quarantäne, [d580e9b1d2a9e650b771e29617ec0df3],
Physische Sektoren: 0
(No malicious items detected)
(end)
ADW Code:
# AdwCleaner v3.214 - Bericht erstellt am 01/07/2014 um 17:56:28
# Aktualisiert 29/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Laxman - LAXMAN-PC
# Gestartet von : C:\Users\Laxman\Downloads\adwcleaner_3.214.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Kaspersky Lab\SafeBrowser
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKCU\Software\SmartBar
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Laxman\AppData\Roaming\Mozilla\Firefox\Profiles\ec69wxq4.default\prefs.js ]
-\\ Google Chrome v25.0.1364.172
[ Datei : C:\Users\Laxman\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [2949 octets] - [29/08/2013 20:45:14]
AdwCleaner[R1].txt - [8668 octets] - [24/01/2014 20:20:36]
AdwCleaner[R2].txt - [1301 octets] - [26/01/2014 09:21:14]
AdwCleaner[R3].txt - [1936 octets] - [01/04/2014 22:47:55]
AdwCleaner[R4].txt - [12861 octets] - [28/06/2014 19:09:56]
AdwCleaner[R5].txt - [2513 octets] - [01/07/2014 17:51:37]
AdwCleaner[R6].txt - [2573 octets] - [01/07/2014 17:53:23]
AdwCleaner[S0].txt - [2927 octets] - [29/08/2013 20:45:58]
AdwCleaner[S1].txt - [7372 octets] - [24/01/2014 20:22:10]
AdwCleaner[S2].txt - [1362 octets] - [26/01/2014 09:24:05]
AdwCleaner[S3].txt - [1997 octets] - [01/04/2014 22:48:46]
AdwCleaner[S4].txt - [11247 octets] - [28/06/2014 19:10:40]
AdwCleaner[S5].txt - [2195 octets] - [01/07/2014 17:56:28]
########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [2255 octets] ##########
JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Laxman on 01.07.2014 at 18:13:20,10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Laxman\AppData\Roaming\mozilla\firefox\profiles\ec69wxq4.default\minidumps [38 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.07.2014 at 18:24:27,96
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02
Ran by Laxman (administrator) on LAXMAN-PC on 01-07-2014 18:25:03
Running from C:\Users\Laxman\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
() C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-08-06] (Egis Technology Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7981088 2009-07-20] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1063200 2013-10-18] (NVIDIA Corporation)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-08-12] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [Hotkey Utility] => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [629280 2009-08-18] ()
HKLM-x32\...\Run: [ArcadeDeluxeAgent] => C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [128296 2009-07-31] (CyberLink Corp.)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKU\.DEFAULT\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-3176568229-742132424-851327841-1003\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [162336 2009-07-22] ()
HKU\S-1-5-21-3176568229-742132424-851327841-1003\...\Policies\Explorer: [NoSetActiveDesktop] 0
HKU\S-1-5-21-3176568229-742132424-851327841-1003\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
Startup: C:\Users\Laxman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll (Egis Technology Inc.)
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\psdprotect.dll (Egis Technology Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.de
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.0.47\coIEPlg.dll No File
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Zonealarm Helper Object - {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} - No File
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.47\coIEPlg.dll No File
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.0.47\coIEPlg.dll No File
Toolbar: HKLM-x32 - ZoneAlarm Security Toolbar - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - No File
Toolbar: HKLM-x32 - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.47\coIEPlg.dll No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Laxman\AppData\Roaming\Mozilla\Firefox\Profiles\ec69wxq4.default
FF NewTab: chrome://lightning/content/newtab.html
FF Homepage: hxxp://uk.yahoo.com/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ReloadEvery - C:\Users\Laxman\AppData\Roaming\Mozilla\Firefox\Profiles\ec69wxq4.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2013-03-16]
FF HKLM-x32\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.0.47\coFFPlgn
FF Extension: Norton Identity Safe Toolbar - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.0.47\coFFPlgn [2014-06-29]
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-29]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-29]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-29]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-29]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-29]
FF HKCU\...\Firefox\Extensions: [{77f1dfb8-d6ce-4f47-bc6a-979e2a14d42a}] - C:\Program Files (x86)\TubeSaver\131.xpi
Chrome:
=======
CHR HomePage: hxxp://www.yahoo.de/
CHR RestoreOnStartup: "hxxp://www.yahoo.de/"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Laxman\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-29]
CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Laxman\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-06-29]
CHR Extension: (Modul zum Sperren von gefährlichen Webseiten) - C:\Users\Laxman\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-06-29]
CHR Extension: (Virtual Keyboard) - C:\Users\Laxman\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-06-29]
CHR Extension: (Norton Identity Protection) - C:\Users\Laxman\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2013-06-13]
CHR Extension: (Anti-Banner) - C:\Users\Laxman\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-29]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2014-05-28]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2014-05-28]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2014-05-28]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2014-05-28]
CHR HKLM-x32\...\Chrome\Extension: [nppllibpnmahfaklnpggkibhkapjkeob] - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.47\Exts\Chrome.crx [2014-05-28]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2014-05-28]
==================== Services (Whitelisted) =================
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2014-05-28] (Kaspersky Lab ZAO)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1155072 2009-02-03] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [311592 2009-08-06] (Egis Technology Inc.)
S2 NCO; C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.47\NST.exe [130104 2014-05-14] (Symantec Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-18] (NVIDIA Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2412344 2014-01-28] (TuneUp Software)
==================== Drivers (Whitelisted) ====================
R0 34385472; C:\Windows\System32\DRIVERS\34385472.sys [460888 2014-06-29] (Kaspersky Lab ZAO)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 ccSet_NST; C:\Windows\system32\drivers\NSTx64\7DE07000.02F\ccSetx64.sys [162392 2014-02-21] (Symantec Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-05-28] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-05-28] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-05-28] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2014-05-28] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-05-28] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2014-05-28] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-05-28] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-01] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation)
S1 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-11-16] (TuneUp Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-01 18:25 - 2014-07-01 18:25 - 00020703 _____ () C:\Users\Laxman\Desktop\FRST.txt
2014-07-01 18:24 - 2014-07-01 18:24 - 00000759 _____ () C:\Users\Laxman\Desktop\JRT.txt
2014-07-01 17:45 - 2014-07-01 17:45 - 00012591 _____ () C:\Users\Laxman\Desktop\backdoor.txt
2014-07-01 10:59 - 2014-07-01 10:59 - 00002262 _____ () C:\Users\Laxman\Downloads\the_shoemakers_daughter.mid
2014-06-30 19:37 - 2014-06-30 19:37 - 01346519 _____ () C:\Users\Laxman\Downloads\adwcleaner_3.214.exe
2014-06-30 19:37 - 2014-06-30 19:37 - 01016261 _____ (Thisisu) C:\Users\Laxman\Downloads\JRT.exe
2014-06-30 19:26 - 2014-06-30 19:26 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-30 19:26 - 2014-06-30 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-30 19:26 - 2014-06-30 19:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-30 19:26 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-30 19:26 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-30 19:26 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-30 19:25 - 2014-06-30 19:25 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Laxman\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-29 17:42 - 2014-06-29 17:44 - 00053420 _____ () C:\Users\Laxman\Downloads\Addition.txt
2014-06-29 17:41 - 2014-06-29 17:44 - 00046123 _____ () C:\Users\Laxman\Downloads\FRST.txt
2014-06-29 17:40 - 2014-06-29 17:40 - 02083328 _____ (Farbar) C:\Users\Laxman\Desktop\FRST64.exe
2014-06-29 17:04 - 2014-06-29 17:18 - 00000000 ___SD () C:\ComboFix
2014-06-29 17:03 - 2014-06-29 17:03 - 05212118 ____R (Swearware) C:\Users\Laxman\Downloads\ComboFix.exe
2014-06-29 16:56 - 2014-06-29 16:56 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Laxman\Downloads\revosetup95.exe
2014-06-29 10:32 - 2014-06-29 11:32 - 00460888 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\34385472.sys
2014-06-29 10:31 - 2014-06-29 10:31 - 00001128 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2014-06-29 10:31 - 2014-06-29 10:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2014-06-29 10:31 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2014-06-29 10:30 - 2014-07-01 18:13 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-29 10:30 - 2014-06-29 10:30 - 00000000 ____D () C:\Windows\ELAMBKUP
2014-06-29 10:30 - 2014-06-29 10:30 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-06-29 10:30 - 2014-05-28 16:38 - 00625248 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-06-29 10:30 - 2014-05-28 16:38 - 00115296 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-06-29 10:11 - 2014-06-29 10:18 - 245907264 _____ () C:\Users\Laxman\Downloads\kis14.0.0.4651abcdefg_de_6138.exe
2014-06-29 09:56 - 2014-06-29 09:56 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-06-29 09:56 - 2014-06-29 09:56 - 00000000 _____ () C:\autoexec.bat
2014-06-29 09:55 - 2014-06-29 16:48 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-06-29 08:50 - 2014-06-29 08:51 - 00000000 ____D () C:\NPE
2014-06-28 19:10 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-27 21:09 - 2014-06-27 21:09 - 00000000 ____D () C:\Qoobox
2014-06-27 21:09 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-27 21:09 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-27 21:09 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-27 21:09 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-27 21:09 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-27 21:09 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-27 21:09 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-27 21:09 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-27 21:00 - 2014-06-29 18:01 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-24 09:59 - 2014-06-24 09:59 - 00000000 ____D () C:\Windows\System32\Tasks\Norton Identity Safe
2014-06-23 21:36 - 2014-06-29 17:03 - 00000000 ____D () C:\Program Files (x86)\Norton Identity Safe
2014-06-23 21:36 - 2014-06-23 21:36 - 00000000 ____D () C:\Windows\system32\Drivers\NSTx64
2014-06-15 07:52 - 2014-06-15 07:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-12 19:11 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-12 19:11 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-12 19:11 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-12 19:11 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-12 19:11 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-12 19:11 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-12 19:11 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-12 19:11 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-12 19:11 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-12 19:11 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-12 19:11 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-12 19:11 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-12 19:11 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-12 19:11 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-12 19:11 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-12 19:11 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-12 19:11 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-12 19:11 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-12 19:11 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 19:11 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 19:11 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-12 19:11 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-12 19:11 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-12 19:11 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-12 19:11 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-12 19:11 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-12 19:11 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-12 19:11 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-12 19:11 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-12 19:11 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-12 19:11 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-12 19:11 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-12 19:11 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-12 19:11 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-12 19:11 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-12 19:11 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-12 19:11 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-12 19:11 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-12 19:11 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-12 19:11 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-12 19:11 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-12 19:11 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-12 19:11 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-12 19:11 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-12 19:11 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-12 19:11 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-12 19:11 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-12 19:11 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-12 19:11 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-12 19:11 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-12 19:11 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-12 19:11 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-12 19:11 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 19:11 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 19:11 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 19:11 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 19:11 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 19:11 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 19:11 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-12 19:11 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-12 19:11 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 19:11 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-12 19:11 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-12 19:11 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-12 19:08 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-12 19:08 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-10 08:49 - 2014-06-10 08:49 - 04447041 _____ () C:\Users\Laxman\Desktop\Sewing for Baby.pdf.5tn3hh5.partial
2014-06-07 21:33 - 2014-06-07 21:34 - 00000000 ____D () C:\Program Files (x86)\Dark Tales - Der Untergang des Hauses Usher von Edgar Allan Poe Sammleredition
2014-06-07 21:33 - 2014-06-07 21:33 - 00000000 ____D () C:\Users\Laxman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dark Tales - Der Untergang des Hauses Usher von Edgar Allan Poe Sammleredition
2014-06-07 21:33 - 2014-06-07 21:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dark Tales - Der Untergang des Hauses Usher von Edgar Allan Poe Sammleredition
==================== One Month Modified Files and Folders =======
2014-07-01 18:26 - 2014-07-01 18:25 - 00020703 _____ () C:\Users\Laxman\Desktop\FRST.txt
2014-07-01 18:25 - 2014-01-24 21:45 - 00000000 ____D () C:\FRST
2014-07-01 18:25 - 2013-03-17 08:49 - 00001284 _____ () C:\Users\Laxman\AppData\Roaming\wklnhst.dat
2014-07-01 18:25 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-07-01 18:24 - 2014-07-01 18:24 - 00000759 _____ () C:\Users\Laxman\Desktop\JRT.txt
2014-07-01 18:13 - 2014-06-29 10:30 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-07-01 18:10 - 2014-03-18 08:07 - 00104448 _____ () C:\Users\Laxman\Desktop\mögen die englein.wps
2014-07-01 18:05 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-01 18:05 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-01 17:59 - 2014-04-01 22:30 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-01 17:58 - 2013-11-06 09:42 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-01 17:58 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-01 17:58 - 2009-07-14 06:51 - 00176623 _____ () C:\Windows\setupact.log
2014-07-01 17:57 - 2013-03-16 04:51 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-01 17:57 - 2009-09-03 11:10 - 16816386 _____ () C:\Windows\PFRO.log
2014-07-01 17:56 - 2013-08-29 20:45 - 00000000 ____D () C:\AdwCleaner
2014-07-01 17:56 - 2013-03-16 03:41 - 01991604 _____ () C:\Windows\WindowsUpdate.log
2014-07-01 17:45 - 2014-07-01 17:45 - 00012591 _____ () C:\Users\Laxman\Desktop\backdoor.txt
2014-07-01 10:59 - 2014-07-01 10:59 - 00002262 _____ () C:\Users\Laxman\Downloads\the_shoemakers_daughter.mid
2014-07-01 07:24 - 2013-03-16 05:15 - 00000000 ____D () C:\Users\Laxman\Documents\DVDVideoSoft
2014-06-30 20:29 - 2013-03-25 22:45 - 00000000 ____D () C:\Users\Laxman\AppData\Local\Windows Live
2014-06-30 19:37 - 2014-06-30 19:37 - 01346519 _____ () C:\Users\Laxman\Downloads\adwcleaner_3.214.exe
2014-06-30 19:37 - 2014-06-30 19:37 - 01016261 _____ (Thisisu) C:\Users\Laxman\Downloads\JRT.exe
2014-06-30 19:26 - 2014-06-30 19:26 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-30 19:26 - 2014-06-30 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-30 19:26 - 2014-06-30 19:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-30 19:25 - 2014-06-30 19:25 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Laxman\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-30 02:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-29 18:01 - 2014-06-27 21:00 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-29 17:44 - 2014-06-29 17:42 - 00053420 _____ () C:\Users\Laxman\Downloads\Addition.txt
2014-06-29 17:44 - 2014-06-29 17:41 - 00046123 _____ () C:\Users\Laxman\Downloads\FRST.txt
2014-06-29 17:40 - 2014-06-29 17:40 - 02083328 _____ (Farbar) C:\Users\Laxman\Desktop\FRST64.exe
2014-06-29 17:18 - 2014-06-29 17:04 - 00000000 ___SD () C:\ComboFix
2014-06-29 17:03 - 2014-06-29 17:03 - 05212118 ____R (Swearware) C:\Users\Laxman\Downloads\ComboFix.exe
2014-06-29 17:03 - 2014-06-23 21:36 - 00000000 ____D () C:\Program Files (x86)\Norton Identity Safe
2014-06-29 16:59 - 2009-09-03 11:27 - 00000000 ____D () C:\ProgramData\Symantec
2014-06-29 16:56 - 2014-06-29 16:56 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Laxman\Downloads\revosetup95.exe
2014-06-29 16:48 - 2014-06-29 09:55 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-06-29 11:32 - 2014-06-29 10:32 - 00460888 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\34385472.sys
2014-06-29 10:31 - 2014-06-29 10:31 - 00001128 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2014-06-29 10:31 - 2014-06-29 10:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2014-06-29 10:31 - 2011-03-20 19:29 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files
2014-06-29 10:30 - 2014-06-29 10:30 - 00000000 ____D () C:\Windows\ELAMBKUP
2014-06-29 10:30 - 2014-06-29 10:30 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-06-29 10:23 - 2009-11-09 10:20 - 00000000 ____D () C:\ProgramData\Norton
2014-06-29 10:18 - 2014-06-29 10:11 - 245907264 _____ () C:\Users\Laxman\Downloads\kis14.0.0.4651abcdefg_de_6138.exe
2014-06-29 09:56 - 2014-06-29 09:56 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-06-29 09:56 - 2014-06-29 09:56 - 00000000 _____ () C:\autoexec.bat
2014-06-29 08:56 - 2013-04-20 07:48 - 00000000 ____D () C:\Users\Laxman\AppData\Local\NPE
2014-06-29 08:51 - 2014-06-29 08:50 - 00000000 ____D () C:\NPE
2014-06-28 19:10 - 2013-03-16 03:53 - 00000000 ____D () C:\Users\Laxman
2014-06-27 21:09 - 2014-06-27 21:09 - 00000000 ____D () C:\Qoobox
2014-06-27 21:09 - 2014-01-25 21:16 - 00000000 ____D () C:\Windows\erdnt
2014-06-24 09:59 - 2014-06-24 09:59 - 00000000 ____D () C:\Windows\System32\Tasks\Norton Identity Safe
2014-06-23 21:56 - 2013-03-16 04:25 - 00000000 ____D () C:\Users\Laxman\Documents\Symantec
2014-06-23 21:36 - 2014-06-23 21:36 - 00000000 ____D () C:\Windows\system32\Drivers\NSTx64
2014-06-23 20:40 - 2013-04-14 07:34 - 00000000 ____D () C:\Users\Laxman\AppData\Local\CrashDumps
2014-06-16 06:45 - 2013-03-16 04:16 - 00000000 ____D () C:\Users\Public\Downloads\Norton
2014-06-15 17:44 - 2013-03-16 09:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-15 11:51 - 2013-04-13 09:13 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2014-06-15 09:20 - 2014-05-10 08:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2014-06-15 07:52 - 2014-06-15 07:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-12 19:51 - 2013-08-15 00:33 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-12 19:45 - 2013-03-16 12:07 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 19:44 - 2009-09-03 10:54 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-12 19:39 - 2014-04-30 09:44 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-10 08:49 - 2014-06-10 08:49 - 04447041 _____ () C:\Users\Laxman\Desktop\Sewing for Baby.pdf.5tn3hh5.partial
2014-06-09 10:04 - 2014-01-28 19:25 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-06-08 11:13 - 2014-06-12 19:08 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-12 19:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-07 21:34 - 2014-06-07 21:33 - 00000000 ____D () C:\Program Files (x86)\Dark Tales - Der Untergang des Hauses Usher von Edgar Allan Poe Sammleredition
2014-06-07 21:34 - 2013-03-23 08:15 - 00016504 _____ () C:\Windows\wininit.ini
2014-06-07 21:33 - 2014-06-07 21:33 - 00000000 ____D () C:\Users\Laxman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dark Tales - Der Untergang des Hauses Usher von Edgar Allan Poe Sammleredition
2014-06-07 21:33 - 2014-06-07 21:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dark Tales - Der Untergang des Hauses Usher von Edgar Allan Poe Sammleredition
2014-06-07 21:33 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-06-07 21:16 - 2009-09-11 11:00 - 00000000 ____D () C:\ProgramData\Temp
2014-06-07 19:40 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
Some content of TEMP:
====================
C:\Users\Laxman\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-30 02:43
==================== End Of Log ============================ --- --- --- |