Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 09.10.2014
Suchlauf-Zeit: 17:29:56
Logdatei: malware.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.10.09.06
Rootkit Datenbank: v2014.10.08.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows XP Service Pack 3
CPU: x86
Dateisystem: NTFS
Benutzer: Markus
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 413167
Verstrichene Zeit: 14 Min, 26 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 7
PUP.Optional.Snapdo.T, HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [307aa17154281323ff9a657089797b85],
PUP.Optional.Snapdo.T, HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [307aa17154281323ff9a657089797b85],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-113541960-917040865-2127168359-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [307aa17154281323ff9a657089797b85],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [307aa17154281323ff9a657089797b85],
PUP.Optional.WPM.A, HKLM\SOFTWARE\supWindowsMangerProtect, In Quarantäne, [a80241d1b6c6d26460c2dea153b11ae6],
PUP.Optional.Incredibar.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\IB Updater, In Quarantäne, [bded759d75070e286d1e4aec0ef57d83],
PUP.Optional.FastStart.A, HKU\S-1-5-21-113541960-917040865-2127168359-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [644618faff7d3105220a2ee840c3d42c],
Registrierungswerte: 5
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [8a20d63ca4d84ee85470d93ef2111fe1]
PUP.Optional.Snapdo.T, HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [d8d22be7b1cb979f1c5b002143c0dd23]
PUP.Optional.Snapdo.T, HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [a00ad53d8bf185b11b5c5ac7a65d06fa]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-113541960-917040865-2127168359-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [57532ee4423abf77f78040e1de2552ae]
PUP.Optional.FastStart.A, HKU\S-1-5-21-113541960-917040865-2127168359-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, In Quarantäne, [644618faff7d3105220a2ee840c3d42c]
Registrierungsdaten: 17
PUP.Optional.SnapDo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[9911ff134e2edd5932fda966f015cf31]
PUP.Optional.SnapDo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[5c4e7c967a02ed4938f8ba5543c26898]
PUP.Optional.Snapdo, HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKBMiqac3dhkGs7WhAThzd5M3MBx_Uyz-SB1xhFWw6lbQe3Fog35VEw6JuWKa5Lfw,,, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKBMiqac3dhkGs7WhAThzd5M3MBx_Uyz-SB1xhFWw6lbQe3Fog35VEw6JuWKa5Lfw,,),Ersetzt,[c3e7769cf8845cda078be23663a2cf31]
PUP.Optional.Snapdo, HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[208a868c6d0f00365d3358c012f3da26]
PUP.Optional.Snapdo, HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[d7d30f0366162610b3de4dcb80850000]
PUP.Optional.Snapdo, HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[2585ae64d6a6af87761d59bf679e7888]
PUP.Optional.Snapdo, HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[fab06ca62656cc6aaee69a7e8184de22]
PUP.Optional.SnapDo.A, HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[6a4082907408092d69c7040b887d34cc]
PUP.Optional.Snapdo, HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKBMiqac3dhkGs7WhAThzd5M3MBx_Uyz-SB1xhFWw6lbQe3Fog35VEw6JuWKa5Lfw,,, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKBMiqac3dhkGs7WhAThzd5M3MBx_Uyz-SB1xhFWw6lbQe3Fog35VEw6JuWKa5Lfw,,),Ersetzt,[8327a66c532988aedbb737e1768f9070]
PUP.Optional.Snapdo, HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[129861b1c2ba6fc72c64fe1a699c649c]
PUP.Optional.Snapdo, HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[2e7cf61c403c9d997c15b06823e214ec]
PUP.Optional.Snapdo, HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[149651c1e696f5410c873ddb7d8822de]
PUP.Optional.Snapdo, HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[b0fa8c865923072f9301150357ae05fb]
PUP.Optional.SnapDo.A, HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiVw,,&q={searchTerms}),Ersetzt,[07a371a156267db953dd19f6887de020]
PUP.Optional.Snapdo, HKU\S-1-5-21-113541960-917040865-2127168359-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiUA,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiUA,,&q={searchTerms}),Ersetzt,[496156bcc2ba3afc7c1775a3877e926e]
PUP.Optional.Snapdo, HKU\S-1-5-21-113541960-917040865-2127168359-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiUA,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiUA,,&q={searchTerms}),Ersetzt,[5951be541e5e0531890b2bed29dc40c0]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-113541960-917040865-2127168359-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiUA,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmPNQVEgaIidPex4G7rsuODcsSJcd2LO827fkyOTYZ68Jwx4znIYDNclo5z4KQGq9qpNB2V9PveIAnfEGnrBs7x42fGKN8JN3azUS7tkyNnOicGUixZ5skLoXL_XkBNJWWNOZfOo8YmbvcJFbasmPQHyiUA,,&q={searchTerms}),Ersetzt,[8129cc46b4c8fa3c49e7a16ed72eba46]
Ordner: 4
PUP.Optional.OffersWizard.A, C:\Programme\Gemeinsame Dateien\Config, In Quarantäne, [a20852c0dd9f43f3c80e71b0eb18d22e],
PUP.Optional.WPM.A, C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WindowsMangerProtect, In Quarantäne, [555566ac96e62511356105f8fe0433cd],
PUP.Optional.Fabulous.Discounts.T, C:\Dokumente und Einstellungen\Markus\Lokale Einstellungen\Anwendungsdaten\fabulous_06301213, In Quarantäne, [3278977b512bab8b17513dc20101d030],
PUP.Optional.GenesisOffers, C:\Dokumente und Einstellungen\Markus\Lokale Einstellungen\Anwendungsdaten\Genesis_06301211, In Quarantäne, [58521af8dd9f092d02973fc82bd8a35d],
Dateien: 2
PUP.Optional.OffersWizard.A, C:\Programme\Gemeinsame Dateien\Config\ver.xml, In Quarantäne, [a20852c0dd9f43f3c80e71b0eb18d22e],
PUP.Optional.OffersWizard.A, C:\Programme\Gemeinsame Dateien\Config\uninstinethnfd.exe, In Quarantäne, [a20852c0dd9f43f3c80e71b0eb18d22e],
Physische Sektoren: 0
(No malicious items detected) Code:
# AdwCleaner v3.311 - Bericht erstellt am 09/10/2014 um 19:16:37
# Aktualisiert 30/09/2014 von Xplode
# Betriebssystem : Microsoft Windows XP Service Pack 3 (32 bits)
# Benutzername : Markus - MICHAEL
# Gestartet von : C:\Dokumente und Einstellungen\Markus\Eigene Dateien\Downloads\AdwCleaner_3.311.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : WindowsMangerProtect
Dienst Gelöscht : UserAccess7
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\WINDOWS\system32\UAService7.exe
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Search.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\InetStat
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
***** [ Browser ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v32.0.3 (x86 de)
[ Datei : C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\Mozilla\Firefox\Profiles\ag3yte0o.default\prefs.js ]
Zeile gelöscht : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-but[...]
Zeile gelöscht : user_pref("extensions.oCdUaOqOxBsk.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sum[...]
Zeile gelöscht : user_pref("extensions.quick_start.enable_search1", false);
Zeile gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [37737 octets] - [20/03/2014 16:27:26]
AdwCleaner[R1].txt - [10711 octets] - [03/07/2014 11:36:42]
AdwCleaner[R2].txt - [2961 octets] - [09/10/2014 19:14:13]
AdwCleaner[S0].txt - [37205 octets] - [20/03/2014 16:44:20]
AdwCleaner[S1].txt - [8697 octets] - [03/07/2014 11:37:49]
AdwCleaner[S2].txt - [2713 octets] - [09/10/2014 19:16:37]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2773 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.2 (10.09.2014:1)
OS: Microsoft Windows XP x86
Ran by Markus on 09.10.2014 at 20:09:24,64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted [File] C:\Dokumente und Einstellungen\All Users\Microsoft\DRM\awh3.tmp [TDL4 Trace]
Successfully deleted [File] C:\Dokumente und Einstellungen\All Users\Microsoft\DRM\awh9.tmp [TDL4 Trace]
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\mozilla\firefox\profiles\ag3yte0o.default\prefs.js
user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-
Emptied folder: C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\mozilla\firefox\profiles\ag3yte0o.default\minidumps [15 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09.10.2014 at 20:12:39,40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-10-2014
Ran by Markus (administrator) on MICHAEL on 09-10-2014 20:14:21
Running from C:\Dokumente und Einstellungen\Markus\Desktop
Loaded Profile: Markus (Available profiles: Markus)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\Programme\Gemeinsame Dateien\DeviceHelper\DeviceManager.exe
(Oracle Corporation) C:\Programme\Java\jre7\bin\jqs.exe
(Hewlett-Packard Company) C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
(Nero AG) C:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe
(Prolific Technology Inc.) C:\Programme\Nero\Nero BackItUp 4\IoctlSvc.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Agere Systems) C:\WINDOWS\AGRSMMSG.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe
(Team H2O) C:\Programme\Syncrosoft\POS\H2O\cledx.exe
(Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
(Dropbox, Inc.) C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\Dropbox\bin\Dropbox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [igfxhkcmd] => C:\WINDOWS\system32\hkcmd.exe [77824 2006-02-07] (Intel Corporation)
HKLM\...\Run: [igfxpers] => C:\WINDOWS\system32\igfxpers.exe [118784 2006-02-07] (Intel Corporation)
HKLM\...\Run: [SkyTel] => C:\WINDOWS\SkyTel.EXE [2879488 2006-05-16] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AGRSMMSG] => C:\WINDOWS\AGRSMMSG.exe [88203 2005-09-09] (Agere Systems)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16239616 2006-06-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [H2O] => C:\Programme\SyncroSoft\Pos\H2O\cledx.exe [385024 2005-10-23] (Team H2O)
HKLM\...\Run: [NBKeyScan] => C:\Programme\Nero\Nero BackItUp 4\NBKeyScan.exe [2254120 2008-12-05] (Nero AG)
HKLM\...\Run: [Adobe ARM] => C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\RunServicesOnce: [capscanuninstall] => "C:\WINDOWS\system32\command.com" /c del "C:\DOKUME~1\Markus\LOKALE~1\Temp\uninstal.exe" <===== ATTENTION
Startup: C:\Dokumente und Einstellungen\Markus\Startmenü\Programme\Autostart\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Dokumente und Einstellungen\Schlee\Startmenü\Programme\Autostart\OpenOffice.org 2.0.lnk
ShortcutTarget: OpenOffice.org 2.0.lnk -> C:\Programme\OpenOffice.org 2.0\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} hxxp://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\Mozilla\Firefox\Profiles\ag3yte0o.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Programme\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\Mozilla\Firefox\Profiles\ag3yte0o.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\Mozilla\Firefox\Profiles\ag3yte0o.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-08-10]
FF Extension: Java Console - C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-09-24]
FF Extension: Java Console - C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-09-24]
FF Extension: Java Console - C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-09-24]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-15]
FF HKCU\...\Thunderbird\Extensions: [{380AE6CB-09B9-4373-B360-D01C2462A6E7}] - C:\Programme\BullGuard Ltd\BullGuard\backup\thunderbirdbkplugin
FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] - C:\Programme\BullGuard Ltd\BullGuard\antispam\tbspamfilter
Chrome:
=======
CHR CustomProfile: C:\Dokumente und Einstellungen\Markus\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 6to4; C:\WINDOWS\System32\6to4svc.dll [100864 2010-02-12] (Microsoft Corporation)
R2 DeviceManager; C:\Programme\Gemeinsame Dateien\DeviceHelper\DeviceManager.exe [40960 2009-05-25] () [File not signed]
S3 IDriverT; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Programme\Java\jre7\bin\jqs.exe [182696 2014-07-25] (Oracle Corporation)
R2 LightScribeService; C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe [73728 2005-11-15] (Hewlett-Packard Company) [File not signed]
R2 MDM; C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe [270336 2001-02-23] (Microsoft Corporation) [File not signed]
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [114288 2014-09-24] (Mozilla Foundation)
R2 Nero BackItUp Scheduler 4.0; C:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe [935208 2008-12-05] (Nero AG)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [89136 2003-07-28] (Microsoft Corporation)
R2 PLFlash DeviceIoControl Service; C:\Programme\Nero\Nero BackItUp 4\IoctlSvc.exe [81920 2008-12-05] (Prolific Technology Inc.) [File not signed]
S3 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation)
S2 2248c867; "C:\WINDOWS\system32\rundll32.exe" "c:\progra~1\suppor~1\SupporterSvc.dll",service
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [20747 2010-07-24] (Meetinghouse Data Communications) [File not signed]
S3 AWINDIS5; C:\WINDOWS\system32\AWINDIS5.SYS [16194 2006-02-25] (AMBIT Microsystems Corporation.) [File not signed]
R2 BVRPMPR5; C:\WINDOWS\system32\drivers\BVRPMPR5.SYS [49904 2007-02-21] (Avanquest Software) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 CLEDX; C:\WINDOWS\System32\DRIVERS\cledx.sys [33792 2005-05-09] (Team H2O) [File not signed]
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 NETGEAR_WG511_SERVICE; C:\WINDOWS\System32\DRIVERS\wg511nd5.sys [488992 2006-03-23] (Atheros Communications, Inc.)
S3 qcusbser; C:\WINDOWS\System32\DRIVERS\qcusbser.sys [103552 2009-05-25] (TCT International Mobile Ltd)
R3 RT73; C:\WINDOWS\System32\DRIVERS\rt73.sys [252928 2006-01-12] (Ralink Technology, Corp.)
S3 SIVDRIVER; C:\WINDOWS\system32\Drivers\SIVX32.sys [19944 2007-02-24] (Ray Hinchliffe)
R1 Tcpip6; C:\WINDOWS\System32\DRIVERS\tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
S3 YMIDUSB; C:\WINDOWS\System32\Drivers\ymidusb.sys [14464 2005-07-25] (YAMAHA Corporation) [File not signed]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz127; \??\C:\DOKUME~1\Markus\LOKALE~1\Temp\cpuz_x32.sys [X]
S3 GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [X]
S3 GPU-Z; \??\C:\DOKUME~1\Markus\LOKALE~1\Temp\GPU-Z.sys [X]
S4 IntelIde; No ImagePath
S3 L6PODX3LV; System32\Drivers\L6PODX3LV.sys [X]
S0 O2MDRDR; system32\DRIVERS\o2media.sys [X]
S0 O2SDRDR; system32\DRIVERS\o2sd.sys [X]
S3 Profos; \??\C:\Programme\BullGuard Ltd\BullGuard\antirootkit\profos.sys [X]
S0 rseb; No ImagePath
S4 s24trans; system32\DRIVERS\s24trans.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 SPOTIGOSp50; System32\Drivers\SPOTIGOSp50.sys [X]
U3 TlntSvr; No ImagePath
S3 Trufos; \??\C:\Programme\BullGuard Ltd\BullGuard\antirootkit\trufos.sys [X]
S3 w39n51; system32\DRIVERS\w39n51.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-09 20:12 - 2014-10-09 20:12 - 00001276 _____ () C:\Dokumente und Einstellungen\Markus\Desktop\JRT.txt
2014-10-09 20:04 - 2014-10-09 20:04 - 00002853 _____ () C:\Dokumente und Einstellungen\Markus\Desktop\AdwCleaner[S2].txt
2014-10-09 18:01 - 2014-10-09 18:01 - 00016251 _____ () C:\Dokumente und Einstellungen\Markus\Desktop\malware.txt
2014-10-09 17:29 - 2014-10-09 17:29 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-10-09 17:28 - 2014-10-09 17:28 - 00000749 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-09 17:28 - 2014-10-09 17:28 - 00000000 ____D () C:\Programme\Malwarebytes Anti-Malware
2014-10-09 17:28 - 2014-10-09 17:28 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes Anti-Malware
2014-10-09 17:28 - 2014-05-12 07:26 - 00053208 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-10-09 17:28 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-10-07 23:11 - 2014-10-07 23:11 - 00072225 ____C () C:\ComboFix.txt
2014-10-07 23:11 - 2014-10-07 23:11 - 00000000 ____D () C:\Dokumente und Einstellungen\Schlee\Lokale Einstellungen\temp
2014-10-07 23:11 - 2014-10-07 23:11 - 00000000 ____D () C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\temp
2014-10-07 23:11 - 2014-10-07 23:11 - 00000000 ____D () C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\temp
2014-10-07 23:04 - 2014-10-09 20:14 - 00000000 ____D () C:\Dokumente und Einstellungen\Markus\Lokale Einstellungen\temp
2014-10-07 23:04 - 2014-10-07 23:04 - 00008192 ____H () C:\WINDOWS\system32\config\SECURITY.tmp.LOG
2014-10-07 23:04 - 2014-10-07 23:04 - 00000000 ____H () C:\WINDOWS\system32\config\system.tmp.LOG
2014-10-07 23:04 - 2014-10-07 23:04 - 00000000 ____H () C:\WINDOWS\system32\config\software.tmp.LOG
2014-10-07 23:04 - 2014-10-07 23:04 - 00000000 ____H () C:\WINDOWS\system32\config\SAM.tmp.LOG
2014-10-07 23:04 - 2014-10-07 23:04 - 00000000 ____H () C:\WINDOWS\system32\config\default.tmp.LOG
2014-10-07 14:55 - 2014-10-07 14:55 - 05582481 ___RC (Swearware) C:\Dokumente und Einstellungen\Markus\Desktop\ComboFix.exe
2014-10-07 14:46 - 2014-10-07 14:46 - 00000889 _____ () C:\Dokumente und Einstellungen\Markus\Desktop\Revo Uninstaller.lnk
2014-10-07 14:46 - 2014-10-07 14:46 - 00000000 ____D () C:\Programme\VS Revo Group
2014-10-06 13:01 - 2014-10-09 20:14 - 00015000 _____ () C:\Dokumente und Einstellungen\Markus\Desktop\FRST.txt
2014-10-06 13:01 - 2014-10-06 13:01 - 00105303 _____ () C:\Dokumente und Einstellungen\Markus\Desktop\Addition.txt
2014-10-06 13:01 - 2014-10-06 13:01 - 00066755 _____ () C:\Dokumente und Einstellungen\Markus\Desktop\Shortcut.txt
2014-10-06 12:50 - 2014-10-06 12:50 - 01101312 ____C (Farbar) C:\Dokumente und Einstellungen\Markus\Desktop\FRST.exe
2014-10-04 12:49 - 2014-10-04 12:50 - 00000000 ____D () C:\Dokumente und Einstellungen\Markus\Desktop\Neuer Ordner
2014-09-27 15:33 - 2014-09-27 15:37 - 00000000 ____D () C:\Dokumente und Einstellungen\Markus\Desktop\Breakfast in America
2014-09-24 22:43 - 2014-09-24 22:44 - 00000000 ____D () C:\Programme\Mozilla Firefox
2014-09-24 13:04 - 2014-09-24 13:04 - 03675824 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-09-11 16:31 - 2014-09-11 16:31 - 00027987 _____ () C:\Dokumente und Einstellungen\Markus\Lokale Einstellungen\Anwendungsdaten\recently-used.xbel
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-09 20:14 - 2014-03-16 17:37 - 00000000 ___DC () C:\FRST
2014-10-09 20:04 - 2012-07-17 15:19 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-10-09 19:19 - 2013-03-12 14:27 - 00000000 ___RD () C:\Dokumente und Einstellungen\Markus\Eigene Dateien\Dropbox
2014-10-09 19:19 - 2013-03-12 14:24 - 00000000 ____D () C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\Dropbox
2014-10-09 19:19 - 2006-08-17 23:36 - 01802211 _____ () C:\WINDOWS\WindowsUpdate.log
2014-10-09 19:19 - 2006-08-17 23:22 - 00002206 ____C () C:\WINDOWS\system32\wpa.dbl
2014-10-09 19:18 - 2014-03-15 16:30 - 00000224 _____ () C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Benachrichtigung – Anmeldung.job
2014-10-09 19:18 - 2013-08-14 19:20 - 00241399 _____ () C:\WINDOWS\setupapi.log
2014-10-09 19:18 - 2006-08-18 00:32 - 00000159 ____C () C:\WINDOWS\wiadebug.log
2014-10-09 19:18 - 2006-08-18 00:32 - 00000050 ____C () C:\WINDOWS\wiaservc.log
2014-10-09 19:18 - 2006-08-17 23:40 - 00000006 ___HC () C:\WINDOWS\Tasks\SA.DAT
2014-10-09 19:16 - 2014-03-20 16:27 - 00000000 ___DC () C:\AdwCleaner
2014-10-09 19:16 - 2006-10-30 11:48 - 00000190 __SHC () C:\Dokumente und Einstellungen\Markus\ntuser.ini
2014-10-09 19:16 - 2006-08-17 23:40 - 00032332 _____ () C:\WINDOWS\SchedLgU.Txt
2014-10-09 17:28 - 2006-08-18 00:29 - 00000000 ___RD () C:\Programme
2014-10-09 17:28 - 2006-08-18 00:29 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme
2014-10-09 13:51 - 2006-08-17 23:40 - 00000000 __SHD () C:\Dokumente und Einstellungen\NetworkService
2014-10-08 15:03 - 2014-03-15 16:30 - 00000218 _____ () C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Monatliche Benachrichtigung.job
2014-10-07 23:11 - 2014-03-19 14:40 - 00000000 ___DC () C:\Qoobox
2014-10-07 23:06 - 2006-08-17 23:22 - 00000227 ____C () C:\WINDOWS\system.ini
2014-10-07 23:05 - 2006-08-18 01:27 - 34078720 _____ () C:\WINDOWS\system32\config\software.bak
2014-10-07 23:05 - 2006-08-18 01:27 - 09437184 _____ () C:\WINDOWS\system32\config\system.bak
2014-10-07 23:05 - 2006-08-18 01:27 - 00524288 _____ () C:\WINDOWS\system32\config\default.bak
2014-10-07 23:05 - 2006-08-18 00:28 - 00262144 _____ () C:\WINDOWS\system32\config\SECURITY.bak
2014-10-07 23:05 - 2006-08-18 00:28 - 00262144 _____ () C:\WINDOWS\system32\config\SAM.bak
2014-10-07 23:04 - 2014-03-19 14:40 - 00000000 ____D () C:\WINDOWS\erdnt
2014-10-07 14:46 - 2006-10-30 11:48 - 00000000 ___RD () C:\Dokumente und Einstellungen\Markus\Startmenü\Programme
2014-10-06 16:44 - 2013-01-27 15:36 - 00003120 _____ () C:\WINDOWS\setupact.log
2014-10-04 12:50 - 2009-02-25 00:26 - 00000000 ____D () C:\Dokumente und Einstellungen\Markus\Anwendungsdaten\vlc
2014-09-30 00:46 - 2014-09-01 15:50 - 00000000 ____D () C:\Dokumente und Einstellungen\Markus\Desktop\ZA komplett
2014-09-29 15:47 - 2014-06-04 10:42 - 00079360 ___SH () C:\Dokumente und Einstellungen\Markus\Desktop\Thumbs.db
2014-09-28 14:01 - 2008-04-12 18:59 - 00000000 ___DC () C:\Temp
2014-09-25 10:50 - 2012-05-06 13:10 - 00000000 ____D () C:\Programme\Mozilla Maintenance Service
2014-09-24 13:04 - 2012-04-11 10:40 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-09-24 13:04 - 2011-05-15 21:18 - 00071344 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-09-20 09:33 - 2006-10-30 11:48 - 00000000 ___RD () C:\Dokumente und Einstellungen\Markus\Startmenü\Programme\Autostart
2014-09-20 09:32 - 2013-11-03 19:43 - 00001033 _____ () C:\Dokumente und Einstellungen\Markus\Desktop\Dropbox.lnk
2014-09-20 09:32 - 2013-11-03 19:41 - 00000000 ____D () C:\Dokumente und Einstellungen\Markus\Startmenü\Programme\Dropbox
2014-09-11 16:31 - 2014-09-05 12:31 - 00000000 ____D () C:\Dokumente und Einstellungen\Markus\.gimp-2.8
2014-09-11 16:28 - 2014-09-05 12:34 - 00000000 ____D () C:\Dokumente und Einstellungen\Markus\Lokale Einstellungen\Anwendungsdaten\gtk-2.0
2014-09-10 13:35 - 2013-08-14 19:28 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-09-10 13:30 - 2006-11-03 11:49 - 98758480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-09-10 11:28 - 2006-10-30 13:03 - 00060928 ____C () C:\Dokumente und Einstellungen\Markus\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some content of TEMP:
====================
C:\Dokumente und Einstellungen\Markus\Lokale Einstellungen\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmphnx8ew.dll
C:\Dokumente und Einstellungen\Markus\Lokale Einstellungen\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================ --- --- ---
alle 4 dateien.
grüße |