Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 01.02.2015
Suchlauf-Zeit: 10:51:04
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.02.01.01
Rootkit Datenbank: v2015.01.14.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Admin
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 337306
Verstrichene Zeit: 22 Min, 0 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 0
(Keine schädliche Elemente erkannt)
Registrierungswerte: 2
PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Vosteran\\, In Quarantäne, [46ff57c2c8c2fd39249a70987095e21e]
PUP.Optional.Vosteran, HKU\S-1-5-21-1065548463-2339556138-460890249-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Vosteran, In Quarantäne, [87be5ebb66242214ce5458b1996c649c]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 0
(Keine schädliche Elemente erkannt)
Dateien: 7
PUP.Optional.OpenCandy.A, C:\Users\Admin\Downloads\winamp565_full_emusic-7plus_all.exe, In Quarantäne, [56ef60b9177352e4d0ffa59df70928d8],
PUP.Optional.MultiPlug.A, C:\Users\Admin\Downloads\Download.exe, In Quarantäne, [e1641dfcbcce7db994ec93775ea42fd1],
PUP.Optional.FriedCookie, C:\Users\Admin\Downloads\adobe_flash_setup(1).exe, In Quarantäne, [d4710613c0caa690f4ee19818f76b050],
PUP.Optional.FriedCookie, C:\Users\Admin\Downloads\adobe_flash_setup(2).exe, In Quarantäne, [85c01bfeb6d4e452c81a5a408c79659b],
PUP.Optional.FriedCookie, C:\Users\Admin\Downloads\adobe_flash_setup(3).exe, In Quarantäne, [b78ed841b0da2610b72bbae0b94cc53b],
PUP.Optional.FriedCookie, C:\Users\Admin\Downloads\adobe_flash_setup(4).exe, In Quarantäne, [261f14051179fe38ae34415962a320e0],
PUP.Optional.FriedCookie, C:\Users\Admin\Downloads\adobe_flash_setup.exe, In Quarantäne, [59ec20f9addd71c5ca181b7fd2337789],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end)
und mal ein zwischendurch dankeschön für mittendrin :-)
AdwCleaner Logfile:
Code:
# AdwCleaner v4.109 - Bericht erstellt am 01/02/2015 um 11:43:01
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-01-26.1 [Live]
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzername : Admin - NB_01
# Gestartet von : C:\Users\Admin\Desktop\AdwCleaner_4.109.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\v2thpemd.default\Extensions\{cc5be304-cd48-4ebc-bd30-67f7edeaefb7}
Datei Gelöscht : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\v2thpemd.default\searchplugins\securesearch.xml
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D37BD00-E9FD-40D1-80E7-1795E510ECAA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\adawarebp
Schlüssel Gelöscht : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v35.0.1 (x86 de)
*************************
AdwCleaner[R0].txt - [12285 octets] - [04/01/2015 16:56:59]
AdwCleaner[R1].txt - [3447 octets] - [01/02/2015 11:27:26]
AdwCleaner[S0].txt - [11105 octets] - [04/01/2015 16:59:21]
AdwCleaner[S1].txt - [3210 octets] - [01/02/2015 11:43:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3270 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Ultimate x64
Ran by Admin on 01.02.2015 at 11:50:27,34
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\v2thpemd.default\prefs.js
user_pref("browser.search.selectedEngine", "Ad-Aware SecureSearch");
user_pref("extensions.9bWaJCDESkGo3tKR.url", "hxxp://guardt.net/sync2/?q=hfZ9ofV9CShEAen0rTwGrHgMg708BNmGWj8blchGheDUojw9rjsGqHsErdUEqihIC7n0rjnFrTs6rTaGqHk4tNhVCT94tMVKhd98rj
Emptied folder: C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\v2thpemd.default\minidumps [125 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.02.2015 at 11:53:46,45
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by Admin (administrator) on NB_01 on 01-02-2015 12:13:25
Running from C:\Users\Admin\Downloads
Loaded Profiles: Admin (Available profiles: Admin)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.2.9.5\LavasoftTcpService.exe
() C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.5.202.7299\AdAwareTray.exe
(Lavasoft) C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Thisisu) C:\Users\Admin\Desktop\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Admin\Downloads\FRST64(3).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3023600 2013-02-25] (Synaptics Incorporated)
HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.5.202.7299\AdAwareTray.exe [8947008 2014-12-18] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1065548463-2339556138-460890249-1000\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1367360 2014-12-16] (Lavasoft)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1065548463-2339556138-460890249-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1065548463-2339556138-460890249-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1065548463-2339556138-460890249-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\v2thpemd.default
FF NewTab: https://www.google.com/
FF Homepage: https://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.5.202.7299\AdAwareService.exe [713568 2014-12-18] ()
R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.2.9.5\LavasoftTcpService.exe [1351512 2014-12-16] (Lavasoft Limited)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [15208 2014-12-16] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 SMSCIRDA; C:\Windows\System32\DRIVERS\SMSCir64.sys [37760 2007-04-25] (SMSC)
S3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [389240 2014-10-09] (BitDefender S.R.L.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-01 12:13 - 2015-02-01 12:13 - 02131456 _____ (Farbar) C:\Users\Admin\Downloads\FRST64(3).exe
2015-02-01 11:53 - 2015-02-01 11:53 - 00001126 _____ () C:\Users\Admin\Desktop\JRT.txt
2015-02-01 11:50 - 2015-02-01 11:50 - 00000000 ____D () C:\Windows\ERUNT
2015-02-01 11:49 - 2015-02-01 11:49 - 01707939 _____ (Thisisu) C:\Users\Admin\Desktop\JRT.exe
2015-02-01 11:48 - 2015-02-01 11:49 - 01707939 _____ (Thisisu) C:\Users\Admin\Downloads\JRT.exe
2015-02-01 11:26 - 2015-02-01 11:25 - 02194432 _____ () C:\Users\Admin\Desktop\AdwCleaner_4.109.exe
2015-02-01 11:25 - 2015-02-01 11:25 - 02194432 _____ () C:\Users\Admin\Downloads\AdwCleaner_4.109.exe
2015-02-01 11:19 - 2015-02-01 11:19 - 00002500 _____ () C:\Users\Admin\Desktop\mbam.txt
2015-02-01 10:50 - 2015-02-01 11:46 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-01 10:50 - 2015-02-01 10:50 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-01 10:50 - 2015-02-01 10:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-01 10:49 - 2015-02-01 10:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-01 10:49 - 2015-02-01 10:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-01 10:49 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-01 10:49 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-01 10:49 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-01 10:46 - 2015-02-01 10:47 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-31 20:42 - 2015-01-31 20:42 - 00016055 _____ () C:\ComboFix.txt
2015-01-31 20:12 - 2015-01-31 20:08 - 05611408 ____R (Swearware) C:\Users\Admin\Desktop\ComboFix.exe
2015-01-31 20:12 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-01-31 20:12 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-01-31 20:12 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-01-31 20:12 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-01-31 20:12 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-01-31 20:12 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-01-31 20:12 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-01-31 20:12 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-01-31 20:09 - 2015-01-31 20:43 - 00000000 ____D () C:\Qoobox
2015-01-31 20:09 - 2015-01-31 20:40 - 00000000 ____D () C:\Windows\erdnt
2015-01-31 20:07 - 2015-01-31 20:08 - 05611408 ____R (Swearware) C:\Users\Admin\Downloads\ComboFix.exe
2015-01-31 20:01 - 2015-01-31 20:01 - 00001276 _____ () C:\Users\Admin\Desktop\Revo Uninstaller.lnk
2015-01-31 20:01 - 2015-01-31 20:01 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-01-31 20:00 - 2015-01-31 20:01 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Admin\Downloads\revosetup95.exe
2015-01-30 23:12 - 2015-01-30 23:12 - 02130432 _____ (Farbar) C:\Users\Admin\Downloads\FRST64(2).exe
2015-01-30 19:24 - 2015-01-30 23:25 - 00029785 _____ () C:\Users\Admin\Downloads\Addition.txt
2015-01-30 19:23 - 2015-02-01 12:13 - 00007954 _____ () C:\Users\Admin\Downloads\FRST.txt
2015-01-30 19:22 - 2015-02-01 12:13 - 00000000 ____D () C:\FRST
2015-01-30 19:22 - 2015-01-30 19:22 - 02130432 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2015-01-30 19:22 - 2015-01-30 19:22 - 02130432 _____ (Farbar) C:\Users\Admin\Downloads\FRST64(1).exe
2015-01-26 22:33 - 2015-01-26 22:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-15 11:12 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-15 11:12 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-15 11:12 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-15 11:12 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-15 11:12 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-15 11:12 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-15 11:12 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 21:00 - 2015-01-26 22:00 - 04070576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-01-14 08:31 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 08:31 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 08:31 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 08:31 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 08:31 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 08:31 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-04 17:39 - 2015-01-04 17:39 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\LavasoftStatistics
2015-01-04 17:39 - 2015-01-04 17:39 - 00000000 ____D () C:\Users\Admin\AppData\Local\Lavasoft
2015-01-04 17:38 - 2015-01-04 17:38 - 00004648 _____ () C:\Windows\SysWOW64\LavasoftTcpService.ini
2015-01-04 17:38 - 2015-01-04 17:38 - 00002480 _____ () C:\Windows\SysWOW64\LavasoftTcpServiceOff.ini
2015-01-04 17:38 - 2015-01-04 17:38 - 00002480 _____ () C:\Windows\system32\LavasoftTcpServiceOff.ini
2015-01-04 17:38 - 2014-12-16 12:10 - 00358736 _____ (Lavasoft Limited) C:\Windows\system32\LavasoftTcpService64.dll
2015-01-04 17:38 - 2014-12-16 12:10 - 00312424 _____ (Lavasoft Limited) C:\Windows\SysWOW64\LavasoftTcpService.dll
2015-01-04 17:37 - 2015-01-04 17:37 - 00000000 ____D () C:\Program Files (x86)\Lavasoft
2015-01-04 17:36 - 2015-02-01 11:45 - 00002333 _____ () C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2015-01-04 17:36 - 2015-01-04 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2015-01-04 17:29 - 2015-01-04 17:29 - 00000000 ____D () C:\Program Files\Lavasoft
2015-01-04 17:22 - 2015-01-04 17:36 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Lavasoft
2015-01-04 17:21 - 2015-01-04 17:21 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2015-01-04 17:09 - 2015-01-04 17:36 - 00000000 ____D () C:\ProgramData\Lavasoft
2015-01-04 17:09 - 2015-01-04 17:09 - 01937320 _____ () C:\Users\Admin\Downloads\AdAware115WebInstaller.exe
2015-01-04 16:56 - 2015-02-01 11:43 - 00000000 ____D () C:\AdwCleaner
2015-01-04 16:56 - 2015-01-04 16:56 - 02173952 _____ () C:\Users\Admin\Downloads\adwcleaner_4.106.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-01 12:00 - 2013-08-20 18:58 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-01 11:52 - 2009-07-14 05:45 - 00023312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-01 11:52 - 2009-07-14 05:45 - 00023312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-01 11:44 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-01 11:44 - 2009-07-14 05:51 - 00080927 _____ () C:\Windows\setupact.log
2015-02-01 11:43 - 2013-08-20 20:07 - 00108146 _____ () C:\Windows\PFRO.log
2015-02-01 11:43 - 2013-08-11 17:28 - 01779480 _____ () C:\Windows\WindowsUpdate.log
2015-01-31 22:16 - 2014-02-26 10:19 - 01594104 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-01-31 22:16 - 2009-07-14 18:58 - 00699470 _____ () C:\Windows\system32\perfh007.dat
2015-01-31 22:16 - 2009-07-14 18:58 - 00149578 _____ () C:\Windows\system32\perfc007.dat
2015-01-31 22:16 - 2009-07-14 06:13 - 01594104 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-31 20:42 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-01-31 20:37 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-01-27 10:00 - 2013-08-20 18:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-26 22:00 - 2013-08-20 18:58 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-26 22:00 - 2013-08-20 18:58 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-26 22:00 - 2013-08-20 18:58 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-26 10:35 - 2014-08-07 20:33 - 00000000 ____D () C:\Users\Admin\Desktop\Ly
2015-01-14 09:25 - 2013-08-20 20:58 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 09:22 - 2013-08-11 19:20 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-04 16:05 - 2014-12-28 18:05 - 00000089 _____ () C:\Users\Admin\AppData\Roaming\WB.CFG
2015-01-04 09:56 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
==================== Files in the root of some directories =======
2014-12-28 18:05 - 2015-01-04 16:05 - 0000089 _____ () C:\Users\Admin\AppData\Roaming\WB.CFG
Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\Quarantine.exe
C:\Users\Admin\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-26 17:33
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
Hallo! Noch eine letzte Frage , muss ich noch was machen - derzeit sind die beschriebenen Probleme nämlich weg ! Vielen Dank, erstmal .. wie kann ich mich nun am besten vor wiederholungstätern schützen, gibts da empfehlungen :-) ? Und wie kann man sich bei euch fleissigen Helferlein erkenntlich zeigen? Ein riesendanke kann ich ja schon mal loswerden :-)