kleine20 | 16.02.2015 22:26 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 16.02.2015 20:34:09, SYSTEM, KERSTIN-PC, Protection, Malware Protection, Starting,
Protection, 16.02.2015 20:34:09, SYSTEM, KERSTIN-PC, Protection, Malware Protection, Started,
Protection, 16.02.2015 20:34:09, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Starting,
Update, 16.02.2015 20:34:10, SYSTEM, KERSTIN-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Update, 16.02.2015 20:34:10, SYSTEM, KERSTIN-PC, Manual, Rootkit Database, 2014.11.18.1, 2015.2.3.1,
Update, 16.02.2015 20:34:32, SYSTEM, KERSTIN-PC, Manual, Malware Database, 2014.11.20.6, 2015.2.16.7,
Protection, 16.02.2015 20:34:32, SYSTEM, KERSTIN-PC, Protection, Refresh, Starting,
Protection, 16.02.2015 20:34:49, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Started,
Protection, 16.02.2015 20:34:50, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Stopping,
Protection, 16.02.2015 20:34:50, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Stopped,
Protection, 16.02.2015 20:35:05, SYSTEM, KERSTIN-PC, Protection, Refresh, Success,
Protection, 16.02.2015 20:35:05, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Starting,
Protection, 16.02.2015 20:35:06, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Started,
Update, 16.02.2015 20:53:38, SYSTEM, KERSTIN-PC, Scheduler, Malware Database, 2015.2.16.7, 2015.2.16.8,
Protection, 16.02.2015 20:53:38, SYSTEM, KERSTIN-PC, Protection, Refresh, Starting,
Protection, 16.02.2015 20:53:38, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Stopping,
Protection, 16.02.2015 20:53:38, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Stopped,
Protection, 16.02.2015 20:54:29, SYSTEM, KERSTIN-PC, Protection, Refresh, Success,
Protection, 16.02.2015 20:54:29, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Starting,
Protection, 16.02.2015 20:54:36, SYSTEM, KERSTIN-PC, Protection, Malicious Website Protection, Started,
(end) Code:
# AdwCleaner v4.110 - Bericht erstellt 16/02/2015 um 21:36:21
# Aktualisiert 05/02/2015 von Xplode
# Datenbank : 2015-02-14.2 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : Kerstin - KERSTIN-PC
# Gestarted von : C:\Users\Kerstin\Downloads\AdwCleaner_4.110.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\ProgramData\Registry Helper
Ordner Gelöscht : C:\ProgramData\drivergenius
Ordner Gelöscht : C:\Program Files (x86)\predm
Ordner Gelöscht : C:\Users\Kerstin\AppData\Local\Genesis
Ordner Gelöscht : C:\Users\Kerstin\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Kerstin\AppData\Roaming\Activeris
Ordner Gelöscht : C:\Users\Kerstin\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\sparpilot@sparpilot.com
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Windows\SysWOW64\RegistryHelperLM.ocx
Datei Gelöscht : C:\Windows\System32\drivers\netfilter64.sys
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\Kerstin\AppData\Local\AnyProtectScannerSetup.exe
Datei Gelöscht : C:\Users\Kerstin\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\ask-search.xml
Datei Gelöscht : C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\user.js
Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_api.ciuvo.com_0.localstorage
Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_api.ciuvo.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\Desktop\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\Desktop\Search.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (3).lnk
Verknüpfung Desinfiziert : C:\Users\Kerstin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6EC77D09-02CB-4E1F-E3C4-FB141B2610B3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522842288}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555845588}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566846688}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544844488}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555845588}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566846688}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\genesis
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\simplytech
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\Tune
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Driver-Soft
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\Registry Helper
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Tune
Schlüssel Gelöscht : HKLM\SOFTWARE\Taronja
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Activeris AntiMalware_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\32DA746012E6D4F488AAD113D6FA4A44
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF767AE36C8829547ACD71A4249A42B9
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\526AB318AF0B8D84B9579557C9882C91
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\default-search.net
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\portaldosites.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\trovi.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\webssearches.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.portaldosites.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.trovi.com
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v35.0.1 (x86 de)
[vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.order.1", "default-search.net");
[vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.afaf73efed6aa46eb8014e0b47ac07eada90d6ab4be694e96a9791fd9c1ae6f92com58488.58488.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
[vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
[vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false);
[vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
[vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.Visibility", false);
[vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.keepAliveLastevent", "1402754098");
[vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("{01856272-60D2-48c0-8F8F-852C369B15A1}.ScriptData_whiteListSearch", "{\"search.babylon.com\":\"q\",\"search.yahoo.com\":\"p\",\"www.bing.com\":\"q\",\"www.google.com\":\"q\",\"www.google.co[...]
[vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}.ScriptData_VBATES_partn_time_mmotraffic.com", "not set");
[vokiukc3.default\prefs.js] - Zeile Gelöscht : user_pref("{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}.ScriptData_whiteListSearch", "{\"isearch.babylon.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"home.mywebsearch.com\":\"se[...]
-\\ Google Chrome v40.0.2214.111
[C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1407066410&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062&q={searchTerms}
[C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1407066410&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062&q={searchTerms}
[C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1402826947&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062&q={searchTerms}
[C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1402826947&from=tugs&uid=WDCXWD3200AZDX-00SC2B0_WD-WMC1U125506255062&q={searchTerms}
*************************
AdwCleaner[R0].txt - [11363 Bytes] - [16/02/2015 21:31:57]
AdwCleaner[S0].txt - [12428 Bytes] - [16/02/2015 21:36:21]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12488 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by Kerstin on 16.02.2015 at 22:02:11,45
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{25919770-5BAD-48FC-8AD0-ABE381933FBC}
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{2AD651C0-A973-4ED6-8DA9-3DFD46C17179}
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{32EBC90B-3383-4647-A7E4-83042D61BBAA}
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{60232E7F-D4DA-4E82-A1A4-6BB2BDE70F81}
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{81A78961-263A-47A6-8B38-0B90A567867E}
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{B4A2C882-B21E-4B65-B513-4C4DDE94450C}
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{C161DA7A-77D8-48F8-A5F3-96607D6A7080}
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{CDC2E683-777F-40DC-97EB-EC4D56C5948F}
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{D6B18C6B-E2AB-4773-BEEF-758EFDCEABF9}
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{DC94419E-9C42-48A7-A70D-DD48E3331F9C}
Successfully deleted: [Empty Folder] C:\Users\Kerstin\appdata\local\{E54590EC-BE83-449F-8AE5-6F3812ACD647}
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Kerstin\AppData\Roaming\mozilla\firefox\profiles\vokiukc3.default\extensions\toolbar@web.de
Successfully deleted the following from C:\Users\Kerstin\AppData\Roaming\mozilla\firefox\profiles\vokiukc3.default\prefs.js
user_pref("ZooToolbar_25361.global.DisplayRecentSearches", "true");
user_pref("{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}.ScriptData_VBATES_executeCode", "var VBATES_IsValidUrl=function(currentUrl,currentBrowser,queryParam){try{var urlParts=curren
user_pref("{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}.ScriptData_VBATES_partners", "{\"www.brandalley.co.uk\":\"www.awin1.com/awclick.php?mid=3676&id=178119\",\"www.currys.co.uk\"
Emptied folder: C:\Users\Kerstin\AppData\Roaming\mozilla\firefox\profiles\vokiukc3.default\minidumps [143 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.02.2015 at 22:11:59,50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-02-2015
Ran by Kerstin (administrator) on KERSTIN-PC on 16-02-2015 22:18:46
Running from C:\Users\Kerstin\Downloads
Loaded Profiles: Kerstin (Available profiles: Kerstin)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Spotify Ltd) C:\Users\Kerstin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Farbar) C:\Users\Kerstin\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor)
HKLM\...\Run: [ESET-Phase2] => C:\ProgramData\ESET\ESET-phase2.exe [1100656 2010-11-10] ()
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-01-27] (Apple Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [Spotify Web Helper] => C:\Users\Kerstin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-02-15] (Spotify Ltd)
HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [Spotify] => C:\Users\Kerstin\AppData\Roaming\Spotify\spotify.exe [6737976 2015-02-15] (Spotify Ltd)
HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Run: [AirDroid 3] => C:\Program Files (x86)\AirDroid\AirDroid.exe [11662848 2015-02-05] (Sand Studio)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://syb.msn.com
SearchScopes: HKLM -> {05B62290-31C8-45EC-99C6-F05963923521} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSBTDF&pc=MASB&src=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default
FF Homepage: hxxp://go.1und1.de/tb/mff_startpage|hxxp://www.giga.de/androidnews/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2890383179-3499982190-3409672644-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kerstin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2890383179-3499982190-3409672644-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\searchplugins\google-maps.xml
FF Extension: anonymoX - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\client@anonymox.net.xpi [2014-05-08]
FF Extension: Trusted Shops Add-On für Firefox - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\jid1-PBNne26X1Kn6hQ@jetpack.xpi [2014-08-05]
FF Extension: {0db9152f-2c09-4a6a-b006-6852e1787975} - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\Extensions\{0db9152f-2c09-4a6a-b006-6852e1787975}.xpi [2015-02-10]
FF HKLM\...\Firefox\Extensions: [{01856272-60D2-48c0-8F8F-852C369B15A1}] - C:\Program Files\Slotomania Coin Expansion Pack\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{01856272-60D2-48c0-8F8F-852C369B15A1}] - C:\Program Files\Slotomania Coin Expansion Pack\Firefox
FF HKU\S-1-5-21-2890383179-3499982190-3409672644-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Kerstin\AppData\Roaming\Mozilla\Firefox\Profiles\vokiukc3.default\extensions\cliqz@cliqz.com
Chrome:
=======
CHR Profile: C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-16]
CHR Extension: (Google Drive) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-16]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27]
CHR Extension: (YouTube) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-16]
CHR Extension: (Slotomania Coin Expansion Pack) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmonpfhhpdjphhlanhockbccaakgahgh [2014-05-28]
CHR Extension: (Google-Suche) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-16]
CHR Extension: (Google Wallet) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-16]
CHR Extension: (Google Mail) - C:\Users\Kerstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-16]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-07] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-07] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-05-09] (Avira Operations GmbH & Co. KG)
R3 igddim64; C:\Windows\System32\DRIVERS\igddim64.sys [1703936 2011-08-30] (Intel Corporation)
R3 imgkmd64; C:\Windows\System32\DRIVERS\imgkmd64.sys [479232 2011-08-30] (Imagination Technologies)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 s1029bus; C:\Windows\System32\DRIVERS\s1029bus.sys [116264 2009-05-25] (MCCI Corporation)
S3 s1029mdfl; C:\Windows\System32\DRIVERS\s1029mdfl.sys [19496 2009-05-25] (MCCI Corporation)
S3 s1029mdm; C:\Windows\System32\DRIVERS\s1029mdm.sys [158760 2009-05-25] (MCCI Corporation)
S3 s1029mgmt; C:\Windows\System32\DRIVERS\s1029mgmt.sys [139304 2009-05-25] (MCCI Corporation)
S3 s1029nd5; C:\Windows\System32\DRIVERS\s1029nd5.sys [34856 2009-05-25] (MCCI Corporation)
S3 s1029obex; C:\Windows\System32\DRIVERS\s1029obex.sys [135208 2009-05-25] (MCCI Corporation)
S3 s1029unic; C:\Windows\System32\DRIVERS\s1029unic.sys [151592 2009-05-25] (MCCI Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 massfilter_hs; \??\C:\Windows\system32\drivers\massfilter_hs.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X]
S3 zghsmdm; system32\DRIVERS\zghsmdm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-16 22:18 - 2015-02-16 22:18 - 02085888 _____ (Farbar) C:\Users\Kerstin\Downloads\FRST64(1).exe
2015-02-16 22:11 - 2015-02-16 22:11 - 00002703 _____ () C:\Users\Kerstin\Desktop\JRT.txt
2015-02-16 22:01 - 2015-02-16 22:01 - 01388274 _____ (Thisisu) C:\Users\Kerstin\Downloads\JRT.exe
2015-02-16 21:58 - 2015-02-16 21:58 - 00012617 _____ () C:\Users\Kerstin\Desktop\AdwCleaner[S0].txt
2015-02-16 21:50 - 2015-02-16 21:50 - 00316536 _____ () C:\Windows\Minidump\021615-14913-01.dmp
2015-02-16 21:31 - 2015-02-16 21:36 - 00000000 ____D () C:\AdwCleaner
2015-02-16 21:30 - 2015-02-16 21:30 - 02112512 _____ () C:\Users\Kerstin\Downloads\AdwCleaner_4.110.exe
2015-02-16 21:08 - 2015-02-16 21:08 - 00002081 _____ () C:\Users\Kerstin\Desktop\mbam.txt
2015-02-16 20:33 - 2015-02-16 21:52 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-16 20:33 - 2015-02-16 20:33 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-16 20:33 - 2015-02-16 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-16 20:33 - 2015-02-16 20:33 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-16 20:33 - 2015-02-16 20:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-16 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-16 20:33 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-16 20:33 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-16 20:31 - 2015-02-16 20:32 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Kerstin\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-16 00:57 - 2015-02-16 00:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-02-16 00:57 - 2015-02-16 00:57 - 00000000 ____D () C:\Program Files\7-Zip
2015-02-16 00:54 - 2015-02-16 00:54 - 01513472 _____ () C:\Users\Kerstin\Downloads\7z938-x64.msi
2015-02-15 23:16 - 2015-02-15 23:23 - 00000000 ____D () C:\Users\Kerstin\Documents\AirDroid
2015-02-15 23:08 - 2015-02-15 23:22 - 00000000 ____D () C:\Program Files (x86)\AirDroid
2015-02-15 23:08 - 2015-02-15 23:16 - 00001889 _____ () C:\Users\Public\Desktop\AirDroid.lnk
2015-02-15 23:08 - 2015-02-15 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirDroid
2015-02-15 22:57 - 2015-02-15 22:58 - 09146874 _____ () C:\Users\Kerstin\Downloads\AirDroid_Desktop_Client_3.0.4.exe
2015-02-15 18:49 - 2015-02-15 18:49 - 00040320 _____ () C:\Users\Kerstin\Desktop\combofix.txt
2015-02-15 17:27 - 2015-02-15 17:27 - 00040320 _____ () C:\ComboFix.txt
2015-02-15 17:17 - 2015-02-15 17:17 - 00000000 _____ () C:\Windows\SysWOW64\shoA06B.tmp
2015-02-15 16:54 - 2015-02-15 16:54 - 00001485 _____ () C:\Users\Kerstin\Desktop\ComboFix - Verknüpfung.lnk
2015-02-15 16:54 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-15 16:54 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-15 16:54 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-15 16:54 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-15 16:54 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-15 16:54 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-15 16:54 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-15 16:54 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-15 16:53 - 2015-02-15 17:27 - 00000000 ____D () C:\Qoobox
2015-02-15 16:52 - 2015-02-15 17:23 - 00000000 ____D () C:\Windows\erdnt
2015-02-15 16:51 - 2015-02-15 16:51 - 05611771 ____R (Swearware) C:\Users\Kerstin\Downloads\ComboFix.exe
2015-02-15 15:53 - 2015-02-15 15:53 - 00001268 _____ () C:\Users\Kerstin\Desktop\Revo Uninstaller.lnk
2015-02-15 15:52 - 2015-02-15 15:52 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-02-15 15:37 - 2015-02-15 15:51 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Kerstin\Downloads\revosetup95.exe
2015-02-15 00:37 - 2015-02-15 00:37 - 00000000 _____ () C:\Windows\SysWOW64\sho50B4.tmp
2015-02-15 00:25 - 2015-02-15 00:25 - 00000000 ____D () C:\Program Files\SAMSUNG
2015-02-15 00:25 - 2014-10-13 06:57 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2015-02-15 00:25 - 2014-10-13 06:57 - 00110336 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2015-02-14 22:22 - 2015-02-14 22:22 - 00380416 _____ () C:\Users\Kerstin\Downloads\Gmer-19357(1).exe
2015-02-14 22:18 - 2015-02-14 22:18 - 00380416 _____ () C:\Users\Kerstin\Downloads\Gmer-19357.exe
2015-02-14 22:18 - 2015-02-14 22:18 - 00000859 _____ () C:\Users\Kerstin\Desktop\trojaner-board.txt
2015-02-14 22:16 - 2015-02-14 22:47 - 00000000 ____D () C:\Users\Kerstin\Desktop\logdateien
2015-02-14 22:12 - 2015-02-14 22:14 - 00029291 _____ () C:\Users\Kerstin\Downloads\Addition.txt
2015-02-14 22:08 - 2015-02-16 22:18 - 00016140 _____ () C:\Users\Kerstin\Downloads\FRST.txt
2015-02-14 22:08 - 2015-02-16 22:18 - 00000000 ____D () C:\FRST
2015-02-14 22:06 - 2015-02-14 22:06 - 02134528 _____ (Farbar) C:\Users\Kerstin\Downloads\FRST64.exe
2015-02-14 22:01 - 2015-02-14 22:01 - 00000000 _____ () C:\Users\Kerstin\defogger_reenable
2015-02-14 21:58 - 2015-02-14 21:58 - 00050477 _____ () C:\Users\Kerstin\Desktop\Defogger.exe
2015-02-14 01:41 - 2015-02-15 00:25 - 00000000 ____D () C:\ProgramData\Samsung
2015-02-14 00:50 - 2015-02-14 01:42 - 00000000 ____D () C:\Users\Kerstin\Documents\samsung
2015-02-14 00:50 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log
2015-02-14 00:50 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Kerstin\Documents\SelfMV
2015-02-14 00:49 - 2015-02-14 00:50 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Samsung
2015-02-14 00:49 - 2015-02-14 00:49 - 00001973 _____ () C:\Users\Public\Desktop\Samsung Kies 3.lnk
2015-02-14 00:49 - 2015-02-14 00:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2015-02-14 00:49 - 2015-02-14 00:49 - 00000000 ____D () C:\Program Files (x86)\Samsung
2015-02-14 00:49 - 2014-05-07 17:42 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\SysWOW64\secman.dll
2015-02-14 00:39 - 2015-02-14 00:40 - 42498888 _____ (Samsung Electronics Co., Ltd.) C:\Users\Kerstin\Downloads\Kies3Setup.exe
2015-02-14 00:00 - 2015-02-14 00:00 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\MyPhoneExplorer
2015-02-13 23:59 - 2015-02-13 23:59 - 00002061 _____ () C:\Users\Public\Desktop\MyPhoneExplorer.lnk
2015-02-13 23:59 - 2015-02-13 23:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2015-02-13 23:58 - 2015-02-13 23:59 - 00000000 ____D () C:\Program Files (x86)\MyPhoneExplorer
2015-02-13 23:40 - 2015-02-13 23:40 - 00659464 _____ () C:\Users\Kerstin\Downloads\myphoneexplorer.exe
2015-02-12 18:28 - 2014-12-05 11:32 - 139196615 _____ () C:\Users\Kerstin\20141205_113135.mp4
2015-02-12 18:28 - 2014-12-01 11:24 - 232466986 _____ () C:\Users\Kerstin\20141201_112247.mp4
2015-02-12 18:28 - 2014-11-30 11:30 - 275072892 _____ () C:\Users\Kerstin\20141130_112831.mp4
2015-02-12 18:27 - 2014-11-23 22:31 - 208943022 _____ () C:\Users\Kerstin\20141123_222952.mp4
2015-02-12 18:27 - 2014-11-14 19:52 - 136757681 _____ () C:\Users\Kerstin\20141114_195143.mp4
2015-02-12 18:27 - 2014-11-14 13:46 - 311908025 _____ () C:\Users\Kerstin\20141114_134342.mp4
2015-02-12 18:26 - 2015-01-26 08:34 - 143517436 _____ () C:\Users\Kerstin\20150126_083313.mp4
2015-02-12 18:26 - 2015-01-12 22:21 - 346180627 _____ () C:\Users\Kerstin\20150112_221907.mp4
2015-02-12 18:26 - 2015-01-01 00:11 - 00351735 _____ () C:\Users\Kerstin\20150101_001052.mp4
2015-02-12 18:26 - 2014-12-27 15:34 - 74917974 _____ () C:\Users\Kerstin\20141227_153416.mp4
2015-02-12 18:26 - 2014-12-27 15:32 - 41031175 _____ () C:\Users\Kerstin\20141227_153210.mp4
2015-02-12 18:26 - 2014-12-25 21:13 - 157444083 _____ () C:\Users\Kerstin\20141225_211203.mp4
2015-02-12 18:26 - 2014-11-09 18:32 - 356998952 _____ () C:\Users\Kerstin\20141109_182926.mp4
2015-02-12 18:25 - 2014-12-25 21:11 - 180618452 _____ () C:\Users\Kerstin\20141225_211021.mp4
2015-02-12 18:25 - 2014-12-25 14:36 - 207078718 _____ () C:\Users\Kerstin\20141225_143453.mp4
2015-02-12 18:25 - 2014-12-24 18:41 - 06138834 _____ () C:\Users\Kerstin\20141224_184113.mp4
2015-02-12 18:25 - 2014-12-20 14:14 - 239835541 _____ () C:\Users\Kerstin\20141220_141233.mp4
2015-02-12 18:25 - 2014-12-19 19:42 - 101770616 _____ () C:\Users\Kerstin\20141219_194114.mp4
2015-02-12 18:24 - 2014-12-15 19:04 - 244473975 _____ () C:\Users\Kerstin\20141215_190217.mp4
2015-02-12 18:24 - 2014-12-14 19:26 - 211934675 _____ () C:\Users\Kerstin\20141214_192449.mp4
2015-02-12 17:00 - 2015-02-12 17:00 - 00001753 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-02-12 17:00 - 2015-02-12 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-02-12 16:57 - 2015-02-12 16:59 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-02-12 16:57 - 2015-02-12 16:59 - 00000000 ____D () C:\Program Files\iTunes
2015-02-12 16:57 - 2015-02-12 16:57 - 00000000 ____D () C:\Program Files\iPod
2015-02-12 16:57 - 2015-02-12 16:57 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-02-11 14:47 - 2015-02-11 14:47 - 00000000 _____ () C:\Windows\SysWOW64\sho8A0A.tmp
2015-02-10 19:38 - 2015-02-10 19:54 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Genymobile
2015-02-10 19:38 - 2015-02-10 19:50 - 00000000 ____D () C:\Users\Kerstin\.VirtualBox
2015-02-10 19:36 - 2013-04-12 11:41 - 00237840 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2015-02-10 19:33 - 2013-04-12 11:40 - 00120080 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2015-02-10 19:31 - 2015-02-10 19:31 - 00000000 ____D () C:\Program Files\Genymobile
2015-02-10 19:29 - 2015-02-10 19:29 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Temp515a80549b13c62719b8b0be014862d3
2015-02-10 16:37 - 2015-02-10 17:55 - 00002004 _____ () C:\Users\Kerstin\Desktop\WhatsApp.lnk
2015-01-31 22:17 - 2015-01-31 22:17 - 00000000 _____ () C:\Windows\SysWOW64\sho83D.tmp
2015-01-31 11:58 - 2015-02-11 11:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-25 00:12 - 2015-01-25 00:12 - 00000000 _____ () C:\Windows\SysWOW64\sho29F1.tmp
2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-01-22 17:03 - 2015-01-22 17:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-01-21 19:55 - 2015-01-21 19:55 - 00386448 _____ () C:\Windows\Minidump\012115-17035-01.dmp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-16 22:00 - 2009-07-14 05:45 - 00028896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-16 22:00 - 2009-07-14 05:45 - 00028896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-16 21:54 - 2014-06-16 19:25 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Spotify
2015-02-16 21:54 - 2014-06-16 19:24 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Spotify
2015-02-16 21:53 - 2014-05-04 20:18 - 01109174 _____ () C:\Users\Kerstin\Documents\ESET-installation-phase2.log
2015-02-16 21:50 - 2014-06-20 16:18 - 00000000 ____D () C:\Windows\Minidump
2015-02-16 21:50 - 2014-05-16 19:46 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-16 21:50 - 2014-05-14 21:26 - 294253685 _____ () C:\Windows\MEMORY.DMP
2015-02-16 21:50 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-16 21:50 - 2009-07-14 05:51 - 00051389 _____ () C:\Windows\setupact.log
2015-02-16 21:43 - 2014-05-04 19:26 - 01764462 _____ () C:\Windows\WindowsUpdate.log
2015-02-16 21:37 - 2010-11-21 04:47 - 00690896 _____ () C:\Windows\PFRO.log
2015-02-16 21:36 - 2014-06-14 14:53 - 00001083 _____ () C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2015-02-16 21:36 - 2014-06-14 14:53 - 00001053 _____ () C:\Users\Kerstin\Desktop\Search.lnk
2015-02-16 21:36 - 2014-05-16 19:47 - 00001282 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-02-16 21:36 - 2014-05-16 19:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-16 21:36 - 2014-05-04 22:58 - 00001065 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-16 21:36 - 2014-05-04 22:58 - 00001053 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-16 21:36 - 2014-05-04 19:34 - 00000999 _____ () C:\Users\Kerstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-16 21:36 - 2014-05-04 19:33 - 00001156 _____ () C:\Users\Kerstin\Desktop\Internet Explorer.lnk
2015-02-16 21:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\L2Schemas
2015-02-16 21:08 - 2014-05-15 22:36 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\com
2015-02-16 21:07 - 2014-05-06 21:32 - 00000000 ____D () C:\temp
2015-02-16 17:06 - 2014-05-04 20:14 - 00000000 ____D () C:\ProgramData\ESET
2015-02-16 16:46 - 2015-01-14 18:25 - 00000112 _____ () C:\ProgramData\5uKMmosV2.dat
2015-02-16 16:35 - 2015-01-10 00:53 - 00000000 ____D () C:\Users\Kerstin\Desktop\Neuer Ordner (2)
2015-02-15 23:25 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\VirtualStore
2015-02-15 17:27 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-02-15 17:19 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-02-14 22:01 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin
2015-02-14 01:55 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-02-14 00:49 - 2014-05-04 19:55 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-02-12 18:29 - 2014-06-14 23:45 - 00792576 ___SH () C:\Users\Kerstin\Thumbs.db
2015-02-12 17:46 - 2010-11-21 07:50 - 00699386 _____ () C:\Windows\system32\perfh007.dat
2015-02-12 17:46 - 2010-11-21 07:50 - 00149268 _____ () C:\Windows\system32\perfc007.dat
2015-02-12 17:46 - 2009-07-14 06:13 - 01620248 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-12 16:57 - 2014-08-24 18:38 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-02-12 16:55 - 2014-08-24 18:40 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2015-02-11 21:05 - 2014-05-04 19:33 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Windows Live
2015-02-10 16:41 - 2014-05-21 09:54 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2015-02-09 14:19 - 2014-05-16 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-02-09 14:19 - 2014-05-16 10:01 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-02-09 14:19 - 2014-05-13 22:59 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-07 21:11 - 2014-05-16 19:46 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-07 21:11 - 2014-05-16 19:46 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-07 21:11 - 2014-05-16 19:46 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-07 19:29 - 2014-08-22 07:58 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Adobe
2015-02-07 19:29 - 2014-05-04 21:42 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-07 19:29 - 2014-05-04 21:42 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-31 22:17 - 2014-05-04 22:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-24 20:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2015-01-19 12:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
==================== Files in the root of some directories =======
2014-05-06 21:56 - 2014-05-06 21:56 - 0000046 _____ () C:\Users\Kerstin\AppData\Roaming\WB.CFG
2015-01-14 18:25 - 2015-02-16 16:46 - 0000112 _____ () C:\ProgramData\5uKMmosV2.dat
2014-05-13 21:56 - 2014-05-13 21:56 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Files to move or delete:
====================
C:\ProgramData\5uKMmosV2.dat
Some content of TEMP:
====================
C:\Users\Kerstin\AppData\Local\Temp\avgnt.exe
C:\Users\Kerstin\AppData\Local\Temp\Quarantine.exe
C:\Users\Kerstin\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-15 17:44
==================== End Of Log ============================ --- --- ---
--- --- --- |