Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Virus? Firefox öffnet unaufgefordert neue Seiten

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 26.06.2014, 13:07   #1
Tara86
 
Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



Hallo!

Unser Latop ist relativ neu. Wir haben uns einige Programme aus dem Internet runtergeladen, dabei scheint sich ein Virus eingeschlichen zu haben. Unser Virusprogramm findet allerdings nichts. Und zwar öffnen sich beim surfen einfach Seiten. Meistens sind das Hinweise, wonach wir angblich z.B. den Media Player aktualisieren sollen. Ich denke allerdings nicht, dass der Media Player wirklich dafür verantwortlich ist.
Ich hoffe, ich hab jetzt nicht zu viel geschrieben und ihr könnt mir helfen.
Ich hätte gern schon irgendwas gescannt, falls ihr was braucht, aber ehrlich gesagt, seh ich hier noch nicht richtig durch, obwohl ihr mir schonmal geholfen habt.

LG
Tara

Alt 26.06.2014, 13:30   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 26.06.2014, 14:41   #3
Tara86
 
Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



FRST - Editor


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014
Ran by sebastian (administrator) on GHOTS on 26-06-2014 15:38:10
Running from C:\Users\sebastian\Pictures
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
() C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Client Connect LTD) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe
(Client Connect LTD) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe
(Client Connect LTD) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe
(Reimage®) C:\Program Files\Reimage\Reimage Express\ReiGuard.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Runonce: [reimageexpresslqhf] -  [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-398813873-3760832578-3833595727-1002\...\RunOnce: [Uninstall C:\Users\sebastian\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220\amd64] - C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\sebastian\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220\amd64"
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [220480 2014-06-23] (Client Connect LTD)
AppInit_DLLs:  C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL => C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL File Not Found
AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [181568 2014-06-23] (Client Connect LTD)
AppInit_DLLs-x32:  c:\progra~2\amazon\amazon~1\\amazon~3.dll => "c:\progra~2\amazon\amazon~1\\amazon~3.dll" File Not Found
AppInit_DLLs-x32: ,C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV=
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;form=IE10TR&amp;src=IE10TR&amp;pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: V-bates - {21EAF666-26B3-4a3c-ABD0-CA2F5A326744} - C:\Program Files\V-bates\Extension64.dll No File
BHO: The Amazon 1Button App for IE - {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} - C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonAppIE64.dll No File
BHO-x32: V-bates - {21EAF666-26B3-4a3c-ABD0-CA2F5A326744} - C:\Program Files\V-bates\Extension32.dll No File
BHO-x32: The Amazon 1Button App for IE - {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} - C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonAppIE.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default
FF NewTab: hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0
FF DefaultSearchEngine: Trovi search
FF SearchEngineOrder.1: Amazon 
FF SelectedSearchEngine: Trovi search
FF Homepage: hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV=
FF Keyword.URL: hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p23_serp_ff_de_display?ie=UTF8&tagbase=bds-p23&tag=bds-p23-serp-de-ff-21&tbrId=v1_abb-channel-23_71ca4b1b0fab486b8631b54e7091ae6a_39_1006_20140406_DE_ff_ab_adppi15&query=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\searchplugins\amazon.xml
FF SearchPlugin: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\searchplugins\default-search.xml
FF SearchPlugin: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\searchplugins\trovi-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\webssearches.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: MediaPlayerplus - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com [2014-05-21]
FF Extension: Plus-HD-V1.3 - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\ba9147e3-ae8c-4ced-9c9a-240425bd7d8e@6ddffb66-c974-42d7-8752-9e6a4ec073b0.com [2014-06-26]
FF Extension: Freeven Pro 1.3 - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\e20dc619-d8c4-48f1-ae07-641cefb43165@3c4d943f-ad97-4f6e-aa94-d9671175a3d0.com [2014-04-04]
FF Extension: HQ-Video-Pro-1.9 - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com [2014-04-04]
FF Extension: video MediaPlayer - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\ff806580-6db3-4c09-ba06-d6caf0e99172@8453cb25-7fef-4ed5-8934-b08be5605617.com [2014-06-26]
FF Extension: BuenoSearch - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\ffxtlbr@buenosearch.com [2014-04-03]
FF Extension: CoupExteNSion - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\jyaiu@yiyyw.org [2014-06-26]
FF Extension: CostMin - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\qfswxw@rwqvf.edu [2014-06-19]
FF Extension: Quick Start - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\quick_start@gmail.com [2014-06-19]
FF Extension: Settings Manager - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\{34FA153F-3A2C-364C-E68F-3F8A21AA8D9D} [2014-06-19]
FF Extension: Amazon 1Button App for Firefox - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\abb@amazon.com.xpi [2014-01-31]
FF Extension: Adblock Plus - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\h833r8hr.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-04]
FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi
FF HKCU\...\Firefox\Extensions: [{c1f9049a-3290-4967-9a3d-448f242ce94c}] - C:\Program Files (x86)\Re-markit Corp\158.xpi
FF Extension: Re-markit - C:\Program Files (x86)\Re-markit Corp\158.xpi [2014-04-04]

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19]
CHR Extension: (No Name) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpieepnfhpcpkjklohnpmmmmdhcbmd [2014-06-19]

==================== Services (Whitelisted) =================

R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS)
R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2832704 2014-06-23] (Client Connect LTD)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 ReimageRealTimeProtection; C:\Program Files\Reimage\Reimage Express\ReiGuard.exe [5100384 2014-04-27] (Reimage®)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X]
S2 V-bates Updater; C:\Program Files\V-bates\ExtensionUpdaterService.exe [X]
S2 vosr; C:\Users\sebastian\AppData\Roaming\VOPackage\VOsrv.exe [X]

==================== Drivers (Whitelisted) ====================

R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61120 2014-04-04] (StdLib)
R3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
U0 msahci; 

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-26 15:38 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST
2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:48 - 2014-06-26 13:48 - 00000000 ____D () C:\Program Files\Reimage
2014-06-26 13:47 - 2014-06-26 13:47 - 00000000 _____ () C:\END
2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml
2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-26 06:00 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\CCOupExettension
2014-06-21 22:36 - 2014-06-26 13:48 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2014-06-21 22:36 - 2014-06-21 22:36 - 00000000 ____D () C:\Users\sebastian\AppData\Local\SearchProtect
2014-06-20 18:08 - 2014-06-23 21:49 - 00002004 _____ () C:\Windows\PFRO.log
2014-06-19 17:35 - 2014-06-19 17:35 - 00000000 ____D () C:\Users\sebastian\AppData\Local\freeSOFTtoday
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 17:31 - 2014-06-19 17:31 - 00000000 ____D () C:\ProgramData\374311380
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 16:02 - 2014-06-26 12:26 - 00000000 ____D () C:\Users\sebastian\AppData\Local\PennyBee
2014-06-19 16:02 - 2014-06-19 16:02 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\Settings Manager
2014-06-19 16:02 - 2014-06-19 16:02 - 00000000 ____D () C:\Program Files (x86)\Settings Manager
2014-06-19 15:32 - 2014-06-19 15:32 - 00623616 _____ (Click Me In Limited) C:\Users\sebastian\AppData\Local\nsgF480.tmp
2014-06-19 15:32 - 2014-06-19 15:32 - 00002918 _____ () C:\Users\sebastian\AppData\Roaming\aps.scan.results
2014-06-19 15:32 - 2014-06-19 15:32 - 00001150 _____ () C:\Users\sebastian\AppData\Roaming\aps.scan.quick.results
2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB
2014-06-19 14:22 - 2014-06-26 12:33 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-06-19 14:22 - 2014-06-26 12:33 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-06-19 14:22 - 2014-06-26 12:33 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-06-19 14:22 - 2014-06-26 12:29 - 00000000 ____D () C:\Program Files (x86)\video MediaPlayer
2014-06-19 14:22 - 2014-06-26 12:29 - 00000000 ____D () C:\Program Files (x86)\HQ-V1.3
2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\Documents\Optimizer Pro
2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\SupTab
2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\AppData\Local\globalUpdate
2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-06-19 14:21 - 2014-06-26 12:29 - 00000000 ____D () C:\Program Files (x86)\fst_de_47
2014-06-19 14:21 - 2014-06-26 12:29 - 00000000 ____D () C:\Program Files (x86)\CostMin
2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-19 14:21 - 2014-06-26 12:26 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-06-19 14:21 - 2014-06-25 06:38 - 00000000 ____D () C:\Users\sebastian\AppData\Local\fst_de_47
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Torch
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Chromatic Browser
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Torch
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Chromatic Browser
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Torch
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Chromatic Browser
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\CostMin

==================== One Month Modified Files and Folders =======

2014-06-26 15:38 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST
2014-06-26 15:31 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-06-26 14:32 - 2014-04-06 16:22 - 01241162 _____ () C:\Windows\WindowsUpdate.log
2014-06-26 14:25 - 2014-04-03 19:25 - 00000318 _____ () C:\Windows\Tasks\AppCloudUpdater.job
2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002
2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-26 13:48 - 2014-06-26 13:48 - 00000000 ____D () C:\Program Files\Reimage
2014-06-26 13:48 - 2014-06-21 22:36 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2014-06-26 13:47 - 2014-06-26 13:47 - 00000000 _____ () C:\END
2014-06-26 13:46 - 2014-05-20 06:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 13:46 - 2014-04-04 19:29 - 00001450 _____ () C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-1.job
2014-06-26 13:45 - 2014-04-04 19:28 - 00002210 _____ () C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-4.job
2014-06-26 13:45 - 2014-04-04 19:27 - 00003146 _____ () C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-3.job
2014-06-26 13:44 - 2014-04-03 19:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB
2014-06-26 13:30 - 2014-04-04 19:29 - 00001346 _____ () C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-2.job
2014-06-26 13:29 - 2014-04-04 19:28 - 00001348 _____ () C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-1.job
2014-06-26 13:27 - 2014-04-04 19:27 - 00002366 _____ () C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-4.job
2014-06-26 13:26 - 2014-04-04 19:26 - 00002790 _____ () C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-3.job
2014-06-26 13:01 - 2014-04-04 19:25 - 00000410 _____ () C:\Windows\Tasks\Re-markit_wd.job
2014-06-26 13:01 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys
2014-06-26 12:59 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-26 12:58 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-26 12:57 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-26 12:39 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1
2014-06-26 12:39 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2
2014-06-26 12:33 - 2014-06-19 14:22 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-06-26 12:33 - 2014-06-19 14:22 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-06-26 12:33 - 2014-06-19 14:22 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-06-26 12:32 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep
2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G
2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2014-06-26 12:29 - 2014-06-19 14:22 - 00000000 ____D () C:\Program Files (x86)\video MediaPlayer
2014-06-26 12:29 - 2014-06-19 14:22 - 00000000 ____D () C:\Program Files (x86)\HQ-V1.3
2014-06-26 12:29 - 2014-06-19 14:21 - 00000000 ____D () C:\Program Files (x86)\fst_de_47
2014-06-26 12:29 - 2014-06-19 14:21 - 00000000 ____D () C:\Program Files (x86)\CostMin
2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 12:27 - 2014-06-26 06:00 - 00000000 ____D () C:\ProgramData\CCOupExettension
2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-26 12:26 - 2014-06-19 16:02 - 00000000 ____D () C:\Users\sebastian\AppData\Local\PennyBee
2014-06-26 12:26 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-06-26 12:25 - 2014-04-06 15:58 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\Systweak
2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration
2014-06-25 06:38 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\fst_de_47
2014-06-24 19:59 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-06-23 21:49 - 2014-06-20 18:08 - 00002004 _____ () C:\Windows\PFRO.log
2014-06-21 22:36 - 2014-06-21 22:36 - 00000000 ____D () C:\Users\sebastian\AppData\Local\SearchProtect
2014-06-19 17:35 - 2014-06-19 17:35 - 00000000 ____D () C:\Users\sebastian\AppData\Local\freeSOFTtoday
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 17:31 - 2014-06-19 17:31 - 00000000 ____D () C:\ProgramData\374311380
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 16:02 - 2014-06-19 16:02 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\Settings Manager
2014-06-19 16:02 - 2014-06-19 16:02 - 00000000 ____D () C:\Program Files (x86)\Settings Manager
2014-06-19 15:32 - 2014-06-19 15:32 - 00623616 _____ (Click Me In Limited) C:\Users\sebastian\AppData\Local\nsgF480.tmp
2014-06-19 15:32 - 2014-06-19 15:32 - 00002918 _____ () C:\Users\sebastian\AppData\Roaming\aps.scan.results
2014-06-19 15:32 - 2014-06-19 15:32 - 00001150 _____ () C:\Users\sebastian\AppData\Roaming\aps.scan.quick.results
2014-06-19 15:32 - 2014-04-04 20:03 - 00000314 _____ () C:\Users\sebastian\AppData\Roaming\aps.uninstall.scan.results
2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\Documents\Optimizer Pro
2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\AppData\Roaming\SupTab
2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Users\sebastian\AppData\Local\globalUpdate
2014-06-19 14:22 - 2014-06-19 14:22 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Torch
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Chromatic Browser
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Torch
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Chromatic Browser
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Torch
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Chromatic Browser
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\CostMin
2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-06-09 12:00 - 2014-04-06 13:40 - 00000272 _____ () C:\Windows\Tasks\AppSafe.job
2014-05-31 07:16 - 2014-04-06 15:42 - 00703992 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-31 07:16 - 2014-04-06 15:42 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-24 19:53

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Addition - Editor

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-06-2014
Ran by sebastian at 2014-06-26 15:38:51
Running from C:\Users\sebastian\Pictures
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player Packages (HKCU\...\Adobe Flash Player Packages) (Version:  - ) <==== ATTENTION
Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 3.4.117.01527 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 3.4.117.01527 - Alcor Micro Corp.) Hidden
Amazon 1Button App (x32 Version: 1.0.4 - Amazon) Hidden
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.2.2 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 3.0.4 - ASUS)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 2.1.4 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 2.01.0005 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.5 - ASUS)
ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5230.52 - CyberLink Corp.)
ASUSDVD (x32 Version: 10.0.5230.52 - CyberLink Corp.) Hidden
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0030 - ASUS)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2884 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
Junk Mail filter update (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
LPT System Updater Service (x32 Version: 1.0.0.0 - LPT) Hidden <==== ATTENTION
Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden
NVIDIA Optimus 1.15.2 (Version: 1.15.2 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0325 - NVIDIA Corporation) Hidden
NVIDIA PhysX System Software 9.13.0325 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0325 - NVIDIA Corporation)
NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden
NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden
Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Raccolta foto (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6804 - Realtek Semiconductor Corp.)
Reimage Protector (HKLM\...\Reimage Protector) (Version:  - Reimage)
Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.15.10.118 - Client Connect LTD) <==== ATTENTION
Shopping Helper Smartbar Engine (HKCU\...\{5455b53d-a019-4d5a-8501-2201234d0ae5}) (Version: 10.215.63.15249 - ReSoft Ltd.) <==== ATTENTION
Windows Driver Package - ASUS (ATP) Mouse  (01/10/2013 1.0.0.170) (HKLM\...\4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5) (Version: 01/10/2013 1.0.0.170 - ASUS)
Windows Live (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.42.0 - ASUS)

==================== Restore Points  =========================

10-06-2014 21:03:02 Windows Update
19-06-2014 11:35:24 Geplanter Prüfpunkt
26-06-2014 10:18:57 Wiederherstellungsvorgang
26-06-2014 11:52:49 Reimage Express Restore Point

==================== Hosts content: ==========================

2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {046AB098-8757-429F-A45A-34560CDE705F} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-11-28] (ASUS)
Task: {118ECA63-B444-4C6B-ACDD-EA70001C2996} - System32\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-3 => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-3.exe <==== ATTENTION
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2D000AE6-50A7-4810-ABD9-94BD2A983C68} - \RegClean Pro No Task File <==== ATTENTION
Task: {4FDAB20D-FBEB-428A-876B-260705A17E82} - System32\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-1 => C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-codedownloader.exe <==== ATTENTION
Task: {50CA362E-DD77-492B-A3EF-CD7B44E39027} - \Re-markit Update No Task File <==== ATTENTION
Task: {55C7CA32-C53F-45E8-BB08-1EA932922133} - System32\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-1 => C:\Program Files (x86)\HQVid8.1b\HQVid8.1b-codedownloader.exe <==== ATTENTION
Task: {701AA13B-6D58-4923-9F4B-D7E32B1D6595} - System32\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-2 => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-2.exe <==== ATTENTION
Task: {76E1069C-436A-4C90-AE56-36AA673F4A60} - System32\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-4 => C:\Program Files (x86)\MediaPlayerplus\b8e2dbf6-f651-4529-84b2-6113f5365cc5-4.exe <==== ATTENTION
Task: {78C8EFD9-8BDD-4BFD-8251-7B3E62428EC8} - System32\Tasks\Systweak Support Dock => C:\Program Files (x86)\Systweak Support Dock\SystweakDock.exe
Task: {79E86E45-CDE9-4F68-8D1B-1FD551407222} - System32\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-4 => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-4.exe <==== ATTENTION
Task: {7B9522FD-40CE-4535-8AB6-C5D3E1ADA2A1} - System32\Tasks\ASUS Splendid ColorU => C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [2013-02-26] (ASUSTeK Computer Inc.)
Task: {905FFE6D-70A6-44C1-9058-CD47BE06AA54} - \RegClean Pro_DEFAULT No Task File <==== ATTENTION
Task: {90BF9536-DE52-4584-911B-074070AFE345} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2013-03-20] (ASUSTeK Computer Inc.)
Task: {91CD476A-0DBB-44E4-B8E7-D06C9318CCB9} - \RegClean Pro_UPDATES No Task File <==== ATTENTION
Task: {93A2B49F-56B4-4B5F-8313-064C4AACF124} - System32\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-3 => C:\Program Files (x86)\MediaPlayerplus\b8e2dbf6-f651-4529-84b2-6113f5365cc5-3.exe <==== ATTENTION
Task: {A408F286-A6C0-4938-AC8C-2CA24BA9A79E} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {AEB90AA0-7FD5-422D-BACA-502B48554C29} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2013-06-19] (ASUS)
Task: {B1EFB696-E8A9-45FC-90C1-FDAD4B903950} - System32\Tasks\ASUS InstantOn Config => C:\Program Files\ASUS\P4G\InsOnCfg.exe
Task: {B3262ECA-6CA4-41CB-B62E-C1BFA8146D46} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {B680E34E-6844-4054-9EC3-39B382319F09} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.)
Task: {BC1F14A4-2461-48B8-AAF2-FDDEF8769442} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {BF1FB413-5000-49CE-8A1B-36239E4C8FBC} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2013-03-20] (ASUSTeK Computer Inc.)
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {CCB636B3-A9F6-4AAB-AEF1-0F8F9B97D176} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-04-29] (AsusTek)
Task: {D88F9953-CE70-4A07-9CB3-D2ACF8DAC4BE} - System32\Tasks\Re-markit_wd => C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe [2014-04-04] () <==== ATTENTION
Task: {D9F25AF7-06A5-4BD6-B55E-DC91432DB33B} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-04-19] (Microsoft Corporation)
Task: {E6C71457-35B0-4F6D-A5FB-2032C39053E0} - System32\Tasks\AppCloudUpdater => C:\Users\SEBAST~1\AppData\Roaming\APPCLO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {E7F4D682-CAC9-4421-B0D8-FE65B6535B13} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-06-26] (Microsoft Corporation)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {F93511CC-728E-4A08-AEC7-0CAFAE9827C3} - System32\Tasks\AppSafe => C:\Program Files (x86)\AppSafe\AppSafe.exe <==== ATTENTION
Task: {FF19C4A5-5389-41E7-AA7F-A5E0CC036656} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-20] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-1.job => C:\Program Files (x86)\HQVid8.1b\HQVid8.1b-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-2.job => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-3.job => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\74d52b3c-be80-4a90-bd6c-4b7266540f32-4.job => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AppCloudUpdater.job => C:\Users\SEBAST~1\AppData\Roaming\APPCLO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\AppSafe.job => C:\Program Files (x86)\AppSafe\AppSafe.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-1.job => C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-3.job => C:\Program Files (x86)\MediaPlayerplus\b8e2dbf6-f651-4529-84b2-6113f5365cc5-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\b8e2dbf6-f651-4529-84b2-6113f5365cc5-4.job => C:\Program Files (x86)\MediaPlayerplus\b8e2dbf6-f651-4529-84b2-6113f5365cc5-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\Re-markit_wd.job => C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe <==== ATTENTION
Task: C:\Windows\Tasks\temp_74d52b3c-be80-4a90-bd6c-4b7266540f32-2.job => C:\Program Files (x86)\HQVid8.1b\74d52b3c-be80-4a90-bd6c-4b7266540f32-2.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2013-12-10 08:13 - 2013-12-10 08:13 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2013-11-22 15:32 - 2013-10-23 10:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-06-19 22:49 - 2013-06-19 22:49 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2014-04-04 19:25 - 2014-04-04 19:25 - 00077312 _____ () C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe
2014-04-04 15:31 - 2014-04-04 15:31 - 00176048 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll
2013-06-28 11:18 - 2012-11-21 10:58 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
2014-06-22 16:13 - 2014-05-20 06:49 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-12-10 08:13 - 2013-12-10 08:13 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2013-11-22 15:38 - 2012-06-25 12:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:373E1720
AlternateDataStreams: C:\ProgramData\Temp:AD022376

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========

HKLM\...\StartupApproved\Run32: => "BingDesktop"
HKCU\...\StartupApproved\Run: => "PC Speed Maximizer"
HKCU\...\StartupApproved\Run: => "Optimizer Pro"

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/26/2014 02:00:00 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1400) SRUJet: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\Windows\system32\SRU\SRU00237.log.

Error: (06/26/2014 01:52:48 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
   Generatordaten werden gesammelt

Kontext:
   Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Generatorname: System Writer
   Generatorinstanz-ID: {f972e5a7-0a7d-4c30-9fb6-dbe8a907663f}

Error: (06/26/2014 01:38:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: regsvr32.exe, Version: 6.2.9200.16384, Zeitstempel: 0x5010a4f2
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16579, Zeitstempel: 0x51637f77
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000005612
ID des fehlerhaften Prozesses: 0x8ec
Startzeit der fehlerhaften Anwendung: 0xregsvr32.exe0
Pfad der fehlerhaften Anwendung: regsvr32.exe1
Pfad des fehlerhaften Moduls: regsvr32.exe2
Berichtskennung: regsvr32.exe3
Vollständiger Name des fehlerhaften Pakets: regsvr32.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: regsvr32.exe5

Error: (06/26/2014 06:00:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 30.0.0.5269, Zeitstempel: 0x53914233
Name des fehlerhaften Moduls: mozalloc.dll, Version: 30.0.0.5269, Zeitstempel: 0x53911393
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0xd14
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Vollständiger Name des fehlerhaften Pakets: plugin-container.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: plugin-container.exe5

Error: (06/25/2014 05:42:28 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (06/23/2014 09:24:36 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (06/20/2014 07:53:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_SSDPSRV, Version: 6.2.9200.16420, Zeitstempel: 0x505a9a4e
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16579, Zeitstempel: 0x51637f77
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000006b4f
ID des fehlerhaften Prozesses: 0x654
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe_SSDPSRV0
Pfad der fehlerhaften Anwendung: svchost.exe_SSDPSRV1
Pfad des fehlerhaften Moduls: svchost.exe_SSDPSRV2
Berichtskennung: svchost.exe_SSDPSRV3
Vollständiger Name des fehlerhaften Pakets: svchost.exe_SSDPSRV4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe_SSDPSRV5

Error: (06/20/2014 05:51:32 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: Bei der Aktivierung der App „Microsoft.BingFinance_8wekyb3d8bbwe!AppexFinance“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (06/20/2014 05:51:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (06/20/2014 05:21:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.


System errors:
=============
Error: (06/26/2014 00:59:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Service Component of VO" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (06/26/2014 00:35:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Service Component of VO" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (06/26/2014 00:19:47 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (06/26/2014 00:19:47 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (06/23/2014 09:51:05 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Search Protect Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (06/23/2014 09:49:05 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (06/23/2014 09:49:05 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (06/23/2014 09:49:01 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (06/23/2014 09:49:01 PM) (Source: DCOM) (EventID: 10010) (User: GHOTS)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (06/20/2014 07:53:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Zeitbroker" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.


Microsoft Office Sessions:
=========================
Error: (06/26/2014 02:00:00 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost1400SRUJet: C:\Windows\system32\SRU\SRU00237.log-1811 (0xfffff8ed)

Error: (06/26/2014 01:52:48 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Zugriff verweigert


Vorgang:
   Generatordaten werden gesammelt

Kontext:
   Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Generatorname: System Writer
   Generatorinstanz-ID: {f972e5a7-0a7d-4c30-9fb6-dbe8a907663f}

Error: (06/26/2014 01:38:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: regsvr32.exe6.2.9200.163845010a4f2ntdll.dll6.2.9200.1657951637f77c000000500000000000056128ec01cf91332d92125fC:\Windows\system32\regsvr32.exeC:\Windows\SYSTEM32\ntdll.dll6b6beba0-fd26-11e3-be84-bcee7bb99978

Error: (06/26/2014 06:00:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe30.0.0.526953914233mozalloc.dll30.0.0.526953911393800000030000141bd1401cf8f1c962465ffC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll70c47d56-fce6-11e3-be87-bcee7bb99978

Error: (06/25/2014 05:42:28 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (06/23/2014 09:24:36 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (06/20/2014 07:53:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe_SSDPSRV6.2.9200.16420505a9a4entdll.dll6.2.9200.1657951637f77c00000050000000000006b4f65401cf8ca1de67f183C:\Windows\system32\svchost.exeC:\Windows\SYSTEM32\ntdll.dllc7f8d47c-f8a3-11e3-be86-bcee7bb99978

Error: (06/20/2014 05:51:32 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: Microsoft.BingFinance_8wekyb3d8bbwe!AppexFinance-2144927141

Error: (06/20/2014 05:51:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2144927141

Error: (06/20/2014 05:21:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2144927141


==================== Memory info =========================== 

Percentage of memory in use: 46%
Total physical RAM: 3981.57 MB
Available physical RAM: 2141.06 MB
Total Pagefile: 4685.57 MB
Available Pagefile: 2803.07 MB
Total Virtual: 8192 MB
Available Virtual: 8191.76 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:149.97 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Data) (Fixed) (Total:258.34 GB) (Free:258.22 GB) NTFS
Drive e: (zahni) (CDROM) (Total:0.69 GB) (Free:0.01 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 0FE4DC0A)

Partition: GPT Partition Type.

==================== End Of Log ============================
         
Richtig?
__________________

Alt 27.06.2014, 07:27   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



Adware & Co. deinstallieren
  • Lade Dir bitte von hier Revo Uninstaller herunter.
  • Installiere und starte das Programm.
  • Suche im Uninstallerfeld nach den Programmen, die unter:

    diesen Zusatz haben:
  • Wähle die Programme nacheinander aus und klicke jedesmal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter:




Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 27.06.2014, 16:32   #5
Tara86
 
Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



Erledigt!

Code:
ATTFilter
ComboFix 14-06-27.01 - sebastian 27.06.2014  17:21:35.1.4 - x64
Microsoft Windows 8  6.2.9200.0.1252.49.1031.18.3982.2453 [GMT 2:00]
ausgeführt von:: c:\users\sebastian\Downloads\ComboFix.exe
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\program files (x86)\CostMin
c:\program files (x86)\CostMin\f0WXJ.dat
c:\programdata\374311380
c:\programdata\374311380\BIT86EA.tmp
c:\programdata\CostMin
c:\programdata\CostMin\qbs3Z3.dat
c:\programdata\SetStretch.exe
c:\programdata\SetStretch.VBS
c:\users\sebastian\AppData\Local\nsgF480.tmp
c:\users\sebastian\AppData\Local\nsk8393.tmp
c:\users\sebastian\AppData\Local\nstF1C.tmp
.
.
(((((((((((((((((((((((   Dateien erstellt von 2014-05-27 bis 2014-06-27  ))))))))))))))))))))))))))))))
.
.
2014-06-27 14:48 . 2014-06-05 10:54	10779000	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{AA55453C-46AD-4759-9DCA-8F9E4A1ED89D}\mpengine.dll
2014-06-27 14:45 . 2014-06-27 14:45	--------	d-----w-	c:\program files (x86)\VS Revo Group
2014-06-26 15:32 . 2014-06-26 15:32	--------	d-----w-	c:\program files (x86)\Mozilla Maintenance Service
2014-06-26 13:38 . 2014-06-26 13:39	--------	d-----w-	C:\FRST
2014-06-26 11:56 . 2014-06-26 11:56	--------	d-----w-	c:\users\sebastian\AppData\Local\Diagnostics
2014-06-26 11:48 . 2014-06-26 11:55	--------	d-----w-	c:\programdata\Reimage Express
2014-06-26 10:52 . 2014-04-03 03:44	619008	----a-w-	c:\windows\system32\drivers\srv2.sys
2014-06-26 10:52 . 2014-04-03 11:19	328024	----a-w-	c:\windows\system32\drivers\Classpnp.sys
2014-06-26 10:52 . 2014-03-24 23:42	305152	----a-w-	c:\windows\SysWow64\wusa.exe
2014-06-26 10:52 . 2014-03-24 22:56	309760	----a-w-	c:\windows\system32\wusa.exe
2014-06-26 10:52 . 2014-04-03 11:22	2233176	----a-w-	c:\windows\system32\drivers\tcpip.sys
2014-06-26 10:52 . 2014-05-03 05:47	3246592	----a-w-	c:\windows\system32\rdpcorets.dll
2014-06-26 10:52 . 2014-05-03 03:34	235520	----a-w-	c:\windows\system32\rdpudd.dll
2014-06-26 10:52 . 2014-04-29 22:32	1301504	----a-w-	c:\windows\system32\gdi32.dll
2014-06-26 10:52 . 2014-04-29 22:22	1023488	----a-w-	c:\windows\SysWow64\gdi32.dll
2014-06-26 10:52 . 2014-03-07 00:47	1419264	----a-w-	c:\windows\SysWow64\msxml3.dll
2014-06-26 10:52 . 2014-03-07 00:08	1845760	----a-w-	c:\windows\system32\msxml3.dll
2014-06-26 04:00 . 2014-06-26 10:27	--------	d-----w-	c:\programdata\CCOupExettension
2014-06-21 20:36 . 2014-06-27 15:12	--------	d-----w-	c:\program files (x86)\SearchProtect
2014-06-20 08:30 . 2014-06-27 06:00	283312	----a-w-	c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10242.bin
2014-06-19 15:35 . 2014-06-19 15:35	--------	d-----w-	c:\users\sebastian\AppData\Local\freeSOFTtoday
2014-06-19 15:33 . 2014-06-19 15:33	--------	d-----w-	c:\programdata\ASUS
2014-06-19 14:04 . 2014-06-19 14:04	--------	d-----w-	c:\programdata\Microsoft SkyDrive
2014-06-19 14:02 . 2014-06-26 10:26	--------	d-----w-	c:\users\sebastian\AppData\Local\PennyBee
2014-06-19 14:02 . 2014-06-19 14:02	--------	d-----w-	c:\users\sebastian\AppData\Roaming\Settings Manager
2014-06-19 14:02 . 2014-06-19 14:02	--------	d-----w-	c:\program files (x86)\Settings Manager
2014-06-19 12:29 . 2014-06-26 11:39	--------	d-----w-	c:\programdata\CDB
2014-06-19 12:22 . 2014-06-19 12:22	--------	d-----w-	c:\users\sebastian\AppData\Roaming\SupTab
2014-06-19 12:22 . 2014-06-26 10:33	--------	d-----w-	c:\programdata\WindowsProtectManger
2014-06-19 12:22 . 2014-06-26 10:33	--------	d-----w-	c:\programdata\IePluginServices
2014-06-19 12:22 . 2014-06-26 10:33	--------	d-----w-	c:\program files (x86)\SupTab
2014-06-19 12:22 . 2014-06-19 12:22	--------	d-----w-	c:\program files (x86)\globalUpdate
2014-06-19 12:22 . 2014-06-19 12:22	--------	d-----w-	c:\users\sebastian\AppData\Local\globalUpdate
2014-06-19 12:22 . 2014-06-26 10:29	--------	d-----w-	c:\program files (x86)\HQ-V1.3
2014-06-19 12:22 . 2014-06-26 10:29	--------	d-----w-	c:\program files (x86)\video MediaPlayer
2014-06-19 12:22 . 2014-06-26 10:25	--------	d-----w-	c:\users\sebastian\AppData\Roaming\webssearches
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-27 04:14 . 2014-04-03 16:49	62	----a-w-	c:\users\sebastian\AppData\Roaming\sp_data.sys
2014-06-26 10:55 . 2014-04-04 02:58	95414520	----a-w-	c:\windows\system32\MRT.exe
2014-06-19 07:37 . 2014-04-04 12:32	50784	----a-w-	c:\programdata\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2014-05-31 05:16 . 2014-04-06 13:42	703992	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-31 05:16 . 2014-04-06 13:42	105464	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-19 09:39 . 2014-05-06 03:14	628024	----a-w-	c:\windows\system32\NotificationUI.exe
2014-04-19 08:45 . 2014-05-06 03:14	693760	----a-w-	c:\windows\system32\WSShared.dll
2014-04-19 08:45 . 2014-05-06 03:14	163840	----a-w-	c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-19 06:57 . 2014-05-06 03:14	566784	----a-w-	c:\windows\SysWow64\WSShared.dll
2014-04-19 06:57 . 2014-05-06 03:14	124928	----a-w-	c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-12 09:27 . 2014-05-20 03:46	172888	----a-w-	c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 09:10 . 2014-05-20 03:46	578048	----a-w-	c:\windows\system32\winlogon.exe
2014-04-12 09:09 . 2014-05-20 03:46	208896	----a-w-	c:\windows\system32\wdigest.dll
2014-04-12 09:09 . 2014-05-20 03:46	1043968	----a-w-	c:\windows\system32\usercpl.dll
2014-04-12 09:09 . 2014-05-20 03:46	94720	----a-w-	c:\windows\system32\TSpkg.dll
2014-04-12 09:09 . 2014-05-20 03:46	588288	----a-w-	c:\windows\system32\SHCore.dll
2014-04-12 09:08 . 2014-05-20 03:46	318464	----a-w-	c:\windows\system32\msv1_0.dll
2014-04-12 09:08 . 2014-05-20 03:46	1281536	----a-w-	c:\windows\system32\lsasrv.dll
2014-04-12 09:08 . 2014-05-20 03:46	439808	----a-w-	c:\windows\system32\lsm.dll
2014-04-12 09:08 . 2014-05-20 03:46	827904	----a-w-	c:\windows\system32\kerberos.dll
2014-04-12 09:07 . 2014-05-20 03:46	20480	----a-w-	c:\windows\system32\credssp.dll
2014-04-12 07:23 . 2014-05-20 03:46	178688	----a-w-	c:\windows\SysWow64\wdigest.dll
2014-04-12 07:23 . 2014-05-20 03:46	961536	----a-w-	c:\windows\SysWow64\usercpl.dll
2014-04-12 07:23 . 2014-05-20 03:46	76800	----a-w-	c:\windows\SysWow64\TSpkg.dll
2014-04-12 07:23 . 2014-05-20 03:46	452608	----a-w-	c:\windows\SysWow64\SHCore.dll
2014-04-12 07:23 . 2014-05-20 03:46	273920	----a-w-	c:\windows\SysWow64\msv1_0.dll
2014-04-12 07:22 . 2014-05-20 03:46	666624	----a-w-	c:\windows\SysWow64\kerberos.dll
2014-04-12 07:22 . 2014-05-20 03:46	17408	----a-w-	c:\windows\SysWow64\credssp.dll
2014-04-12 06:58 . 2014-05-20 03:46	14848	----a-w-	c:\windows\system32\workerdd.dll
2014-04-04 12:32 . 2014-04-04 12:32	17536	----a-w-	c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2014-04-04 03:07 . 2014-04-04 03:07	61120	----a-w-	c:\windows\system32\drivers\wStLibG64.sys
2014-04-03 16:48 . 2012-07-26 08:13	22240	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-04-03 09:08 . 2014-04-04 17:58	1176896	----a-w-	c:\users\sebastian\AppData\Local\AnyProtectScannerSetup.exe
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2013-04-25 3187360]
"RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2013-03-08 95192]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"SpUninstallCleanUp"="REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect" [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""
.
3;4 CltMngSvc;Search Protect Service;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe [x]
R2 0204171396638742mcinstcleanup;McAfee Application Installer Cleanup (0204171396638742);c:\users\SEBAST~1\AppData\Local\Temp\020417~1.EXE;c:\users\SEBAST~1\AppData\Local\Temp\020417~1.EXE [x]
R2 V-bates Updater;V-bates Updater;c:\program files\V-bates\ExtensionUpdaterService.exe;c:\program files\V-bates\ExtensionUpdaterService.exe [x]
R2 vosr;Service Component of VO;c:\users\sebastian\AppData\Roaming\VOPackage\VOsrv.exe;c:\users\sebastian\AppData\Roaming\VOPackage\VOsrv.exe [x]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
R3 RTL8168;Realtek 8168 NT-Treiber;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
S1 wStLibG64;wStLibG64;c:\windows\system32\drivers\wStLibG64.sys;c:\windows\SYSNATIVE\drivers\wStLibG64.sys [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files\ASUS\P4G\InsOnSrv.exe;c:\program files\ASUS\P4G\InsOnSrv.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AiCharger.sys [x]
S3 ATP;ASUS Input Device;c:\windows\System32\drivers\AsusTP.sys;c:\windows\SYSNATIVE\drivers\AsusTP.sys [x]
S3 cpuz134;cpuz134;c:\users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys;c:\users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]
S3 HIDSwitch;ASUS Wireless Radio Control;c:\windows\System32\drivers\AsHIDSwitch64.sys;c:\windows\SYSNATIVE\drivers\AsHIDSwitch64.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C63x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C63x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2013-12-21 06:04	215416	----a-w-	c:\program files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll
.
Inhalt des "geplante Tasks" Ordners
.
2014-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-03 03:50]
.
2014-06-27 c:\windows\Tasks\Re-markit_wd.job
- c:\program files (x86)\Re-markit Corp\Re-markit_wd.exe [2014-04-04 17:25]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-11-21 171064]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-11-21 399416]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-12-12 13263072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV=
mDefault_Search_URL = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} - c:\program files\V-bates\Extension32.dll
Toolbar-Locked - (no file)
BHO-{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} - c:\program files\V-bates\Extension64.dll
Toolbar-Locked - (no file)
AddRemove-Activeris AntiMalware_is1 - c:\program files (x86)\Activeris AntiMalware\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Zeit der Fertigstellung: 2014-06-27  17:28:40
ComboFix-quarantined-files.txt  2014-06-27 15:28
.
Vor Suchlauf: 9 Verzeichnis(se), 160.733.929.472 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 160.450.875.392 Bytes frei
.
- - End Of File - - BC54B9EF8A4AB62FB86114D1547CC5B1
         


Alt 28.06.2014, 13:48   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
--> Virus? Firefox öffnet unaufgefordert neue Seiten

Alt 28.06.2014, 21:26   #7
Tara86
 
Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



mbam.txt

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 28.06.2014
Suchlauf-Zeit: 21:39:43
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.06.28.04
Rootkit Datenbank: v2014.06.23.02
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: sebastian

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 334712
Verstrichene Zeit: 11 Min, 21 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 1
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe, 2392, Löschen bei Neustart, [3f9596e73744171fc56c2d6d43bf16ea]

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 33
PUP.Optional.SearchProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarantäne, [e9eb5a23a3d8f442d4c23e53798859a7], 
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [fcd84934b2c90f27790a420b5fa39e62], 
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, In Quarantäne, [fcd84934b2c90f27790a420b5fa39e62], 
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [34a06617186367cf0fa13512aa589868], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{708D0DD7-FBC0-4437-B525-C098F450A62C}, In Quarantäne, [e3f181fca3d8d95d3b73341319e9619f], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchHlpr, In Quarantäne, [4f85f08de893b1856b441d668082ef11], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchHlpr.1, In Quarantäne, [ddf70a73e09bbf7700af8bf860a221df], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchHlpr, In Quarantäne, [ddf70a73e09bbf7700af8bf860a221df], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchHlpr.1, In Quarantäne, [ddf70a73e09bbf7700af8bf860a221df], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchdskBnd, In Quarantäne, [399b3746cdaefe38f9b7394aaf5353ad], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchdskBnd.1, In Quarantäne, [e8ecbcc1334815214e625d26f60c20e0], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchdskBnd, In Quarantäne, [e8ecbcc1334815214e625d26f60c20e0], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchdskBnd.1, In Quarantäne, [e8ecbcc1334815214e625d26f60c20e0], 
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\V-bates, In Quarantäne, [be163e3f156655e14bb3d0025ca6df21], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\esrv.buenosearchESrvc, In Quarantäne, [2fa5097492e9d66009803a93da28a759], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\esrv.buenosearchESrvc.1, In Quarantäne, [9e366f0eb5c6a88e3a4f0dc0ec16b050], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\buenosearch LTD, In Quarantäne, [3d97463791ea68ce1a6ca726be446b95], 
PUP.Optional.HQVid.A, HKLM\SOFTWARE\WOW6432NODE\HQVid8.1b, In Quarantäne, [8252a8d5b6c50d292d2cc6f738ca3dc3], 
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\MediaPlayerplus, In Quarantäne, [a23258254c2f8fa720c4f3d04bb7659b], 
PUP.Optional.MegaBrowse.A, HKLM\SOFTWARE\WOW6432NODE\Mega Browse, In Quarantäne, [f8dc5924106bca6c4d0bdfe944be0cf4], 
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\WOW6432NODE\V-bates, In Quarantäne, [4a8ad9a49edd8aac0fefb22037cb1de3], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.buenosearchESrvc, In Quarantäne, [05cff38abebd7eb8dfaa903d0200a55b], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.buenosearchESrvc.1, In Quarantäne, [def63a436219eb4b6a1f27a66c9615eb], 
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\acfoobbgoakpihljnfedbcfaipcdlfhk, In Quarantäne, [8252a7d6235850e6ad215e92c53e25db], 
PUP.Optional.Linkury.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}, In Quarantäne, [12c20a73f388a78f21a23e7926dcd62a], 
PUP.Optional.VbatesHelper.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\V-bates Updater, In Quarantäne, [567eaad32a515dd9ac4fb71b05fddc24], 
PUP.Optional.Feven.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Freeven Pro 1.3, In Quarantäne, [e1f3700d5c1f84b24550a110ab57738d], 
PUP.Optional.HQVid.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQVid8.1b, In Quarantäne, [5381c2bbd4a70f27c2958934b15114ec], 
PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, In Quarantäne, [f1e308755e1d5dd95393982b44bef808], 
PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\buenosearch LTD, In Quarantäne, [805499e45a21a195dcab1cb1bf439b65], 
PUP.Optional.MegaBrowse.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Mega Browse, In Quarantäne, [fcd8cab3e39886b0fc5b18b03bc7f60a], 
PUP.Optional.HQVid.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQVid8.1b, In Quarantäne, [a52fa4d9a1daec4a97c0ba031ee47d83], 
PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, In Quarantäne, [6c68afce7cff77bf5f87d0f3b9490df3], 

Registrierungswerte: 1
PUP.Optional.QuickStart.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, quick_start@gmail.com, In Quarantäne, [5c783449dc9f92a46ac8cde2976b7e82]

Registrierungsdaten: 8
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[5480e39a1c5f1125d90aa5e5dc28c33d]
PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[ffd5324bde9d7db9ba99ee9cae56b54b]
PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS5PD3rJOgw1pGzhTiN_LeZ3h5uqN9RPSYE5jaU9HNvWzyB5Fd9mOdB-PM7Siu3UQ,,, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS5PD3rJOgw1pGzhTiN_LeZ3h5uqN9RPSYE5jaU9HNvWzyB5Fd9mOdB-PM7Siu3UQ,,),Ersetzt,[f8dc14692556e94d33217b0f73915fa1]
PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[00d4b1cc6516979f72e05238a55f9a66]
PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[775d2c510a71fc3a8cc9800ae81c8c74]
PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[cd075825d4a70f2774e25139a85c629e]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[963ea1dc3a41c175f3fb4f31a262847c]
PUP.Optional.Trovi.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV=),Ersetzt,[f1e3d2ab9eddfb3b31f1c8b857ad8c74]

Ordner: 21
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp, Löschen bei Neustart, [3f9596e73744171fc56c2d6d43bf16ea], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk, In Quarantäne, [8c48d8a577049b9b6a9f910a26dc51af], 
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], 
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], 
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47\1.10, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], 
Adware.EoRezo, C:\Program Files (x86)\fst_de_47, In Quarantäne, [34a0cbb216656dc94821fba2689ab64a], 
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], 
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\components, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], 
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\content, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], 
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [ab295429eb902511a350aefb778bda26], 
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [ab295429eb902511a350aefb778bda26], 
PUP.Optional.CrossRider.A, C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpieepnfhpcpkjklohnpmmmmdhcbmd, In Quarantäne, [4f85add01a611c1a68920a9f6c966c94], 
PUP.Optional.CrossRider.A, C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpieepnfhpcpkjklohnpmmmmdhcbmd\1.26.24_0, In Quarantäne, [4f85add01a611c1a68920a9f6c966c94], 
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\update, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73], 
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], 

Dateien: 55
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, Löschen bei Neustart, [e9eb5a23a3d8f442d4c23e53798859a7], 
PUP.Optional.SuperCoolApps, C:\Users\sebastian\Downloads\AdobeFlashPlayer.exe, In Quarantäne, [07cd0f6ea4d752e4d58e73a1ae56c040], 
PUP.Optional.DomalQ, C:\Users\sebastian\Downloads\Setup_V2.exe, In Quarantäne, [508483fa1764ea4c216aa29ba35d9e62], 
PUP.Optional.ReMarkIt.A, C:\Windows\Tasks\Re-markit_wd.job, In Quarantäne, [34a065184d2e6cca5062467ff40efc04], 
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\158.crx, In Quarantäne, [3f9596e73744171fc56c2d6d43bf16ea], 
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\158.xpi, In Quarantäne, [3f9596e73744171fc56c2d6d43bf16ea], 
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe, Löschen bei Neustart, [3f9596e73744171fc56c2d6d43bf16ea], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\124.json, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\MessageBox.xml, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\uninstallDlg2.xml, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\bg.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\bg1.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\bk_shadow.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\button.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\button1.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\checkbox.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\checkbox_select.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\checked.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\close.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\loading_bg.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\loading_light.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\min.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\scrollbar.bmp, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\Thumbs.db, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\unchecked.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code1.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code2.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code3.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code4.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code5.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code6.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\Thumbs.db, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3], 
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\upfst_de_47.cyl, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], 
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\user_profil.cyp, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], 
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47\1.10\cnf.cyl, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], 
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47\1.10\eorezo.cyl, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54], 
Adware.EoRezo, C:\Program Files (x86)\fst_de_47\unins000.dat, In Quarantäne, [34a0cbb216656dc94821fba2689ab64a], 
Adware.EoRezo, C:\Program Files (x86)\fst_de_47\unins000.msg, In Quarantäne, [34a0cbb216656dc94821fba2689ab64a], 
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\install.rdf, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], 
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF.xpt, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], 
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\content\overlay.xul, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1], 
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [ab295429eb902511a350aefb778bda26], 
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\1293297481.mxaddon, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], 
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\360-58360.crx, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], 
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\58360.crx, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], 
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\58360.xpi, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], 
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\59d0aba1-9438-4ba8-979a-e06b975a27f4.crx, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], 
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\background.html, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log\wprotectmanager_2014-06-19[14-22-42-729].log, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73], 
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\1293297481.mxaddon, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], 
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\360-59599.crx, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], 
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\59599.crx, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], 
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\59599.xpi, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], 
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\background.html, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], 
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\d5da2132-5fc4-4df1-9e78-5533f7681ac1.crx, In Quarantäne, [15bf5b22621972c4af18bceece34ad53], 

Physische Sektoren: 0
(No malicious items detected)


(end)
         
AdwCleaner

Code:
ATTFilter
# AdwCleaner v3.213 - Bericht erstellt am 28/06/2014 um 22:01:11
# Aktualisiert 23/06/2014 von Xplode
# Betriebssystem : Windows 8  (64 bits)
# Benutzername : sebastian - GHOTS
# Gestartet von : C:\Users\sebastian\Downloads\adwcleaner_3.213.exe
# Option : Löschen

***** [ Dienste ] *****

[#] Dienst Gelöscht : vosr
Dienst Gelöscht : wStLibG64

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\CCOupExettension
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\Settings Manager
Ordner Gelöscht : C:\Program Files (x86)\SupTab
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\torch
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\Gast\AppData\Local\torch
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\Freesofttoday
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\Genesis
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\PennyBee
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\torch
Ordner Gelöscht : C:\Users\sebastian\AppData\LocalLow\DataMngr
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\AppCloudUpdater
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\AppSafe
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Settings Manager
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppSafe
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
Ordner Gelöscht : C:\Users\sebastian\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\torch
Datei Gelöscht : C:\Windows\System32\drivers\wStLibG64.sys
Datei Gelöscht : C:\Users\sebastian\daemonprocess.txt
Datei Gelöscht : C:\Users\sebastian\AppData\Local\AnyProtectScannerSetup.exe
Datei Gelöscht : C:\Users\sebastian\AppData\Roaming\aps.scan.quick.results
Datei Gelöscht : C:\Users\sebastian\AppData\Roaming\aps.scan.results
Datei Gelöscht : C:\Users\sebastian\AppData\Roaming\aps.uninstall.scan.results

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{c1f9049a-3290-4967-9a3d-448f242ce94c}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ActiverisAntiMalware_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ActiverisAntiMalware_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MegaBrowse_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MegaBrowse_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateMegaBrowse_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateMegaBrowse_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\utilMegaBrowse_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\utilMegaBrowse_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{67FCE87F-F3EF-4A3C-87C2-8BD46E68807B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4CC15FBA-46A4-4CB5-BFAF-F2335365AE76}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5B6E533F-F78F-4525-B316-312BAF1295D1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8322EB6E-B594-41F6-A30B-CF3F800E1874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{67FCE87F-F3EF-4A3C-87C2-8BD46E68807B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E6772887-C1E1-405E-94BB-D8760A1CF8DF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\AppCloudUpdater
Schlüssel Gelöscht : HKCU\Software\AppSafe
Schlüssel Gelöscht : HKCU\Software\genesis
Schlüssel Gelöscht : HKLM\Software\AppSafe

***** [ Browser ] *****

-\\ Internet Explorer v10.0.9200.16921


-\\ Mozilla Firefox v30.0 (de)

[ Datei : C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208\prefs.js ]


-\\ Google Chrome v

*************************

AdwCleaner[R1].txt - [8015 octets] - [28/06/2014 22:00:42]
AdwCleaner[S1].txt - [7673 octets] - [28/06/2014 22:01:11]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [7733 octets] ##########
         
JRT.txt

Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by sebastian on 28.06.2014 at 22:08:38,81
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.06.2014 at 22:14:26,82
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
FRST


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02
Ran by sebastian (administrator) on GHOTS on 28-06-2014 22:20:41
Running from C:\Users\sebastian\Pictures
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;form=IE10TR&amp;src=IE10TR&amp;pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;form=IE10TR&amp;src=IE10TR&amp;pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19]

==================== Services (Whitelisted) =================

R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-28] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
U0 msahci; 

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe
2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt
2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT
2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe
2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt
2014-06-28 22:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-28 22:00 - 2014-06-28 22:01 - 00000000 ____D () C:\AdwCleaner
2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe
2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt
2014-06-28 21:38 - 2014-06-28 22:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-28 21:37 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-28 21:37 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-28 21:36 - 2014-06-28 21:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt
2014-06-27 17:20 - 2014-06-27 17:28 - 00000000 ____D () C:\Qoobox
2014-06-27 17:20 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-27 17:20 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-27 17:20 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-27 17:19 - 2014-06-27 17:26 - 00000000 ____D () C:\Windows\erdnt
2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk
2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 15:38 - 2014-06-28 22:20 - 00000000 ____D () C:\FRST
2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml
2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-20 18:08 - 2014-06-28 22:03 - 00035110 _____ () C:\Windows\PFRO.log
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB
2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator

==================== One Month Modified Files and Folders =======

2014-06-28 22:20 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST
2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe
2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt
2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT
2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe
2014-06-28 22:06 - 2014-06-28 21:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt
2014-06-28 22:04 - 2014-04-06 16:22 - 01414287 _____ () C:\Windows\WindowsUpdate.log
2014-06-28 22:03 - 2014-06-20 18:08 - 00035110 _____ () C:\Windows\PFRO.log
2014-06-28 22:03 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys
2014-06-28 22:03 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-28 22:02 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-28 22:01 - 2014-06-28 22:00 - 00000000 ____D () C:\AdwCleaner
2014-06-28 22:01 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian
2014-06-28 22:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe
2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt
2014-06-28 21:54 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker
2014-06-28 21:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-06-28 21:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt
2014-06-27 17:28 - 2014-06-27 17:20 - 00000000 ____D () C:\Qoobox
2014-06-27 17:28 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-06-27 17:26 - 2014-06-27 17:19 - 00000000 ____D () C:\Windows\erdnt
2014-06-27 17:26 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe
2014-06-27 17:04 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk
2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-27 16:44 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1
2014-06-27 16:44 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2
2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002
2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB
2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep
2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G
2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration
2014-06-24 19:59 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator
2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-05-31 07:16 - 2014-04-06 15:42 - 00703992 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-31 07:16 - 2014-04-06 15:42 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

Some content of TEMP:
====================
C:\Users\sebastian\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-24 19:53

==================== End Of Log ============================
         
--- --- ---

Alt 29.06.2014, 12:29   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 29.06.2014, 16:26   #9
Tara86
 
Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=d8612a777599594291c7c94102f69d8a
# engine=18938
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-06-29 03:07:42
# local_time=2014-06-29 05:07:42 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT 
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 69762 8445351 0 0
# scanned=162766
# found=5
# cleaned=0
# scan_time=5027
sh=B814422F7EE1E98A56D8B9F17F0BB542F8E446E6 ft=1 fh=c71c001197996c13 vn="Win32/AnyProtect.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\sebastian\AppData\Local\AnyProtectScannerSetup.exe.vir"
sh=F3AC96D68C2DBF10829ADEC639382DD25D6D6057 ft=1 fh=abbd31e397996c13 vn="Win32/AnyProtect.D evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\sebastian\AppData\Local\nstF1C.tmp.vir"
sh=3947DC53990D4C0F5E5F655818233800CF9F601B ft=0 fh=0000000000000000 vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\10bb944.msi"
sh=F4BBB551315DBE49911663D85F079AFE8B5F8F51 ft=1 fh=96414ff33da39282 vn="Variante von Win32/Toolbar.BitCocktail.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\update[1]"
sh=F4BBB551315DBE49911663D85F079AFE8B5F8F51 ft=1 fh=96414ff33da39282 vn="Variante von Win32/Toolbar.BitCocktail.B evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\update[1]"
         
Security Check

Ich hab es runter geladen und gespeichert, wenn ich es aufführe, öffnet sich die DOS-Box und fordert mich auf, eine beliebige Taste zu drücken. Das hab ich getan, danach öffnete sich ein neues Fenster checkup - Editor mit Inhalt "UNSUPPORTED OPERATING SYSTEM! ABORTED!"


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02
Ran by sebastian (administrator) on GHOTS on 29-06-2014 17:24:15
Running from C:\Users\sebastian\Pictures
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
() C:\Users\sebastian\Downloads\SecurityCheck.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;form=IE10TR&amp;src=IE10TR&amp;pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;form=IE10TR&amp;src=IE10TR&amp;pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19]

==================== Services (Whitelisted) =================

R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-29] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
U0 msahci; 

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-29 17:15 - 2014-06-29 17:15 - 00854367 _____ () C:\Users\sebastian\Downloads\SecurityCheck.exe
2014-06-29 15:38 - 2014-06-29 15:38 - 02347384 _____ (ESET) C:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe
2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe
2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt
2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT
2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe
2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt
2014-06-28 22:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-28 22:00 - 2014-06-28 22:01 - 00000000 ____D () C:\AdwCleaner
2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe
2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt
2014-06-28 21:38 - 2014-06-29 17:10 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-28 21:37 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-28 21:37 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-28 21:36 - 2014-06-28 21:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt
2014-06-27 17:20 - 2014-06-27 17:28 - 00000000 ____D () C:\Qoobox
2014-06-27 17:20 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-27 17:20 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-27 17:20 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-27 17:19 - 2014-06-27 17:26 - 00000000 ____D () C:\Windows\erdnt
2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk
2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 15:38 - 2014-06-29 17:24 - 00000000 ____D () C:\FRST
2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml
2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-20 18:08 - 2014-06-28 22:03 - 00035110 _____ () C:\Windows\PFRO.log
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB
2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator

==================== One Month Modified Files and Folders =======

2014-06-29 17:24 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST
2014-06-29 17:17 - 2014-04-06 16:22 - 01473215 _____ () C:\Windows\WindowsUpdate.log
2014-06-29 17:15 - 2014-06-29 17:15 - 00854367 _____ () C:\Users\sebastian\Downloads\SecurityCheck.exe
2014-06-29 17:10 - 2014-06-28 21:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-29 17:03 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-29 15:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-29 15:39 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1
2014-06-29 15:39 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2
2014-06-29 15:38 - 2014-06-29 15:38 - 02347384 _____ (ESET) C:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe
2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe
2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt
2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT
2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe
2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt
2014-06-28 22:03 - 2014-06-20 18:08 - 00035110 _____ () C:\Windows\PFRO.log
2014-06-28 22:03 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys
2014-06-28 22:03 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-28 22:02 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-28 22:01 - 2014-06-28 22:00 - 00000000 ____D () C:\AdwCleaner
2014-06-28 22:01 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian
2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe
2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt
2014-06-28 21:54 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker
2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-06-28 21:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt
2014-06-27 17:28 - 2014-06-27 17:20 - 00000000 ____D () C:\Qoobox
2014-06-27 17:28 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-06-27 17:26 - 2014-06-27 17:19 - 00000000 ____D () C:\Windows\erdnt
2014-06-27 17:26 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe
2014-06-27 17:04 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk
2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002
2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB
2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep
2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G
2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration
2014-06-24 19:59 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator
2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-05-31 07:16 - 2014-04-06 15:42 - 00703992 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-31 07:16 - 2014-04-06 15:42 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

Some content of TEMP:
====================
C:\Users\sebastian\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-24 19:53

==================== End Of Log ============================
         
--- --- ---


Ich glaube aber, dass Problem ist schon behoben. Was sagst du zu dem Security Check. Das kann doch nicht richtig sein, oder?

Alt 30.06.2014, 11:37   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



Security check ignorieren, ist ne Zicke.


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.






Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 01.07.2014, 21:15   #11
Tara86
 
Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten




FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02
Ran by sebastian (administrator) on GHOTS on 01-07-2014 22:11:19
Running from C:\Users\sebastian\Pictures
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16683_none_62280e15510f8e79\TiWorker.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;form=IE10TR&amp;src=IE10TR&amp;pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;form=IE10TR&amp;src=IE10TR&amp;pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19]

==================== Services (Whitelisted) =================

R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-01] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
U0 msahci; 

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-29 17:15 - 2014-06-29 17:15 - 00854367 _____ () C:\Users\sebastian\Downloads\SecurityCheck.exe
2014-06-29 15:38 - 2014-06-29 15:38 - 02347384 _____ (ESET) C:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe
2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe
2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt
2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT
2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe
2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt
2014-06-28 22:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-28 22:00 - 2014-06-28 22:01 - 00000000 ____D () C:\AdwCleaner
2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe
2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt
2014-06-28 21:38 - 2014-07-01 22:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-28 21:37 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-28 21:37 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-28 21:36 - 2014-06-28 21:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt
2014-06-27 17:20 - 2014-06-27 17:28 - 00000000 ____D () C:\Qoobox
2014-06-27 17:20 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-27 17:20 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-27 17:20 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-27 17:19 - 2014-06-27 17:26 - 00000000 ____D () C:\Windows\erdnt
2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk
2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 15:38 - 2014-07-01 22:11 - 00000000 ____D () C:\FRST
2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml
2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-20 18:08 - 2014-06-28 22:03 - 00035110 _____ () C:\Windows\PFRO.log
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB
2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator

==================== One Month Modified Files and Folders =======

2014-07-01 22:11 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST
2014-07-01 22:07 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-07-01 22:06 - 2014-06-28 21:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-29 17:17 - 2014-04-06 16:22 - 01479702 _____ () C:\Windows\WindowsUpdate.log
2014-06-29 17:15 - 2014-06-29 17:15 - 00854367 _____ () C:\Users\sebastian\Downloads\SecurityCheck.exe
2014-06-29 15:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-29 15:39 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1
2014-06-29 15:39 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2
2014-06-29 15:38 - 2014-06-29 15:38 - 02347384 _____ (ESET) C:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe
2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe
2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt
2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT
2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe
2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt
2014-06-28 22:03 - 2014-06-20 18:08 - 00035110 _____ () C:\Windows\PFRO.log
2014-06-28 22:03 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys
2014-06-28 22:03 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-28 22:02 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-28 22:01 - 2014-06-28 22:00 - 00000000 ____D () C:\AdwCleaner
2014-06-28 22:01 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian
2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe
2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt
2014-06-28 21:54 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker
2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-28 21:37 - 2014-06-28 21:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt
2014-06-27 17:28 - 2014-06-27 17:20 - 00000000 ____D () C:\Qoobox
2014-06-27 17:28 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-06-27 17:26 - 2014-06-27 17:19 - 00000000 ____D () C:\Windows\erdnt
2014-06-27 17:26 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe
2014-06-27 17:04 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk
2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002
2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB
2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep
2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G
2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration
2014-06-24 19:59 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator
2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent

Some content of TEMP:
====================
C:\Users\sebastian\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-24 19:53

==================== End Of Log ============================
         
--- --- ---


Alles weitere mach ich dann gleich. Danke für deine Tipps und vorallem für deine Hilfe!
Ihr habt mir hier schon zum 2. Mal sehr geholfen und ich hoffe, euch nicht so schnell wieder belästigen zu müssen.

Sag mal, wären diese Schritte nicht auch allgemein sehr nützlich, wenn man schlechtes Zeug auf dem Laptop hat?

Alt 02.07.2014, 14:45   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



Die sind immer ein wenig individuell. DU hast den letzten FRST Fix vergessen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 08.07.2014, 09:19   #13
Tara86
 
Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



In meinem letzten Beitrag ist doch FRST Logfile.
Da ich schon alles gelöscht habe, hab ichs neu runter geladen und schick dir beide Datein.

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-07-2014 01
Ran by sebastian at 2014-07-08 10:16:05
Running from C:\Users\sebastian\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Adobe Flash Player 14 Plugin (HKLM-x32\...\{C4B32291-F7B2-4BEC-BA4D-4195676A08CC}) (Version: 14.0.0.125 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 3.4.117.01527 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 3.4.117.01527 - Alcor Micro Corp.) Hidden
Amazon 1Button App (x32 Version: 1.0.4 - Amazon) Hidden
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.2.2 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 3.0.4 - ASUS)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 2.1.4 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 2.01.0005 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.5 - ASUS)
ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5230.52 - CyberLink Corp.)
ASUSDVD (x32 Version: 10.0.5230.52 - CyberLink Corp.) Hidden
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0030 - ASUS)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2884 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
Junk Mail filter update (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden
NVIDIA Optimus 1.15.2 (Version: 1.15.2 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0325 - NVIDIA Corporation) Hidden
NVIDIA PhysX System Software 9.13.0325 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0325 - NVIDIA Corporation)
NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden
NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden
Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Raccolta foto (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6804 - Realtek Semiconductor Corp.)
Windows Driver Package - ASUS (ATP) Mouse  (01/10/2013 1.0.0.170) (HKLM\...\4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5) (Version: 01/10/2013 1.0.0.170 - ASUS)
Windows Live (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.42.0 - ASUS)

==================== Restore Points  =========================

01-07-2014 21:12:47 Ende der Bereinigung
06-07-2014 04:04:23 Windows Update

==================== Hosts content: ==========================

2012-07-26 07:26 - 2014-06-27 17:26 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {046AB098-8757-429F-A45A-34560CDE705F} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-11-28] (ASUS)
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2D000AE6-50A7-4810-ABD9-94BD2A983C68} - \RegClean Pro No Task File <==== ATTENTION
Task: {4397CA92-7DE8-4250-BBE2-99C5DA1F9CE4} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2013-03-20] (ASUSTeK Computer Inc.)
Task: {50CA362E-DD77-492B-A3EF-CD7B44E39027} - \Re-markit Update No Task File <==== ATTENTION
Task: {78C8EFD9-8BDD-4BFD-8251-7B3E62428EC8} - System32\Tasks\Systweak Support Dock => C:\Program Files (x86)\Systweak Support Dock\SystweakDock.exe
Task: {7B9522FD-40CE-4535-8AB6-C5D3E1ADA2A1} - System32\Tasks\ASUS Splendid ColorU => C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [2013-02-26] (ASUSTeK Computer Inc.)
Task: {905FFE6D-70A6-44C1-9058-CD47BE06AA54} - \RegClean Pro_DEFAULT No Task File <==== ATTENTION
Task: {91CD476A-0DBB-44E4-B8E7-D06C9318CCB9} - \RegClean Pro_UPDATES No Task File <==== ATTENTION
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {AB04EEEE-ACAE-4EDA-9DDE-0C137A36FE63} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2013-03-20] (ASUSTeK Computer Inc.)
Task: {AEB90AA0-7FD5-422D-BACA-502B48554C29} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2013-06-19] (ASUS)
Task: {B1EFB696-E8A9-45FC-90C1-FDAD4B903950} - System32\Tasks\ASUS InstantOn Config => C:\Program Files\ASUS\P4G\InsOnCfg.exe
Task: {B680E34E-6844-4054-9EC3-39B382319F09} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.)
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {CCB636B3-A9F6-4AAB-AEF1-0F8F9B97D176} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-04-29] (AsusTek)
Task: {D9F25AF7-06A5-4BD6-B55E-DC91432DB33B} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-04-19] (Microsoft Corporation)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {FF19C4A5-5389-41E7-AA7F-A5E0CC036656} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-01] (Adobe Systems Incorporated)
Task: {FF7D8F78-0384-4DD4-AB53-F37847982188} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-06-26] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2013-12-10 08:13 - 2013-12-10 08:13 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2013-11-22 15:32 - 2013-10-23 10:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-11-22 15:38 - 2012-06-25 12:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-12-10 08:13 - 2013-12-10 08:13 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2014-06-26 17:32 - 2014-06-06 06:38 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:373E1720
AlternateDataStreams: C:\ProgramData\Temp:AD022376

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========

HKLM\...\StartupApproved\Run32: => "BingDesktop"
HKCU\...\StartupApproved\Run: => "PC Speed Maximizer"
HKCU\...\StartupApproved\Run: => "Optimizer Pro"

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/05/2014 10:02:21 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: Bei der Aktivierung der App „Microsoft.XboxLIVEGames_8wekyb3d8bbwe!Microsoft.XboxLIVEGames“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/01/2014 11:45:22 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: Bei der Aktivierung der App „winstore_cw5n1h2txyewy!Windows.Store“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/01/2014 11:37:14 PM) (Source: MsiInstaller) (EventID: 1002) (User: NT-AUTORITÄT)
Description: Nicht erwarteter oder fehlender Wert (Name: "PackageCode", Wert: "GUID") für Schlüssel "HKLM\Software\Classes\Installer\Products\B476F94747628E7478C965620AB6A219".

Error: (07/01/2014 11:23:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: Bei der Aktivierung der App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/01/2014 11:22:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: Bei der Aktivierung der App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/01/2014 11:12:15 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error: (06/29/2014 05:19:25 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error: (06/29/2014 03:38:52 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error: (06/29/2014 03:38:50 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.


System errors:
=============
Error: (07/01/2014 11:47:42 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "ASLDR Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (07/01/2014 10:30:26 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (07/01/2014 10:28:29 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.


Microsoft Office Sessions:
=========================
Error: (07/05/2014 10:02:21 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: Microsoft.XboxLIVEGames_8wekyb3d8bbwe!Microsoft.XboxLIVEGames-2144927151

Error: (07/01/2014 11:45:22 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: winstore_cw5n1h2txyewy!Windows.Store-2144927151

Error: (07/01/2014 11:37:14 PM) (Source: MsiInstaller) (EventID: 1002) (User: NT-AUTORITÄT)
Description: PackageCodeGUIDHKLM\Software\Classes\Installer\Products\B476F94747628E7478C965620AB6A219(NULL)(NULL)(NULL)

Error: (07/01/2014 11:23:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos-2144927151

Error: (07/01/2014 11:22:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: GHOTS)
Description: microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos-2144927151

Error: (07/01/2014 11:12:15 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe

Error: (06/29/2014 05:19:25 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe

Error: (06/29/2014 03:38:52 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe

Error: (06/29/2014 03:38:50 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\sebastian\Downloads\esetsmartinstaller_deu.exe


CodeIntegrity Errors:
===================================
  Date: 2014-06-27 17:25:40.382
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info =========================== 

Percentage of memory in use: 46%
Total physical RAM: 3981.57 MB
Available physical RAM: 2137.54 MB
Total Pagefile: 4877.57 MB
Available Pagefile: 2783.35 MB
Total Virtual: 8192 MB
Available Virtual: 8191.77 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:155.24 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Data) (Fixed) (Total:258.34 GB) (Free:258.22 GB) NTFS
Drive e: (zahni) (CDROM) (Total:0.69 GB) (Free:0.01 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 0FE4DC0A)

Partition: GPT Partition Type.

==================== End Of Log ============================
         

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-07-2014 01
Ran by sebastian (administrator) on GHOTS on 08-07-2014 10:15:13
Running from C:\Users\sebastian\Downloads
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16683_none_62280e15510f8e79\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;form=IE10TR&amp;src=IE10TR&amp;pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;form=IE10TR&amp;src=IE10TR&amp;pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: NoScript - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-07-01]
FF Extension: Adblock Edge - C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2014-07-01]
FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19]

==================== Services (Whitelisted) =================

R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
R3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
U0 msahci; 

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-08 10:15 - 2014-07-08 10:15 - 00007760 _____ () C:\Users\sebastian\Downloads\FRST.txt
2014-07-08 10:15 - 2014-07-08 10:15 - 00000000 ____D () C:\FRST
2014-07-08 10:14 - 2014-07-08 10:14 - 02084352 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe
2014-07-06 06:05 - 2014-05-15 03:02 - 00059424 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-07-06 06:05 - 2014-05-15 00:43 - 03286528 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-07-06 06:05 - 2014-05-15 00:43 - 01623040 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-07-06 06:05 - 2014-05-15 00:43 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-07-06 06:05 - 2014-05-15 00:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-07-01 23:51 - 2014-07-01 23:51 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Adobe
2014-07-01 23:47 - 2014-07-01 23:47 - 00448512 _____ (OldTimer Tools) C:\Users\sebastian\Desktop\TFC.exe
2014-07-01 23:46 - 2014-07-01 23:46 - 00700980 _____ () C:\Users\sebastian\Downloads\adblock_edge-2.0.7-sm+an+tb+fx-windows.xpi
2014-07-01 23:37 - 2014-07-01 23:37 - 00000411 _____ () C:\Windows\SecuniaPackage.log
2014-07-01 23:35 - 2014-07-01 23:35 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Secunia PSI
2014-07-01 23:35 - 2014-07-01 23:35 - 00000000 ____D () C:\Program Files (x86)\Secunia
2014-06-28 22:08 - 2014-07-01 23:12 - 00000000 ____D () C:\Windows\ERUNT
2014-06-28 22:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-27 17:19 - 2014-06-27 17:26 - 00000000 ____D () C:\Windows\erdnt
2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml
2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-20 18:08 - 2014-06-28 22:03 - 00035110 _____ () C:\Windows\PFRO.log
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB
2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator

==================== One Month Modified Files and Folders =======

2014-07-08 10:15 - 2014-07-08 10:15 - 00007760 _____ () C:\Users\sebastian\Downloads\FRST.txt
2014-07-08 10:15 - 2014-07-08 10:15 - 00000000 ____D () C:\FRST
2014-07-08 10:14 - 2014-07-08 10:14 - 02084352 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe
2014-07-08 10:14 - 2014-04-06 16:22 - 01846805 _____ () C:\Windows\WindowsUpdate.log
2014-07-07 16:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-07-07 15:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-06 06:08 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-07-05 10:01 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1
2014-07-05 10:01 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2
2014-07-01 23:51 - 2014-07-01 23:51 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Adobe
2014-07-01 23:47 - 2014-07-01 23:47 - 00448512 _____ (OldTimer Tools) C:\Users\sebastian\Desktop\TFC.exe
2014-07-01 23:46 - 2014-07-01 23:46 - 00700980 _____ () C:\Users\sebastian\Downloads\adblock_edge-2.0.7-sm+an+tb+fx-windows.xpi
2014-07-01 23:37 - 2014-07-01 23:37 - 00000411 _____ () C:\Windows\SecuniaPackage.log
2014-07-01 23:37 - 2014-05-01 08:41 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-01 23:35 - 2014-07-01 23:35 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Secunia PSI
2014-07-01 23:35 - 2014-07-01 23:35 - 00000000 ____D () C:\Program Files (x86)\Secunia
2014-07-01 23:12 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT
2014-07-01 22:38 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-07-01 22:30 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-06-28 22:03 - 2014-06-20 18:08 - 00035110 _____ () C:\Windows\PFRO.log
2014-06-28 22:03 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys
2014-06-28 22:03 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-28 22:02 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-28 22:01 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian
2014-06-28 21:54 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker
2014-06-27 17:28 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-06-27 17:26 - 2014-06-27 17:19 - 00000000 ____D () C:\Windows\erdnt
2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002
2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB
2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep
2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G
2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator
2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-05 10:17

==================== End Of Log ============================
         
--- --- ---


Ich hab deine Tipps auch umgesetzt, allerdings musste ich Noscript wieder deaktivieren, da einige Sachen nicht mehr richtig angezeigt wurden.

Alt 09.07.2014, 08:10   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



Du musst in NoScript nur die Scripte zulassen.

Du hast den Fix immer noch vergessen. Ich rede nicht von einem FRST Scan, sondern von dem Fix!
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2014, 08:58   #15
Tara86
 
Virus? Firefox öffnet unaufgefordert neue Seiten - Standard

Virus? Firefox öffnet unaufgefordert neue Seiten



Jetzt hab ichs verstanden.

Wenn ich aber Fix klicke, öffnet sich ein Fenster, was mir sagt:

No fixlist.txt found.
The fixlist.txt should be in the same folder/directory the tool is located.

Muss ich da vielleicht noch was umbenennen?

Antwort

Themen zu Virus? Firefox öffnet unaufgefordert neue Seiten
adware.eorezo, neue seite, pup.optional.buenosearch.a, pup.optional.crossrider.a, pup.optional.feven.a, pup.optional.hqvid.a, pup.optional.hqvideo.a, pup.optional.iepluginservices.a, pup.optional.linkury.a, pup.optional.mediaplayerplus.a, pup.optional.megabrowse.a, pup.optional.qone8, pup.optional.quickstart.a, pup.optional.remarkit.a, pup.optional.searchprotect.a, pup.optional.settingsmanager.a, pup.optional.snapdo, pup.optional.snapdo.a, pup.optional.supercoolapps, pup.optional.systemk.a, pup.optional.trovi.a, pup.optional.vbates, pup.optional.vbateshelper.a, pup.optional.videomediaplayer.a, pup.optional.webssearches.a, pup.optional.wpm.a




Ähnliche Themen: Virus? Firefox öffnet unaufgefordert neue Seiten


  1. WIN 7 Firefox öffnet unaufgefordert Tabs
    Plagegeister aller Art und deren Bekämpfung - 01.05.2015 (33)
  2. Mozilla Firefox öffnet unaufgefordert Werbetabs
    Log-Analyse und Auswertung - 29.04.2014 (12)
  3. PUP.optional von Malwarebytes entdeckt, Firefox öffnet ständig neue (leere) Seiten
    Plagegeister aller Art und deren Bekämpfung - 11.04.2014 (3)
  4. Windows 8: Browser öffnet unaufgefordert neue Fenster, Rückkehr zur Startseite
    Log-Analyse und Auswertung - 09.04.2014 (12)
  5. Firefox öffnet ständig neue seiten
    Plagegeister aller Art und deren Bekämpfung - 06.04.2014 (9)
  6. Win 8: Firefox öffnet unaufgefordert Gewinnspielseiten mit Iphone 5
    Plagegeister aller Art und deren Bekämpfung - 03.09.2013 (7)
  7. Firefox öffnet ständig neue Seiten...Computer reagiert sehr langsam
    Log-Analyse und Auswertung - 07.08.2013 (42)
  8. e-ligatus-com, FireFox öffnet unaufgefordert dubiose Internetseite
    Log-Analyse und Auswertung - 19.05.2013 (10)
  9. Computer öffnet unaufgefordert Seiten und komischer Virus gefunden
    Plagegeister aller Art und deren Bekämpfung - 10.10.2012 (46)
  10. Firefox öffnet unaufgefordert schädliche Webseiten
    Plagegeister aller Art und deren Bekämpfung - 12.02.2011 (15)
  11. Trojaner öffnet ständig neue Seiten in Firefox!
    Plagegeister aller Art und deren Bekämpfung - 30.10.2010 (10)
  12. Firefox öffnet neue Seiten
    Log-Analyse und Auswertung - 28.04.2010 (12)
  13. Firefox öffnet unaufgefordert Werbefenster
    Log-Analyse und Auswertung - 19.03.2009 (14)
  14. Firefox öffnet unaufgefordert Werbefenster
    Log-Analyse und Auswertung - 28.09.2008 (16)
  15. Firefox öffnet neue Seiten
    Log-Analyse und Auswertung - 10.07.2008 (1)
  16. Firefox öffnet automatisch neue seiten beim surfen...
    Plagegeister aller Art und deren Bekämpfung - 07.11.2007 (3)
  17. firefox öffnet automatisch neue seiten
    Plagegeister aller Art und deren Bekämpfung - 23.05.2006 (33)

Zum Thema Virus? Firefox öffnet unaufgefordert neue Seiten - Hallo! Unser Latop ist relativ neu. Wir haben uns einige Programme aus dem Internet runtergeladen, dabei scheint sich ein Virus eingeschlichen zu haben. Unser Virusprogramm findet allerdings nichts. Und zwar - Virus? Firefox öffnet unaufgefordert neue Seiten...
Archiv
Du betrachtest: Virus? Firefox öffnet unaufgefordert neue Seiten auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.