Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: _GETWINDOWINFO-Trojaner

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 24.11.2013, 12:49   #1
LikeASiR
 
_GETWINDOWINFO-Trojaner - Ausrufezeichen

_GETWINDOWINFO-Trojaner



Hallo Leute,

Heute Früh, nachdem ich den PC angeschaltet habe, hat sich interessanterweise der Internet Explorer mit dem Link: hxxp://www_getwindowinfo/ geöffnet, welcher nicht geschlossen werden kann.
Interessante Anmerkung: Ich hatte am Vortag keine Downloads durchgeführt und einen Internet Explorer hatte ich auch nie.

Mittlerweile hab ich gesehen, dass viele Leute dieses Problem haben, aber bei jedem die Anleitungen von den Admins anders waren. Was aber gleich blieb ist der Scan mit Farbar Recovery Scan Tool. Also hab ich mir erlaubt, das herunterzuladen und zu scanen, damit meine und eure Zeit nicht umsonst verschwendet wird. :-D

Wenn wir schon dabei sind:
Seit kurzem taucht immer snap.do als Startseite bei meinen Browsern auf. Daraufhin hab ich mir einen Malwarefighter geholt, und der sagt mir jedes mal, wenn ich meinen Browser schließe: Der IOBit HomePage Schutz hat verhindert, dass ihre Startseite verändert wird. Seitdem taucht es nicht mehr auf, aber blockieren ist sicherlich nicht die endgültige Lösung.
Betriebssystem ist Win 7.

Hier sind die Ergebnisse:



FRST.txt:

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2013 03
Ran by Admin (administrator) on PC on 24-11-2013 11:57:20
Running from C:\Users\Admin\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\Tor\tor.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Smartbar) C:\Users\Admin\AppData\Local\Smartbar\Application\SnapDo.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(BitTorrent, Inc.) C:\Program Files (x86)\BitTorrent\BitTorrent.exe
(Windows Net) C:\Users\Admin\AppData\Roaming\Windows Net Data\net.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-07-03] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-06-13] (Adobe Systems Incorporated)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
HKCU\...\Run: [Browser Infrastructure Helper] - C:\Users\Admin\AppData\Local\Smartbar\Application\SnapDo.exe [21024 2013-08-04] (Smartbar)
HKCU\...\Run: [BitTorrent] - C:\Program Files (x86)\BitTorrent\BitTorrent.exe [1279384 2012-11-24] (BitTorrent, Inc.)
HKCU\...\Run: [Win Update] - C:\Users\Admin\AppData\Roaming\Win Update.exe
HKCU\...\Run: [DarkComet RAT] - C:\Users\Admin\Documents\DCSCMIN\IMDCSC.exe
HKCU\...\Policies\Explorer: [] 
HKCU\...\Policies\Explorer: [DisallowRun] 1
MountPoints2: {039796ea-03da-11e2-acc2-806e6f6e6963} - D:\start.exe
MountPoints2: {853f4d50-4465-11e2-9c82-001bfcfb8327} - H:\Fairlight\Installer.exe
HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-09-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM-x32\...\Run: [IObit Malware Fighter] - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [1549120 2013-08-16] (IObit)
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
ShortcutTarget: net.lnk -> C:\Users\Admin\AppData\Roaming\Windows Net Data\net.exe (Windows Net)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2B8F4B822CAECD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
HKCU\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/software/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
SearchScopes: HKCU - F4FA9A3599F049448F02069E95A87F8C URL = hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=1A054C60DE739903&affID=119357&tsp=4985
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
SearchScopes: HKCU - {26681076-2DF8-44B1-900B-06D059B96AA0} URL = hxxp://search.toggle.com/?lang=en&cid=adfaa7a7&q={searchTerms}
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: Speed Test Analysis - {310D38FE-EB4C-467C-8781-B7C2AEB7847D} - C:\Program Files (x86)\Speed Test Analysis\ScriptHost64.dll No File
BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Speed Test Analysis - {310D38FE-EB4C-467C-8781-B7C2AEB7847D} - C:\Program Files (x86)\Speed Test Analysis\ScriptHost.dll No File
BHO-x32: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: AccelerateTab - {48A789BF-F6D6-4930-9C8B-77855A63EDE1} - C:\Program Files (x86)\Secure Speed Dial\IE\SpeedDial.dll (Secure Speed Dial)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Utility Chest - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files (x86)\UtilityChest_49\bar\1.bin\49bar.dll No File
Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {CF67755F-9265-449C-87CF-B945519E073B} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default
FF DefaultSearchEngine: Web Search
FF SelectedSearchEngine: Web Search
FF Homepage: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013|hxxp://www.giga.de/software/
FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&installDate=27/10/2013&q=
FF NewTab: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=nt&installDate=27/10/2013
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\bingp.xml
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\toggle.xml
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\Web Search.xml
FF Extension: Amazon-Icon - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\amazon-icon@giga.de
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\ascsurfingprotection@iobit.com
FF Extension: HDvid Codec - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\hdvc@hdvc.com
FF Extension: AD Block - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\searchads@instair.net
FF Extension: AccelerateTab - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\speeddial@instair.net
FF Extension: Speed Test Analysis - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\speedtestanalysis@SpeedAnalysis.com
FF Extension: No Name - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\staged
FF Extension: WebSite Recommendation - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\WebSiteRecommendation@weliketheweb.com
FF Extension: Snap.Do  - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\{96e1573f-e7e4-9f36-0509-dd0e99161bc7}
FF Extension: No Name - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\WTB_GLOBAL.sqlite

Chrome: 
=======
CHR HomePage: chrome://newtab
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013"
CHR DefaultSearchURL: (Web) - hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
CHR DefaultSuggestURL: (Web) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR Extension: () - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html
CHR Extension: (Speed Test Analysis) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb\1.0.0.5_1
CHR Extension: (Amazon-Icon) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg\1.0_0
CHR Extension: (	"name":"Advanced SystemCare Surfing Protection",) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0
CHR Extension: (Google Wallet) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_1
CHR HKLM-x32\...\Chrome\Extension: [kckgnnipheglejoddfhekdjpbdbinhmb] - C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis\SpeedTestAnalysis.crx
CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Admin\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx
CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx

==================== Services (Whitelisted) =================

R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [878368 2013-10-25] (IObit)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [335168 2013-04-25] (IObit)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-10-25] (IObit)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-01-26] ()
S2 SecureUpdateSvc; C:\Program Files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [2472272 2013-10-23] ()
R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-31] ()
S4 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [x]
S2 Update WebConnect; "C:\Program Files (x86)\WebConnect\updateWebConnect.exe" [x]
S2 UtilityChest_49Service; C:\PROGRA~2\UTILIT~2\bar\1.bin\49barsvc.exe [x]
S2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [x]
S2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [x]

==================== Drivers (Whitelisted) ====================

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-12] (DT Soft Ltd)
S4 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34336 2013-03-26] (IObit.com)
S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [67024 2013-03-12] (Fuzhou Rockchip Electronics Co,Ltd.)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] ()
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [204568 2013-08-20] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-03-26] (IObit.com)
S3 WinRing0_1_2_0; C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [14544 2012-08-01] (OpenLibSys.org)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-24 11:57 - 2013-11-24 11:57 - 00020033 _____ C:\Users\Admin\Downloads\FRST.txt
2013-11-24 11:56 - 2013-11-24 11:56 - 00000000 ____D C:\FRST
2013-11-24 11:14 - 2013-11-24 11:15 - 01958396 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2013-11-23 14:50 - 2013-11-23 14:50 - 00006310 _____ C:\Users\Admin\Downloads\Universal Unbanner v1.0_mpgh.net.rar
2013-11-23 14:47 - 2013-11-23 14:47 - 05718872 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_x64.exe
2013-11-23 13:43 - 2013-11-24 10:52 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Windows Net Data
2013-11-23 13:43 - 2013-11-23 13:43 - 00000187 _____ C:\Users\Admin\Desktop\Amazon.de.url
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\Downloads\Fast-IP-Changer
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\ChromeExtensions
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Tempf72101802004da32e7f86b1d7a0eeae3
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Temp8bed7913ae785723085e8a147597e773
2013-11-23 13:42 - 2013-11-23 13:43 - 00669952 _____ C:\Users\Admin\Downloads\Fast-IP-Changer-Setup.exe
2013-11-22 16:25 - 2013-11-22 16:25 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-22 16:24 - 2013-11-22 16:24 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00023287 _____ C:\Windows\system32\nvinfo.pb
2013-11-22 16:20 - 2013-11-22 16:20 - 00002850 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Admin
2013-11-22 16:20 - 2013-11-22 16:20 - 00001141 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2013-11-22 16:19 - 2013-11-24 10:51 - 00000286 _____ C:\Windows\Tasks\Driver Booster Update.job
2013-11-22 16:19 - 2013-11-22 16:20 - 00002133 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2013-11-22 16:19 - 2013-11-22 16:19 - 00003220 _____ C:\Windows\System32\Tasks\Driver Booster Scan
2013-11-22 16:19 - 2013-11-22 16:19 - 00002582 _____ C:\Windows\System32\Tasks\Driver Booster Update
2013-11-22 16:19 - 2013-11-22 16:19 - 00001108 _____ C:\Users\Public\Desktop\Driver Booster.lnk
2013-11-21 20:35 - 2013-11-21 20:35 - 00278869 _____ C:\Users\Admin\Documents\Unbenannt.wma
2013-11-20 18:05 - 2013-11-20 18:05 - 00004644 _____ C:\Users\Admin\Downloads\invite.ics
2013-11-19 16:56 - 2013-11-19 16:56 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2013-11-17 23:49 - 2013-11-17 23:49 - 00000000 ____D C:\Users\Admin\Documents\FIFA 12
2013-11-17 23:43 - 2013-11-17 23:43 - 01699550 _____ C:\Users\Admin\Downloads\fifapadconfig.exe
2013-11-17 21:57 - 2013-11-19 20:29 - 00000000 ____D C:\Users\Admin\Documents\FIFA 13
2013-11-17 21:53 - 2013-11-17 21:53 - 00002324 _____ C:\Users\Admin\Desktop\Play FIFA 13 nosTEAM.lnk
2013-11-17 15:18 - 2013-11-17 21:53 - 00000000 ____D C:\Users\Admin\Downloads\FIFA 13 =FIFA Soccer 13= PC full game ^^nosTEAM^^
2013-11-17 01:12 - 2013-11-17 01:12 - 00000132 _____ C:\Users\Admin\AppData\Roaming\Adobe IllExport-Filter CC - Voreinstellungen
2013-11-15 16:41 - 2013-11-15 16:42 - 58575443 _____ C:\Users\Admin\Downloads\TGN Branding Kit 2.4.zip
2013-11-14 18:51 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 18:51 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 18:51 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-14 18:51 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-14 18:51 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-14 18:51 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-14 18:51 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 18:51 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-14 18:51 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-14 18:51 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-14 18:07 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 18:07 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-14 18:07 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-14 18:06 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 18:06 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 18:06 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 18:06 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-14 18:06 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-14 18:06 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 18:06 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-14 18:06 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 18:06 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 18:06 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 18:06 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 18:06 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 18:06 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 18:06 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 18:06 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 18:06 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-14 18:06 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-14 18:06 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-14 18:06 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-14 18:06 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 18:06 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-12 18:20 - 2013-11-12 18:20 - 00003166 _____ C:\Windows\System32\Tasks\SmartDefrag_Startup
2013-11-12 18:20 - 2013-11-12 18:20 - 00003164 _____ C:\Windows\System32\Tasks\SmartDefragUpdate
2013-11-12 18:20 - 2013-05-22 18:49 - 00032600 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe
2013-11-12 18:16 - 2013-11-12 18:16 - 00883928 _____ (Realtek                                            ) C:\Windows\system32\Drivers\Rt64win7.sys
2013-11-12 18:16 - 2013-11-12 18:16 - 00108760 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2013-11-12 18:16 - 2013-11-12 18:16 - 00074456 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2013-11-12 18:11 - 2013-11-12 18:11 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll
2013-11-12 18:11 - 2013-11-12 18:11 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll
2013-11-12 18:07 - 2013-11-12 18:07 - 00001177 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk
2013-11-12 18:07 - 2013-11-12 18:07 - 00001174 _____ C:\Users\Public\Desktop\Smart Defrag 2.lnk
2013-11-12 18:07 - 2013-05-22 18:49 - 00017720 _____ C:\Windows\system32\Drivers\SmartDefragDriver.sys
2013-11-12 18:00 - 2013-11-22 16:20 - 00001165 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2013-11-12 18:00 - 2013-11-22 16:18 - 00000000 ____D C:\Program Files (x86)\IObit
2013-11-12 18:00 - 2013-11-19 16:57 - 00000000 ____D C:\ProgramData\ProductData
2013-11-12 18:00 - 2013-11-19 16:57 - 00000000 ____D C:\ProgramData\IObit
2013-11-12 18:00 - 2013-11-12 18:07 - 00000000 ____D C:\Users\Admin\AppData\Roaming\IObit
2013-11-12 18:00 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-11-08 22:42 - 2013-11-23 14:43 - 00000000 ____D C:\Users\Admin\Desktop\TGN
2013-11-05 16:37 - 2013-11-05 16:38 - 00000000 ____D C:\Users\Admin\Documents\RZDB
2013-11-05 16:37 - 2013-11-05 16:37 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mursoft
2013-11-04 21:41 - 2013-11-04 21:42 - 00000000 ____D C:\Program Files (x86)\Audio Recorder Pro
2013-11-03 21:52 - 2013-11-03 21:52 - 00000000 ____D C:\Users\Admin\AppData\Local\TeknoGods_TotalKillaz.eu
2013-11-02 12:35 - 2013-11-02 12:47 - 23244493 _____ C:\Users\Admin\Documents\Media_Intro.mp4
2013-11-01 15:46 - 2013-11-01 15:57 - 03249771 _____ C:\Users\Admin\Documents\GAY.mp4
2013-11-01 12:05 - 2013-11-01 12:17 - 23113631 _____ C:\Users\Admin\Documents\Media Sergio Aktuell.mp4
2013-10-28 20:03 - 2013-10-28 20:06 - 00000600 _____ C:\Users\Admin\PUTTY.RND
2013-10-27 21:31 - 2013-10-27 21:31 - 00000000 ____D C:\Program Files (x86)\SimilarSites
2013-10-27 21:30 - 2013-10-27 21:30 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SimilarSites
2013-10-27 16:57 - 2013-11-12 18:00 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Apple Computer
2013-10-27 12:47 - 2013-10-27 12:48 - 00000000 ____D C:\Users\Admin\AppData\Local\Smartbar
2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis
2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\ProgramData\IBUpdaterService
2013-10-27 12:01 - 2013-10-27 12:01 - 00000000 ____D C:\ProgramData\Apple Computer
2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\Users\Admin\AppData\Local\Apple
2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\ProgramData\Apple
2013-10-27 11:43 - 2008-01-30 18:36 - 00090112 _____ (MindVision Software) C:\Windows\unvise32.exe
2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\REVisionEffects
2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Program Files (x86)\REVisionEffects
2013-10-26 13:44 - 2013-10-26 15:03 - 00000000 ____D C:\Users\Admin\AppData\Local\LooksBuilder
2013-10-26 12:28 - 2013-10-26 12:32 - 00000000 ____D C:\ProgramData\RedGiant
2013-10-26 12:28 - 2013-10-26 12:28 - 00003642 _____ C:\Windows\System32\Tasks\Red Giant Link
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\ProgramData\Red Giant
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant Link
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\LooksBuilder
2013-10-26 12:28 - 2013-10-08 14:33 - 04890624 _____ C:\Windows\system32\LS3Renderer_x64.dll

==================== One Month Modified Files and Folders =======

2013-11-24 11:57 - 2013-11-24 11:57 - 00020033 _____ C:\Users\Admin\Downloads\FRST.txt
2013-11-24 11:56 - 2013-11-24 11:56 - 00000000 ____D C:\FRST
2013-11-24 11:53 - 2012-11-24 21:59 - 00000000 ____D C:\Users\Admin\AppData\Roaming\BitTorrent
2013-11-24 11:52 - 2013-09-13 23:51 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype
2013-11-24 11:15 - 2013-11-24 11:14 - 01958396 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2013-11-24 11:01 - 2012-11-03 18:19 - 00000000 ____D C:\Users\Admin\AppData\Local\Adobe
2013-11-24 10:59 - 2013-07-27 17:49 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-24 10:59 - 2009-07-14 05:45 - 00015168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-24 10:59 - 2009-07-14 05:45 - 00015168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-24 10:56 - 2012-09-21 11:52 - 01049363 _____ C:\Windows\WindowsUpdate.log
2013-11-24 10:52 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Windows Net Data
2013-11-24 10:51 - 2013-11-22 16:19 - 00000286 _____ C:\Windows\Tasks\Driver Booster Update.job
2013-11-24 10:51 - 2013-10-18 14:30 - 00010932 _____ C:\autoupdate.log
2013-11-24 10:51 - 2013-07-27 17:49 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-24 10:51 - 2012-10-19 22:41 - 00096332 _____ C:\Windows\PFRO.log
2013-11-24 10:51 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-24 10:51 - 2009-07-14 05:51 - 00093444 _____ C:\Windows\setupact.log
2013-11-23 14:50 - 2013-11-23 14:50 - 00006310 _____ C:\Users\Admin\Downloads\Universal Unbanner v1.0_mpgh.net.rar
2013-11-23 14:47 - 2013-11-23 14:47 - 05718872 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_x64.exe
2013-11-23 14:43 - 2013-11-08 22:42 - 00000000 ____D C:\Users\Admin\Desktop\TGN
2013-11-23 13:43 - 2013-11-23 13:43 - 00000187 _____ C:\Users\Admin\Desktop\Amazon.de.url
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\Downloads\Fast-IP-Changer
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\ChromeExtensions
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Tempf72101802004da32e7f86b1d7a0eeae3
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Temp8bed7913ae785723085e8a147597e773
2013-11-23 13:43 - 2013-11-23 13:42 - 00669952 _____ C:\Users\Admin\Downloads\Fast-IP-Changer-Setup.exe
2013-11-23 13:43 - 2012-09-21 11:56 - 00000000 ___RD C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-23 13:43 - 2012-09-21 11:56 - 00000000 ____D C:\Users\Admin
2013-11-22 16:30 - 2013-07-08 10:23 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-22 16:25 - 2013-11-22 16:25 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-22 16:25 - 2009-07-13 22:59 - 18286416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-22 16:24 - 2013-11-22 16:24 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00023287 _____ C:\Windows\system32\nvinfo.pb
2013-11-22 16:24 - 2013-07-08 10:22 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-11-22 16:24 - 2013-07-08 10:22 - 02695200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-11-22 16:24 - 2009-06-10 21:37 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-11-22 16:20 - 2013-11-22 16:20 - 00002850 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Admin
2013-11-22 16:20 - 2013-11-22 16:20 - 00001141 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2013-11-22 16:20 - 2013-11-22 16:19 - 00002133 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2013-11-22 16:20 - 2013-11-12 18:00 - 00001165 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2013-11-22 16:19 - 2013-11-22 16:19 - 00003220 _____ C:\Windows\System32\Tasks\Driver Booster Scan
2013-11-22 16:19 - 2013-11-22 16:19 - 00002582 _____ C:\Windows\System32\Tasks\Driver Booster Update
2013-11-22 16:19 - 2013-11-22 16:19 - 00001108 _____ C:\Users\Public\Desktop\Driver Booster.lnk
2013-11-22 16:18 - 2013-11-12 18:00 - 00000000 ____D C:\Program Files (x86)\IObit
2013-11-21 20:35 - 2013-11-21 20:35 - 00278869 _____ C:\Users\Admin\Documents\Unbenannt.wma
2013-11-21 20:34 - 2012-09-21 11:56 - 00000000 ____D C:\Users\Admin\AppData\Local\VirtualStore
2013-11-20 22:08 - 2013-09-15 19:07 - 00000000 ____D C:\Users\Admin\AppData\Local\Windows Live
2013-11-20 18:29 - 2013-09-21 22:27 - 00000000 ____D C:\Users\Admin\AppData\Roaming\TS3Client
2013-11-20 18:05 - 2013-11-20 18:05 - 00004644 _____ C:\Users\Admin\Downloads\invite.ics
2013-11-19 20:52 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-19 20:29 - 2013-11-17 21:57 - 00000000 ____D C:\Users\Admin\Documents\FIFA 13
2013-11-19 16:59 - 2013-10-22 15:26 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-11-19 16:58 - 2012-10-19 20:17 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Adobe
2013-11-19 16:57 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\ProductData
2013-11-19 16:57 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\IObit
2013-11-19 16:56 - 2013-11-19 16:56 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2013-11-17 23:49 - 2013-11-17 23:49 - 00000000 ____D C:\Users\Admin\Documents\FIFA 12
2013-11-17 23:43 - 2013-11-17 23:43 - 01699550 _____ C:\Users\Admin\Downloads\fifapadconfig.exe
2013-11-17 21:53 - 2013-11-17 21:53 - 00002324 _____ C:\Users\Admin\Desktop\Play FIFA 13 nosTEAM.lnk
2013-11-17 21:53 - 2013-11-17 15:18 - 00000000 ____D C:\Users\Admin\Downloads\FIFA 13 =FIFA Soccer 13= PC full game ^^nosTEAM^^
2013-11-17 20:07 - 2013-09-03 22:23 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-17 13:33 - 2009-07-14 18:58 - 00696620 _____ C:\Windows\system32\perfh007.dat
2013-11-17 13:33 - 2009-07-14 18:58 - 00147916 _____ C:\Windows\system32\perfc007.dat
2013-11-17 13:33 - 2009-07-14 06:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-17 02:00 - 2013-10-22 17:40 - 00000132 _____ C:\Users\Admin\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen
2013-11-17 01:12 - 2013-11-17 01:12 - 00000132 _____ C:\Users\Admin\AppData\Roaming\Adobe IllExport-Filter CC - Voreinstellungen
2013-11-15 16:42 - 2013-11-15 16:41 - 58575443 _____ C:\Users\Admin\Downloads\TGN Branding Kit 2.4.zip
2013-11-15 16:40 - 2013-10-21 15:41 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 18:51 - 2012-12-20 23:52 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-14 18:48 - 2013-10-21 15:41 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-12 18:20 - 2013-11-12 18:20 - 00003166 _____ C:\Windows\System32\Tasks\SmartDefrag_Startup
2013-11-12 18:20 - 2013-11-12 18:20 - 00003164 _____ C:\Windows\System32\Tasks\SmartDefragUpdate
2013-11-12 18:16 - 2013-11-12 18:16 - 00883928 _____ (Realtek                                            ) C:\Windows\system32\Drivers\Rt64win7.sys
2013-11-12 18:16 - 2013-11-12 18:16 - 00108760 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2013-11-12 18:16 - 2013-11-12 18:16 - 00074456 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2013-11-12 18:13 - 2012-12-06 20:48 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-11-12 18:11 - 2013-11-12 18:11 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll
2013-11-12 18:11 - 2013-11-12 18:11 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll
2013-11-12 18:07 - 2013-11-12 18:07 - 00001177 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk
2013-11-12 18:07 - 2013-11-12 18:07 - 00001174 _____ C:\Users\Public\Desktop\Smart Defrag 2.lnk
2013-11-12 18:07 - 2013-11-12 18:00 - 00000000 ____D C:\Users\Admin\AppData\Roaming\IObit
2013-11-12 18:00 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-11-12 18:00 - 2013-10-27 16:57 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Apple Computer
2013-11-11 05:50 - 2012-10-19 20:14 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-06 22:11 - 2013-03-10 11:57 - 00000000 ____D C:\Users\Admin\Downloads\cod mw3
2013-11-05 21:00 - 2013-10-06 18:47 - 00000000 ____D C:\Users\Admin\Documents\Bandicam
2013-11-05 16:38 - 2013-11-05 16:37 - 00000000 ____D C:\Users\Admin\Documents\RZDB
2013-11-05 16:37 - 2013-11-05 16:37 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mursoft
2013-11-05 16:07 - 2013-09-13 23:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-11-05 16:07 - 2013-09-13 23:51 - 00000000 ____D C:\ProgramData\Skype
2013-11-04 21:42 - 2013-11-04 21:41 - 00000000 ____D C:\Program Files (x86)\Audio Recorder Pro
2013-11-04 00:33 - 2013-09-27 19:08 - 00000000 ____D C:\Users\Admin\AppData\Local\fabi.me
2013-11-03 21:52 - 2013-11-03 21:52 - 00000000 ____D C:\Users\Admin\AppData\Local\TeknoGods_TotalKillaz.eu
2013-11-02 12:47 - 2013-11-02 12:35 - 23244493 _____ C:\Users\Admin\Documents\Media_Intro.mp4
2013-11-01 15:57 - 2013-11-01 15:46 - 03249771 _____ C:\Users\Admin\Documents\GAY.mp4
2013-11-01 12:17 - 2013-11-01 12:05 - 23113631 _____ C:\Users\Admin\Documents\Media Sergio Aktuell.mp4
2013-10-28 20:06 - 2013-10-28 20:03 - 00000600 _____ C:\Users\Admin\PUTTY.RND
2013-10-28 16:15 - 2013-10-17 19:18 - 00000000 ____D C:\Program Files (x86)\Secure Speed Dial
2013-10-27 21:31 - 2013-10-27 21:31 - 00000000 ____D C:\Program Files (x86)\SimilarSites
2013-10-27 21:30 - 2013-10-27 21:30 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SimilarSites
2013-10-27 12:48 - 2013-10-27 12:47 - 00000000 ____D C:\Users\Admin\AppData\Local\Smartbar
2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis
2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\ProgramData\IBUpdaterService
2013-10-27 12:45 - 2013-10-22 17:20 - 00000000 ____D C:\Users\Admin\AppData\Roaming\OpenCandy
2013-10-27 12:45 - 2013-10-22 17:20 - 00000000 ____D C:\Users\Admin\AppData\Roaming\DVDVideoSoft
2013-10-27 12:01 - 2013-10-27 12:01 - 00000000 ____D C:\ProgramData\Apple Computer
2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\Users\Admin\AppData\Local\Apple
2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\ProgramData\Apple
2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\REVisionEffects
2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Program Files (x86)\REVisionEffects
2013-10-26 15:03 - 2013-10-26 13:44 - 00000000 ____D C:\Users\Admin\AppData\Local\LooksBuilder
2013-10-26 12:32 - 2013-10-26 12:28 - 00000000 ____D C:\ProgramData\RedGiant
2013-10-26 12:32 - 2012-11-17 19:11 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-26 12:30 - 2013-02-03 10:27 - 00000000 ____D C:\Users\Admin\AppData\Local\Downloaded Installations
2013-10-26 12:28 - 2013-10-26 12:28 - 00003642 _____ C:\Windows\System32\Tasks\Red Giant Link
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\ProgramData\Red Giant
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant Link
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\LooksBuilder

Files to move or delete:
====================
C:\Users\Admin\jagex_cl_loginapplet_LIVE.dat
C:\Users\Admin\jagex_cl_oldschool_LIVE.dat
C:\Users\Admin\jagex_cl_runescape_LIVE.dat
C:\Users\Admin\jagex_cl_runescape_LIVE1.dat
C:\Users\Admin\jagex_cl_runescape_LIVE2.dat
C:\Users\Admin\jagex_cl_runescape_LIVE3.dat
C:\Users\Admin\random.dat


Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\2qywsnv1.dll
C:\Users\Admin\AppData\Local\Temp\amazonicon_v3.exe
C:\Users\Admin\AppData\Local\Temp\amazoninstallernircmdc.exe
C:\Users\Admin\AppData\Local\Temp\bdfilters.dll
C:\Users\Admin\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\Admin\AppData\Local\Temp\install_helper.exe
C:\Users\Admin\AppData\Local\Temp\jna1421531977279418979.dll
C:\Users\Admin\AppData\Local\Temp\jna2667399310951771970.dll
C:\Users\Admin\AppData\Local\Temp\jna51258232191993720.dll
C:\Users\Admin\AppData\Local\Temp\NGMDll.dll
C:\Users\Admin\AppData\Local\Temp\NGMResource.dll
C:\Users\Admin\AppData\Local\Temp\NGMSetup.exe
C:\Users\Admin\AppData\Local\Temp\ose00000.exe
C:\Users\Admin\AppData\Local\Temp\Quarantine.exe
C:\Users\Admin\AppData\Local\Temp\S63GJTpcBQ.exe
C:\Users\Admin\AppData\Local\Temp\sdanircmdc.exe
C:\Users\Admin\AppData\Local\Temp\sdapskill.exe
C:\Users\Admin\AppData\Local\Temp\setup_fsu_cid.exe
C:\Users\Admin\AppData\Local\Temp\SimilarBundleGenericDl.exe
C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Admin\AppData\Local\Temp\SmartbarExeInstaller.exe
C:\Users\Admin\AppData\Local\Temp\SpeedTestSetup.exe
C:\Users\Admin\AppData\Local\Temp\unicows.dll
C:\Users\Admin\AppData\Local\Temp\uninst1.exe
C:\Users\Admin\AppData\Local\Temp\Uninstaller-3788.exe
C:\Users\Admin\AppData\Local\Temp\w0chwtqt.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-21 07:19

==================== End Of Log ============================
         

Und Addition.txt:

Code:
ATTFilter
Ran by Admin at 2013-11-24 12:12:12
Running from C:\Users\Admin\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}

==================== Installed Programs ======================

AccelerateTab (x32 Version: 1.4)
Adobe Creative Cloud (x32 Version: 2.1.2.232)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Photoshop CC (x32 Version: 14.0)
Adobe Premiere Pro CC (x32 Version: 7.0.0)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05)
Adobe Shockwave Player 12.0 (x32 Version: 12.0.3.133)
Advanced SystemCare 7 (x32 Version: 7.0.6)
Akamai NetSession Interface (HKCU)
Apple Application Support (x32 Version: 2.1.5)
Apple Software Update (x32 Version: 2.1.3.127)
Audio Recorder Pro 3.70 (x32)
AutoCAD 2013 - Deutsch (German) (Version: 19.0.55.0)
AutoCAD 2013 Language Pack - Deutsch (German) (Version: 19.0.55.0)
Autodesk Content Service (x32 Version: 3.0.84.0)
Autodesk Content Service Language Pack (x32 Version: 3.0.84.0)
Autodesk Material Library 2013 (x32 Version: 3.0.13)
Autodesk Material Library Base Resolution Image Library 2013 (x32 Version: 3.0.13)
Autodesk Sync (Version: 3.5.24.0)
Bandicam (x32)
Bandisoft MPEG-1 Decoder (x32)
BitTorrent (x32 Version: 7.7.2.28499)
Color Suite v11.0.1 (x32 Version: 11.0.1)
D3DX10 (x32 Version: 15.4.2368.0902)
DAEMON Tools Lite (x32 Version: 4.46.1.0327)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
Driver Booster (x32 Version: 1.0)
Effects Suite 64-bit (Version: 11.1.0)
Effects Suite 64-bit (x32 Version: 11.1.0)
FARO LS 1.1.406.58 (x32 Version: 4.6.58.2)
Fotogalerie (x32 Version: 16.4.3508.0205)
Free YouTube Download version 3.2.14.1022 (x32 Version: 3.2.14.1022)
Free YouTube to MP3 Converter version 3.12.13.925 (x32 Version: 3.12.13.925)
Google Chrome (x32 Version: 31.0.1650.57)
Google Earth Plug-in (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (Version: 25.0.571.0)
HP Deskjet 3050A J611 series Hilfe (x32 Version: 140.0.2.2)
HP Update (x32 Version: 5.003.000.004)
IObit Malware Fighter (x32 Version: 2.1)
IObit Uninstaller (x32 Version: 3.0.4.1082)
Java 7 Update 9 (x32 Version: 7.0.90)
Java Auto Updater (x32 Version: 2.1.9.0)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Excel 2010 (Version: 14.0.6029.1000)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Excel 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 32-bit MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft PowerPoint 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Word 2010 (Version: 14.0.6029.1000)
Movie Maker (x32 Version: 16.4.3508.0205)
Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1)
Mozilla Maintenance Service (x32 Version: 23.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT Redists (Version: 1.0)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MyFreeCodec (HKCU)
Nexon Game Manager (x32)
NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49)
NVIDIA GeForce Experience 1.5.1 (Version: 1.5.1)
NVIDIA Install Application (Version: 2.1002.133.889)
NVIDIA PhysX (x32 Version: 9.13.0604)
NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604)
NVIDIA Systemsteuerung 331.65 (Version: 331.65)
NVIDIA Update 6.4.23 (Version: 6.4.23)
NVIDIA Update Components (Version: 6.4.23)
PDF Settings CC (x32 Version: 12.0)
Photo Common (x32 Version: 16.4.3508.0205)
Photo Gallery (x32 Version: 16.4.3508.0205)
PunkBuster Services (x32 Version: 0.993)
QuickTime (x32 Version: 7.71.80.42)
Razer Game Booster (x32 Version: 3.7)
Red Giant Link (x32 Version: 1.7.19.0)
ReelSmart Motion Blur 4, After Effects-compatible plugin set (x32)
RuckZuck (x32 Version: 6.0.10)
Samsung Kies (x32 Version: 2.6.0.13091_9)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0)
Skype™ 6.10 (x32 Version: 6.10.104)
Smart Defrag 2 (x32 Version: 2.9)
Snap.Do (x32 Version: 1.102.1.11691)
Speed Test Analysis (x32 Version: 1.0.0.5)
Surfing Protection (x32 Version: 1.0)
Sweet Home 3D version 3.7 (x32)
swMSM (x32 Version: 12.0.0.1)
System Requirements Lab CYRI (x32 Version: 5.0.6.0)
TeamSpeak 3 Client (Version: 3.0.12)
Twixtor 5, After Effects-compatible plugin set (x32)
Twixtor 6, After Effects-compatible plugin set (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition
Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition
Update for Microsoft Word 2010 (KB2827323) 64-Bit Edition
Utility Chest Internet Explorer Toolbar (x32)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205)
Windows Live Essentials (x32 Version: 16.4.3508.0205)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (x32 Version: 16.4.3508.0205)
Windows Live Photo Common (x32 Version: 16.4.3508.0205)
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205)
Windows Live SOXE (x32 Version: 16.4.3508.0205)
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205)
Windows Live UX Platform (x32 Version: 16.4.3508.0205)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205)
Windows Utils (x32)
WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0)
WinZipper (x32 Version: 1.4.8)

==================== Restore Points  =========================

14-11-2013 17:47:26 Windows Update
19-11-2013 15:52:51 Windows Update
22-11-2013 15:23:43 Driver Booster : NVIDIA GeForce 8800 GTS

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {135AE771-2D3B-462E-8F30-CE5D99E1CCC4} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {1ECDF9E5-1736-47FA-9F68-D17777C66F26} - System32\Tasks\Red Giant Link => C:\Program Files (x86)\Red Giant Link\Red Giant Link.exe [2013-10-10] ()
Task: {32E25F8E-1749-45A9-9721-9794EB156E14} - System32\Tasks\SmartDefragUpdate => C:\Program Files (x86)\IObit\Smart Defrag 2\AutoUpdate.exe [2013-05-22] (IObit)
Task: {4AA883C5-A4D9-4094-937C-E3D07281461C} - System32\Tasks\ASC7_SkipUac_Admin => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe [2013-11-14] (IObit)
Task: {5C452C96-E65D-4030-B3C1-A20719FA7A7D} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2013-09-08] (IObit)
Task: {6D939925-0559-4FFF-983F-100C4B9510E2} - System32\Tasks\Razer_Game_Booster_AutoUpdate => C:\Program Files (x86)\Razer\Razer Game Booster\AutoUpdate.exe [2013-06-05] ()
Task: {71D4CCA7-7AE8-4EAB-B078-AC718607E749} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03] (Sun Microsystems, Inc.)
Task: {89659F6B-903E-4AE9-8638-3F6299D0CCB4} - \CPU Grid Computing No Task File
Task: {8D5768D7-0BF7-4B7E-B4EF-2B533AF729A3} - System32\Tasks\SmartDefrag_Startup => C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe [2013-09-13] (IObit)
Task: {8DE526A6-E0DE-4613-B213-435FFB35B8F7} - \The Bluetooth service discovery No Task File
Task: {A327627E-50BC-4181-AFB4-661E3EB00912} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [2011-03-24] (Hewlett-Packard)
Task: {A72FE025-AA38-40EE-BCF7-ABC9A84C4852} - \AdobeFlashPlayerUpdate 2 No Task File
Task: {A7B37A96-087C-4BC9-BCE0-469A9FAABD66} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2013-09-08] (IObit)
Task: {AC6C9BFE-6D97-4EC4-8BCA-482E1FF41A1C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-27] (Google Inc.)
Task: {AE193498-0C1E-4429-9017-6CC81CA63ACA} - System32\Tasks\AdobeAAMUpdater-1.0-PC-Admin => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2013-06-13] (Adobe Systems Incorporated)
Task: {C37565D0-014E-47D4-83EA-4411ED708EF9} - System32\Tasks\hpUrlLauncher.exe_{F897C458-ADC9-403E-BBD9-FF9E01A0A29F} => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\utils\hpUrlLauncher.exe [2011-06-08] (Hewlett-Packard Co.)
Task: {DB0FF65C-8F09-4C52-BAEC-0FAD6A5A706C} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe
Task: {E35029B4-73DE-4341-8C43-FFAADAF0D4FB} - \AdobeFlashPlayerUpdate No Task File
Task: {E389FFAE-9FD5-4610-BB82-17FA20CF858E} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {E4D749A2-89E1-4257-81F6-3F4FBE02D0D5} - System32\Tasks\{901D29C3-49F3-49F5-9378-C1DCB736EDE9} => C:\Users\Admin\Downloads\Xpadder.exe
Task: {F1E0DC7B-D17A-4019-B6D8-0AB183F8E8E0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-27] (Google Inc.)
Task: C:\Windows\Tasks\Driver Booster Update.job => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-08-30 09:01 - 2013-08-30 09:01 - 03358064 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
2013-11-22 16:19 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\sqlite3.dll
2013-11-12 18:07 - 2013-09-11 19:06 - 00048960 _____ () C:\Program Files (x86)\IObit\Smart Defrag 2\NtfsData.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00032800 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00056352 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00150560 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00112672 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 01767456 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00078880 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00013344 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00726048 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00081952 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00014368 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00016928 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll
2013-08-04 19:51 - 2013-08-04 19:51 - 00020512 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll
2013-08-04 19:51 - 2013-08-04 19:51 - 00026144 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00057888 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00014368 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll
2013-07-16 13:20 - 2013-07-16 13:20 - 00911128 _____ () C:\Windows\assembly\GAC_32\System.Data.SQLite\1.0.66.0__db937bc2d44ff139\System.Data.SQLite.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00014880 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00052256 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00048160 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\MACTrackBarLib.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00026144 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll
2013-08-04 19:51 - 2013-08-04 19:51 - 00026144 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll
2013-08-04 19:41 - 2013-08-04 19:41 - 00194080 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.dll
2013-08-04 19:40 - 2013-08-04 19:40 - 00068640 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00246304 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.NetSeer.dll
2013-09-03 14:25 - 2013-09-03 14:25 - 32726528 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll
2013-03-13 12:42 - 2013-06-05 13:21 - 00071560 _____ () C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\zlib1.dll
2013-08-30 09:00 - 2013-08-30 09:00 - 00381808 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CCInvokeAAM.dll
2013-11-17 20:07 - 2013-11-14 12:28 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libglesv2.dll
2013-11-17 20:07 - 2013-11-14 12:28 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libegl.dll
2013-11-17 20:07 - 2013-11-14 12:29 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll
2013-11-17 20:07 - 2013-11-14 12:29 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll
2013-11-17 20:07 - 2013-11-14 12:28 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
2013-11-17 20:07 - 2013-11-14 12:29 - 13582800 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:373E1720

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/18/2013 01:10:17 AM) (Source: IMFservice) (User: )
Description: Das Handle ist ungültig

Error: (11/18/2013 01:10:17 AM) (Source: IMFservice) (User: )
Description: Das Handle ist ungültig

Error: (11/10/2013 11:52:02 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel: 0x4f186c8f
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0xffff3fa4
ID des fehlerhaften Prozesses: 0x330
Startzeit der fehlerhaften Anwendung: 0xiw5mp.exe0
Pfad der fehlerhaften Anwendung: iw5mp.exe1
Pfad des fehlerhaften Moduls: iw5mp.exe2
Berichtskennung: iw5mp.exe3

Error: (11/10/2013 11:47:10 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel: 0x4f186c8f
Name des fehlerhaften Moduls: nvd3dum.dll, Version: 9.18.13.2049, Zeitstempel: 0x51c40fa2
Ausnahmecode: 0xc0000005
Fehleroffset: 0x004af57a
ID des fehlerhaften Prozesses: 0x10c0
Startzeit der fehlerhaften Anwendung: 0xiw5mp.exe0
Pfad der fehlerhaften Anwendung: iw5mp.exe1
Pfad des fehlerhaften Moduls: iw5mp.exe2
Berichtskennung: iw5mp.exe3

Error: (11/10/2013 07:02:25 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel: 0x4f186c8f
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0xffff3f80
ID des fehlerhaften Prozesses: 0x880
Startzeit der fehlerhaften Anwendung: 0xiw5mp.exe0
Pfad der fehlerhaften Anwendung: iw5mp.exe1
Pfad des fehlerhaften Moduls: iw5mp.exe2
Berichtskennung: iw5mp.exe3

Error: (11/10/2013 00:58:58 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: WoulClass.vshost.exe, Version: 11.0.50727.1, Zeitstempel: 0x5011d446
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677
Ausnahmecode: 0xe0434f4d
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xWoulClass.vshost.exe0
Pfad der fehlerhaften Anwendung: WoulClass.vshost.exe1
Pfad des fehlerhaften Moduls: WoulClass.vshost.exe2
Berichtskennung: WoulClass.vshost.exe3

Error: (11/10/2013 00:58:47 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: WoulClass.vshost.exe, Version: 11.0.50727.1, Zeitstempel: 0x5011d446
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677
Ausnahmecode: 0xe0434f4d
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xWoulClass.vshost.exe0
Pfad der fehlerhaften Anwendung: WoulClass.vshost.exe1
Pfad des fehlerhaften Moduls: WoulClass.vshost.exe2
Berichtskennung: WoulClass.vshost.exe3

Error: (11/03/2013 09:52:42 PM) (Source: Application Hang) (User: )
Description: Programm iw5mp.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 560

Startzeit: 01ced8d68fca516b

Endzeit: 38

Anwendungspfad: C:\Users\Admin\Downloads\Teknogods 2.7.1.2\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exe

Berichts-ID: df0dbe24-44c9-11e3-95d6-001bfcfb8327

Error: (10/28/2013 11:52:29 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (10/28/2013 11:52:29 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.


System errors:
=============
Error: (11/24/2013 10:53:42 AM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005

Error: (11/24/2013 10:52:26 AM) (Source: Service Control Manager) (User: )
Description: Dienst "SecureUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/24/2013 10:51:26 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Utility ChestService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/24/2013 10:51:26 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Update WebConnect" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/24/2013 10:51:17 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Wsys Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/24/2013 10:51:17 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WinZiper service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/23/2013 10:27:08 AM) (Source: Service Control Manager) (User: )
Description: Dienst "SecureUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/23/2013 10:26:08 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Utility ChestService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/23/2013 10:26:08 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Update WebConnect" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/23/2013 10:25:59 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Wsys Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2


Microsoft Office Sessions:
=========================
Error: (11/18/2013 01:10:17 AM) (Source: IMFservice)(User: )
Description: Das Handle ist ungültig

Error: (11/18/2013 01:10:17 AM) (Source: IMFservice)(User: )
Description: Das Handle ist ungültig

Error: (11/10/2013 11:52:02 PM) (Source: Application Error)(User: )
Description: iw5mp.exe0.0.0.04f186c8funknown0.0.0.000000000c0000005ffff3fa433001cede66d2662730C:\Users\Admin\Downloads\cod mw3\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exeunknownb6270760-4a5a-11e3-9172-001bfcfb8327

Error: (11/10/2013 11:47:10 PM) (Source: Application Error)(User: )
Description: iw5mp.exe0.0.0.04f186c8fnvd3dum.dll9.18.13.204951c40fa2c0000005004af57a10c001cede6570685656C:\Users\Admin\Downloads\cod mw3\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exeC:\Windows\system32\nvd3dum.dll081bb54f-4a5a-11e3-9172-001bfcfb8327

Error: (11/10/2013 07:02:25 PM) (Source: Application Error)(User: )
Description: iw5mp.exe0.0.0.04f186c8funknown0.0.0.000000000c0000005ffff3f8088001cede3ef2a128a2C:\Users\Admin\Downloads\cod mw3\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exeunknown40a9e580-4a32-11e3-9172-001bfcfb8327

Error: (11/10/2013 00:58:58 AM) (Source: Application Error)(User: )
Description: WoulClass.vshost.exe11.0.50727.15011d446KERNELBASE.dll6.1.7601.1822951fb1677e0434f4d000000000000940d

Error: (11/10/2013 00:58:47 AM) (Source: Application Error)(User: )
Description: WoulClass.vshost.exe11.0.50727.15011d446KERNELBASE.dll6.1.7601.1822951fb1677e0434f4d000000000000940d

Error: (11/03/2013 09:52:42 PM) (Source: Application Hang)(User: )
Description: iw5mp.exe0.0.0.056001ced8d68fca516b38C:\Users\Admin\Downloads\Teknogods 2.7.1.2\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exedf0dbe24-44c9-11e3-95d6-001bfcfb8327

Error: (10/28/2013 11:52:29 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Admin\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe

Error: (10/28/2013 11:52:29 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Users\Admin\Downloads\SoftonicDownloader_fuer_winrar.exe


==================== Memory info =========================== 

Percentage of memory in use: 56%
Total physical RAM: 4095.18 MB
Available physical RAM: 1770.45 MB
Total Pagefile: 8188.54 MB
Available Pagefile: 5518.29 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:297.99 GB) (Free:153.12 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D13C098D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         

Alt 24.11.2013, 12:53   #2
M-K-D-B
/// TB-Ausbilder
 
_GETWINDOWINFO-Trojaner - Standard

_GETWINDOWINFO-Trojaner






Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen.


Bitte beachte folgende Hinweise:
  • Falls wir Hinweise auf illegal erworbene Software finden, werden wir den Support unterbrechen bis jegliche Art von illegaler Software vom Rechner entfernt wurde.
  • Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags.
  • Lies dir die Anleitungen sorgfältig durch. Solltest du Probleme haben, stoppe mit deiner Bearbeitung und beschreibe mir dein Problem so gut es geht.
  • Solltest du mir nicht innerhalb von 4 Tagen antworten, gehe ich davon aus, dass du keine Hilfe mehr benötigst. Dann lösche ich dein Thema aus meinem Abo.
    Solltest du einmal länger abwesend sein, so gib mir bitte Bescheid!
  • Während der Bereinigung bitte nichts installieren oder deinstallieren, außer ich bitte dich darum!
  • Alle zu verwendenen Programme sind auf dem Desktop abzuspeichern und von dort zu starten!
    Ich kann Dir niemals eine Garantie geben, dass auch ich alles finde. Eine Formatierung ist meist der schnellere und immer der sicherste Weg.
    Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis dir jemand vom Team sagt, dass Du clean bist.




Zitat:
Running from C:\Users\Admin\Downloads
Alle Tools auf dem Desktop speichern und von dort starten. FRST vom Ordner Downloads in auf den Desktop verschieben!






Schritt 1
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.






Schritt 2
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).





Schritt 3

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei von ComboFix,
  • die Logdatei von AdwCleaner,
  • die Logdatei von JRT.
__________________


Alt 24.11.2013, 13:17   #3
LikeASiR
 
_GETWINDOWINFO-Trojaner - Standard

_GETWINDOWINFO-Trojaner



Danke für die schnelle Antwort.
Eine Frage bleibt noch offen: Reicht es eine Verknüpfung der Programme auf dem Desktop zu erstellen, oder muss das ganze Programm am Desktop sein?
__________________

Alt 24.11.2013, 13:28   #4
M-K-D-B
/// TB-Ausbilder
 
_GETWINDOWINFO-Trojaner - Standard

_GETWINDOWINFO-Trojaner



Zitat:
Zitat von LikeASiR Beitrag anzeigen
Eine Frage bleibt noch offen: Reicht es eine Verknüpfung der Programme auf dem Desktop zu erstellen, oder muss das ganze Programm am Desktop sein?
Diese Frage bleibt nicht offen, da ich nichts von einer Verknüpfung geschrieben habe.
Programme direkt auf dem Desktop speichern!

Ich verstehe nicht, warum Leute immer ein Problem damit haben, die Programme auf dem Desktop zu speichern, ist doch das Einfachste der Welt...
Zudem entfernen wir am Ende der Bereinigung alle Tools mit einem Schlag, aber das klappt halt nur, wenn sich die Tools auf dem Desktop befinden.

Alt 24.11.2013, 14:33   #5
LikeASiR
 
_GETWINDOWINFO-Trojaner - Ausrufezeichen

_GETWINDOWINFO-Trojaner



Danke für die ersten Infos Matthias.

Hier kommen alle von dir angeforderten .txt Dateien.

Combifix.txt
Code:
ATTFilter
ComboFix 13-11-23.02 - Admin 24.11.2013  13:25:32.1.4 - x64
Microsoft Windows 7 Professional   6.1.7601.1.1252.43.1031.18.4095.2125 [GMT 1:00]
ausgeführt von:: c:\users\Admin\Desktop\ComboFix.exe
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\protected
c:\users\Admin\AppData\Roaming\dclogs
c:\users\Admin\AppData\Roaming\dclogs\2013-11-10-1.dc
c:\windows\SysWow64\frapsvid.dll
.
.
(((((((((((((((((((((((((((((((((((((((   Treiber/Dienste   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_WsysSvc
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-10-24 bis 2013-11-24  ))))))))))))))))))))))))))))))
.
.
2013-11-24 12:32 . 2013-11-24 12:32	--------	d-----w-	c:\users\UpdatusUser\AppData\Local\temp
2013-11-24 10:56 . 2013-11-24 10:56	--------	d-----w-	C:\FRST
2013-11-23 12:43 . 2013-11-24 09:52	--------	d-----w-	c:\users\Admin\AppData\Roaming\Windows Net Data
2013-11-23 12:43 . 2013-11-23 12:43	--------	d-----w-	c:\users\Admin\AppData\Local\Tempf72101802004da32e7f86b1d7a0eeae3
2013-11-23 12:43 . 2013-11-23 12:43	--------	d-----w-	c:\users\Admin\ChromeExtensions
2013-11-23 12:43 . 2013-11-23 12:43	--------	d-----w-	c:\users\Admin\AppData\Local\Temp8bed7913ae785723085e8a147597e773
2013-11-22 15:25 . 2013-11-22 15:25	15855568	----a-w-	c:\windows\SysWow64\nvwgf2um.dll
2013-11-22 15:25 . 2013-11-22 15:25	9480328	----a-w-	c:\windows\SysWow64\nvopencl.dll
2013-11-22 15:25 . 2013-11-22 15:25	11374520	----a-w-	c:\windows\system32\nvopencl.dll
2013-11-22 15:25 . 2013-11-22 15:25	30344480	----a-w-	c:\windows\system32\nvoglv64.dll
2013-11-22 15:25 . 2013-11-22 15:25	22933792	----a-w-	c:\windows\SysWow64\nvoglv32.dll
2013-11-22 15:25 . 2013-11-08 03:12	10285968	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{492276FF-1DAE-4362-9D2D-D00A517BFA72}\mpengine.dll
2013-11-14 17:51 . 2013-10-12 06:35	2706432	----a-w-	c:\windows\system32\mshtml.tlb
2013-11-14 17:07 . 2013-10-05 20:25	1474048	----a-w-	c:\windows\system32\crypt32.dll
2013-11-14 17:07 . 2013-10-05 19:57	1168384	----a-w-	c:\windows\SysWow64\crypt32.dll
2013-11-14 17:07 . 2013-09-28 01:09	497152	----a-w-	c:\windows\system32\drivers\afd.sys
2013-11-12 17:20 . 2013-05-22 17:49	32600	----a-w-	c:\windows\system32\SmartDefragBootTime.exe
2013-11-12 17:16 . 2013-11-12 17:16	883928	----a-w-	c:\windows\system32\drivers\Rt64win7.sys
2013-11-12 17:16 . 2013-11-12 17:16	74456	----a-w-	c:\windows\system32\RtNicProp64.dll
2013-11-12 17:16 . 2013-11-12 17:16	108760	----a-w-	c:\windows\system32\RTNUninst64.dll
2013-11-12 17:11 . 2013-11-12 17:11	1884448	----a-w-	c:\windows\system32\nvdispco6433158.dll
2013-11-12 17:11 . 2013-11-12 17:11	1511712	----a-w-	c:\windows\system32\nvdispgenco6433158.dll
2013-11-12 17:07 . 2013-05-22 17:49	17720	----a-w-	c:\windows\system32\drivers\SmartDefragDriver.sys
2013-11-12 17:00 . 2013-11-19 15:57	--------	d-----w-	c:\programdata\ProductData
2013-11-12 17:00 . 2013-11-12 17:00	--------	d-----w-	c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-11-12 17:00 . 2013-11-19 15:57	--------	d-----w-	c:\programdata\IObit
2013-11-12 17:00 . 2013-11-12 17:07	--------	d-----w-	c:\users\Admin\AppData\Roaming\IObit
2013-11-12 17:00 . 2013-11-22 15:18	--------	d-----w-	c:\program files (x86)\IObit
2013-11-04 20:41 . 2013-11-04 20:42	--------	d-----w-	c:\program files (x86)\Audio Recorder Pro
2013-11-03 20:52 . 2013-11-03 20:52	--------	d-----w-	c:\users\Admin\AppData\Local\TeknoGods_TotalKillaz.eu
2013-10-27 20:31 . 2013-10-27 20:31	--------	d-----w-	c:\program files (x86)\SimilarSites
2013-10-27 20:30 . 2013-10-27 20:30	--------	d-----w-	c:\users\Admin\AppData\Roaming\SimilarSites
2013-10-27 15:57 . 2013-11-12 17:00	--------	d-----w-	c:\users\Admin\AppData\Roaming\Apple Computer
2013-10-27 11:47 . 2013-10-27 11:47	--------	d-----w-	c:\programdata\IBUpdaterService
2013-10-27 11:47 . 2013-10-27 11:47	--------	d-----w-	c:\users\Admin\AppData\Roaming\SpeedTestAnalysis
2013-10-27 11:47 . 2013-10-27 11:48	--------	d-----w-	c:\users\Admin\AppData\Local\Smartbar
2013-10-27 11:01 . 2013-10-27 11:01	159744	----a-w-	c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2013-10-27 11:01 . 2013-10-27 11:01	159744	----a-w-	c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2013-10-27 11:01 . 2013-10-27 11:01	159744	----a-w-	c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-10-27 11:01 . 2013-10-27 11:01	159744	----a-w-	c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-10-27 11:01 . 2013-10-27 11:01	159744	----a-w-	c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-10-27 11:01 . 2013-10-27 11:01	159744	----a-w-	c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-10-27 11:01 . 2013-10-27 11:01	159744	----a-w-	c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-10-27 11:01 . 2013-10-27 11:01	--------	d-----w-	c:\programdata\Apple Computer
2013-10-27 10:59 . 2013-10-27 10:59	--------	d-----w-	c:\program files (x86)\Common Files\Apple
2013-10-27 10:59 . 2013-10-27 10:59	--------	d-----w-	c:\users\Admin\AppData\Local\Apple
2013-10-27 10:59 . 2013-10-27 10:59	--------	d-----w-	c:\programdata\Apple
2013-10-27 10:43 . 2008-01-30 17:36	90112	----a-w-	c:\windows\unvise32.exe
2013-10-27 10:40 . 2013-10-27 10:40	--------	d-----w-	c:\program files (x86)\REVisionEffects
2013-10-26 12:44 . 2013-10-26 14:03	--------	d-----w-	c:\users\Admin\AppData\Local\LooksBuilder
2013-10-26 11:28 . 2013-10-26 11:28	--------	d-----w-	c:\programdata\Red Giant
2013-10-26 11:28 . 2013-10-26 11:28	--------	d-----w-	c:\program files (x86)\Red Giant Link
2013-10-26 11:28 . 2013-10-26 11:28	--------	d-----w-	c:\program files (x86)\LooksBuilder
2013-10-26 11:28 . 2013-10-26 11:28	--------	d-----w-	c:\program files (x86)\Red Giant
2013-10-26 11:28 . 2013-10-08 13:33	4890624	----a-w-	c:\windows\system32\LS3Renderer_x64.dll
2013-10-26 11:28 . 2013-10-26 11:32	--------	d-----w-	c:\programdata\RedGiant
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-22 15:25 . 2009-07-13 21:59	18286416	----a-w-	c:\windows\system32\nvwgf2umx.dll
2013-11-22 15:24 . 2009-06-10 20:37	15212336	----a-w-	c:\windows\SysWow64\nvd3dum.dll
2013-11-22 15:24 . 2013-07-08 09:22	3067560	----a-w-	c:\windows\system32\nvapi64.dll
2013-11-22 15:24 . 2013-07-08 09:22	2695200	----a-w-	c:\windows\SysWow64\nvapi.dll
2013-11-14 17:48 . 2013-10-21 14:41	82896128	----a-w-	c:\windows\system32\MRT.exe
2013-11-11 04:50 . 2012-10-19 19:14	267936	------w-	c:\windows\system32\MpSigStub.exe
2013-10-23 08:20 . 2013-07-08 09:23	6669600	----a-w-	c:\windows\system32\nvcpl.dll
2013-10-23 08:20 . 2013-07-08 09:23	3489568	----a-w-	c:\windows\system32\nvsvc64.dll
2013-10-23 08:20 . 2013-07-08 09:23	922912	----a-w-	c:\windows\system32\nvvsvc.exe
2013-10-23 08:20 . 2013-07-08 09:23	63776	----a-w-	c:\windows\system32\nvshext.dll
2013-10-23 08:20 . 2013-07-08 09:23	219424	----a-w-	c:\windows\system32\nvmctray.dll
2013-10-21 15:02 . 2013-10-21 15:02	97280	----a-w-	c:\windows\system32\mshtmled.dll
2013-10-21 15:02 . 2013-10-21 15:02	92160	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2013-10-21 15:02 . 2013-10-21 15:02	905728	----a-w-	c:\windows\system32\mshtmlmedia.dll
2013-10-21 15:02 . 2013-10-21 15:02	81408	----a-w-	c:\windows\system32\icardie.dll
2013-10-21 15:02 . 2013-10-21 15:02	77312	----a-w-	c:\windows\system32\tdc.ocx
2013-10-21 15:02 . 2013-10-21 15:02	762368	----a-w-	c:\windows\system32\ieapfltr.dll
2013-10-21 15:02 . 2013-10-21 15:02	73728	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2013-10-21 15:02 . 2013-10-21 15:02	719360	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2013-10-21 15:02 . 2013-10-21 15:02	62976	----a-w-	c:\windows\system32\pngfilt.dll
2013-10-21 15:02 . 2013-10-21 15:02	61952	----a-w-	c:\windows\SysWow64\tdc.ocx
2013-10-21 15:02 . 2013-10-21 15:02	599552	----a-w-	c:\windows\system32\vbscript.dll
2013-10-21 15:02 . 2013-10-21 15:02	523264	----a-w-	c:\windows\SysWow64\vbscript.dll
2013-10-21 15:02 . 2013-10-21 15:02	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2013-10-21 15:02 . 2013-10-21 15:02	51200	----a-w-	c:\windows\system32\imgutil.dll
2013-10-21 15:02 . 2013-10-21 15:02	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2013-10-21 15:02 . 2013-10-21 15:02	48640	----a-w-	c:\windows\system32\mshtmler.dll
2013-10-21 15:02 . 2013-10-21 15:02	452096	----a-w-	c:\windows\system32\dxtmsft.dll
2013-10-21 15:02 . 2013-10-21 15:02	441856	----a-w-	c:\windows\system32\html.iec
2013-10-21 15:02 . 2013-10-21 15:02	38400	----a-w-	c:\windows\SysWow64\imgutil.dll
2013-10-21 15:02 . 2013-10-21 15:02	361984	----a-w-	c:\windows\SysWow64\html.iec
2013-10-21 15:02 . 2013-10-21 15:02	281600	----a-w-	c:\windows\system32\dxtrans.dll
2013-10-21 15:02 . 2013-10-21 15:02	27648	----a-w-	c:\windows\system32\licmgr10.dll
2013-10-21 15:02 . 2013-10-21 15:02	270848	----a-w-	c:\windows\system32\iedkcs32.dll
2013-10-21 15:02 . 2013-10-21 15:02	247296	----a-w-	c:\windows\system32\webcheck.dll
2013-10-21 15:02 . 2013-10-21 15:02	235008	----a-w-	c:\windows\system32\url.dll
2013-10-21 15:02 . 2013-10-21 15:02	23040	----a-w-	c:\windows\SysWow64\licmgr10.dll
2013-10-21 15:02 . 2013-10-21 15:02	226304	----a-w-	c:\windows\system32\elshyph.dll
2013-10-21 15:02 . 2013-10-21 15:02	216064	----a-w-	c:\windows\system32\msls31.dll
2013-10-21 15:02 . 2013-10-21 15:02	197120	----a-w-	c:\windows\system32\msrating.dll
2013-10-21 15:02 . 2013-10-21 15:02	185344	----a-w-	c:\windows\SysWow64\elshyph.dll
2013-10-21 15:02 . 2013-10-21 15:02	173568	----a-w-	c:\windows\system32\ieUnatt.exe
2013-10-21 15:02 . 2013-10-21 15:02	167424	----a-w-	c:\windows\system32\iexpress.exe
2013-10-21 15:02 . 2013-10-21 15:02	158720	----a-w-	c:\windows\SysWow64\msls31.dll
2013-10-21 15:02 . 2013-10-21 15:02	1509376	----a-w-	c:\windows\system32\inetcpl.cpl
2013-10-21 15:02 . 2013-10-21 15:02	150528	----a-w-	c:\windows\SysWow64\iexpress.exe
2013-10-21 15:02 . 2013-10-21 15:02	149504	----a-w-	c:\windows\system32\occache.dll
2013-10-21 15:02 . 2013-10-21 15:02	144896	----a-w-	c:\windows\system32\wextract.exe
2013-10-21 15:02 . 2013-10-21 15:02	1441280	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2013-10-21 15:02 . 2013-10-21 15:02	1400416	----a-w-	c:\windows\system32\ieapfltr.dat
2013-10-21 15:02 . 2013-10-21 15:02	138752	----a-w-	c:\windows\SysWow64\wextract.exe
2013-10-21 15:02 . 2013-10-21 15:02	13824	----a-w-	c:\windows\system32\mshta.exe
2013-10-21 15:02 . 2013-10-21 15:02	137216	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2013-10-21 15:02 . 2013-10-21 15:02	136192	----a-w-	c:\windows\system32\iepeers.dll
2013-10-21 15:02 . 2013-10-21 15:02	135680	----a-w-	c:\windows\system32\IEAdvpack.dll
2013-10-21 15:02 . 2013-10-21 15:02	12800	----a-w-	c:\windows\SysWow64\mshta.exe
2013-10-21 15:02 . 2013-10-21 15:02	12800	----a-w-	c:\windows\system32\msfeedssync.exe
2013-10-21 15:02 . 2013-10-21 15:02	110592	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2013-10-21 15:02 . 2013-10-21 15:02	1054720	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe
2013-10-21 15:02 . 2013-10-21 15:02	102912	----a-w-	c:\windows\system32\inseng.dll
2013-10-21 14:57 . 2013-10-21 14:57	9728	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	9728	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	648192	----a-w-	c:\windows\system32\d3d10level9.dll
2013-10-21 14:57 . 2013-10-21 14:57	604160	----a-w-	c:\windows\SysWow64\d3d10level9.dll
2013-10-21 14:57 . 2013-10-21 14:57	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	522752	----a-w-	c:\windows\system32\XpsGdiConverter.dll
2013-10-21 14:57 . 2013-10-21 14:57	465920	----a-w-	c:\windows\system32\WMPhoto.dll
2013-10-21 14:57 . 2013-10-21 14:57	417792	----a-w-	c:\windows\SysWow64\WMPhoto.dll
2013-10-21 14:57 . 2013-10-21 14:57	4096	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	4096	---ha-w-	c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	3928064	----a-w-	c:\windows\system32\d2d1.dll
2013-10-21 14:57 . 2013-10-21 14:57	364544	----a-w-	c:\windows\SysWow64\XpsGdiConverter.dll
2013-10-21 14:57 . 2013-10-21 14:57	363008	----a-w-	c:\windows\system32\dxgi.dll
2013-10-21 14:57 . 2013-10-21 14:57	3584	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	3584	---ha-w-	c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	3419136	----a-w-	c:\windows\SysWow64\d2d1.dll
2013-10-21 14:57 . 2013-10-21 14:57	333312	----a-w-	c:\windows\system32\d3d10_1core.dll
2013-10-21 14:57 . 2013-10-21 14:57	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	296960	----a-w-	c:\windows\system32\d3d10core.dll
2013-10-21 14:57 . 2013-10-21 14:57	293376	----a-w-	c:\windows\SysWow64\dxgi.dll
2013-10-21 14:57 . 2013-10-21 14:57	2776576	----a-w-	c:\windows\system32\msmpeg2vdec.dll
2013-10-21 14:57 . 2013-10-21 14:57	2565120	----a-w-	c:\windows\system32\d3d10warp.dll
2013-10-21 14:57 . 2013-10-21 14:57	2560	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	2560	---ha-w-	c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-10-21 14:57 . 2013-10-21 14:57	249856	----a-w-	c:\windows\SysWow64\d3d10_1core.dll
2013-10-21 14:57 . 2013-10-21 14:57	245248	----a-w-	c:\windows\system32\WindowsCodecsExt.dll
2013-10-21 14:57 . 2013-10-21 14:57	2284544	----a-w-	c:\windows\SysWow64\msmpeg2vdec.dll
2013-10-21 14:57 . 2013-10-21 14:57	221184	----a-w-	c:\windows\system32\UIAnimation.dll
2013-10-21 14:57 . 2013-10-21 14:57	220160	----a-w-	c:\windows\SysWow64\d3d10core.dll
2013-10-21 14:57 . 2013-10-21 14:57	207872	----a-w-	c:\windows\SysWow64\WindowsCodecsExt.dll
2013-10-21 14:57 . 2013-10-21 14:57	1988096	----a-w-	c:\windows\SysWow64\d3d10warp.dll
2013-10-21 14:57 . 2013-10-21 14:57	194560	----a-w-	c:\windows\system32\d3d10_1.dll
2013-10-21 14:57 . 2013-10-21 14:57	187392	----a-w-	c:\windows\SysWow64\UIAnimation.dll
2013-10-21 14:57 . 2013-10-21 14:57	1682432	----a-w-	c:\windows\system32\XpsPrint.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]
2010-11-05 01:58	297808	----a-w-	c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-10-21 20549280]
"Browser Infrastructure Helper"="c:\users\Admin\AppData\Local\Smartbar\Application\SnapDo.exe" [2013-08-04 21024]
"BitTorrent"="c:\program files (x86)\BitTorrent\BitTorrent.exe" [2012-11-24 1279384]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-09-03 2237328]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"IObit Malware Fighter"="c:\program files (x86)\IObit\IObit Malware Fighter\IMF.exe" [2013-08-16 1549120]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 7"="c:\program files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" [2013-11-11 2283808]
.
c:\users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
net.lnk - c:\users\Admin\AppData\Roaming\Windows Net Data\net.exe [2013-11-23 709120]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Sweetpacks Communicator"=c:\program files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"HP Software Update"=c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SecureUpdateSvc;SecureUpdate;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 Update WebConnect;Update WebConnect;c:\program files (x86)\WebConnect\updateWebConnect.exe;c:\program files (x86)\WebConnect\updateWebConnect.exe [x]
R2 UtilityChest_49Service;Utility ChestService;c:\progra~2\UTILIT~2\bar\1.bin\49barsvc.exe;c:\progra~2\UTILIT~2\bar\1.bin\49barsvc.exe [x]
R2 winzipersvc;WinZiper service;c:\program files (x86)\WinZipper\winzipersvc.exe;c:\program files (x86)\WinZipper\winzipersvc.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
R3 Rockusb;Driver for Rockusb Device;c:\windows\system32\DRIVERS\rockusb.sys;c:\windows\SYSNATIVE\DRIVERS\rockusb.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssudserd.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [x]
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AdvancedSystemCareService7;Advanced SystemCare Service 7;c:\program files (x86)\IObit\Advanced SystemCare 7\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [x]
S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
S2 tor;Tor Win32 Service;c:\program files (x86)\Tor\tor.exe;c:\program files (x86)\Tor\tor.exe [x]
S3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-11-17 19:02	1210320	----a-w-	c:\program files (x86)\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-11-24 c:\windows\Tasks\Driver Booster Update.job
- c:\program files (x86)\IObit\Driver Booster\AutoUpdate.exe [2013-11-22 10:12]
.
2013-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-27 16:49]
.
2013-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-27 16:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
2013-11-22 15:20	2486592	----a-w-	c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2013-08-30 08:01	3358064	----a-w-	c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2013-08-30 08:01	3358064	----a-w-	c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2013-08-30 08:01	3358064	----a-w-	c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-03 1028896]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-06-13 472984]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013
uDefault_Search_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
mDefault_Search_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
mSearch Bar = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
uCustomizeSearch = hxxp://www.google.com
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
mCustomizeSearch = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 10.0.0.138
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{310D38FE-EB4C-467C-8781-B7C2AEB7847D} - c:\program files (x86)\Speed Test Analysis\ScriptHost.dll
Toolbar-{cf67755f-9265-449c-87cf-b945519e073b} - c:\program files (x86)\UtilityChest_49\bar\1.bin\49bar.dll
Wow6432Node-HKLM-Run-QuickTime Task - c:\program files (x86)\QuickTime\QTTask.exe
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
AddRemove-Mozilla Firefox 23.0.1 (x86 de) - c:\program files (x86)\Mozilla Firefox\uninstall\helper.exe
AddRemove-MozillaMaintenanceService - c:\program files (x86)\Mozilla Maintenance Service\uninstall.exe
AddRemove-PunkBusterSvc - c:\ubisoft\Ghost Recon Online\PDC-Live\pbsvc_gro.exe
AddRemove-Speed Test Analysis - c:\program files (x86)\Speed Test Analysis\uninst.exe
AddRemove-Sweet Home 3D_is1 - c:\program files (x86)\Sweet Home 3D\unins000.exe
AddRemove-WinZipper - c:\program files (x86)\WinZipper\eUninstall.exe
AddRemove-MyFreeCodec - c:\program files (x86)\MyFree Codec\1.0b beta\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,80,df,39,0f,52,40,3a,42,98,8f,03,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,80,df,39,0f,52,40,3a,42,98,8f,03,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-11-24  13:38:59 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2013-11-24 12:38
.
Vor Suchlauf: 12 Verzeichnis(se), 200.647.741.440 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 216.885.616.640 Bytes frei
.
- - End Of File - - 957696A4995BC4BBD1FAA39476DEA6E3
A36C5E4F47E84449FF07ED3517B43A31
         

Adwcleaner[S1].txt

Code:
ATTFilter
# AdwCleaner v3.013 - Bericht erstellt am 24/11/2013 um 13:43:14
# Updated 24/11/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Admin - PC
# Gestartet von : C:\Users\Admin\Desktop\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****

[#] Dienst Gelöscht : Update WebConnect
[#] Dienst Gelöscht : winzipersvc

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\IBUpdaterService
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
Ordner Gelöscht : C:\Program Files (x86)\SimilarSites
Ordner Gelöscht : C:\Users\Admin\AppData\Local\Smartbar
Ordner Gelöscht : C:\Users\Admin\AppData\LocalLow\Smartbar
Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\SimilarSites
Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\Windows Net Data
Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\speedtestanalysis@SpeedAnalysis.com
Datei Gelöscht : C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
Datei Gelöscht : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\bingp.xml
Datei Gelöscht : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\Web Search.xml
Datei Gelöscht : C:\Windows\System32\Tasks\Desk 365 RunAsStdUser

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\AddonsFramework.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ButtonSite.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHost.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{19975B78-1907-4DD6-A437-4C48120F46A4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9317-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7C28CEF1-A4A6-4B6A-8B97-C44F1267753C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\smartbarbackup
Schlüssel Gelöscht : HKCU\Software\smartbarlog
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\Software\hdcode
Schlüssel Gelöscht : HKLM\Software\Myfree Codec
Schlüssel Gelöscht : HKLM\Software\winzipersvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winzipper
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\237AA359BFA99C94484AF769ACA080AD
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\237AA359BFA99C94484AF769ACA080AD

***** [ Browser ] *****

-\\ Internet Explorer v10.0.9200.16736

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]

-\\ Mozilla Firefox v23.0.1 (de)

[ Datei : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\prefs.js ]

Zeile gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013|hxxp://www.gi[...]
Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Zeile gelöscht : user_pref("extensions.helperbar.Visibility", true);
Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "at");
Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "snapdoocyb");
Zeile gelöscht : user_pref("extensions.helperbar.installationid", "96e1573f-e7e4-9f36-0509-dd0e99161bc7");
Zeile gelöscht : user_pref("extensions.helperbar.installdate", "27/10/2013");
Zeile gelöscht : user_pref("extensions.helperbar.publisher", "snapdoocyb");
Zeile gelöscht : user_pref("extensions.searchads.insertDomains", "{\"search.snapdo.com\":1,\"superhqporn.com\":1,\"cdncache1-a.akamaihd.net\":1}");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&installDate=27/10/2013&q=");
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=nt&installDate=27/10/2013");

-\\ Google Chrome v31.0.1650.57

[ Datei : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht : icon_url
Gelöscht : search_url
Gelöscht : keyword
Gelöscht : urls_to_restore_on_startup

*************************

AdwCleaner[R1].txt - [14294 octets] - [24/11/2013 13:42:31]
AdwCleaner[S1].txt - [13028 octets] - [24/11/2013 13:43:14]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [13089 octets] ##########
         

JRT.txt

Code:
ATTFilter
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Professional x64
Ran by Admin on 24.11.2013 at 13:48:16,13
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r706-n-bf_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r706-n-bf_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r706-n-bf_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r706-n-bf_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{26681076-2DF8-44B1-900B-06D059B96AA0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Program Files (x86)\secure speed dial"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24.11.2013 at 14:25:54,51
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         


Danke schon mal für die Hilfe.


Alt 25.11.2013, 16:12   #6
M-K-D-B
/// TB-Ausbilder
 
_GETWINDOWINFO-Trojaner - Standard

_GETWINDOWINFO-Trojaner



Servus,





Schritt 1
Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.







Schritt 2
Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
  • Bitte deaktiviere während des Scans alle Virenscanner, da sie das Ergebnis beeinflussen
  • Starte Zoek.exe mit einem Doppelklick.
  • Achtung: Das folgende Skript wurde nur für diesen speziellen Fall geschrieben und könnte andere Computer beschädigen.
  • Kopiere den Text der folgenden Box in das Skriptfenster von zoek:
    Code:
    ATTFilter
    FFdefaults;
    CHRdefaults;
    iedefaults;
    emptyclsid;
    autoclean;
             
  • Nun klicke auf "Run script" und sei geduldig bis das Skript durchläuft.
  • Wenn das Tool fertig ist wird sich Notepad mit dem Logfile öffnen (ggf. erst nach einem Neustart). Das Log befindet sich aber auch noch unter c:
  • Bitte poste mir das ZOEK-Log (möglichst in CODE-Tags - #-Symbol im Antwortfenster klicken)





Bitte poste mit deiner nächsten Antwort
  • die Logdatei von MBAM,
  • die Logdatei von Zoek.

Alt 26.11.2013, 16:17   #7
LikeASiR
 
_GETWINDOWINFO-Trojaner - Standard

_GETWINDOWINFO-Trojaner



Hallo,

Ich nutz mal hier die Gelegenheit um dir vielmals zu danken, da das ja eigentlich keine Selbstverständlichkeit ist, dass solche Dienstleistungen gratis angeboten werden.
Was ich hier so im Forum lese, dass sich Leute nach 12 Stunden aufregen immer noch keine Antwort bekommen zu haben, ist ja eine Frechheit. Ihr könntet genauso gut Geld für die Hilfe verlangen.
Also von mir kommt da denke ich eine Spende rein, auch wenn es nur ein paar Euros sein werden.

Logdatei Zoek:

Code:
ATTFilter
Zoek.exe Version 4.0.0.5 Updated 24-November-2013
Tool run by Admin on 25.11.2013 at 19:06:19,29.
Microsoft Windows 7 Professional  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Admin\Desktop\zoek.exe [Script inserted] 

==== System Restore Info ======================

25.11.2013 19:07:20 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} deleted successfully
HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{cf67755f-9265-449c-87cf-b945519e073b} deleted successfully
HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{cf67755f-9265-449c-87cf-b945519e073b} deleted successfully
HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{310D38FE-EB4C-467C-8781-B7C2AEB7847D} deleted successfully
HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{310D38FE-EB4C-467C-8781-B7C2AEB7847D} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{cf67755f-9265-449c-87cf-b945519e073b} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{310D38FE-EB4C-467C-8781-B7C2AEB7847D} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{310D38FE-EB4C-467C-8781-B7C2AEB7847D} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{31ad400d-1b06-4e33-a59a-90c2c140cba0} deleted successfully
HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully
HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{cf67755f-9265-449c-87cf-b945519e073b} deleted successfully
HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{310D38FE-EB4C-467C-8781-B7C2AEB7847D} deleted successfully
HKEY_USERS\S-1-5-21-2953639101-1623858838-2121489674-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{48A789BF-F6D6-4930-9C8B-77855A63EDE1} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{cf67755f-9265-449c-87cf-b945519e073b} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UtilityChest_49Service deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\UtilityChest_49Service deleted successfully

==== FireFox Fix ======================

Deleted from C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\prefs.js:
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default

user.js not found
---- Lines toggle removed from prefs.js ----
user_pref("extensions.toggle.admin", false);
user_pref("extensions.toggle.aflt", "orgnl");
user_pref("extensions.toggle.appId", "{EE5558C0-C65E-4EF7-8C52-39632E6A21F3}");
user_pref("extensions.toggle.autoRvrt", "false");
user_pref("extensions.toggle.cid", "adfaa7a7");
user_pref("extensions.toggle.dfltLng", "en");
user_pref("extensions.toggle.dfltSrch", true);
user_pref("extensions.toggle.dnsErr", true);
user_pref("extensions.toggle.excTlbr", true);
user_pref("extensions.toggle.ffxUnstlRst", false);
user_pref("extensions.toggle.hmpg", true);
user_pref("extensions.toggle.hmpgUrl", "hxxp://search.toggle.com/?lang=en&cid=adfaa7a7");
user_pref("extensions.toggle.hpOld0", "https://www.google.at/");
user_pref("extensions.toggle.id", "1a05b559000000000000001bfcfb8327");
user_pref("extensions.toggle.instlDay", "15760");
user_pref("extensions.toggle.instlRef", "");
user_pref("extensions.toggle.kw_url", "hxxp://search.toggle.com/?lang=en&cid=adfaa7a7&q=");
user_pref("extensions.toggle.newTab", true);
user_pref("extensions.toggle.newTabUrl", "hxxp://search.toggle.com/?lang=en&cid=adfaa7a7");
user_pref("extensions.toggle.prdct", "toggle");
user_pref("extensions.toggle.prtnrId", "toggle");
user_pref("extensions.toggle.rvrt", "true");
user_pref("extensions.toggle.smplGrp", "none");
user_pref("extensions.toggle.tlbrId", "base");
user_pref("extensions.toggle.tlbrSrchUrl", "hxxp://search.toggle.com/?lang={dfltLng}&cid={cid}&q=");
user_pref("extensions.toggle.vrsn", "1.8.12.7");
user_pref("extensions.toggle.vrsni", "1.8.12.7");
user_pref("extensions.toggle.vrsnTs", "1.8.12.711:01:32");
---- Lines speedtestanalysis removed from prefs.js ----
user_pref("extensions.speedtestanalysis@SpeedAnalysis.com.id", "\"d7b5ae02-e81b-caca-611b-8eba259e2fac\"");
user_pref("extensions.speedtestanalysis@SpeedAnalysis.com.mzID", "69");
user_pref("extensions.speedtestanalysis@SpeedAnalysis.com.uuid", "\"14eb5848-4250-11e3-8099-0025901ef77c\"");
---- Lines speedtestanalysis modified from prefs.js ----

user_pref("extensions.enabledAddons", "speedtestanalysis%40SpeedAnalysis.com:1.0.0.5,speeddial%40instair.net:1.4.1,%7B96e1573f-e7e4-9f36-0509-dd0e9916
user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program
---- Lines SpeedAnalysis modified from prefs.js ----

user_pref("extensions.enabledAddons", "disabled%40SpeedAnalysis.com:1.0.0.5,speeddial%40instair.net:1.4.1,%7B96e1573f-e7e4-9f36-0509-dd0e99161bc7%7D:1
user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program
---- FireFox user.js and prefs.js backups ---- 

prefs__1941_.backup

==== Deleting Files \ Folders ======================

C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\speedtestanalysis@SpeedAnalysis.com not found
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\speedtestanalysis@SpeedAnalysis.com not found
"C:\Windows\Installer\131f08.msi" not found
C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} deleted
C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} deleted
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\Users\Admin\ChromeExtensions deleted
C:\User Data\Default\Extensions deleted
C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis deleted
C:\Users\Admin\AppData\Local\avgchrome deleted
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx deleted
C:\user.js deleted
C:\Windows\Launcher.exe deleted
C:\Windows\SysWow64\searchplugins deleted
C:\Windows\SysWow64\Extensions deleted
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\jetpack deleted
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\staged deleted
"C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\toggle.xml" deleted

==== Firefox Extensions ======================

ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default
- Undetermined - C:\Program Files (x86)\IObit Apps Toolbar\FF
- Amazon-Icon - %ProfilePath%\extensions\amazon-icon@giga.de
- Advanced SystemCare Surfing Protection - %ProfilePath%\extensions\ascsurfingprotection@iobit.com
- HDvid Codec - %ProfilePath%\extensions\hdvc@hdvc.com
- AD Block - %ProfilePath%\extensions\searchads@instair.net
- AccelerateTab - %ProfilePath%\extensions\speeddial@instair.net
- WebSite Recommendation - %ProfilePath%\extensions\WebSiteRecommendation@weliketheweb.com
- Snap.Do - %ProfilePath%\extensions\{96e1573f-e7e4-9f36-0509-dd0e99161bc7}

==== Firefox Plugins ======================

Profilepath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default
4BF70B35B943BD73BD6E13EB7C1BA4B3	- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll -	Shockwave Flash
AE7B288233C212C62CD544BF768C45E6	- C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll -	Shockwave for Director / Shockwave for Director
FFF2362F6B4A46D4BC1D147E79A7547B	- C:\ProgramData\NexonEU\NGM\npNxGameeu.dll -	Nexon Game Controller
2C82D753EF779945977C82A3908DA20A	- C:\Windows\SysWOW64\npDeployJava1.dll -	Java Deployment Toolkit 7.0.90.5
15E298B5EC5B89C5994A59863969D9FF	- C:\Windows\SysWOW64\npmproxy.dll -	Microsoft® Windows® Operating System


==== Deleted Firefox Extensions ======================

C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\speeddial@instair.net deleted
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\{96e1573f-e7e4-9f36-0509-dd0e99161bc7} deleted
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\extensions\hdvc@hdvc.com deleted

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
kckgnnipheglejoddfhekdjpbdbinhmb - C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis\SpeedTestAnalysis.crx[]
mkcedibhemacmilmkpndpkoidlnmgngg - C:\Users\Admin\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx[]
nfengeggddojhakldhlpjdlddgkkjkdd - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx[12.10.2013 13:04]

Price Alarm - Admin - Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab
Speed Test Analysis - Admin - Default\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb
Amazon-Icon - Admin - Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg
Advanced SystemCare Surfing Protection - Admin - Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd
Speed Test Analysis - Admin - Profile 1\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb
Amazon-Icon - Admin - Profile 1\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg
Advanced SystemCare Surfing Protection - Admin - Profile 1\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd

==== Chrome Fix ======================

C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab deleted successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fmlgoencnlndpglbocajlimaikjohmab_0.localstorage deleted successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fmlgoencnlndpglbocajlimaikjohmab_0.localstorage-journal deleted successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb deleted successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb deleted successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kckgnnipheglejoddfhekdjpbdbinhmb_0.localstorage deleted successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg deleted successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013"
"Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s"
"Default"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s"
"Default"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.protectedsearch.com?si=41570&bs=true&tid=3026&q=%s"
"Default"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"CustomizeSearch"="hxxp://www.google.com"
"SearchAssistant"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Default_Search_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"CustomizeSearch"="hxxp://www.google.com"
"SearchAssistant"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Start Default_Page_URL"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026"
"Default_Search_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"Search Page"="hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q="
"CustomizeSearch"="hxxp://www.google.com"
"SearchAssistant"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{006ee092-9658-4fd6-bd8e-a21a348e59f5}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"CustomizeSearch"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm"
"SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"CustomizeSearch"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm"
"SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"CustomizeSearch"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm"
"SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{006ee092-9658-4fd6-bd8e-a21a348e59f5} Web Search Url="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Reset Google Chrome ======================

C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\237AA359BFA99C94484AF769ACA080AD deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7E09412E-7A0E-4C61-B304-888C760F61D4} deleted successfully
HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\E21490E7E0A716C43B4088C867F0164D deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesAirMessage deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPreload deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KPeerNexonEU deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Overwolf deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Utility Chest Home Page Guard 64 bit deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MC9QY34B will be deleted at reboot
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VPX4PAEL will be deleted at reboot
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2VIDXTY will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\jgb2a5vb.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Application Cache\Cache emptied successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache is not empty, a reboot is needed

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Admin\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MC9QY34B" not found
"C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VPX4PAEL" not found
"C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2VIDXTY" not found
"C:\Users\Admin\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\SDRQWGNG\empire-s.assets.zgncdn.com"  not found
"C:\Users\Admin\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\SDRQWGNG\synd.travelplus.tv"  not found

==== EOF on 25.11.2013 at 21:54:45,42 ======================
         

Logdatei Mbam:

Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.11.25.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16428
Admin :: PC [Administrator]

Schutz: Aktiviert

25.11.2013 18:56:57
mbam-log-2013-11-25 (18-56-57).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 233873
Laufzeit: 4 Minute(n), 

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 3
C:\Windows\Installer\131f08.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Installer\bd5bdd.msi (PUP.Optional.SmartBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\User Data\Default\Extensions\newtab.crx (PUP.Optional.Elex.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)
         
Nochmals vielen Dank für die wirklich schnelle Antwort.

Btw: Wenn wir schon dabei sind: Könntest du mir vielleicht ein paar Softwares vorschlagen (wenn möglich kostenfrei), die solchen Problemen effizient vorbeugen?
Was benutzt du so?

Vielleicht irgendein Programm, dass den Computer nicht all zu sehr belastet, da ich mit meiner 8800 GTS und nem AMD Quad-Core Prozessor nicht ganz zeitgemäß ausgestattet bin :-D

Gestern war alles wie gewollt und heute ist die Snap.do Startseite wieder da...
Hast du irgendwas hilfreiches gegen diese Sotfware?

Alt 26.11.2013, 19:33   #8
M-K-D-B
/// TB-Ausbilder
 
_GETWINDOWINFO-Trojaner - Standard

_GETWINDOWINFO-Trojaner



Servus,








Wir spüren die letzten Reste auf, damit wir sie später entfernen können:





Schritt 1
Kontrollscan mit FRST
Führe wie zuvor beschrieben einen Scan mit FRST aus.
Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan.
Es werden wieder zwei Logdateien erzeugt. Poste mir diese.





Schritt 2
Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop:
SystemLook (32 bit) | SystemLook (64 bit)
  • Doppelklicke auf die SystemLook.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:

    Code:
    ATTFilter
    :filefind
    *snap.do*
    *Speed Test Analysis*
    *hdvc.com*
    *WebConnect*
    *Babylon*
    *IBUpdater*
    *SimilarSites*
    *Windows Net Data*
    *Desk 365*
    
    :folderfind
    *snap.do*
    *Speed Test Analysis*
    *hdvc.com*
    *WebConnect*
    *Babylon*
    *IBUpdater*
    *SimilarSites*
    *Windows Net Data*
    *Desk 365*
    
    :regfind
    snap.do
    Speed Test Analysis
    hdvc.com
    WebConnect
    Babylon
    IBUpdater
    SimilarSites
    Windows Net Data
    Desk 365
             
  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auch auf dem Desktop als SystemLook.txt gespeichert.








In welchem Browser ist die snap.do Seite wieder aufgetaucht?
Wie läuft der Rechner derzeit?






Bitte poste mit deiner nächsten Antwort
  • die beiden Logdateien von FRST,
  • die Logdatei von SystemLook,
  • die Beantwortung der gestellten Fragen.

Alt 01.12.2013, 10:25   #9
M-K-D-B
/// TB-Ausbilder
 
_GETWINDOWINFO-Trojaner - Standard

_GETWINDOWINFO-Trojaner



Fehlende Rückmeldung
Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten.
PM an mich falls Du denoch weiter machen willst.

Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen!

Antwort

Themen zu _GETWINDOWINFO-Trojaner
amazon-icon, branding, browser, darkcomet, darkcomet rat, defender, driver booster, excel, flash player, getwindowinfo, google, internet, internet exlorer, internet explorer, mozilla, newtab, plug-in, pup.optional.elex.a, pup.optional.smartbar.a, pup.optional.snapdo, pup.optional.sweetim, realtek, richtlinie, schutz, services.exe, smartbar, svchost.exe, trojaner, vcredist




Zum Thema _GETWINDOWINFO-Trojaner - Hallo Leute, Heute Früh, nachdem ich den PC angeschaltet habe, hat sich interessanterweise der Internet Explorer mit dem Link: hxxp://www_getwindowinfo/ geöffnet, welcher nicht geschlossen werden kann. Interessante Anmerkung : Ich - _GETWINDOWINFO-Trojaner...
Archiv
Du betrachtest: _GETWINDOWINFO-Trojaner auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.