![]() |
| |||||||
Log-Analyse und Auswertung: Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| | #1 | ||
![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Hallo, ich habe hier 2 PCs (Windows 7) und einen Laptop (8) mit dem gleichen Problem. Beim Öffnen von Links kommt Werbung/ Meldungen und nicht das gewünschte Ziel. Mal öffnet sich nur ein Fenster, mal ganz viele. Es sind ca. 6 verschiedene Meldungen die sich wiederholen: - Windows PC Reparatur - Bitte aktualisieren sie Java/ Mediaplay/ Videoplayer/ Firefox - Ihr Windows hat einen Fehler Avira hat 4 Wahrnungen gefunden und die in die Quarantäne gesteckt, aber das Problem war damit nicht behoben. Hier die Avira Ergebnisse: Leider bin ich zu blöd die exportierrten Ergebisse einzufügen und habe auch nirgendwo eine Hilfe dazu gefunden. Hier die defogger_disable Ergebnisse: Zitat:
FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 01
Ran by Lorelay (ATTENTION: The logged in user is not administrator) on Lorelay-PC on 13-04-2014 17:45:30
Running from C:\Users\Lorelay\Downloads
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(Dropbox, Inc.) C:\Users\Lorelay\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\EvernoteClipper.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Iminent) C:\Program Files (x86)\Iminent\Iminent.exe
(Iminent) C:\Program Files (x86)\Iminent\Iminent.Messengers.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\Evernote.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\EvernoteTray.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated)
HKLM\...\Run: [Samsung Link] - C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [600928 2014-03-13] (Copyright 2013 SAMSUNG)
HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1573584 2012-10-10] (Ask)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Iminent] - C:\Program Files (x86)\Iminent\Iminent.exe [1074376 2012-12-12] (Iminent)
HKLM-x32\...\Run: [IminentMessenger] - C:\Program Files (x86)\Iminent\Iminent.Messengers.exe [884936 2012-12-12] (Iminent)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [LexwareInfoService] - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Runonce: [VOPackage] - C:\Users\Lorelay\AppData\Roaming\VOPackage\VOPackage.exe /runonce [X]
HKU\S-1-5-21-3979088316-405595985-3978638949-1001\...\Run: [icq] - C:\Users\Lorelay\AppData\Roaming\ICQM\icq.exe [27453288 2013-03-07] (ICQ)
HKU\S-1-5-21-3979088316-405595985-3978638949-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3979088316-405595985-3978638949-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3979088316-405595985-3978638949-1001\...\MountPoints2: {47e8a16e-0ef0-11e2-bdbf-001e8c804aa9} - G:\pushinst.exe
HKU\S-1-5-21-3979088316-405595985-3978638949-1001\...\MountPoints2: {f474a15f-0edf-11e2-aa4b-806e6f6e6963} - J:\Start.exe
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Lorelay\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-3979088316-405595985-3978638949-1001\User: Group Policy restriction detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:13828
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.iminent.com/?appId=932475FC-7416-4A83-9341-C862AD5B7DA2
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xDD14BC0505F1CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?type=hp&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?type=hp&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968&q={searchTerms}
SearchScopes: HKLM-x32 - {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://search.iminent.com/?appId=[AppInstanceUid]&ref=toolbox&q={searchTerms}
SearchScopes: HKCU - DefaultScope {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://search.iminent.com/?appId=[AppInstanceUid]&ref=toolbox&q={searchTerms}
SearchScopes: HKCU - bProtectorDefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
SearchScopes: HKCU - {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://search.iminent.com/?appId=[AppInstanceUid]&ref=toolbox&q={searchTerms}
SearchScopes: HKCU - {FFEBBF0A-C22C-4172-89FF-45215A135AC8} URL = hxxp://search.icq.com/search/results.php?q=%s&ch_id=hm&search_mode=web
BHO: MediaPlayerplus - {11111111-1111-1111-1111-110511421146} - C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho64.dll (Freeven)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: MediaPlayerplus - {11111111-1111-1111-1111-110511421146} - C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho.dll (Freeven)
BHO-x32: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.3.8\bh\BabylonToolbar.dll (Babylon BHO)
BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
BHO-x32: FoxTab - {4DF4AC8C-FFA8-40FF-91F0-EB8389314B78} - C:\Users\Lorelay\AppData\LocalLow\FoxTab\IE\FoxTab.dll No File
BHO-x32: TBSB01620 Class - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files (x86)\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM-x32 - Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.3.8\BabylonToolbarTlbr.dll (Babylon Ltd.)
Toolbar: HKLM-x32 - IMinent Toolbar - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\r7mxushs.default
FF NewTab: user_pref("browser.newtab.url", "");
FF SearchEngineOrder.1: Search the web (Babylon)
FF SelectedSearchEngine: SearchTheWeb
FF Homepage: about:home
FF Keyword.URL: hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-4&o=APN10261&locale=de_DE&apn_uid=d4a97d28-fddb-49b8-aef5-b9f6e29800ee&apn_ptnrs=%5EAGS&apn_sauid=723C7D07-093F-41FC-8299-10356595D3FA&apn_dtid=%5EYYYYYY%5EYY%5EDE&&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\webssearches.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: MediaPlayerplus - C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\r7mxushs.default\Extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com [2014-04-11]
FF Extension: FoxTab - C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\r7mxushs.default\Extensions\addon@foxtab.com [2012-11-15]
FF HKLM-x32\...\Firefox\Extensions: [webbooster@iminent.com] - C:\Program Files (x86)\Iminent\webbooster@iminent.com
FF Extension: Iminent Minibar - C:\Program Files (x86)\Iminent\webbooster@iminent.com [2013-01-05]
FF HKLM-x32\...\Firefox\Extensions: [quick_start@gmail.com] - C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default\extensions\quick_start@gmail.com
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://istart.webssearches.com/?type=sc&ts=1397243795&from=tugs&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EC62896828968
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor9.0; D:\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [169408 2010-09-30] (Adobe Systems Incorporated)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36392 2014-03-14] (Just Develop It)
R2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [688240 2014-03-31] (Cherished Technololgy LIMITED)
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 Re-markit; C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe [141824 2014-04-11] ()
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [609632 2014-03-13] (Copyright 2013 SAMSUNG)
R2 SProtection; C:\Program Files (x86)\Common Files\Umbrella\Umbrella.exe [2620016 2013-01-24] (Iminent)
R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [566272 2014-04-11] (Cherished Technololgy LIMITED)
R2 vosr; C:\Users\Lorelay\AppData\Roaming\VOPackage\VOsrv.exe [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1627520 2009-06-10] (NXP Semiconductors)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-13 17:45 - 2014-04-13 17:45 - 00019866 _____ () C:\Users\Lorelay\Downloads\FRST.txt
2014-04-13 17:45 - 2014-04-13 17:45 - 00000000 ____D () C:\FRST
2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe
2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log
2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe
2014-04-11 21:19 - 2014-04-11 21:24 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\ProgramData\WPM
2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\ProgramData\IePluginService
2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-04-11 21:18 - 2014-04-12 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-04-11 21:18 - 2014-04-11 21:39 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-04-11 21:17 - 2014-04-13 17:27 - 00001520 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-5.job
2014-04-11 21:17 - 2014-04-13 17:27 - 00001442 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-1.job
2014-04-11 21:17 - 2014-04-13 17:27 - 00001430 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-2.job
2014-04-11 21:16 - 2014-04-13 17:27 - 00003138 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-3.job
2014-04-11 21:16 - 2014-04-13 17:27 - 00002210 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-4.job
2014-04-11 21:16 - 2014-04-11 21:18 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2014-04-11 21:16 - 2014-04-11 21:17 - 00000000 ____D () C:\Program Files (x86)\MediaPlayerplus
2014-04-11 21:16 - 2014-04-11 21:16 - 00000000 ____D () C:\Program Files (x86)\Uniblue
2014-04-11 21:15 - 2014-04-13 17:27 - 00000422 _____ () C:\Windows\Tasks\Re-markit Update.job
2014-04-11 21:15 - 2014-04-13 17:27 - 00000412 _____ () C:\Windows\Tasks\Re-markit_wd.job
2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-04-11 21:15 - 2014-04-11 21:15 - 00000000 ____D () C:\Program Files (x86)\Re-markit-soft
2014-04-11 21:11 - 2014-04-11 21:11 - 00634288 _____ () C:\Users\Lorelay\Downloads\Player_Setup.exe
2014-04-11 21:11 - 2014-04-11 21:11 - 00634288 _____ () C:\Users\Lorelay\Downloads\Player_Setup(1).exe
2014-04-10 20:30 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-10 20:30 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-10 20:30 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-10 20:30 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-10 20:30 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-10 20:30 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-10 20:30 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-10 20:30 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-10 20:30 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-10 20:30 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-10 20:30 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-10 20:30 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-10 20:30 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-10 20:30 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-10 20:29 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-10 20:29 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-06 11:34 - 2014-04-06 11:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG
2014-03-18 19:17 - 2014-03-18 19:18 - 00000000 ____D () C:\Program Files\Samsung
2014-03-18 18:59 - 2014-03-18 19:06 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe
2014-03-18 17:44 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-18 17:44 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-18 17:44 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-18 17:43 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-18 17:43 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-18 17:43 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-18 17:43 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-18 17:43 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-18 17:43 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-18 17:43 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-18 17:43 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-18 17:43 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-18 17:43 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-18 17:43 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-18 17:43 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-18 17:43 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-18 17:43 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-18 17:43 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-18 17:43 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-18 17:43 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-18 17:43 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-18 17:43 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-18 17:43 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-18 17:43 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-18 17:43 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-18 17:43 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-18 17:43 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-18 17:43 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-18 17:43 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-18 17:43 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-18 17:43 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-18 17:43 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-18 17:43 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-18 17:43 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-18 17:43 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-18 17:43 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-18 17:43 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-18 17:43 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-18 17:43 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-18 17:43 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-18 17:43 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-18 17:43 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-18 17:43 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-18 17:43 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
==================== One Month Modified Files and Folders =======
2014-04-13 17:45 - 2014-04-13 17:45 - 00019866 _____ () C:\Users\Lorelay\Downloads\FRST.txt
2014-04-13 17:45 - 2014-04-13 17:45 - 00000000 ____D () C:\FRST
2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe
2014-04-13 17:41 - 2012-11-15 18:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log
2014-04-13 17:40 - 2012-10-05 13:36 - 00000000 ____D () C:\Users\Lorelay2
2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe
2014-04-13 17:37 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-13 17:37 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-13 17:33 - 2012-10-05 13:32 - 01845728 _____ () C:\Windows\WindowsUpdate.log
2014-04-13 17:29 - 2014-01-04 14:37 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Dropbox
2014-04-13 17:27 - 2014-04-11 21:17 - 00001520 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-5.job
2014-04-13 17:27 - 2014-04-11 21:17 - 00001442 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-1.job
2014-04-13 17:27 - 2014-04-11 21:17 - 00001430 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-2.job
2014-04-13 17:27 - 2014-04-11 21:16 - 00003138 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-3.job
2014-04-13 17:27 - 2014-04-11 21:16 - 00002210 _____ () C:\Windows\Tasks\0b09b8b1-b267-4ac3-a1e3-c3f904efd354-4.job
2014-04-13 17:27 - 2014-04-11 21:15 - 00000422 _____ () C:\Windows\Tasks\Re-markit Update.job
2014-04-13 17:27 - 2014-04-11 21:15 - 00000412 _____ () C:\Windows\Tasks\Re-markit_wd.job
2014-04-13 17:23 - 2013-01-05 17:18 - 00000266 _____ () C:\Windows\Tasks\AutoKMS.job
2014-04-13 17:23 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-13 17:23 - 2009-07-14 06:51 - 00044308 _____ () C:\Windows\setupact.log
2014-04-12 21:19 - 2014-04-11 21:18 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-04-11 23:54 - 2012-10-13 16:59 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-11 23:54 - 2012-10-13 16:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-11 21:39 - 2014-04-11 21:18 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-04-11 21:24 - 2014-04-11 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-04-11 21:23 - 2012-10-08 17:18 - 00171972 _____ () C:\Windows\PFRO.log
2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\ProgramData\WPM
2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\ProgramData\IePluginService
2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-04-11 21:18 - 2014-04-11 21:16 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2014-04-11 21:17 - 2014-04-11 21:16 - 00000000 ____D () C:\Program Files (x86)\MediaPlayerplus
2014-04-11 21:16 - 2014-04-11 21:16 - 00000000 ____D () C:\Program Files (x86)\Uniblue
2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-04-11 21:15 - 2014-04-11 21:15 - 00000000 ____D () C:\Program Files (x86)\Re-markit-soft
2014-04-11 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-11 21:11 - 2014-04-11 21:11 - 00634288 _____ () C:\Users\Lorelay\Downloads\Player_Setup.exe
2014-04-11 21:11 - 2014-04-11 21:11 - 00634288 _____ () C:\Users\Lorelay\Downloads\Player_Setup(1).exe
2014-04-10 23:33 - 2013-01-05 16:56 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-10 23:32 - 2013-07-24 22:51 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 23:30 - 2013-01-27 19:31 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-09 18:47 - 2012-10-13 17:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-08 21:58 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat
2014-04-08 21:58 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat
2014-04-08 21:58 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-06 11:34 - 2014-04-06 11:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-31 03:16 - 2014-04-10 20:30 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-10 20:30 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-20 21:07 - 2012-10-05 15:27 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Adobe
2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe
2014-03-20 16:14 - 2009-07-14 06:45 - 00442712 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload
2014-03-18 19:19 - 2012-10-05 14:59 - 00000000 ____D () C:\Users\Lorelay
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG
2014-03-18 19:18 - 2014-03-18 19:17 - 00000000 ____D () C:\Program Files\Samsung
2014-03-18 19:06 - 2014-03-18 18:59 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe
2014-03-18 18:47 - 2013-03-12 13:54 - 00002669 _____ () C:\Users\Public\Desktop\TAXMAN 2013 spezial.lnk
Some content of TEMP:
====================
C:\Users\Lorelay\AppData\Local\Temp\avgnt.exe
C:\Users\Lorelay\AppData\Local\Temp\i4jdel0.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================
--- --- --- Hier die Addition Ergebnisse: Zitat:
Ich habe die Log-Files jetzt erstmal nur an einem PC gemacht, bei bedarf kann ich das auch bei den anderene machen. Vielen dank im Vorraus Emmaline PS. Es ist etwas blöd, das man manche Worte nicht im Titel verweden kann, weil so kann man das Problem nicht genau darstellen. Die Meldung heißt meist "Bitte aktualisieren sie ihr Programm". da das Wort "Bitte" im Titel nicht benutzbar ist, konnte ich das nicht so schreiben. Geändert von Emmaline (13.04.2014 um 20:04 Uhr) |
| | #2 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) hi,
__________________unsere Tools brauchen immer Adminrechte. Revo Uninstaller - Download - Filepony Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION Mit Revo auch Moderat die Reste entfernen lassen. Downloade Dir bitte
Downloade Dir bitte
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
| | #3 | |
![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Also,
__________________ich habe mit "Revo Uninstaller" alles deinstalliert was zu finden war. Ein Programm hat er allerdings nicht angezeigt, aber jetzt nach allen Anwendungen ist es verschwunden (MyPC Backup). Ich habe noch ein weiteres Program gelöscht (Bing Bar). Beim löschen über "Revo Uninstaller" meldeten sich immeer wieder die "Uninstall" Programme der Programme selbst. Die habe ich einfach übergangen. War das in Ordnung so? Malwarebytes Anti-Malware hat sehr viele Funde gehabt. Die Maske des "Suchlauf Protokoll" bleibt nach einem Klick auf Ansicht allerdings leer und wenn man es speichern will kommt eine Fehlermeldung. Kannd aas an der Größe liegen? AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 14/04/2014 um 00:04:01
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzername : Lorelay - Lorelay PC
# Gestartet von : C:\Users\Lorelay\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : BackupStack
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Iminent
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Program Files (x86)\BabylonToolbar
Ordner Gelöscht : C:\Program Files (x86)\Iminent
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\uniblue
Ordner Gelöscht : C:\Program Files (x86)\Common Files\Umbrella
Ordner Gelöscht : C:\Users\\Lorelay~1\AppData\Local\Temp\AskSearch
Ordner Gelöscht : C:\Users\\Lorelay\AppData\LocalLow\BabylonToolbar
Ordner Gelöscht : C:\Users\Lorelay\AppData\LocalLow\FoxTab
Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\BabylonToolbar
Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\Iminent
Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\VOPackage
Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
Ordner Gelöscht : C:\Users\Lorelay\AppData\Local\AskToolbar
Ordner Gelöscht : C:\Users\Lorelay\AppData\LocalLow\BabylonToolbar
Ordner Gelöscht : C:\Users\Lorelay\AppData\LocalLow\Toolbar4
Ordner Gelöscht : C:\Users\Lorelay\AppData\Roaming\Iminent
Datei Gelöscht : C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
Datei Gelöscht : C:\Users\Lorelay\Desktop\MyPC Backup.lnk
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\user.js
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Lorelay\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Lorelay\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [webbooster@iminent.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Schlüssel Gelöscht : HKCU\Software\f6db8ae269eb43
Schlüssel Gelöscht : HKLM\SOFTWARE\f6db8ae269eb43
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02C9C7B0-C7C8-4AAC-A9E4-55295BF60F8F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0398B101-6DA7-473F-A290-17D2FBC88CC0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0CC36196-8589-4B80-A771-D659411D7F90}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{143D96F9-EB64-48B3-B192-91C2C41A1F43}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{14F7D91F-F669-45C9-9F42-BACBFDB86EAD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{187A6488-6E71-4A2A-B118-7BEFBFE58257}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2D065204-A024-4C39-8A38-EE7078EC7ACF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30F5476C-677B-4DB0-B397-51F5BFD86840}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3223F2FB-D9B9-45FC-9D66-CD717FFA4EE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{351798B1-C1D2-45AB-92B4-4D6C2D6AB5AF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3AEA1BEF-6195-46F4-ACA2-0ED14F7EFA1B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3D7F9AC3-BAC3-4E51-81D7-D121D79E550A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4498C5E9-93C6-4142-B6BE-F0C6DC48B77A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{479BF2D6-E362-4A99-B1AB-BC764D7B97AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{492A108F-51D0-4BD8-899D-AD4AB2893064}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4B6D6E60-FBD2-4E79-BF4B-886BC98F1797}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{60893E02-2E5B-43F9-A93A-BAD60C2DF6EF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6D39931F-451E-4BDD-BAF4-37FB96DBBA5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{76C684D2-C35D-4284-976A-D862F53ADB81}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{796D822A-C3F9-4A97-BAAB-42FE7628EA63}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{79EF3691-EC1A-4705-A01A-D2E36EC11758}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82F41418-8E64-47EB-A7F1-4702A974D289}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{85D920CE-63A7-46DC-8992-41D1D2E07FAD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{895ED5E8-ABB4-40C3-A0CA-2571964268E2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8AAC123A-1959-4A45-BFC5-E2D50783098A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A07956CD-81F8-4A03-B524-5D87E690DC83}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B5E3B26B-6E5C-4865-A63D-58D04B10E245}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B84D2DC5-42B2-4E5E-BF61-7B48152FF8EF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B89D5309-0367-4494-A92F-3D4C94F88307}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C014EBF8-8854-448B-B5A4-557C4090EDCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C31191DB-2F64-464C-B97C-6AC81ACB7AAC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C342C7A7-F622-4EF3-8B7F-ABB9FBE73F14}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C4765B07-BC2F-477B-925C-B2BF24887823}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C875C0A1-09E3-48D5-9F8E-BD337796FD14}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD126DA6-FF5B-4181-AC13-54A62240D2FA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DD438708-AAB4-422D-A322-B619589F5680}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E812AE43-7799-4E67-8CF8-4104297A2D16}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F0BAAEC7-9AE0-49FF-9C4B-86E774FF397F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F92193FD-2243-4401-9ACC-49FF30885898}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD21B8A2-910B-45AC-9C10-45E6A8B84984}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ACA608DB-A210-4253-B799-3FD24E9A7BF5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKCU\Software\Iminent
Schlüssel Gelöscht : HKCU\Software\Microsoft\Babylon
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\IePlugin
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : HKLM\Software\supTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\Umbrella
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Tarma Installer
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\482AA67AD25E6E74E9F48BD5FBE8533C
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\482AA67AD25E6E74E9F48BD5FBE8533C
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default\prefs.js ]
Zeile gelöscht : user_pref("avg.install.userHPSettings", "hxxp://search.babylon.com/?affID=109958&tt=4612_5&babsrc=HP_ss&mntrId=d05cfe72000000000000001c4af5625a");
Zeile gelöscht : user_pref("avg.install.userSPSettings", "Search the web (Babylon)");
Zeile gelöscht : user_pref("browser.search.order.1", "Search the web (Babylon)");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "SearchTheWeb");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://search.iminent.com/?appId=932475FC-7416-4A83-9341-C862AD5B7DA2");
Zeile gelöscht : user_pref("extensions.crossrider.bic", "1455cc604f931a1f054fabb0c87cf0d6");
[ Datei : C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\r7mxushs.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.order.1", "Search the web (Babylon)");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "SearchTheWeb");
Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-4&o=APN10261&locale=de_DE&apn_uid=d4a97d28-fddb-49b8-aef5-b9f6e29800ee&apn_ptnrs=%5EAGS&apn_sauid=723C7D07-093F-41FC[...]
-\\ Google Chrome v
[ Datei : C:\Users\Lorelay\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht : homepage
Gelöscht : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [19470 octets] - [14/04/2014 00:03:09]
AdwCleaner[S0].txt - [17844 octets] - [14/04/2014 00:04:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [17905 octets] ##########
JRT: Zitat:
FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 01
Ran by Lorelay (administrator) on Lorelay-PC on 14-04-2014 00:23:20
Running from C:\Users\Lorelay\Downloads
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Adobe Systems Incorporated) D:\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated)
HKLM\...\Run: [Samsung Link] - C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [600928 2014-03-13] (Copyright 2013 SAMSUNG)
HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [LexwareInfoService] - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Run: [EA Core] - "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Lorelay\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\EvernoteClipper.exe (No File)
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-3979088316-405595985-3978638949-1001\User: Group Policy restriction detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: FoxTab - {4DF4AC8C-FFA8-40FF-91F0-EB8389314B78} - C:\Users\Lorelay\AppData\LocalLow\FoxTab\IE\FoxTab.dll No File
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: Google
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: GMX MailCheck - C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default\Extensions\toolbar@gmx.net.xpi [2014-04-13]
FF HKCU\...\Firefox\Extensions: [{372479DD-B552-F0A8-F0E5-EEEEA6602285}] - C:\Program Files (x86)\Re-markit-soft\158.xpi
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Extension: (No Name) - C:\Users\Lorelay\AppData\Local\Google\Chrome\User Data\Default\Extensions\2.0.0.0_0 [2013-01-05]
CHR Extension: (Re-markit) - C:\Users\Lorelay\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc [2014-04-11]
CHR HKLM-x32\...\Chrome\Extension: [pailhpppfllmijejfccffanaigjphjnb] - C:\Users\Lorelay\AppData\LocalLow\FoxTab\CHROME\FoxTab.crx [2014-04-11]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor9.0; D:\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [169408 2010-09-30] (Adobe Systems Incorporated)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [609632 2014-03-13] (Copyright 2013 SAMSUNG)
S2 vosr; C:\Users\Lorelay\AppData\Roaming\VOPackage\VOsrv.exe [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1627520 2009-06-10] (NXP Semiconductors)
R3 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-14 00:18 - 2014-04-14 00:18 - 00000957 _____ () C:\Users\Lorelay\Desktop\JRT.txt
2014-04-14 00:11 - 2014-04-14 00:11 - 00000000 ____D () C:\Windows\ERUNT
2014-04-14 00:10 - 2014-04-14 00:10 - 01016261 _____ (Thisisu) C:\Users\Lorelay\Downloads\JRT.exe
2014-04-14 00:06 - 2014-04-14 00:08 - 00018126 _____ () C:\Users\Lorelay\Desktop\AdwCleaner[S0].txt
2014-04-14 00:02 - 2014-04-14 00:04 - 00000000 ____D () C:\AdwCleaner
2014-04-14 00:00 - 2014-04-14 00:01 - 01426178 _____ () C:\Users\Lorelay\Downloads\adwcleaner.exe
2014-04-13 23:54 - 2014-04-13 23:54 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys
2014-04-13 23:28 - 2014-04-13 23:59 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-13 23:28 - 2014-04-13 23:28 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-04-13 23:28 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-13 23:28 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-13 23:28 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-13 23:27 - 2014-04-13 23:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Lorelay\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-13 22:38 - 2014-04-13 22:38 - 00001271 _____ () C:\Users\Lorelay\Desktop\Revo Uninstaller.lnk
2014-04-13 22:38 - 2014-04-13 22:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-13 22:36 - 2014-04-13 22:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lorelay\Downloads\revosetup95.exe
2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG
2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\.swt
2014-04-13 18:05 - 2014-04-13 18:05 - 00000490 _____ () C:\Users\Lorelay\Desktop\defogger_disable.log
2014-04-13 17:50 - 2014-04-13 17:50 - 00380416 _____ () C:\Users\Lorelay\Downloads\Gmer-19357.exe
2014-04-13 17:49 - 2014-04-13 20:32 - 00039065 _____ () C:\Users\Lorelay\Desktop\Addition.txt
2014-04-13 17:49 - 2014-04-13 20:29 - 00037713 _____ () C:\Users\Lorelay\Desktop\FRST.txt
2014-04-13 17:46 - 2014-04-13 17:46 - 00039075 _____ () C:\Users\Lorelay\Downloads\Addition.txt
2014-04-13 17:45 - 2014-04-14 00:23 - 00012184 _____ () C:\Users\Lorelay\Downloads\FRST.txt
2014-04-13 17:45 - 2014-04-14 00:23 - 00000000 ____D () C:\FRST
2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe
2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log
2014-04-13 17:40 - 2014-04-13 17:40 - 00000000 _____ () C:\Users\Lorelay\defogger_reenable
2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe
2014-04-11 21:19 - 2014-04-11 21:24 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-04-11 21:19 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\com
2014-04-11 21:18 - 2014-04-12 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-04-11 21:18 - 2014-04-11 21:39 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-04-11 21:18 - 2014-04-11 21:19 - 00002846 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2014-04-11 21:18 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2014-04-11 21:18 - 2014-04-11 21:18 - 00001976 _____ () C:\Users\Lorelay\Desktop\Sync Folder.lnk
2014-04-11 21:17 - 2014-04-11 21:19 - 00000322 _____ () C:\Users\Lorelay\AppData\Roaming\aps.uninstall.scan.results
2014-04-11 21:16 - 2014-04-11 21:16 - 01100856 _____ (AnyProtect.com) C:\Users\Lorelay\AppData\Local\nsz6B72.tmp
2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-04-10 20:30 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-10 20:30 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-10 20:30 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-10 20:30 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-10 20:30 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-10 20:30 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-10 20:30 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-10 20:30 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-10 20:30 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-10 20:30 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-10 20:30 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-10 20:30 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-10 20:30 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-10 20:30 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-10 20:29 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-10 20:29 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-06 11:34 - 2014-04-14 00:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG
2014-03-18 19:17 - 2014-03-18 19:18 - 00000000 ____D () C:\Program Files\Samsung
2014-03-18 18:59 - 2014-03-18 19:06 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe
2014-03-18 17:44 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-18 17:44 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-18 17:44 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-18 17:43 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-18 17:43 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-18 17:43 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-18 17:43 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-18 17:43 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-18 17:43 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-18 17:43 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-18 17:43 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-18 17:43 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-18 17:43 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-18 17:43 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-18 17:43 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-18 17:43 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-18 17:43 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-18 17:43 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-18 17:43 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-18 17:43 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-18 17:43 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-18 17:43 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-18 17:43 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-18 17:43 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-18 17:43 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-18 17:43 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-18 17:43 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-18 17:43 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-18 17:43 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-18 17:43 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-18 17:43 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-18 17:43 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-18 17:43 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-18 17:43 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-18 17:43 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-18 17:43 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-18 17:43 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-18 17:43 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-18 17:43 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-18 17:43 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-18 17:43 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-18 17:43 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-18 17:43 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-18 17:43 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
==================== One Month Modified Files and Folders =======
2014-04-14 00:24 - 2014-04-13 17:45 - 00012184 _____ () C:\Users\Lorelay\Downloads\FRST.txt
2014-04-14 00:23 - 2014-04-13 17:45 - 00000000 ____D () C:\FRST
2014-04-14 00:18 - 2014-04-14 00:18 - 00000957 _____ () C:\Users\Lorelay\Desktop\JRT.txt
2014-04-14 00:15 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-14 00:15 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-14 00:11 - 2014-04-14 00:11 - 00000000 ____D () C:\Windows\ERUNT
2014-04-14 00:10 - 2014-04-14 00:10 - 01016261 _____ (Thisisu) C:\Users\Lorelay\Downloads\JRT.exe
2014-04-14 00:08 - 2014-04-14 00:06 - 00018126 _____ () C:\Users\Lorelay\Desktop\AdwCleaner[S0].txt
2014-04-14 00:05 - 2013-01-05 17:18 - 00000266 _____ () C:\Windows\Tasks\AutoKMS.job
2014-04-14 00:05 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-14 00:05 - 2009-07-14 06:51 - 00044588 _____ () C:\Windows\setupact.log
2014-04-14 00:04 - 2014-04-14 00:02 - 00000000 ____D () C:\AdwCleaner
2014-04-14 00:04 - 2014-04-06 11:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-14 00:04 - 2012-10-05 13:37 - 00001018 _____ () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-14 00:04 - 2012-10-05 13:36 - 00000000 ___RD () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-14 00:04 - 2012-10-05 13:32 - 01908279 _____ () C:\Windows\WindowsUpdate.log
2014-04-14 00:01 - 2014-04-14 00:00 - 01426178 _____ () C:\Users\Lorelay\Downloads\adwcleaner.exe
2014-04-13 23:59 - 2014-04-13 23:28 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-13 23:54 - 2014-04-13 23:54 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys
2014-04-13 23:51 - 2012-10-08 17:18 - 00316094 _____ () C:\Windows\PFRO.log
2014-04-13 23:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas
2014-04-13 23:50 - 2014-01-04 14:37 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Dropbox
2014-04-13 23:41 - 2012-11-15 18:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-13 23:28 - 2014-04-13 23:28 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-04-13 23:27 - 2014-04-13 23:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Lorelay\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-13 22:38 - 2014-04-13 22:38 - 00001271 _____ () C:\Users\Lorelay\Desktop\Revo Uninstaller.lnk
2014-04-13 22:38 - 2014-04-13 22:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-13 22:36 - 2014-04-13 22:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lorelay\Downloads\revosetup95.exe
2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG
2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\.swt
2014-04-13 22:25 - 2012-10-05 13:36 - 00000000 ____D () C:\Users\Lorelay
2014-04-13 20:32 - 2014-04-13 17:49 - 00039065 _____ () C:\Users\Lorelay\Desktop\Addition.txt
2014-04-13 20:29 - 2014-04-13 17:49 - 00037713 _____ () C:\Users\Lorelay\Desktop\FRST.txt
2014-04-13 18:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-13 18:05 - 2014-04-13 18:05 - 00000490 _____ () C:\Users\Lorelay\Desktop\defogger_disable.log
2014-04-13 17:50 - 2014-04-13 17:50 - 00380416 _____ () C:\Users\Lorelay\Downloads\Gmer-19357.exe
2014-04-13 17:46 - 2014-04-13 17:46 - 00039075 _____ () C:\Users\Lorelay\Downloads\Addition.txt
2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe
2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log
2014-04-13 17:40 - 2014-04-13 17:40 - 00000000 _____ () C:\Users\Lorelay\defogger_reenable
2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe
2014-04-12 21:19 - 2014-04-11 21:18 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-04-11 23:54 - 2013-01-05 13:21 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Adobe
2014-04-11 23:54 - 2012-11-15 18:42 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-11 23:54 - 2012-10-13 16:59 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-11 23:54 - 2012-10-13 16:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-11 21:39 - 2014-04-11 21:18 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-04-11 21:24 - 2014-04-11 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-04-11 21:19 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\com
2014-04-11 21:19 - 2014-04-11 21:18 - 00002846 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2014-04-11 21:19 - 2014-04-11 21:18 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2014-04-11 21:19 - 2014-04-11 21:17 - 00000322 _____ () C:\Users\Lorelay\AppData\Roaming\aps.uninstall.scan.results
2014-04-11 21:18 - 2014-04-11 21:18 - 00001976 _____ () C:\Users\Lorelay\Desktop\Sync Folder.lnk
2014-04-11 21:16 - 2014-04-11 21:16 - 01100856 _____ (AnyProtect.com) C:\Users\Lorelay\AppData\Local\nsz6B72.tmp
2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-04-11 21:15 - 2013-01-05 13:24 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Mozilla
2014-04-11 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-10 23:33 - 2013-01-05 16:56 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-10 23:32 - 2013-07-24 22:51 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 23:30 - 2013-01-27 19:31 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-09 18:47 - 2012-10-13 17:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-08 21:58 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat
2014-04-08 21:58 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat
2014-04-08 21:58 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-03 09:51 - 2014-04-13 23:28 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-13 23:28 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-13 23:28 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 03:16 - 2014-04-10 20:30 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-10 20:30 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-20 21:07 - 2012-10-05 15:27 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Adobe
2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe
2014-03-20 16:14 - 2009-07-14 06:45 - 00442712 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload
2014-03-18 19:19 - 2012-10-05 14:59 - 00000000 ____D () C:\Users\Lorelay
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG
2014-03-18 19:18 - 2014-03-18 19:17 - 00000000 ____D () C:\Program Files\Samsung
2014-03-18 19:06 - 2014-03-18 18:59 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe
2014-03-18 18:47 - 2013-03-12 13:54 - 00002669 _____ () C:\Users\Public\Desktop\TAXMAN 2013 spezial.lnk
Some content of TEMP:
====================
C:\Users\Lorelay\AppData\Local\Temp\avgnt.exe
C:\Users\Lorelay\AppData\Local\Temp\BackupSetup.exe
C:\Users\Lorelay\AppData\Local\Temp\EAD20D8.exe
C:\Users\Lorelay\AppData\Local\Temp\EAD3C25.exe
C:\Users\Lorelay\AppData\Local\Temp\EAD4A77.exe
C:\Users\Lorelay\AppData\Local\Temp\install_flashplayer11x32_mssd_aih.exe
C:\Users\Lorelay\AppData\Local\Temp\Quarantine.exe
C:\Users\Lorelay\AppData\Local\Temp\sqlite3.exe
C:\Users\Lorelay\AppData\Local\Temp\uninst1.exe
C:\Users\Lorelay\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Lorelay\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Lorelay\AppData\Local\Temp\avgnt.exe
C:\Users\Lorelay\AppData\Local\Temp\i4jdel0.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-09 19:17
==================== End Of Log ============================
--- --- ---[/CODE] Was mache ich mit den installierten Programmen? Und den anderen PCs? Noch mal Vielen Dank Emmaline |
| | #4 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Revo startet immer den programmeigenen Uninstaller, nachdem der durch ist wird nach Resten gesucht. ESET Online Scanner
Downloade Dir bitte
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #5 | ||
![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Sooo, hier die ganzen Ergebnisse: Eset: Zitat:
Zitat:
FRST3: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-04-2014 02
Ran by Lorelay (administrator) on Lorelay-PC on 16-04-2014 22:29:10
Running from C:\Users\Lorelay\Desktop\Säuberungsprogramme
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Adobe Systems Incorporated) D:\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\LxWebAccess\LxWebAccess.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated)
HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [600928 2014-03-13] (Copyright 2013 SAMSUNG)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [LexwareInfoService] => C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3979088316-405595985-3978638949-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Lorelay\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Users\Lorelay\AppData\Local\Apps\Evernote\Evernote\EvernoteClipper.exe (No File)
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-3979088316-405595985-3978638949-1001\User: Group Policy restriction detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: FoxTab - {4DF4AC8C-FFA8-40FF-91F0-EB8389314B78} - C:\Users\Lorelay\AppData\LocalLow\FoxTab\IE\FoxTab.dll No File
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: Google
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: GMX MailCheck - C:\Users\Lorelay\AppData\Roaming\Mozilla\Firefox\Profiles\xpbaw7hi.default\Extensions\toolbar@gmx.net.xpi [2014-04-13]
FF HKCU\...\Firefox\Extensions: [{372479DD-B552-F0A8-F0E5-EEEEA6602285}] - C:\Program Files (x86)\Re-markit-soft\158.xpi
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Extension: (No Name) - C:\Users\Lorelay\AppData\Local\Google\Chrome\User Data\Default\Extensions\2.0.0.0_0 [2013-01-05]
CHR Extension: (Re-markit) - C:\Users\Lorelay\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc [2014-04-11]
CHR HKLM-x32\...\Chrome\Extension: [pailhpppfllmijejfccffanaigjphjnb] - C:\Users\Lorelay\AppData\LocalLow\FoxTab\CHROME\FoxTab.crx [2014-04-11]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor9.0; D:\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [169408 2010-09-30] (Adobe Systems Incorporated)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [609632 2014-03-13] (Copyright 2013 SAMSUNG)
S2 vosr; C:\Users\Lorelay\AppData\Roaming\VOPackage\VOsrv.exe [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-14] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1627520 2009-06-10] (NXP Semiconductors)
R3 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-16 22:17 - 2014-04-16 22:17 - 00000813 _____ () C:\Users\Lorelay\Desktop\checkup.txt
2014-04-16 20:30 - 2014-04-16 20:30 - 02347384 _____ (ESET) C:\Users\Lorelay\Downloads\esetsmartinstaller_enu.exe
2014-04-14 00:40 - 2014-04-16 22:29 - 00000000 ____D () C:\Users\Lorelay\Desktop\Säuberungsprogramme
2014-04-14 00:25 - 2014-04-14 00:25 - 00000932 _____ () C:\Users\Lorelay\Desktop\Evernote.lnk
2014-04-14 00:25 - 2014-04-14 00:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Evernote
2014-04-14 00:25 - 2014-04-14 00:25 - 00000000 ____D () C:\Program Files (x86)\Evernote
2014-04-14 00:11 - 2014-04-14 00:11 - 00000000 ____D () C:\Windows\ERUNT
2014-04-14 00:10 - 2014-04-14 00:10 - 01016261 _____ (Thisisu) C:\Users\Lorelay\Downloads\JRT.exe
2014-04-14 00:02 - 2014-04-14 00:04 - 00000000 ____D () C:\AdwCleaner
2014-04-14 00:00 - 2014-04-14 00:01 - 01426178 _____ () C:\Users\Lorelay\Downloads\adwcleaner.exe
2014-04-13 23:54 - 2014-04-13 23:54 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys
2014-04-13 23:28 - 2014-04-14 00:30 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-04-13 23:28 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-13 23:28 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-13 23:28 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-13 23:27 - 2014-04-13 23:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Lorelay\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-13 22:38 - 2014-04-13 22:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-13 22:36 - 2014-04-13 22:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lorelay\Downloads\revosetup95.exe
2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG
2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\.swt
2014-04-13 18:05 - 2014-04-13 18:05 - 00000490 _____ () C:\Users\Lorelay\Desktop\defogger_disable.log
2014-04-13 17:50 - 2014-04-13 17:50 - 00380416 _____ () C:\Users\Lorelay\Downloads\Gmer-19357.exe
2014-04-13 17:49 - 2014-04-13 20:32 - 00039065 _____ () C:\Users\Lorelay\Desktop\Addition.txt
2014-04-13 17:49 - 2014-04-13 20:29 - 00037713 _____ () C:\Users\Lorelay\Desktop\FRST.txt
2014-04-13 17:46 - 2014-04-13 17:46 - 00039075 _____ () C:\Users\Lorelay\Downloads\Addition.txt
2014-04-13 17:45 - 2014-04-16 22:29 - 00000000 ____D () C:\FRST
2014-04-13 17:45 - 2014-04-14 00:25 - 00035216 _____ () C:\Users\Lorelay\Downloads\FRST.txt
2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe
2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log
2014-04-13 17:40 - 2014-04-13 17:40 - 00000000 _____ () C:\Users\Lorelay\defogger_reenable
2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe
2014-04-11 21:19 - 2014-04-11 21:24 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-04-11 21:19 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\com
2014-04-11 21:18 - 2014-04-12 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-04-11 21:18 - 2014-04-11 21:39 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-04-11 21:18 - 2014-04-11 21:19 - 00002846 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2014-04-11 21:18 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2014-04-11 21:18 - 2014-04-11 21:18 - 00001976 _____ () C:\Users\Lorelay\Desktop\Sync Folder.lnk
2014-04-11 21:17 - 2014-04-11 21:19 - 00000322 _____ () C:\Users\Lorelay\AppData\Roaming\aps.uninstall.scan.results
2014-04-11 21:16 - 2014-04-11 21:16 - 01100856 _____ (AnyProtect.com) C:\Users\Lorelay\AppData\Local\nsz6B72.tmp
2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-04-10 20:30 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-10 20:30 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-10 20:30 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-10 20:30 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-10 20:30 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-10 20:30 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-10 20:30 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-10 20:30 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-10 20:30 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-10 20:30 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-10 20:30 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-10 20:30 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-10 20:30 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-10 20:30 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-10 20:30 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-10 20:29 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-10 20:29 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-06 11:34 - 2014-04-14 00:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG
2014-03-18 19:17 - 2014-03-18 19:18 - 00000000 ____D () C:\Program Files\Samsung
2014-03-18 18:59 - 2014-03-18 19:06 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe
2014-03-18 17:44 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-18 17:44 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-18 17:44 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-18 17:43 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-18 17:43 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-18 17:43 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-18 17:43 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-18 17:43 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-18 17:43 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-18 17:43 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-18 17:43 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-18 17:43 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-18 17:43 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-18 17:43 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-18 17:43 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-18 17:43 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-18 17:43 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-18 17:43 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-18 17:43 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-18 17:43 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-18 17:43 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-18 17:43 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-18 17:43 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-18 17:43 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-18 17:43 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-18 17:43 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-18 17:43 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-18 17:43 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-18 17:43 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-18 17:43 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-18 17:43 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-18 17:43 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-18 17:43 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-18 17:43 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-18 17:43 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-18 17:43 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-18 17:43 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-18 17:43 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-18 17:43 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-18 17:43 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-18 17:43 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-18 17:43 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-18 17:43 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-18 17:43 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
==================== One Month Modified Files and Folders =======
2014-04-16 22:29 - 2014-04-14 00:40 - 00000000 ____D () C:\Users\Lorelay\Desktop\Säuberungsprogramme
2014-04-16 22:29 - 2014-04-13 17:45 - 00000000 ____D () C:\FRST
2014-04-16 22:26 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-16 22:26 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-16 22:17 - 2014-04-16 22:17 - 00000813 _____ () C:\Users\Lorelay\Desktop\checkup.txt
2014-04-16 21:41 - 2012-11-15 18:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-16 20:30 - 2014-04-16 20:30 - 02347384 _____ (ESET) C:\Users\Lorelay\Downloads\esetsmartinstaller_enu.exe
2014-04-16 20:18 - 2012-10-05 13:32 - 01931852 _____ () C:\Windows\WindowsUpdate.log
2014-04-16 20:13 - 2013-01-05 17:18 - 00000266 _____ () C:\Windows\Tasks\AutoKMS.job
2014-04-16 20:13 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-16 20:13 - 2009-07-14 06:51 - 00044644 _____ () C:\Windows\setupact.log
2014-04-14 00:30 - 2014-04-13 23:28 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-14 00:25 - 2014-04-14 00:25 - 00000932 _____ () C:\Users\Lorelay\Desktop\Evernote.lnk
2014-04-14 00:25 - 2014-04-14 00:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Evernote
2014-04-14 00:25 - 2014-04-14 00:25 - 00000000 ____D () C:\Program Files (x86)\Evernote
2014-04-14 00:25 - 2014-04-13 17:45 - 00035216 _____ () C:\Users\Lorelay\Downloads\FRST.txt
2014-04-14 00:11 - 2014-04-14 00:11 - 00000000 ____D () C:\Windows\ERUNT
2014-04-14 00:10 - 2014-04-14 00:10 - 01016261 _____ (Thisisu) C:\Users\Lorelay\Downloads\JRT.exe
2014-04-14 00:04 - 2014-04-14 00:02 - 00000000 ____D () C:\AdwCleaner
2014-04-14 00:04 - 2014-04-06 11:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-14 00:04 - 2012-10-05 13:37 - 00001018 _____ () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-14 00:04 - 2012-10-05 13:36 - 00000000 ___RD () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-14 00:01 - 2014-04-14 00:00 - 01426178 _____ () C:\Users\Lorelay\Downloads\adwcleaner.exe
2014-04-13 23:54 - 2014-04-13 23:54 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys
2014-04-13 23:51 - 2012-10-08 17:18 - 00316094 _____ () C:\Windows\PFRO.log
2014-04-13 23:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas
2014-04-13 23:50 - 2014-01-04 14:37 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Dropbox
2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-13 23:28 - 2014-04-13 23:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-04-13 23:27 - 2014-04-13 23:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Lorelay\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-13 22:38 - 2014-04-13 22:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-13 22:36 - 2014-04-13 22:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lorelay\Downloads\revosetup95.exe
2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG
2014-04-13 22:25 - 2014-04-13 22:25 - 00000000 ____D () C:\Users\Lorelay\.swt
2014-04-13 22:25 - 2012-10-05 13:36 - 00000000 ____D () C:\Users\Lorelay
2014-04-13 20:32 - 2014-04-13 17:49 - 00039065 _____ () C:\Users\Lorelay\Desktop\Addition.txt
2014-04-13 20:29 - 2014-04-13 17:49 - 00037713 _____ () C:\Users\Lorelay\Desktop\FRST.txt
2014-04-13 18:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-13 18:05 - 2014-04-13 18:05 - 00000490 _____ () C:\Users\Lorelay\Desktop\defogger_disable.log
2014-04-13 17:50 - 2014-04-13 17:50 - 00380416 _____ () C:\Users\Lorelay\Downloads\Gmer-19357.exe
2014-04-13 17:46 - 2014-04-13 17:46 - 00039075 _____ () C:\Users\Lorelay\Downloads\Addition.txt
2014-04-13 17:44 - 2014-04-13 17:44 - 02157568 _____ (Farbar) C:\Users\Lorelay\Downloads\FRST64.exe
2014-04-13 17:40 - 2014-04-13 17:40 - 00000488 _____ () C:\Users\Lorelay\Downloads\defogger_disable.log
2014-04-13 17:40 - 2014-04-13 17:40 - 00000000 _____ () C:\Users\Lorelay\defogger_reenable
2014-04-13 17:37 - 2014-04-13 17:37 - 00050477 _____ () C:\Users\Lorelay\Downloads\Defogger.exe
2014-04-12 21:19 - 2014-04-11 21:18 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-04-11 23:54 - 2013-01-05 13:21 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Adobe
2014-04-11 23:54 - 2012-11-15 18:42 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-11 23:54 - 2012-10-13 16:59 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-11 23:54 - 2012-10-13 16:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-11 21:39 - 2014-04-11 21:18 - 00000380 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-04-11 21:24 - 2014-04-11 21:19 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-04-11 21:19 - 2014-04-11 21:19 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2014-04-11 21:19 - 2014-04-11 21:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\com
2014-04-11 21:19 - 2014-04-11 21:18 - 00002846 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2014-04-11 21:19 - 2014-04-11 21:18 - 00002844 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2014-04-11 21:19 - 2014-04-11 21:17 - 00000322 _____ () C:\Users\Lorelay\AppData\Roaming\aps.uninstall.scan.results
2014-04-11 21:18 - 2014-04-11 21:18 - 00001976 _____ () C:\Users\Lorelay\Desktop\Sync Folder.lnk
2014-04-11 21:16 - 2014-04-11 21:16 - 01100856 _____ (AnyProtect.com) C:\Users\Lorelay\AppData\Local\nsz6B72.tmp
2014-04-11 21:15 - 2014-04-11 21:15 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-04-11 21:15 - 2013-01-05 13:24 - 00000000 ____D () C:\Users\Lorelay\AppData\Local\Mozilla
2014-04-11 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-10 23:33 - 2013-01-05 16:56 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-10 23:32 - 2013-07-24 22:51 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 23:30 - 2013-01-27 19:31 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-09 18:47 - 2012-10-13 17:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-08 21:58 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat
2014-04-08 21:58 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat
2014-04-08 21:58 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-03 09:51 - 2014-04-13 23:28 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-13 23:28 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-13 23:28 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 03:16 - 2014-04-10 20:30 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-10 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-10 20:30 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-20 21:07 - 2012-10-05 15:27 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Adobe
2014-03-20 21:06 - 2014-03-20 21:06 - 00000000 ____D () C:\Users\Lorelay\Documents\Adobe
2014-03-20 16:14 - 2009-07-14 06:45 - 00442712 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\Samsung Link
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Samsung
2014-03-18 19:19 - 2014-03-18 19:19 - 00000000 ____D () C:\Upload
2014-03-18 19:19 - 2012-10-05 14:59 - 00000000 ____D () C:\Users\Lorelay
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\AppData\Roaming\SAMSUNG
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\Users\Lorelay\.swt
2014-03-18 19:18 - 2014-03-18 19:18 - 00000000 ____D () C:\ProgramData\SAMSUNG
2014-03-18 19:18 - 2014-03-18 19:17 - 00000000 ____D () C:\Program Files\Samsung
2014-03-18 19:06 - 2014-03-18 18:59 - 90675040 _____ (Copyright 2013 SAMSUNG) C:\Users\Lorelay\Downloads\SamsungLink_Installer64.exe
2014-03-18 18:47 - 2013-03-12 13:54 - 00002669 _____ () C:\Users\Public\Desktop\TAXMAN 2013 spezial.lnk
Some content of TEMP:
====================
C:\Users\Lorelay\AppData\Local\Temp\avgnt.exe
C:\Users\Lorelay\AppData\Local\Temp\BackupSetup.exe
C:\Users\Lorelay\AppData\Local\Temp\EAD20D8.exe
C:\Users\Lorelay\AppData\Local\Temp\EAD3C25.exe
C:\Users\Lorelay\AppData\Local\Temp\EAD4A77.exe
C:\Users\Lorelay\AppData\Local\Temp\install_flashplayer11x32_mssd_aih.exe
C:\Users\Lorelay\AppData\Local\Temp\Quarantine.exe
C:\Users\Lorelay\AppData\Local\Temp\sqlite3.exe
C:\Users\Lorelay\AppData\Local\Temp\uninst1.exe
C:\Users\Lorelay\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Lorelay\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Lorelay\AppData\Local\Temp\avgnt.exe
C:\Users\Lorelay\AppData\Local\Temp\i4jdel0.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-09 19:17
==================== End Of Log ============================
Kann ich irgendwo finden nach was die einzelen Scanner eigentlich suchen und was die einzelnen Programme eigentlich machen? Und mach ich das alles jetzt auch mit meinen anderen befallenen PCs? Mein Werbungsproblem ist übriges nicht mehr aufgetaucht. Eine Idee wie ich verhindern kann das es wieder passiert? Übringens, schöne Feierrtage ![]() Emmaline |
| | #6 | |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Java updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\$Recycle.Bin
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Von den anderen Rechnern bitte FRST Logs, nix auf eigene Faust machen. Zitat:
![]() Für hier: Fertig ![]() Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun ![]() Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) |
| | #7 | |
![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Guten Morgen und einen schönen Feiertag Die Fixlog.txt vom Rechner Lorelay ist beim kopieren gelöscht worden (kann sie auf jeden Fall nicht finden). Macht es Sinn sie nochmal zu machen? Und hier wäre die FRST vom zweiten Rechner: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01
Ran by Acidfree (administrator) on ACIDFREE-PC on 18-04-2014 10:06:38
Running from C:\Users\Acidfree\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Adobe Systems Incorporated) E:\Photoshop\PhotoshopElementsFileAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
() C:\Windows\system32\dmwu.exe
() C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
( ) C:\Windows\system32\lxczcoms.exe
() C:\Program Files (x86)\Re-Markable-soft\Re-MarkableyfYnIw.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(ICQ, LLC.) D:\ICQ7.5\ICQ.exe
(Spotify Ltd) C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Spotify Ltd) C:\Users\Acidfree\AppData\Roaming\Spotify\spotify.exe
() C:\Program Files (x86)\FastMediaConverter\FastMediaConverterApp.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(Nullsoft, Inc.) D:\Winamp\winampa.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
() C:\Windows\SysWOW64\jmdp\stij.exe
() C:\Windows\System32\ljkb\stij.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Program Files (x86)\Re-Markable-soft\Re-MarkableyfY158.exe
() C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [DATAMNGR] => C:\PROGRA~2\WIF0E7~1\Datamngr\DATAMN~1.EXE
HKLM-x32\...\Run: [WinampAgent] => D:\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.)
HKLM-x32\...\Run: [Sweetpacks Communicator] => C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1801168 2014-03-26] (APN)
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563608 2014-01-15] (SUPERAntiSpyware)
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [ICQ] => D:\ICQ7.5\ICQ.exe [124480 2011-08-01] (ICQ, LLC.)
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [RegistryBooster] => "C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe" delay 20000
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Hoolapp Android] => /Minimized
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify Web Helper] => C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-11] (Spotify Ltd)
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify] => C:\Users\Acidfree\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-11] (Spotify Ltd)
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [BackgroundContainer] => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Acidfree\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun <===== ATTENTION
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {237ce8bd-cee5-11e0-b0cf-00242178af47} - J:\Startme.exe
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {2518b13b-372c-11e2-87e8-00242178af47} - G:\pushinst.exe
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {5738becf-f4ff-11e1-8895-806e6f6e6963} - explorer index_GB.html
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {afbc22a3-b183-11e1-b4a9-00242178af47} - G:\Setup.exe
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found
AppInit_DLLs: C:\PROGRA~2\WIF0E7~1\Datamngr\x64\datamngr.dll => C:\PROGRA~2\WIF0E7~1\Datamngr\x64\datamngr.dll File Not Found
AppInit_DLLs: C:\PROGRA~2\WIF0E7~1\Datamngr\x64\IEBHO.dll => C:\PROGRA~2\WIF0E7~1\Datamngr\x64\IEBHO.dll File Not Found
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => "C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll" File Not Found
AppInit_DLLs-x32: C:\PROGRA~2\WIF0E7~1\Datamngr\datamngr.dll => "C:\PROGRA~2\WIF0E7~1\Datamngr\datamngr.dll" File Not Found
AppInit_DLLs-x32: C:\PROGRA~2\WIF0E7~1\Datamngr\IEBHO.dll => "C:\PROGRA~2\WIF0E7~1\Datamngr\IEBHO.dll" File Not Found
Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:13828
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP34726308-2245-48C4-BB2E-DE4CA8A513E2&SSPV=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x449DEC206E54CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM-x32 - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
URLSearchHook: HKLM-x32 - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
URLSearchHook: HKCU - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=102&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=102&q={searchTerms}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=102&q={searchTerms}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10025&barid={693EDBF0-504A-11E2-98FC-00242178AF47}
SearchScopes: HKCU - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=102&q={searchTerms}
SearchScopes: HKCU - {A4A37A65-E638-486B-831A-5511E241A09C} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=e25bf9d6-fd67-46ac-bdc0-90268edc5315&apn_sauid=8373C6D9-B47B-4A5A-890A-29C5D75D99F7
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://mysearch.sweetpacks.com?src=6&q={searchTerms}&barid=&&st=23
BHO: UrlHelper Class - {41C4AA37-1DDD-4345-B8DC-734E4B38414D} - C:\PROGRA~2\WIF0E7~1\Datamngr\x64\IEBHO.dll No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: jZip Toolbar - {1e48c56f-08cd-43aa-a6ef-c1ec891551ab} - C:\PROGRA~2\WIF0E7~1\Datamngr\ToolBar\jzipdtx.dll No File
BHO-x32: UrlHelper Class - {41C4AA37-1DDD-4345-B8DC-734E4B38414D} - C:\PROGRA~2\WIF0E7~1\Datamngr\IEBHO.dll No File
BHO-x32: ICQ Sparberater - {5A0D6E4B-B0DF-4148-8B1E-F7A430FF5E24} - C:\Program Files (x86)\icq\Internet Explorer\icq.dll (solute gmbh)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
BHO-x32: DealPly - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly Technologies Ltd)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKLM-x32 - jZip Toolbar - {1e48c56f-08cd-43aa-a6ef-c1ec891551ab} - C:\PROGRA~2\WIF0E7~1\Datamngr\ToolBar\jzipdtx.dll No File
Toolbar: HKLM-x32 - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default
FF user.js: detected! => C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\user.js
FF NewTab: hxxp://www.sweetpacks-search.com/?barid=&src=97&&st=23
FF DefaultSearchEngine: ICQ Search
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: ICQ Search
FF Homepage: hxxp://www.sweetpacks-search.com/?barid=&src=10&&st=23
FF Keyword.URL: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&CUI=UN95533741736100730&UM=&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.10.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\11-suche.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\askcomsearch.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-1.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-10.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-11.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-12.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-13.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-14.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-15.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-16.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-17.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-18.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-19.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-2.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-20.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-21.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-22.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-23.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-24.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-25.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-26.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-27.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-28.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-29.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-3.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-30.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-4.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-5.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-6.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-7.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-8.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-9.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin.gif
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin.src
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\MyStart Search.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\MyStart.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\SearchResults.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\Sweetpacks Search.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DVDVideoSoftTB - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2013-11-20]
FF Extension: Evernote Web Clipper - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} [2013-12-19]
FF Extension: DivX Web Player - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\DivXWebPlayer@divx.com.xpi [2012-03-01]
FF Extension: GMX MailCheck - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar@gmx.net.xpi [2012-05-04]
FF Extension: Ask Toolbar - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-02-25]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-19]
FF HKCU\...\Firefox\Extensions: [{9A963233-37BD-837B-48FF-3AD40489A05D}] - C:\Program Files (x86)\Re-Markable-soft\158.xpi
FF Extension: Re-Markable - C:\Program Files (x86)\Re-Markable-soft\158.xpi [2014-04-13]
Chrome:
=======
CHR HomePage: hxxp://search.jzip.com/
CHR RestoreOnStartup: "hxxp://search.jzip.com/"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll (Skype Technologies S.A.)
CHR Plugin: (registryAccess) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj\7.15.1.0_0\background/registryAccess.dll (APN)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Unity Player) - C:\Users\Acidfree\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File
CHR Extension: (Avira Toolbar) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj [2012-09-02]
CHR Extension: (Re-Markable) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc [2014-04-13]
CHR Extension: (Skype Click to Call) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2011-08-19]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-03-11]
CHR HKCU\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [2012-10-21]
CHR HKLM-x32\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [2012-10-21]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-10-10]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-09-12] (SUPERAntiSpyware.com)
R2 AdobeActiveFileMonitor7.0; E:\Photoshop\PhotoshopElementsFileAgent.exe [169312 2008-09-16] (Adobe Systems Incorporated)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-03-26] (APN LLC.)
R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1859376 2014-02-04] ()
R2 ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [247608 2010-11-21] ()
R2 lxcz_device; C:\Windows\system32\lxczcoms.exe [566192 2007-04-19] ( )
R2 lxcz_device; C:\Windows\SysWOW64\lxczcoms.exe [537520 2007-04-19] ( )
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 Re-Markable; C:\Program Files (x86)\Re-Markable-soft\Re-MarkableyfY158.exe [143360 2014-04-13] ()
S2 CltMngSvc; C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe [X]
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2013-03-07] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [9584 2013-03-07] ()
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-18 10:02 - 2014-04-18 10:02 - 00027723 _____ () C:\Users\Acidfree\Desktop\Addition.txt
2014-04-18 10:00 - 2014-04-18 10:07 - 00029185 _____ () C:\Users\Acidfree\Desktop\FRST.txt
2014-04-18 10:00 - 2014-04-18 10:06 - 00000000 ____D () C:\FRST
2014-04-18 10:00 - 2014-04-18 09:59 - 02158592 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe
2014-04-15 05:13 - 2014-04-18 07:12 - 00003388 _____ () C:\Windows\System32\Tasks\BackgroundContainer Startup Task
2014-04-13 17:56 - 2012-11-04 14:42 - 00001866 _____ () C:\Users\Acidfree\Desktop\SUPERAntiSpyware Free Edition.lnk
2014-04-13 16:52 - 2014-04-18 07:15 - 00000424 _____ () C:\Windows\Tasks\Re-Markable Update.job
2014-04-13 16:52 - 2014-04-13 16:52 - 00003078 _____ () C:\Windows\System32\Tasks\Re-Markable Update
2014-04-13 16:51 - 2014-04-18 09:59 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter
2014-04-13 16:51 - 2014-04-18 07:12 - 00000414 _____ () C:\Windows\Tasks\Re-Markable_wd.job
2014-04-13 16:51 - 2014-04-13 16:52 - 00000000 ____D () C:\Program Files (x86)\Re-Markable-soft
2014-04-13 16:51 - 2014-04-13 16:51 - 00003008 _____ () C:\Windows\System32\Tasks\Re-Markable_wd
2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk
2014-04-13 16:51 - 2014-04-13 16:51 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter
2014-04-09 07:24 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-09 07:24 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-09 07:24 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-09 07:24 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-09 07:24 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 07:24 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 07:24 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 07:24 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 07:24 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 07:24 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 07:24 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 07:24 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 07:24 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 07:24 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 07:24 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 07:24 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 07:24 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 07:24 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 07:24 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 07:24 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 07:24 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\APN
2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork
2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-03-19 14:03 - 2014-03-19 14:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2014-04-18 10:07 - 2014-04-18 10:00 - 00029185 _____ () C:\Users\Acidfree\Desktop\FRST.txt
2014-04-18 10:06 - 2014-04-18 10:00 - 00000000 ____D () C:\FRST
2014-04-18 10:06 - 2012-11-02 09:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-18 10:04 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-18 10:04 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-18 10:02 - 2014-04-18 10:02 - 00027723 _____ () C:\Users\Acidfree\Desktop\Addition.txt
2014-04-18 09:59 - 2014-04-18 10:00 - 02158592 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe
2014-04-18 09:59 - 2014-04-13 16:51 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter
2014-04-18 09:27 - 2011-08-19 21:27 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-18 09:26 - 2014-02-15 19:26 - 00000304 _____ () C:\Windows\Tasks\Hoolapp For Android.job
2014-04-18 08:57 - 2011-08-06 20:48 - 01158927 _____ () C:\Windows\WindowsUpdate.log
2014-04-18 07:42 - 2013-02-01 22:32 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Spotify
2014-04-18 07:15 - 2014-04-13 16:52 - 00000424 _____ () C:\Windows\Tasks\Re-Markable Update.job
2014-04-18 07:12 - 2014-04-15 05:13 - 00003388 _____ () C:\Windows\System32\Tasks\BackgroundContainer Startup Task
2014-04-18 07:12 - 2014-04-13 16:51 - 00000414 _____ () C:\Windows\Tasks\Re-Markable_wd.job
2014-04-18 07:12 - 2014-02-15 19:26 - 00000292 _____ () C:\Windows\Tasks\Hoolapp Init.job
2014-04-18 07:12 - 2011-09-16 05:04 - 00135339 _____ () C:\Windows\setupact.log
2014-04-18 07:12 - 2011-08-19 21:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-18 07:12 - 2011-08-07 10:03 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\ICQ
2014-04-18 07:12 - 2011-08-06 21:24 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-04-18 07:12 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-17 18:25 - 2012-12-27 19:25 - 00000000 ____D () C:\Program Files (x86)\DealPly
2014-04-14 17:29 - 2013-02-01 22:33 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Spotify
2014-04-14 04:21 - 2012-11-02 09:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-14 04:21 - 2012-10-03 13:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-14 04:21 - 2011-08-22 10:13 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Adobe
2014-04-14 04:21 - 2011-08-07 08:14 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-13 16:52 - 2014-04-13 16:52 - 00003078 _____ () C:\Windows\System32\Tasks\Re-Markable Update
2014-04-13 16:52 - 2014-04-13 16:51 - 00000000 ____D () C:\Program Files (x86)\Re-Markable-soft
2014-04-13 16:51 - 2014-04-13 16:51 - 00003008 _____ () C:\Windows\System32\Tasks\Re-Markable_wd
2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk
2014-04-13 16:51 - 2014-04-13 16:51 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter
2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-10 03:57 - 2013-05-23 19:02 - 00000000 ____D () C:\Windows\rescache
2014-04-10 03:02 - 2013-07-24 21:34 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 03:01 - 2011-12-12 08:37 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\APN
2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork
2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-06 17:17 - 2012-09-13 16:16 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-06 17:17 - 2011-12-01 08:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-06 17:17 - 2011-12-01 08:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-06 17:17 - 2011-08-17 16:40 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-04 16:00 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat
2014-04-04 16:00 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat
2014-04-04 16:00 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-31 18:50 - 2013-12-18 19:25 - 00000202 _____ () C:\Users\Acidfree\AppData\Roaming\WB.CFG
2014-03-31 03:16 - 2014-04-09 07:24 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-09 07:24 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-22 09:48 - 2011-10-20 17:38 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Winamp
2014-03-20 17:09 - 2012-05-03 20:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-19 14:03 - 2014-03-19 14:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
Files to move or delete:
====================
C:\ProgramData\nud0repor.pad
Some content of TEMP:
====================
C:\Users\Acidfree\AppData\Local\Temp\APNSetup.exe
C:\Users\Acidfree\AppData\Local\Temp\avgnt.exe
C:\Users\Acidfree\AppData\Local\Temp\DWPUpgradeInstaller.exe
C:\Users\Acidfree\AppData\Local\Temp\InstallFlashPlayer.exe
C:\Users\Acidfree\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Acidfree\AppData\Local\Temp\nsd5F7B.exe
C:\Users\Acidfree\AppData\Local\Temp\nsd623A.exe
C:\Users\Acidfree\AppData\Local\Temp\nsn9DE5.exe
C:\Users\Acidfree\AppData\Local\Temp\nsnA056.exe
C:\Users\Acidfree\AppData\Local\Temp\setup.exe
C:\Users\Acidfree\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-09 06:09
==================== End Of Log ============================
--- --- --- --- --- --- Und die Addition: Zitat:
Danke für die Hilfe, gibt ja leider keine Ostereier als Smilies :-) Liebe Grüße Emmaline Schreib ich auf die Liste der Dinge die ich machen will, wenn meine Kinder größer sind. So uninteressant finde ich das gar nicht :-) |
| | #8 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Gerne, ich bin dann warscheinlich immer noch hier ![]() Revo Uninstaller - Download - Filepony Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION Mit Revo auch Moderat die Reste entfernen lassen. Downloade Dir bitte
Downloade Dir bitte
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #9 |
![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Hallo, ich hab da leider ein Problem. Ich konnte nur die "Installed Progamms" mit "ATTENTION"-Vermerk löschen. Es gibt aber noch einige "Tasks" mit dem Vermerk und die konnte ich nicht löschen. Das andere Problem ist, dass die Malware immer an der gleichen Stelle hängen bleibt und daraufhin der PC abstürzt. Das ist jetzt 3x passiert. Die 2x, die ich den Vorgang beobachtet habe, blieb das Programm an der gleichen Stelle hängen. Eine Audiodatei auf dem Desktop. Was soll ich jetzt machen. Frohe Ostern Emmaline |
| | #10 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Tasks und MBAM weglassen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #11 | ||
![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Sooo, hab die Audiodatei gelöscht und dann ging alles. Hier die ganzen Files Zitat:
Zitat:
FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2014 Ran by Acidfree (administrator) on ACIDFREE-PC on 20-04-2014 14:07:43 Running from C:\Users\Acidfree\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Adobe Systems Incorporated) E:\Photoshop\PhotoshopElementsFileAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe ( ) C:\Windows\system32\lxczcoms.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Spotify Ltd) C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Program Files (x86)\FastMediaConverter\FastMediaConverterApp.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Nullsoft, Inc.) D:\Winamp\winampa.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [WinampAgent] => D:\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [ICQ] => D:\ICQ7.5\ICQ.exe [124480 2011-08-01] (ICQ, LLC.) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Hoolapp Android] => /Minimized HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify Web Helper] => C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-11] (Spotify Ltd) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify] => C:\Users\Acidfree\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-11] (Spotify Ltd) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [PrivacyDr] => C:\Program Files (x86)\Privacy Dr\PrivacyDr.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {237ce8bd-cee5-11e0-b0cf-00242178af47} - J:\Startme.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {2518b13b-372c-11e2-87e8-00242178af47} - G:\pushinst.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {5738becf-f4ff-11e1-8895-806e6f6e6963} - explorer index_GB.html HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {afbc22a3-b183-11e1-b4a9-00242178af47} - G:\Setup.exe Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x449DEC206E54CC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} StartMenuInternet: IEXPLORE.EXE - iexplore.exe BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: ICQ Sparberater - {5A0D6E4B-B0DF-4148-8B1E-F7A430FF5E24} - C:\Program Files (x86)\icq\Internet Explorer\icq.dll (solute gmbh) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default FF NewTab: chrome://quick_start/content/index.html FF SearchEngineOrder.1: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.10.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-26.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-27.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-28.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-29.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-30.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Evernote Web Clipper - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} [2013-12-19] FF Extension: DivX Web Player - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\DivXWebPlayer@divx.com.xpi [2012-03-01] FF Extension: GMX MailCheck - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar@gmx.net.xpi [2012-05-04] FF Extension: Ask Toolbar - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-02-25] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-19] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll No File CHR Plugin: (Skype Toolbars) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll (Skype Technologies S.A.) CHR Plugin: (registryAccess) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj\7.15.1.0_0\background/registryAccess.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Unity Player) - C:\Users\Acidfree\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Extension: (No Name) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj [2012-09-02] CHR Extension: (Skype Click to Call) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2011-08-19] CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-03-11] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-10-10] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AdobeActiveFileMonitor7.0; E:\Photoshop\PhotoshopElementsFileAgent.exe [169312 2008-09-16] (Adobe Systems Incorporated) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-03-26] (APN LLC.) R2 lxcz_device; C:\Windows\system32\lxczcoms.exe [566192 2007-04-19] ( ) R2 lxcz_device; C:\Windows\SysWOW64\lxczcoms.exe [537520 2007-04-19] ( ) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.) S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S2 vosr; C:\Users\Acidfree\AppData\Roaming\VOPackage\VOsrv.exe [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [119512 2014-04-20] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2013-03-07] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [9584 2013-03-07] () S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-20 14:07 - 2014-04-20 14:07 - 00000000 ____D () C:\Users\Acidfree\Desktop\FRST-OlderVersion 2014-04-20 13:57 - 2014-04-20 14:04 - 00002052 _____ () C:\Users\Acidfree\Desktop\JRT.txt 2014-04-20 13:49 - 2014-04-20 13:49 - 01016261 _____ (Thisisu) C:\Users\Acidfree\Desktop\JRT.exe 2014-04-20 13:49 - 2014-04-20 13:49 - 00000000 ____D () C:\Windows\ERUNT 2014-04-20 13:48 - 2014-04-20 13:48 - 00123323 _____ () C:\Users\Acidfree\Desktop\AdwCleaner[S0].txt 2014-04-20 13:17 - 2014-04-20 13:24 - 00000000 ____D () C:\AdwCleaner 2014-04-20 13:17 - 2014-04-20 13:16 - 01308369 _____ () C:\Users\Acidfree\Desktop\adwcleaner.exe 2014-04-20 13:00 - 2014-04-20 13:00 - 00003654 _____ () C:\Users\Acidfree\Desktop\mbam.txt 2014-04-19 21:55 - 2014-04-19 21:55 - 423694260 _____ () C:\Windows\MEMORY.DMP 2014-04-19 21:55 - 2014-04-19 21:55 - 00298800 _____ () C:\Windows\Minidump\041914-17659-01.dmp 2014-04-19 21:13 - 2014-04-20 13:37 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 21:13 - 2014-04-19 21:13 - 00001116 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 21:13 - 2014-04-19 21:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 21:13 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-19 21:13 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-19 21:13 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-19 20:51 - 2014-04-19 20:51 - 00001278 _____ () C:\Users\Acidfree\Desktop\Revo Uninstaller.lnk 2014-04-19 20:51 - 2014-04-19 20:51 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-18 12:01 - 2014-04-18 14:47 - 00003368 _____ () C:\Windows\System32\Tasks\PrivacyDr_Splash 2014-04-18 12:01 - 2014-04-18 12:03 - 00000000 ____D () C:\Users\Acidfree\Documents\PrivacyDr 2014-04-18 12:01 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\HistoryCleaner 2014-04-18 11:58 - 2014-04-18 11:58 - 01097384 _____ (AnyProtect.com) C:\Users\Acidfree\AppData\Local\nsvD72C.tmp 2014-04-18 10:11 - 2014-04-18 10:11 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Evernote 2014-04-18 10:10 - 2014-04-18 10:10 - 00000932 _____ () C:\Users\Acidfree\Desktop\Evernote.lnk 2014-04-18 10:10 - 2014-04-18 10:10 - 00000000 ____D () C:\Program Files (x86)\Evernote 2014-04-18 10:02 - 2014-04-18 10:08 - 00027724 _____ () C:\Users\Acidfree\Desktop\Addition.txt 2014-04-18 10:00 - 2014-04-20 14:07 - 02055680 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe 2014-04-18 10:00 - 2014-04-20 14:07 - 00017482 _____ () C:\Users\Acidfree\Desktop\FRST.txt 2014-04-18 10:00 - 2014-04-20 14:07 - 00000000 ____D () C:\FRST 2014-04-13 16:51 - 2014-04-20 13:48 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter 2014-04-13 16:51 - 2014-04-19 21:06 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk 2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter 2014-04-09 07:24 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 07:24 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 07:24 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 07:24 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 07:24 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 07:24 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 07:24 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 07:24 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 07:24 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 07:24 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 07:24 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 07:24 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 07:24 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 07:24 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 07:24 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 07:24 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork 2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll ==================== One Month Modified Files and Folders ======= 2014-04-20 14:08 - 2014-04-18 10:00 - 00017482 _____ () C:\Users\Acidfree\Desktop\FRST.txt 2014-04-20 14:07 - 2014-04-20 14:07 - 00000000 ____D () C:\Users\Acidfree\Desktop\FRST-OlderVersion 2014-04-20 14:07 - 2014-04-18 10:00 - 02055680 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe 2014-04-20 14:07 - 2014-04-18 10:00 - 00000000 ____D () C:\FRST 2014-04-20 14:06 - 2012-11-02 09:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-20 14:04 - 2014-04-20 13:57 - 00002052 _____ () C:\Users\Acidfree\Desktop\JRT.txt 2014-04-20 13:49 - 2014-04-20 13:49 - 01016261 _____ (Thisisu) C:\Users\Acidfree\Desktop\JRT.exe 2014-04-20 13:49 - 2014-04-20 13:49 - 00000000 ____D () C:\Windows\ERUNT 2014-04-20 13:48 - 2014-04-20 13:48 - 00123323 _____ () C:\Users\Acidfree\Desktop\AdwCleaner[S0].txt 2014-04-20 13:48 - 2014-04-13 16:51 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter 2014-04-20 13:48 - 2013-02-01 22:32 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Spotify 2014-04-20 13:47 - 2011-08-07 10:03 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\ICQ 2014-04-20 13:42 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-20 13:42 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-20 13:37 - 2014-04-19 21:13 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-20 13:36 - 2011-08-19 21:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-20 13:34 - 2011-09-16 05:04 - 00135787 _____ () C:\Windows\setupact.log 2014-04-20 13:34 - 2011-08-06 21:24 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-20 13:34 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-20 13:33 - 2011-08-06 20:48 - 01294945 _____ () C:\Windows\WindowsUpdate.log 2014-04-20 13:27 - 2011-08-19 21:27 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-20 13:24 - 2014-04-20 13:17 - 00000000 ____D () C:\AdwCleaner 2014-04-20 13:16 - 2014-04-20 13:17 - 01308369 _____ () C:\Users\Acidfree\Desktop\adwcleaner.exe 2014-04-20 13:03 - 2011-10-21 08:26 - 00319134 _____ () C:\Windows\PFRO.log 2014-04-20 13:00 - 2014-04-20 13:00 - 00003654 _____ () C:\Users\Acidfree\Desktop\mbam.txt 2014-04-19 22:47 - 2011-08-07 08:15 - 00000000 ____D () C:\Windows\System32\Tasks\Games 2014-04-19 22:40 - 2011-08-06 21:29 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware 2014-04-19 21:55 - 2014-04-19 21:55 - 423694260 _____ () C:\Windows\MEMORY.DMP 2014-04-19 21:55 - 2014-04-19 21:55 - 00298800 _____ () C:\Windows\Minidump\041914-17659-01.dmp 2014-04-19 21:55 - 2011-08-08 06:57 - 00000000 ____D () C:\Windows\Minidump 2014-04-19 21:13 - 2014-04-19 21:13 - 00001116 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 21:13 - 2014-04-19 21:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 21:13 - 2012-09-03 16:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 21:11 - 2011-08-06 21:34 - 00001152 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-19 21:11 - 2011-08-06 21:03 - 00001435 _____ () C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-19 21:06 - 2014-04-13 16:51 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-04-19 20:51 - 2014-04-19 20:51 - 00001278 _____ () C:\Users\Acidfree\Desktop\Revo Uninstaller.lnk 2014-04-19 20:51 - 2014-04-19 20:51 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-18 14:47 - 2014-04-18 12:01 - 00003368 _____ () C:\Windows\System32\Tasks\PrivacyDr_Splash 2014-04-18 12:03 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\Documents\PrivacyDr 2014-04-18 12:01 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\HistoryCleaner 2014-04-18 11:58 - 2014-04-18 11:58 - 01097384 _____ (AnyProtect.com) C:\Users\Acidfree\AppData\Local\nsvD72C.tmp 2014-04-18 10:12 - 2011-08-06 21:03 - 00000000 ___RD () C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-18 10:11 - 2014-04-18 10:11 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Evernote 2014-04-18 10:10 - 2014-04-18 10:10 - 00000932 _____ () C:\Users\Acidfree\Desktop\Evernote.lnk 2014-04-18 10:10 - 2014-04-18 10:10 - 00000000 ____D () C:\Program Files (x86)\Evernote 2014-04-18 10:08 - 2014-04-18 10:02 - 00027724 _____ () C:\Users\Acidfree\Desktop\Addition.txt 2014-04-14 17:29 - 2013-02-01 22:33 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Spotify 2014-04-14 04:21 - 2012-11-02 09:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-14 04:21 - 2012-10-03 13:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-14 04:21 - 2011-08-22 10:13 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Adobe 2014-04-14 04:21 - 2011-08-07 08:14 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk 2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter 2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-10 03:57 - 2013-05-23 19:02 - 00000000 ____D () C:\Windows\rescache 2014-04-10 03:02 - 2013-07-24 21:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 03:01 - 2011-12-12 08:37 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork 2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-04-06 17:17 - 2012-09-13 16:16 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-04-06 17:17 - 2011-12-01 08:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-04-06 17:17 - 2011-12-01 08:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-04-06 17:17 - 2011-08-17 16:40 - 00000000 ____D () C:\Program Files (x86)\Java 2014-04-04 16:00 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-04-04 16:00 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-04-04 16:00 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-03 09:51 - 2014-04-19 21:13 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-19 21:13 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-19 21:13 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 18:50 - 2013-12-18 19:25 - 00000202 _____ () C:\Users\Acidfree\AppData\Roaming\WB.CFG 2014-03-31 03:16 - 2014-04-09 07:24 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 07:24 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-22 09:48 - 2011-10-20 17:38 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Winamp Files to move or delete: ==================== C:\ProgramData\nud0repor.pad Some content of TEMP: ==================== C:\Users\Acidfree\AppData\Local\Temp\APNSetup.exe C:\Users\Acidfree\AppData\Local\Temp\avgnt.exe C:\Users\Acidfree\AppData\Local\Temp\DWPUpgradeInstaller.exe C:\Users\Acidfree\AppData\Local\Temp\installer.exe C:\Users\Acidfree\AppData\Local\Temp\InstallFlashPlayer.exe C:\Users\Acidfree\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Acidfree\AppData\Local\Temp\PrivacyDrSetup_S.exe C:\Users\Acidfree\AppData\Local\Temp\Quarantine.exe C:\Users\Acidfree\AppData\Local\Temp\setup.exe C:\Users\Acidfree\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 06:09 ==================== End Of Log ============================ Ich mach dann mal die Anfangs Logs am Laptop. Den hab ich nicht so oft. Liebe Grüße Emmaline |
| | #12 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...)ESET Online Scanner
Downloade Dir bitte
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #13 | ||
![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Sieht alles ganz gut aus :-) ESET Zitat:
Zitat:
FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014 Ran by Acidfree (administrator) on ACIDFREE-PC on 22-04-2014 13:34:44 Running from C:\Users\Acidfree\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Adobe Systems Incorporated) E:\Photoshop\PhotoshopElementsFileAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe ( ) C:\Windows\system32\lxczcoms.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Spotify Ltd) C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Program Files (x86)\FastMediaConverter\FastMediaConverterApp.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Nullsoft, Inc.) D:\Winamp\winampa.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [WinampAgent] => D:\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [ICQ] => D:\ICQ7.5\ICQ.exe [124480 2011-08-01] (ICQ, LLC.) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Hoolapp Android] => /Minimized HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify Web Helper] => C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-11] (Spotify Ltd) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify] => C:\Users\Acidfree\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-11] (Spotify Ltd) HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [PrivacyDr] => C:\Program Files (x86)\Privacy Dr\PrivacyDr.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {237ce8bd-cee5-11e0-b0cf-00242178af47} - J:\Startme.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {2518b13b-372c-11e2-87e8-00242178af47} - G:\pushinst.exe HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {5738becf-f4ff-11e1-8895-806e6f6e6963} - explorer index_GB.html HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {afbc22a3-b183-11e1-b4a9-00242178af47} - G:\Setup.exe Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x449DEC206E54CC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} StartMenuInternet: IEXPLORE.EXE - iexplore.exe BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: ICQ Sparberater - {5A0D6E4B-B0DF-4148-8B1E-F7A430FF5E24} - C:\Program Files (x86)\icq\Internet Explorer\icq.dll (solute gmbh) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: ICQ Search FF SearchEngineOrder.1: Google FF SelectedSearchEngine: ICQ Search FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.10.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-26.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-27.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-28.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-29.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-30.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Evernote Web Clipper - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} [2013-12-19] FF Extension: DivX Web Player - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\DivXWebPlayer@divx.com.xpi [2012-03-01] FF Extension: GMX MailCheck - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar@gmx.net.xpi [2012-05-04] FF Extension: Ask Toolbar - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-02-25] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-19] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll No File CHR Plugin: (Skype Toolbars) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll (Skype Technologies S.A.) CHR Plugin: (registryAccess) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj\7.15.1.0_0\background/registryAccess.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Unity Player) - C:\Users\Acidfree\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Extension: (No Name) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj [2012-09-02] CHR Extension: (Skype Click to Call) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2011-08-19] CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-03-11] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-10-10] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AdobeActiveFileMonitor7.0; E:\Photoshop\PhotoshopElementsFileAgent.exe [169312 2008-09-16] (Adobe Systems Incorporated) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-03-26] (APN LLC.) R2 lxcz_device; C:\Windows\system32\lxczcoms.exe [566192 2007-04-19] ( ) R2 lxcz_device; C:\Windows\SysWOW64\lxczcoms.exe [537520 2007-04-19] ( ) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.) S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S2 vosr; C:\Users\Acidfree\AppData\Roaming\VOPackage\VOsrv.exe [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-22] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2013-03-07] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [9584 2013-03-07] () S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-22 13:24 - 2014-04-22 13:24 - 00001177 _____ () C:\Users\Acidfree\Desktop\checkup.txt 2014-04-22 13:03 - 2014-04-22 13:02 - 00855379 _____ () C:\Users\Acidfree\Desktop\SecurityCheck.exe 2014-04-22 13:02 - 2014-04-22 13:02 - 00000917 _____ () C:\Users\Acidfree\Desktop\ESET.txt 2014-04-22 12:50 - 2014-04-22 12:50 - 02347384 _____ (ESET) C:\Users\Acidfree\Desktop\esetsmartinstaller_enu.exe 2014-04-20 14:12 - 2014-04-20 14:12 - 00033047 _____ () C:\Users\Acidfree\Desktop\FRST2.txt 2014-04-20 14:07 - 2014-04-22 13:34 - 00000000 ____D () C:\Users\Acidfree\Desktop\FRST-OlderVersion 2014-04-20 13:57 - 2014-04-20 14:04 - 00002052 _____ () C:\Users\Acidfree\Desktop\JRT.txt 2014-04-20 13:49 - 2014-04-20 13:49 - 01016261 _____ (Thisisu) C:\Users\Acidfree\Desktop\JRT.exe 2014-04-20 13:49 - 2014-04-20 13:49 - 00000000 ____D () C:\Windows\ERUNT 2014-04-20 13:48 - 2014-04-20 13:48 - 00123323 _____ () C:\Users\Acidfree\Desktop\AdwCleaner[S0].txt 2014-04-20 13:17 - 2014-04-20 13:24 - 00000000 ____D () C:\AdwCleaner 2014-04-20 13:17 - 2014-04-20 13:16 - 01308369 _____ () C:\Users\Acidfree\Desktop\adwcleaner.exe 2014-04-20 13:00 - 2014-04-20 13:00 - 00003654 _____ () C:\Users\Acidfree\Desktop\mbam.txt 2014-04-19 21:55 - 2014-04-19 21:55 - 423694260 _____ () C:\Windows\MEMORY.DMP 2014-04-19 21:55 - 2014-04-19 21:55 - 00298800 _____ () C:\Windows\Minidump\041914-17659-01.dmp 2014-04-19 21:13 - 2014-04-22 13:28 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 21:13 - 2014-04-19 21:13 - 00001116 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 21:13 - 2014-04-19 21:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 21:13 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-19 21:13 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-19 21:13 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-19 20:51 - 2014-04-19 20:51 - 00001278 _____ () C:\Users\Acidfree\Desktop\Revo Uninstaller.lnk 2014-04-19 20:51 - 2014-04-19 20:51 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-18 12:01 - 2014-04-18 14:47 - 00003368 _____ () C:\Windows\System32\Tasks\PrivacyDr_Splash 2014-04-18 12:01 - 2014-04-18 12:03 - 00000000 ____D () C:\Users\Acidfree\Documents\PrivacyDr 2014-04-18 12:01 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\HistoryCleaner 2014-04-18 11:58 - 2014-04-18 11:58 - 01097384 _____ (AnyProtect.com) C:\Users\Acidfree\AppData\Local\nsvD72C.tmp 2014-04-18 10:11 - 2014-04-18 10:11 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Evernote 2014-04-18 10:10 - 2014-04-18 10:10 - 00000932 _____ () C:\Users\Acidfree\Desktop\Evernote.lnk 2014-04-18 10:10 - 2014-04-18 10:10 - 00000000 ____D () C:\Program Files (x86)\Evernote 2014-04-18 10:02 - 2014-04-18 10:08 - 00027724 _____ () C:\Users\Acidfree\Desktop\Addition.txt 2014-04-18 10:00 - 2014-04-22 13:34 - 02061312 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe 2014-04-18 10:00 - 2014-04-22 13:34 - 00017476 _____ () C:\Users\Acidfree\Desktop\FRST.txt 2014-04-18 10:00 - 2014-04-22 13:34 - 00000000 ____D () C:\FRST 2014-04-13 16:51 - 2014-04-22 13:33 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter 2014-04-13 16:51 - 2014-04-19 21:06 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk 2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter 2014-04-09 07:24 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 07:24 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 07:24 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 07:24 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 07:24 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 07:24 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 07:24 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 07:24 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 07:24 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 07:24 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 07:24 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 07:24 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 07:24 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 07:24 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 07:24 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 07:24 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 07:24 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork 2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll ==================== One Month Modified Files and Folders ======= 2014-04-22 13:34 - 2014-04-20 14:07 - 00000000 ____D () C:\Users\Acidfree\Desktop\FRST-OlderVersion 2014-04-22 13:34 - 2014-04-18 10:00 - 02061312 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe 2014-04-22 13:34 - 2014-04-18 10:00 - 00017476 _____ () C:\Users\Acidfree\Desktop\FRST.txt 2014-04-22 13:34 - 2014-04-18 10:00 - 00000000 ____D () C:\FRST 2014-04-22 13:33 - 2014-04-13 16:51 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter 2014-04-22 13:28 - 2014-04-19 21:13 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-22 13:27 - 2011-08-19 21:27 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-22 13:24 - 2014-04-22 13:24 - 00001177 _____ () C:\Users\Acidfree\Desktop\checkup.txt 2014-04-22 13:06 - 2012-11-02 09:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-22 13:02 - 2014-04-22 13:03 - 00855379 _____ () C:\Users\Acidfree\Desktop\SecurityCheck.exe 2014-04-22 13:02 - 2014-04-22 13:02 - 00000917 _____ () C:\Users\Acidfree\Desktop\ESET.txt 2014-04-22 12:52 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-04-22 12:52 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-04-22 12:52 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-22 12:51 - 2013-02-01 22:32 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Spotify 2014-04-22 12:50 - 2014-04-22 12:50 - 02347384 _____ (ESET) C:\Users\Acidfree\Desktop\esetsmartinstaller_enu.exe 2014-04-22 12:48 - 2011-08-07 10:03 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\ICQ 2014-04-22 12:47 - 2011-08-19 21:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-22 12:46 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-22 12:46 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-22 12:42 - 2011-08-06 20:48 - 01369921 _____ () C:\Windows\WindowsUpdate.log 2014-04-22 12:38 - 2011-09-16 05:04 - 00135955 _____ () C:\Windows\setupact.log 2014-04-22 12:38 - 2011-08-06 21:24 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-22 12:38 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-20 14:12 - 2014-04-20 14:12 - 00033047 _____ () C:\Users\Acidfree\Desktop\FRST2.txt 2014-04-20 14:04 - 2014-04-20 13:57 - 00002052 _____ () C:\Users\Acidfree\Desktop\JRT.txt 2014-04-20 13:49 - 2014-04-20 13:49 - 01016261 _____ (Thisisu) C:\Users\Acidfree\Desktop\JRT.exe 2014-04-20 13:49 - 2014-04-20 13:49 - 00000000 ____D () C:\Windows\ERUNT 2014-04-20 13:48 - 2014-04-20 13:48 - 00123323 _____ () C:\Users\Acidfree\Desktop\AdwCleaner[S0].txt 2014-04-20 13:24 - 2014-04-20 13:17 - 00000000 ____D () C:\AdwCleaner 2014-04-20 13:23 - 2011-08-07 10:03 - 00000000 ____D () C:\ProgramData\ICQ 2014-04-20 13:16 - 2014-04-20 13:17 - 01308369 _____ () C:\Users\Acidfree\Desktop\adwcleaner.exe 2014-04-20 13:03 - 2011-10-21 08:26 - 00319134 _____ () C:\Windows\PFRO.log 2014-04-20 13:00 - 2014-04-20 13:00 - 00003654 _____ () C:\Users\Acidfree\Desktop\mbam.txt 2014-04-19 22:47 - 2011-08-07 08:15 - 00000000 ____D () C:\Windows\System32\Tasks\Games 2014-04-19 22:40 - 2011-08-06 21:29 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware 2014-04-19 21:55 - 2014-04-19 21:55 - 423694260 _____ () C:\Windows\MEMORY.DMP 2014-04-19 21:55 - 2014-04-19 21:55 - 00298800 _____ () C:\Windows\Minidump\041914-17659-01.dmp 2014-04-19 21:55 - 2011-08-08 06:57 - 00000000 ____D () C:\Windows\Minidump 2014-04-19 21:13 - 2014-04-19 21:13 - 00001116 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 21:13 - 2014-04-19 21:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 21:13 - 2012-09-03 16:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 21:11 - 2011-08-06 21:34 - 00001152 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-19 21:11 - 2011-08-06 21:03 - 00001435 _____ () C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-19 21:06 - 2014-04-13 16:51 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-04-19 20:51 - 2014-04-19 20:51 - 00001278 _____ () C:\Users\Acidfree\Desktop\Revo Uninstaller.lnk 2014-04-19 20:51 - 2014-04-19 20:51 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-18 14:47 - 2014-04-18 12:01 - 00003368 _____ () C:\Windows\System32\Tasks\PrivacyDr_Splash 2014-04-18 12:03 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\Documents\PrivacyDr 2014-04-18 12:01 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\HistoryCleaner 2014-04-18 11:58 - 2014-04-18 11:58 - 01097384 _____ (AnyProtect.com) C:\Users\Acidfree\AppData\Local\nsvD72C.tmp 2014-04-18 10:12 - 2011-08-06 21:03 - 00000000 ___RD () C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-18 10:11 - 2014-04-18 10:11 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Evernote 2014-04-18 10:10 - 2014-04-18 10:10 - 00000932 _____ () C:\Users\Acidfree\Desktop\Evernote.lnk 2014-04-18 10:10 - 2014-04-18 10:10 - 00000000 ____D () C:\Program Files (x86)\Evernote 2014-04-18 10:08 - 2014-04-18 10:02 - 00027724 _____ () C:\Users\Acidfree\Desktop\Addition.txt 2014-04-14 17:29 - 2013-02-01 22:33 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Spotify 2014-04-14 04:21 - 2012-11-02 09:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-14 04:21 - 2012-10-03 13:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-14 04:21 - 2011-08-22 10:13 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Adobe 2014-04-14 04:21 - 2011-08-07 08:14 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk 2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter 2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-10 03:57 - 2013-05-23 19:02 - 00000000 ____D () C:\Windows\rescache 2014-04-10 03:02 - 2013-07-24 21:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 03:01 - 2011-12-12 08:37 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork 2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-04-06 17:17 - 2012-09-13 16:16 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-04-06 17:17 - 2011-12-01 08:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-04-06 17:17 - 2011-12-01 08:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-04-06 17:17 - 2011-08-17 16:40 - 00000000 ____D () C:\Program Files (x86)\Java 2014-04-03 09:51 - 2014-04-19 21:13 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-19 21:13 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-19 21:13 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 18:50 - 2013-12-18 19:25 - 00000202 _____ () C:\Users\Acidfree\AppData\Roaming\WB.CFG 2014-03-31 03:16 - 2014-04-09 07:24 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 07:24 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll Files to move or delete: ==================== C:\ProgramData\nud0repor.pad Some content of TEMP: ==================== C:\Users\Acidfree\AppData\Local\Temp\APNSetup.exe C:\Users\Acidfree\AppData\Local\Temp\avgnt.exe C:\Users\Acidfree\AppData\Local\Temp\DWPUpgradeInstaller.exe C:\Users\Acidfree\AppData\Local\Temp\installer.exe C:\Users\Acidfree\AppData\Local\Temp\InstallFlashPlayer.exe C:\Users\Acidfree\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Acidfree\AppData\Local\Temp\PrivacyDrSetup_S.exe C:\Users\Acidfree\AppData\Local\Temp\Quarantine.exe C:\Users\Acidfree\AppData\Local\Temp\setup.exe C:\Users\Acidfree\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-20 14:48 ==================== End Of Log ============================ Danke :-) |
| | #14 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Java und Thunderbird updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Hoolapp Android] => /Minimized
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
C:\ProgramData\nud0repor.pad
Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade dir bitte
Poste bitte den Inhalt hier.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #15 | ||
![]() ![]() | Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) Java habe ich aktuallisiert. Thunderbird wird überhaupt nicht mehr genutzt. Soll ich es trotzdem aktuallisieren? Hier die gewünschten Infos: Fixlog Zitat:
Zitat:
Emmaline |
![]() |
| Themen zu Windows 7 und 8: Statt des Link Zieles kommt Werbung (Erneuern Sie Ihren ...) |
| antivir, antivirus, avg, bingbar, browser, defender, desktop, excel, fehlercode 1, flash player, helper, homepage, iexplore.exe, installation, mozilla, msiinstaller, newtab, object, programm, quick_start, registry, scan, security, services.exe, software, stick, svchost.exe, updates, werbung, windows |