![]() |
| |||||||
Log-Analyse und Auswertung: Win7: SUPERAntiSpyware findet 80 ObjekteWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #5 |
![]() ![]() | Win7: SUPERAntiSpyware findet 80 Objekte O.K., also viel scheinen die Programme nicht gefunden zu haben. Hier die Logs: MBAM: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 20.10.2014 Suchlauf-Zeit: 12:08:03 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.10.20.03 Rootkit Datenbank: v2014.10.17.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: **** Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 346361 Verstrichene Zeit: 26 Min, 4 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristics: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v4.000 - Bericht erstellt am 20/10/2014 um 12:42:52
# DB v2014-10-19.11
# Aktualisiert 12/10/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : **** - XY-PC
# Gestartet von : C:\Users\****\Desktop\AdwCleaner_4.000.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\****\AppData\Roaming\pdfforge
Datei Gelöscht : C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\wn4xmaye.default\invalidprefs.js
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FindRight_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FindRight_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateFindRight_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateFindRight_RASMANCS
Schlüssel Gelöscht : HKCU\Software\Softonic
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17344
-\\ Mozilla Firefox v32.0.3 (x86 de)
[2w39fb8y.default] - Zeile gelöscht : user_pref("browser.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml");
[wn4xmaye.default] - Zeile gelöscht : user_pref("browser.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml");
-\\ Google Chrome v38.0.2125.104
*************************
AdwCleaner[R0].txt - [1870 octets] - [20/10/2014 12:38:22]
AdwCleaner[S0].txt - [1783 octets] - [20/10/2014 12:42:52]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1843 octets] ##########
Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.14.2014:1)
OS: Windows 7 Professional x86
Ran by **** on 20.10.2014 at 12:54:51,52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Users\****\AppData\Roaming\mozilla\firefox\profiles\wn4xmaye.default\extensions\toolbar@gmx.net
Emptied folder: C:\Users\****\AppData\Roaming\mozilla\firefox\profiles\wn4xmaye.default\minidumps [58 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.10.2014 at 12:57:00,28
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-10-2014
Ran by **** (administrator) on XY-PC on 20-10-2014 12:58:33
Running from C:\Users\****\Desktop
Loaded Profile: **** (Available profiles: **** & Gast)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware1\SASCORE.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
() C:\Windows\Samsung\PanelMgr\SSMMgr.exe
(ScanSoft, Inc.) C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
() C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware1\SUPERANTISPYWARE.EXE
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
() C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\saUI.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\saUI.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-07] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [350072 2012-03-09] ()
HKLM\...\Run: [Samsung PanelMgr] => C:\Windows\Samsung\PanelMgr\ssmmgr.exe [614400 2009-08-14] ()
HKLM\...\Run: [SSBkgdUpdate] => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [185896 2006-09-28] (Nuance Communications, Inc.)
HKLM\...\Run: [OpwareSE4] => C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [75304 2006-10-11] (ScanSoft, Inc.)
HKLM\...\Run: [WrtMon.exe] => C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe [20480 2006-09-20] ()
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2617934896-1555523252-518225047-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware1\SUPERAntiSpyware.exe [6692632 2014-10-19] (SUPERAntiSpyware)
HKU\S-1-5-21-2617934896-1555523252-518225047-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [22041192 2014-08-27] (Skype Technologies S.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKCU - {5C746BA8-B2BA-4D72-83F1-138EC0C5FB3C} URL = https://de.search.yahoo.com/search?fr=mcafee&type=B010DE0D20140710&p={SearchTerms}
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 208.67.220.220
FireFox:
========
FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\wn4xmaye.default
FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml
FF DefaultSearchEngine: Sichere Suche
FF SearchEngineOrder.1: Sichere Suche
FF SelectedSearchEngine: Sichere Suche
FF Keyword.URL: https://de.search.yahoo.com/search?fr=mcafee&type=B110DE0D20140710&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\wn4xmaye.default\Extensions\abs@avira.com [2014-10-01]
FF Extension: WOT - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\wn4xmaye.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-03-25]
FF Extension: Adblock Edge - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\wn4xmaye.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2014-03-25]
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2014-01-24]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files\McAfee\SiteAdvisor [2014-05-17]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR DefaultSearchKeyword: Default -> mcafee
CHR DefaultSearchURL: Default -> https://de.search.yahoo.com/search?fr=mcafee&type=A210DE0&p={searchTerms}
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\****\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-14]
CHR Extension: (Avira Browser Safety) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-09-14]
CHR Extension: (Google Wallet) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-09]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware1\SASCORE.EXE [142648 2014-10-19] (SUPERAntiSpyware.com)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-07] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG)
R2 McAfee SiteAdvisor Service; c:\Program Files\McAfee\SiteAdvisor\McSACore.exe [133696 2014-09-23] (McAfee, Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-07] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-07] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-18] (Avira Operations GmbH & Co. KG)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-10-20] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware1\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware1\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-18] (Avira GmbH)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2013-04-10] (Samsung Electronics) [File not signed]
R0 TPkd; C:\Windows\system32\Drivers\TPkd.sys [93336 2012-11-17] (PACE Anti-Piracy, Inc.)
S3 catchme; \??\C:\Users\NIKLAS~1\AppData\Local\Temp\catchme.sys [X]
S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-20 12:57 - 2014-10-20 12:57 - 00000928 _____ () C:\Users\****\Desktop\JRT.txt
2014-10-20 12:53 - 2014-10-20 12:54 - 01705698 _____ (Thisisu) C:\Users\****\Desktop\JRT.exe
2014-10-20 12:37 - 2014-10-20 12:42 - 00000000 ____D () C:\AdwCleaner
2014-10-20 12:36 - 2014-10-20 12:36 - 01976320 _____ () C:\Users\****\Desktop\AdwCleaner_4.000.exe
2014-10-20 12:34 - 2014-10-20 12:34 - 00001166 _____ () C:\Users\****\Desktop\mbam.txt
2014-10-19 18:00 - 2014-10-19 18:00 - 00024686 _____ () C:\Users\****\Desktop\Addition.txt
2014-10-19 17:59 - 2014-10-20 12:58 - 00012458 _____ () C:\Users\****\Desktop\FRST.txt
2014-10-19 17:59 - 2014-10-20 12:58 - 00000000 ____D () C:\FRST
2014-10-19 17:58 - 2014-10-20 12:58 - 01102848 _____ (Farbar) C:\Users\****\Desktop\FRST.exe
2014-10-19 17:04 - 2014-10-20 12:44 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware1
2014-10-19 17:04 - 2014-10-19 17:04 - 00001970 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2014-10-19 17:04 - 2014-10-19 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-10-15 23:16 - 2014-10-10 03:44 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-15 23:16 - 2014-10-10 03:44 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-15 23:16 - 2014-10-10 03:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-15 23:16 - 2014-09-29 02:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-15 23:15 - 2014-10-07 04:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-15 23:15 - 2014-09-26 00:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-15 23:15 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-15 23:15 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-15 23:15 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-15 23:15 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-15 23:15 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-15 23:15 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-15 23:15 - 2014-09-19 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-15 23:15 - 2014-09-19 03:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 23:15 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-15 23:15 - 2014-09-19 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-15 23:15 - 2014-09-19 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-15 23:15 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-15 23:15 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-15 23:15 - 2014-09-19 02:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-15 23:15 - 2014-09-19 02:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-15 23:15 - 2014-09-19 02:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-15 23:15 - 2014-09-19 02:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-15 23:15 - 2014-09-19 02:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-15 23:15 - 2014-09-19 02:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-15 23:15 - 2014-09-19 02:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 23:15 - 2014-09-19 02:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 23:15 - 2014-09-19 02:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-15 23:15 - 2014-09-19 02:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-15 23:15 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-15 23:15 - 2014-09-19 02:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-15 23:15 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-15 23:15 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-15 23:15 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-15 23:15 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-15 23:15 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-15 23:15 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-15 23:15 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-15 23:15 - 2014-07-17 03:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-15 23:15 - 2014-07-17 03:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-15 23:15 - 2014-07-17 03:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-15 23:15 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-15 23:15 - 2014-07-17 03:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-10-15 23:15 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-15 23:15 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-15 23:15 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-15 23:15 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-15 23:15 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-15 23:15 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-15 23:15 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-15 23:15 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-13 23:46 - 2014-10-13 23:46 - 00007575 _____ () C:\Users\****\Downloads\Synthese.zip
2014-10-13 23:45 - 2014-10-13 23:45 - 01956125 _____ () C:\Users\****\Downloads\01-Additive_Synthese.zip
2014-10-13 23:43 - 2014-10-13 23:43 - 00000000 ____D () C:\Users\****\Documents\Max
2014-10-13 23:43 - 2014-10-13 23:43 - 00000000 ____D () C:\Users\****\AppData\Roaming\PACE Anti-Piracy
2014-10-13 23:43 - 2014-10-13 23:43 - 00000000 ____D () C:\Users\****\AppData\Roaming\Cycling '74
2014-10-13 23:43 - 2014-10-13 23:43 - 00000000 ____D () C:\Users\****\AppData\Local\PACE Anti-Piracy
2014-10-13 23:43 - 2014-10-13 23:43 - 00000000 ____D () C:\ProgramData\PACE Anti-Piracy
2014-10-13 23:36 - 2014-10-13 23:36 - 00001951 _____ () C:\Users\Public\Desktop\Max Runtime 6.1.lnk
2014-10-13 23:36 - 2014-10-13 23:36 - 00001935 _____ () C:\Users\Public\Desktop\Max 6.1.lnk
2014-10-13 23:36 - 2014-10-13 23:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cycling '74
2014-10-13 23:36 - 2014-10-13 23:36 - 00000000 ____D () C:\Program Files\Cycling '74
2014-10-12 19:18 - 2014-10-12 19:18 - 00004255 _____ () C:\Users\****\Documents\Es geht ein' dunkle Wolk' herein.aup
2014-10-12 19:18 - 2014-10-12 19:18 - 00000000 ____D () C:\Users\****\Documents\Es geht ein' dunkle Wolk' herein_data
2014-10-10 02:56 - 2014-10-17 19:02 - 00000000 ____D () C:\Program Files\Convar
2014-10-10 02:55 - 2014-10-10 02:55 - 03462033 _____ () C:\Users\****\Downloads\pci_filerecovery.exe
2014-10-10 02:18 - 2014-10-10 02:19 - 02679080 _____ (SharpNight Co,Ltd ) C:\Users\****\Downloads\7data-softonic.exe
2014-10-10 01:42 - 2014-10-10 01:43 - 04210920 _____ (Piriform Ltd) C:\Users\****\Downloads\rcsetup_28329.exe
2014-10-03 15:11 - 2014-10-03 15:26 - 00000000 ____D () C:\Users\****\Documents\Litauen_2014
2014-10-01 17:41 - 2014-10-01 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-10-01 17:41 - 2014-09-23 09:43 - 01070152 _____ (Microsoft Corporation) C:\Windows\system32\MSCOMCTL.OCX
2014-10-01 17:41 - 2014-09-23 09:43 - 00662288 _____ (Microsoft Corporation) C:\Windows\system32\MSCOMCT2.OCX
2014-10-01 17:41 - 2014-09-23 09:43 - 00137000 _____ (Microsoft Corporation) C:\Windows\system32\MSMAPI32.OCX
2014-10-01 17:40 - 2014-10-01 17:41 - 00000000 ____D () C:\Program Files\PDFCreator
2014-10-01 17:40 - 2014-09-23 09:43 - 00095416 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-10-01 17:40 - 2014-09-23 09:43 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\MSMPIDE.DLL
2014-10-01 17:40 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\system32\VB6DE.DLL
2014-10-01 17:40 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\MSCMCDE.DLL
2014-10-01 17:40 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\MSCC2DE.DLL
2014-10-01 14:52 - 2014-10-01 14:52 - 27855352 _____ (pdfforge ) C:\Users\****\Downloads\PDFCreator-1_7_3_setup.exe
2014-09-30 23:59 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-09-30 17:02 - 2014-09-30 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2014-09-30 16:57 - 2014-09-30 16:57 - 07421952 _____ () C:\Users\****\Downloads\LibreOffice_4.2.6-secfix_Win_x86_helppack_de.msi
2014-09-30 16:55 - 2014-09-30 16:56 - 220827648 _____ () C:\Users\****\Downloads\LibreOffice_4.2.6-secfix_Win_x86.msi
2014-09-26 23:10 - 2014-09-26 23:10 - 00015472 _____ () C:\Users\Gast\Desktop\interviu matti carlos.xml
2014-09-26 21:56 - 2014-09-26 16:35 - 33400954 ____N () C:\Users\Gast\Desktop\Balsas 040.m4a
2014-09-26 16:43 - 2014-09-26 16:43 - 00000653 _____ () C:\Users\Gast\Desktop\ežys.choras.sąrašas.txt
2014-09-26 13:56 - 2014-09-26 13:56 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\LibreOffice
2014-09-25 01:15 - 2014-09-25 01:15 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-09-24 13:25 - 2014-09-24 13:25 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-09-24 13:04 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-23 14:20 - 2014-09-23 14:20 - 00000000 ____D () C:\Users\Gast\AppData\Local\Scansoft
2014-09-23 12:37 - 2014-09-23 12:37 - 00040805 _____ () C:\Users\****\Documents\Viola Köster Gedichte.odt
2014-09-22 22:31 - 2014-09-22 22:39 - 00000000 ____D () C:\Users\****\Desktop\Mysteriöse SD-Card
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-20 12:58 - 2014-03-09 22:54 - 00000000 ____D () C:\Users\****\Desktop\FRST-OlderVersion
2014-10-20 12:51 - 2009-07-14 06:34 - 00031872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-20 12:51 - 2009-07-14 06:34 - 00031872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-20 12:44 - 2014-03-09 23:12 - 00001118 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-20 12:44 - 2014-01-27 02:41 - 00000000 ____D () C:\Users\****\AppData\Roaming\Skype
2014-10-20 12:44 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-20 12:44 - 2009-07-14 06:39 - 00128291 _____ () C:\Windows\setupact.log
2014-10-20 12:43 - 2014-01-14 20:40 - 01244788 _____ () C:\Windows\WindowsUpdate.log
2014-10-20 12:43 - 2010-11-20 23:48 - 00714176 _____ () C:\Windows\PFRO.log
2014-10-20 12:35 - 2014-03-09 23:12 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-20 12:07 - 2014-04-14 01:58 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-17 19:08 - 2014-02-07 03:10 - 00000000 ____D () C:\Users\****\Desktop\web_of_trust_wot-20131118-fx
2014-10-17 15:44 - 2014-01-14 20:48 - 00000000 ____D () C:\Users\****
2014-10-17 12:01 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-10-16 20:54 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-16 04:04 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-16 04:04 - 2009-07-14 06:33 - 00348800 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-16 04:03 - 2014-05-06 02:53 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-16 04:03 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-10-16 03:07 - 2014-01-16 02:40 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-16 03:03 - 2014-01-16 02:40 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-15 19:45 - 2014-08-20 23:37 - 00000000 ____D () C:\Users\****\AppData\Local\Adobe
2014-10-15 19:45 - 2014-01-14 21:21 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-10-15 19:45 - 2014-01-14 21:21 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-10-13 23:43 - 2012-10-26 22:12 - 00000000 ___HD () C:\Users\****\AppData\Local\oeevpRqo9D
2014-10-13 23:17 - 2014-08-08 15:33 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-13 23:17 - 2014-01-16 01:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-13 23:17 - 2014-01-16 01:34 - 00000000 ____D () C:\Program Files\Avira
2014-10-10 02:31 - 2010-11-20 23:01 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-10 02:21 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-10-07 13:43 - 2014-02-18 19:58 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-10-07 13:43 - 2014-01-16 01:34 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-10-07 13:43 - 2014-01-16 01:34 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-10-01 14:13 - 2014-05-17 18:01 - 00000000 ____D () C:\Program Files\McAfee
2014-09-30 17:02 - 2014-01-24 21:30 - 00000000 ____D () C:\Program Files\LibreOffice 4
2014-09-30 03:11 - 2014-09-04 00:22 - 00085999 _____ () C:\Users\****\Documents\Unbenannt 2.odt
2014-09-26 22:03 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Public\Libraries
2014-09-25 12:19 - 2014-03-10 23:03 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-09-23 14:20 - 2014-04-19 14:23 - 00083456 _____ () C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-23 12:31 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-20 14:44 - 2014-01-15 01:03 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
Some content of TEMP:
====================
C:\Users\Gast\AppData\Local\Temp\avgnt.exe
C:\Users\****\AppData\Local\Temp\avgnt.exe
C:\Users\****\AppData\Local\Temp\Quarantine.exe
C:\Users\****\AppData\Local\Temp\SAS6_Update.exe
C:\Users\****\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-17 11:50
==================== End Of Log ============================
Zwei Sachen, die mir noch aufgefallen sind (vielleicht belanglos, aber zur Sicherheit frage ich besser nach): 1. Wenn ich jetzt (nach allen durchgeführten Scans) in Firefox einen neuen Tab öffne, erscheint in der Adresszeile des leeren Fensters: "chrome://unitedtb/content/newtab/newtab-page.xhtml". Ist das normal? Soweit ich mich erinnern kann, stand immer gar nichts in der Zeile oder vielleicht höchstens "about:blank". Mich irritiert nur, dass da "Chrome" dabei steht, da ich ja eigentlich in Firefox bin... 2. Dieses "a.akamaihd.net" ist immer noch nicht weg. Allerdings kommt es anscheinend auch nur, wenn ich auf Facebook gehe. Sowohl beim Aufrufen der Fb-Startseite als auch beim Ein- und Ausloggen steht während des Ladens der Seiten unten rechts im Browserfenster kurz: "fbstatic-a.akamaihd.net gelesen". Wie gesagt, dieses "a.akamaihd.net" kommt mir daher bekannt vor, wie mein Computer mal richtig voll war mit Adware. Oder kann ich das ignorieren? Geändert von anonym1 (20.10.2014 um 12:26 Uhr) |
| Themen zu Win7: SUPERAntiSpyware findet 80 Objekte |
| appdata, browser-fenster, code, detected, entfernen, fehlercode 0xc0000006, fehlercode windows, gen, google, js/exploit.agent.nhk, malwarebytes, microsoft, nicht mehr, popups, programme, roaming, superantispyware, surfen, warnung, win, win32/bundled.toolbar.ask, win32/bundled.toolbar.ask.d, win32/bundled.toolbar.ask.g, win32/bundled.toolbar.google.d, win32/installmonetizer.aq |