![]() |
|
Log-Analyse und Auswertung: Nach massiven Hardware-Problemen Win32:GenMaliciousA entdecktWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Nach massiven Hardware-Problemen Win32:GenMaliciousA entdeckt Hallo! Ich hatte massive Hardware-Probleme, der Rechner piepste ständig laut und stürzte ab. Avira hat nichts angezeigt, verhielt sich aber irgendwie "störrisch". Nach Behebung der Hardware-Probleme habe ich Avast installiert und erhielt die Virusmeldung Win32:GenMaliciousA. Der Virus wurde in einem zweiten Scan in Quarantäne geschoben, außerdem zeigte der zweite Scan noch Conduit sowie Win64Adware. Malwarebites hat dann Win32:GenMaliciousA nicht mehr gefunden, meldete dann aber noch ConduitTB.Gen. Danach hab ich mich an eure Anleitung gehalten. Danke schonmal für Eure Hilfe. Beim ersten Avira-Suchlauf war das Log nicht aktiviert, beim zweiten Suchlauf wurde nichts gefunden; eine schnelle letzte Überprüfung brachte folgendes Log: Code:
ATTFilter * * Avast Protokolldatei * Diese Protokolldatei wurde automatisch erstellt * * Prüfungsname: Schnelle Überprüfung * Start: Donnerstag, 2. Juli 2015 23:57:34 * VPS: 150702-2, 02.07.2015 * C:\hiberfil.sys [E] Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird (32) C:\pagefile.sys [E] Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird (32) Infizierte Dateien: 0 Dateien gesamt: 52007 Ordner gesamt: 36633 Gesamtgröße: 30,3 GB * * Prüfung beendet: Freitag, 3. Juli 2015 00:06:56 * Laufzeit war 9 Minute(n), 9 Sekunde(n) * Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 02.07.2015 Suchlaufzeit: 21:57 Protokolldatei: MalwarebitesLog.txt Administrator: Ja Version: 2.1.8.1057 Malware-Datenbank: v2015.07.02.04 Rootkit-Datenbank: v2015.07.01.01 Lizenz: Testversion Malware-Schutz: Aktiviert Schutz vor bösartigen Websites: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: VEnte Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 509708 Abgelaufene Zeit: 32 Min., 45 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 6 PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\HKOAHCAOBJBIHEHLDFIMHBLMHGALCIPM, In Quarantäne, [0eee34a8ed9dca6c27d8f805cb3807f9], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\nmhostct3297265, In Quarantäne, [e913f7e5ec9e72c4e53f7b80758ef709], PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\HKOAHCAOBJBIHEHLDFIMHBLMHGALCIPM, In Quarantäne, [e7158d4fccbeb5815fa12ad457ac3cc4], PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\nmhostct3297265, In Quarantäne, [bb41a33979112c0a2bf49764ef14fc04], PUP.Optional.Conduit.A, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{B2D48FF5-2FA7-4E7D-9484-C86C8B853E7C}, In Quarantäne, [ad4f479501891d19218e669aac58fd03], PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CHCT3297265, In Quarantäne, [d527f4e8553541f5a11ad9bed23323dd], Registrierungswerte: 5 PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\hkoahcaobjbihehldfimhblmhgalcipm|path, C:\Users\VEnte\AppData\Local\CRE\hkoahcaobjbihehldfimhblmhgalcipm.crx, In Quarantäne, [0eee34a8ed9dca6c27d8f805cb3807f9] PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\hkoahcaobjbihehldfimhblmhgalcipm|path, C:\Users\VEnte\AppData\Local\CRE\hkoahcaobjbihehldfimhblmhgalcipm.crx, In Quarantäne, [e7158d4fccbeb5815fa12ad457ac3cc4] PUP.Optional.Conduit.A, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{B2D48FF5-2FA7-4E7D-9484-C86C8B853E7C}|URL, hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3297265&CUI=UN38280467413594276&UM=2&UP=SP512ACDB4-C746-44D0-B1B2-8977DBEB0144&SSPV=, In Quarantäne, [ad4f479501891d19218e669aac58fd03] PUP.Optional.Conduit.A, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{B2D48FF5-2FA7-4E7D-9484-C86C8B853E7C}|SuggestionsURL_JSON, hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}, In Quarantäne, [609c36a6e0aa10267639d42cd4302cd4] PUP.Optional.Conduit.A, HKU\S-1-5-21-350991608-221412360-2685823185-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{B2D48FF5-2FA7-4E7D-9484-C86C8B853E7C}|FaviconURL, hxxp://search.conduit.com/favicon.ico, In Quarantäne, [7b81af2d7f0bd660456a8c742adae020] Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Dateien: 0 (keine bösartigen Elemente erkannt) Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 22:57 on 02/07/2015 (VEnte) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:28-06-2015 01 Ran by Kueken1 (ATTENTION: The logged in user is not administrator) on VEnte on 02-07-2015 22:58:42 Running from C:\Users\Kueken1\Downloads Loaded Profiles: VEnte & Kueken1 (Available Profiles: VEnte & Kueken2 & Kueken1) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) Failed to access process -> smss.exe Failed to access process -> csrss.exe Failed to access process -> csrss.exe Failed to access process -> wininit.exe Failed to access process -> winlogon.exe Failed to access process -> services.exe Failed to access process -> lsass.exe Failed to access process -> lsm.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> AvastSvc.exe Failed to access process -> wlanext.exe Failed to access process -> conhost.exe Failed to access process -> spoolsv.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe Failed to access process -> svchost.exe () C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe Failed to access process -> armsvc.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe Failed to access process -> svchost.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe Failed to access process -> EvtEng.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe Failed to access process -> HeciServer.exe Failed to access process -> Jhi_service.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe Failed to access process -> PowerBiosServer.exe Failed to access process -> RegSrvc.exe Failed to access process -> sqlwriter.exe Failed to access process -> svchost.exe Failed to access process -> ViakaraokeSrv.exe Failed to access process -> SearchIndexer.exe Failed to access process -> wmpnetwk.exe Failed to access process -> svchost.exe Failed to access process -> unsecapp.exe Failed to access process -> WmiPrvSE.exe Failed to access process -> WmiPrvSE.exe Failed to access process -> svchost.exe (Microsoft Corporation) C:\Windows\HelpPane.exe Failed to access process -> BTHSAmpPalService.exe Failed to access process -> BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe Failed to access process -> IAStorDataMgrSvc.exe Failed to access process -> LMS.exe Failed to access process -> UNS.exe Failed to access process -> NASvc.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> TrustedInstaller.exe Failed to access process -> mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe Failed to access process -> mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe Failed to access process -> SearchProtocolHost.exe Failed to access process -> SearchFilterHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [LMADLmon] => C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe [952496 2012-09-07] () HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-05-15] (Intel Corporation) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5119600 2012-05-10] (VIA) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [LMADLmon] => C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe [952496 2012-09-07] () HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-02] (Avast Software s.r.o.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd) HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_190_ActiveX.exe [623792 2015-07-02] (Adobe Systems Incorporated) HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\MountPoints2: {cdf7f1ca-c50f-11e2-b414-0090f5e4f3c3} - H:\ting.exe HKU\S-1-5-18\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect" Startup: C:\Users\Kueken1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-05-24] ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-02] (Avast Software s.r.o.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-350991608-221412360-2685823185-1005\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp URLSearchHook: [S-1-5-21-350991608-221412360-2685823185-1001] ATTENTION ==> Default URLSearchHook is missing SearchScopes: HKLM -> DefaultScope {9CFAA595-7137-4432-9E2C-275AE0F3709D} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {9CFAA595-7137-4432-9E2C-275AE0F3709D} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope value is missing BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-02] (Avast Software s.r.o.) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-02] (Avast Software s.r.o.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{652752FE-12A3-4B90-A2C1-77BE17A56678}: [DhcpNameServer] 192.168.192.2 192.168.192.3 Tcpip\..\Interfaces\{67345BC8-D4B0-45A5-BA1E-50A1D4D13CFC}: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Kueken1\AppData\Roaming\Mozilla\Firefox\Profiles\ilPrvwwf.default FF Homepage: www.ixquick.de FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-07-02] () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-07-02] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-02] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-02] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-350991608-221412360-2685823185-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kueken1\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-03-19] (Unity Technologies ApS) FF Extension: Avira Browser Safety - C:\Users\Kueken1\AppData\Roaming\Mozilla\Firefox\Profiles\ilPrvwwf.default\Extensions\abs@avira.com [2015-05-28] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-07-02] Chrome: ======= CHR Profile: C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira Browser Safety) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-07-02] CHR Extension: (Avast Online Security) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-07-02] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-02] CHR Extension: (Google Wallet) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-02] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-02] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-02] (Avast Software s.r.o.) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-15] (Intel Corporation) R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2011-02-18] () [File not signed] R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-03] (VIA Technologies, Inc.) S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-02] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-02] (Avast Software s.r.o.) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-02] (Avast Software s.r.o.) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-02] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-02] (Avast Software s.r.o.) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-02] (Avast Software s.r.o.) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-02] (Avast Software s.r.o.) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-02] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-02] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) U3 kwryikog; \??\C:\Users\VEnte~1\AppData\Local\Temp\kwryikog.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-02 22:58 - 2015-07-02 22:59 - 00015707 _____ C:\Users\Kueken1\Downloads\FRST.txt 2015-07-02 22:58 - 2015-07-02 22:58 - 02112512 _____ (Farbar) C:\Users\Kueken1\Downloads\FRST64.exe 2015-07-02 22:58 - 2015-07-02 22:58 - 00000000 ____D C:\FRST 2015-07-02 22:57 - 2015-07-02 22:57 - 00000490 _____ C:\Users\Kueken1\Downloads\defogger_disable.log 2015-07-02 22:57 - 2015-07-02 22:57 - 00000000 _____ C:\Users\VEnte\defogger_reenable 2015-07-02 22:56 - 2015-07-02 22:56 - 00050477 _____ C:\Users\Kueken1\Downloads\Defogger.exe 2015-07-02 22:34 - 2015-07-02 22:34 - 00380416 _____ C:\Users\Kueken1\Downloads\gc87s56g.exe 2015-07-02 22:18 - 2015-07-02 22:18 - 01636352 _____ (Farbar) C:\Users\Kueken1\Downloads\FRST.exe 2015-07-02 21:56 - 2015-07-02 21:57 - 02244096 _____ C:\Users\Kueken1\Downloads\AdwCleaner_4.207.exe 2015-07-02 19:43 - 2015-07-02 21:42 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Kueken1\Downloads\mbam-setup-2.1.6.1022.exe 2015-07-02 16:49 - 2015-07-02 16:49 - 18174128 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2015-07-02 16:46 - 2015-07-02 22:51 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-02 15:41 - 2015-07-02 19:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-07-02 15:18 - 2015-07-02 15:18 - 00000000 ____D C:\Users\Kueken1\AppData\Roaming\AVAST Software 2015-07-02 15:14 - 2015-07-02 15:14 - 00001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-07-02 15:14 - 2015-07-02 15:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2015-07-02 15:13 - 2015-07-02 15:13 - 00002247 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-07-02 15:13 - 2015-07-02 15:13 - 00000350 ____H C:\Windows\Tasks\avast! Emergency Update.job 2015-07-02 15:13 - 2015-07-02 15:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-07-02 15:07 - 2015-07-02 19:30 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-02 15:07 - 2015-07-02 15:14 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe 2015-07-02 15:07 - 2015-07-02 15:07 - 00272248 _____ C:\Windows\system32\Drivers\aswVmm.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00065736 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr 2015-07-02 15:07 - 2015-07-02 15:07 - 00029168 _____ C:\Windows\system32\Drivers\aswHwid.sys 2015-07-02 14:51 - 2015-07-02 14:51 - 00000000 ____D C:\Program Files\AVAST Software 2015-07-01 13:33 - 2015-07-01 13:33 - 00000000 ____D C:\Users\VEnte\AppData\Roaming\JAM Software 2015-06-23 21:28 - 2015-06-23 21:28 - 00003224 ____N C:\bootsqm.dat 2015-06-22 19:24 - 2015-07-02 14:46 - 00000000 ____D C:\ProgramData\AVAST Software 2015-06-22 19:23 - 2015-06-22 19:24 - 05481344 _____ (Avast Software s.r.o.) C:\Users\Kueken1\Downloads\avast_free_antivirus_setup.exe 2015-06-22 19:23 - 2015-06-22 19:24 - 05481344 _____ (Avast Software s.r.o.) C:\Users\Public\Desktop\avast_free_antivirus_setup.exe 2015-06-22 19:11 - 2015-06-22 19:12 - 04718584 _____ (Avira Operations GmbH & Co. KG) C:\Users\Kueken1\Downloads\avira_de_av_5588320a39453__ws.exe 2015-06-22 18:01 - 2015-06-22 18:03 - 00000000 ____D C:\OETemp ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-02 22:57 - 2013-05-23 22:06 - 00000000 ____D C:\Users\VEnte 2015-07-02 22:47 - 2014-01-04 20:04 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-07-02 22:43 - 2009-07-14 06:45 - 00031792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-02 22:43 - 2009-07-14 06:45 - 00031792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-02 21:56 - 2014-06-10 16:40 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-07-02 21:52 - 2014-06-10 16:40 - 00001102 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-07-02 21:52 - 2014-06-10 16:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-07-02 21:52 - 2014-06-10 16:40 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-07-02 21:00 - 2013-05-16 12:15 - 01880411 _____ C:\Windows\WindowsUpdate.log 2015-07-02 19:46 - 2013-05-23 23:11 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-02 19:46 - 2013-05-23 23:11 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-02 19:36 - 2010-11-21 08:50 - 00698926 _____ C:\Windows\system32\perfh007.dat 2015-07-02 19:36 - 2010-11-21 08:50 - 00149034 _____ C:\Windows\system32\perfc007.dat 2015-07-02 19:36 - 2009-07-14 07:13 - 01618320 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-02 19:34 - 2015-04-26 21:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-07-02 19:29 - 2015-04-10 13:24 - 00003093 _____ C:\Windows\setupact.log 2015-07-02 19:29 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-02 18:29 - 2014-05-13 19:48 - 00000000 ____D C:\temp 2015-07-02 15:15 - 2015-04-10 13:24 - 00229700 _____ C:\Windows\PFRO.log 2015-07-02 15:13 - 2013-05-23 23:11 - 00000000 ____D C:\Program Files (x86)\Google 2015-06-23 15:47 - 2014-04-08 22:44 - 00000000 _____ C:\Users\Kueken1\AppData\Roaming\FoxitReaderUpdateInfo.txt 2015-06-22 19:20 - 2014-10-09 21:12 - 00000000 ____D C:\ProgramData\Package Cache 2015-06-22 19:14 - 2013-05-23 22:57 - 00000000 ____D C:\ProgramData\Avira 2015-06-22 19:14 - 2013-05-23 22:57 - 00000000 ____D C:\Program Files (x86)\Avira 2015-06-18 08:41 - 2014-06-10 16:40 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-06-18 08:41 - 2014-06-10 16:40 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-06-18 08:41 - 2014-06-10 16:40 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys ==================== Files in the root of some directories ======= 2014-04-08 22:44 - 2015-06-23 15:47 - 0000000 _____ () C:\Users\Kueken1\AppData\Roaming\FoxitReaderUpdateInfo.txt 2013-05-27 22:36 - 2015-01-23 21:57 - 0000600 _____ () C:\Users\Kueken1\AppData\Roaming\winscp.rnd 2013-12-02 15:23 - 2014-05-13 19:48 - 0007168 _____ () C:\Users\Kueken1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini Some files in TEMP: ==================== C:\Users\Kueken1\AppData\Local\Temp\Foxit Reader Updater.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed ==================== End of log ============================ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:28-06-2015 01 Ran by Kueken1 (ATTENTION: The logged in user is not administrator) on VEnte on 02-07-2015 22:58:42 Running from C:\Users\Kueken1\Downloads Loaded Profiles: VEnte & Kueken1 (Available Profiles: VEnte & Kueken2 & Kueken1) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) Failed to access process -> smss.exe Failed to access process -> csrss.exe Failed to access process -> csrss.exe Failed to access process -> wininit.exe Failed to access process -> winlogon.exe Failed to access process -> services.exe Failed to access process -> lsass.exe Failed to access process -> lsm.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> AvastSvc.exe Failed to access process -> wlanext.exe Failed to access process -> conhost.exe Failed to access process -> spoolsv.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe Failed to access process -> svchost.exe () C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe Failed to access process -> armsvc.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe Failed to access process -> svchost.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe Failed to access process -> EvtEng.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe Failed to access process -> HeciServer.exe Failed to access process -> Jhi_service.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe Failed to access process -> PowerBiosServer.exe Failed to access process -> RegSrvc.exe Failed to access process -> sqlwriter.exe Failed to access process -> svchost.exe Failed to access process -> ViakaraokeSrv.exe Failed to access process -> SearchIndexer.exe Failed to access process -> wmpnetwk.exe Failed to access process -> svchost.exe Failed to access process -> unsecapp.exe Failed to access process -> WmiPrvSE.exe Failed to access process -> WmiPrvSE.exe Failed to access process -> svchost.exe (Microsoft Corporation) C:\Windows\HelpPane.exe Failed to access process -> BTHSAmpPalService.exe Failed to access process -> BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe Failed to access process -> IAStorDataMgrSvc.exe Failed to access process -> LMS.exe Failed to access process -> UNS.exe Failed to access process -> NASvc.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> TrustedInstaller.exe Failed to access process -> mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe Failed to access process -> mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe Failed to access process -> SearchProtocolHost.exe Failed to access process -> SearchFilterHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [LMADLmon] => C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe [952496 2012-09-07] () HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-05-15] (Intel Corporation) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5119600 2012-05-10] (VIA) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [LMADLmon] => C:\Program Files (x86)\Lexmark Pro5500 Series\LMADLmon.exe [952496 2012-09-07] () HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-02] (Avast Software s.r.o.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd) HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_190_ActiveX.exe [623792 2015-07-02] (Adobe Systems Incorporated) HKU\S-1-5-21-350991608-221412360-2685823185-1005\...\MountPoints2: {cdf7f1ca-c50f-11e2-b414-0090f5e4f3c3} - H:\ting.exe HKU\S-1-5-18\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect" Startup: C:\Users\Kueken1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-05-24] ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-02] (Avast Software s.r.o.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-350991608-221412360-2685823185-1005\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp URLSearchHook: [S-1-5-21-350991608-221412360-2685823185-1001] ATTENTION ==> Default URLSearchHook is missing SearchScopes: HKLM -> DefaultScope {9CFAA595-7137-4432-9E2C-275AE0F3709D} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {9CFAA595-7137-4432-9E2C-275AE0F3709D} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope value is missing BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-02] (Avast Software s.r.o.) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-02] (Avast Software s.r.o.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{652752FE-12A3-4B90-A2C1-77BE17A56678}: [DhcpNameServer] 192.168.192.2 192.168.192.3 Tcpip\..\Interfaces\{67345BC8-D4B0-45A5-BA1E-50A1D4D13CFC}: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Kueken1\AppData\Roaming\Mozilla\Firefox\Profiles\ilPrvwwf.default FF Homepage: www.ixquick.de FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-07-02] () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-07-02] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-02] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-02] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-350991608-221412360-2685823185-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kueken1\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-03-19] (Unity Technologies ApS) FF Extension: Avira Browser Safety - C:\Users\Kueken1\AppData\Roaming\Mozilla\Firefox\Profiles\ilPrvwwf.default\Extensions\abs@avira.com [2015-05-28] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-07-02] Chrome: ======= CHR Profile: C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira Browser Safety) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-07-02] CHR Extension: (Avast Online Security) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-07-02] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-02] CHR Extension: (Google Wallet) - C:\Users\Kueken1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-02] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-02] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-02] (Avast Software s.r.o.) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-15] (Intel Corporation) R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2011-02-18] () [File not signed] R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-03] (VIA Technologies, Inc.) S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-02] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-02] (Avast Software s.r.o.) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-02] (Avast Software s.r.o.) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-02] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-02] (Avast Software s.r.o.) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-02] (Avast Software s.r.o.) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-02] (Avast Software s.r.o.) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-02] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-02] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) U3 kwryikog; \??\C:\Users\VEnte~1\AppData\Local\Temp\kwryikog.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-02 22:58 - 2015-07-02 22:59 - 00015707 _____ C:\Users\Kueken1\Downloads\FRST.txt 2015-07-02 22:58 - 2015-07-02 22:58 - 02112512 _____ (Farbar) C:\Users\Kueken1\Downloads\FRST64.exe 2015-07-02 22:58 - 2015-07-02 22:58 - 00000000 ____D C:\FRST 2015-07-02 22:57 - 2015-07-02 22:57 - 00000490 _____ C:\Users\Kueken1\Downloads\defogger_disable.log 2015-07-02 22:57 - 2015-07-02 22:57 - 00000000 _____ C:\Users\VEnte\defogger_reenable 2015-07-02 22:56 - 2015-07-02 22:56 - 00050477 _____ C:\Users\Kueken1\Downloads\Defogger.exe 2015-07-02 22:34 - 2015-07-02 22:34 - 00380416 _____ C:\Users\Kueken1\Downloads\gc87s56g.exe 2015-07-02 22:18 - 2015-07-02 22:18 - 01636352 _____ (Farbar) C:\Users\Kueken1\Downloads\FRST.exe 2015-07-02 21:56 - 2015-07-02 21:57 - 02244096 _____ C:\Users\Kueken1\Downloads\AdwCleaner_4.207.exe 2015-07-02 19:43 - 2015-07-02 21:42 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Kueken1\Downloads\mbam-setup-2.1.6.1022.exe 2015-07-02 16:49 - 2015-07-02 16:49 - 18174128 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2015-07-02 16:46 - 2015-07-02 22:51 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-02 15:41 - 2015-07-02 19:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-07-02 15:18 - 2015-07-02 15:18 - 00000000 ____D C:\Users\Kueken1\AppData\Roaming\AVAST Software 2015-07-02 15:14 - 2015-07-02 15:14 - 00001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-07-02 15:14 - 2015-07-02 15:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2015-07-02 15:13 - 2015-07-02 15:13 - 00002247 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-07-02 15:13 - 2015-07-02 15:13 - 00000350 ____H C:\Windows\Tasks\avast! Emergency Update.job 2015-07-02 15:13 - 2015-07-02 15:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-07-02 15:07 - 2015-07-02 19:30 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-02 15:07 - 2015-07-02 15:14 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe 2015-07-02 15:07 - 2015-07-02 15:07 - 00272248 _____ C:\Windows\system32\Drivers\aswVmm.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00065736 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2015-07-02 15:07 - 2015-07-02 15:07 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr 2015-07-02 15:07 - 2015-07-02 15:07 - 00029168 _____ C:\Windows\system32\Drivers\aswHwid.sys 2015-07-02 14:51 - 2015-07-02 14:51 - 00000000 ____D C:\Program Files\AVAST Software 2015-07-01 13:33 - 2015-07-01 13:33 - 00000000 ____D C:\Users\VEnte\AppData\Roaming\JAM Software 2015-06-23 21:28 - 2015-06-23 21:28 - 00003224 ____N C:\bootsqm.dat 2015-06-22 19:24 - 2015-07-02 14:46 - 00000000 ____D C:\ProgramData\AVAST Software 2015-06-22 19:23 - 2015-06-22 19:24 - 05481344 _____ (Avast Software s.r.o.) C:\Users\Kueken1\Downloads\avast_free_antivirus_setup.exe 2015-06-22 19:23 - 2015-06-22 19:24 - 05481344 _____ (Avast Software s.r.o.) C:\Users\Public\Desktop\avast_free_antivirus_setup.exe 2015-06-22 19:11 - 2015-06-22 19:12 - 04718584 _____ (Avira Operations GmbH & Co. KG) C:\Users\Kueken1\Downloads\avira_de_av_5588320a39453__ws.exe 2015-06-22 18:01 - 2015-06-22 18:03 - 00000000 ____D C:\OETemp ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-02 22:57 - 2013-05-23 22:06 - 00000000 ____D C:\Users\VEnte 2015-07-02 22:47 - 2014-01-04 20:04 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-07-02 22:43 - 2009-07-14 06:45 - 00031792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-02 22:43 - 2009-07-14 06:45 - 00031792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-02 21:56 - 2014-06-10 16:40 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-07-02 21:52 - 2014-06-10 16:40 - 00001102 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-07-02 21:52 - 2014-06-10 16:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-07-02 21:52 - 2014-06-10 16:40 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-07-02 21:00 - 2013-05-16 12:15 - 01880411 _____ C:\Windows\WindowsUpdate.log 2015-07-02 19:46 - 2013-05-23 23:11 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-02 19:46 - 2013-05-23 23:11 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-02 19:36 - 2010-11-21 08:50 - 00698926 _____ C:\Windows\system32\perfh007.dat 2015-07-02 19:36 - 2010-11-21 08:50 - 00149034 _____ C:\Windows\system32\perfc007.dat 2015-07-02 19:36 - 2009-07-14 07:13 - 01618320 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-02 19:34 - 2015-04-26 21:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-07-02 19:29 - 2015-04-10 13:24 - 00003093 _____ C:\Windows\setupact.log 2015-07-02 19:29 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-02 18:29 - 2014-05-13 19:48 - 00000000 ____D C:\temp 2015-07-02 15:15 - 2015-04-10 13:24 - 00229700 _____ C:\Windows\PFRO.log 2015-07-02 15:13 - 2013-05-23 23:11 - 00000000 ____D C:\Program Files (x86)\Google 2015-06-23 15:47 - 2014-04-08 22:44 - 00000000 _____ C:\Users\Kueken1\AppData\Roaming\FoxitReaderUpdateInfo.txt 2015-06-22 19:20 - 2014-10-09 21:12 - 00000000 ____D C:\ProgramData\Package Cache 2015-06-22 19:14 - 2013-05-23 22:57 - 00000000 ____D C:\ProgramData\Avira 2015-06-22 19:14 - 2013-05-23 22:57 - 00000000 ____D C:\Program Files (x86)\Avira 2015-06-18 08:41 - 2014-06-10 16:40 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-06-18 08:41 - 2014-06-10 16:40 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-06-18 08:41 - 2014-06-10 16:40 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys ==================== Files in the root of some directories ======= 2014-04-08 22:44 - 2015-06-23 15:47 - 0000000 _____ () C:\Users\Kueken1\AppData\Roaming\FoxitReaderUpdateInfo.txt 2013-05-27 22:36 - 2015-01-23 21:57 - 0000600 _____ () C:\Users\Kueken1\AppData\Roaming\winscp.rnd 2013-12-02 15:23 - 2014-05-13 19:48 - 0007168 _____ () C:\Users\Kueken1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini Some files in TEMP: ==================== C:\Users\Kueken1\AppData\Local\Temp\Foxit Reader Updater.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed ==================== End of log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2015-07-02 23:14:49 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PB4O 465,76GB Running: gc87s56g.exe; Driver: C:\Users\VEnte~1\AppData\Local\Temp\kwryikog.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0cd292472f33 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0cd292472f33 (not active ControlSet) ---- EOF - GMER 2.1 ---- |
Themen zu Nach massiven Hardware-Problemen Win32:GenMaliciousA entdeckt |
adobe, antivirus, avast, avira, browser, defender, desktop, explorer, firefox, flash player, google, helper, homepage, internet, internet explorer, log, mozilla, opera, prozess, registry, scan, software, temp, usb, windows |