AdwCleanerAdwCleaner Logfile:
Code:
# AdwCleaner v2.306 - Datei am 04/08/2013 um 13:41:04 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Samsung - SAMSUNG-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Samsung\Downloads\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\yn1lg684.default\searchplugins\Askcom.xml
Ordner Gelöscht : C:\Program Files (x86)\Ask.com
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\Users\Samsung\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Samsung\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\yn1lg684.default\extensions\toolbar@ask.com
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16635
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v22.0 (de)
Datei : C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\yn1lg684.default\prefs.js
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [1293 octets] - [04/08/2013 13:41:04]
########## EOF - C:\AdwCleaner[S1].txt - [1353 octets] ##########
--- --- ---
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=347e105ea4325a429f3f34f7396220fa
# engine=14644
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-08-04 03:00:00
# local_time=2013-08-04 05:00:00 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 2057156 127258250 0 0
# scanned=206668
# found=0
# cleaned=0
# scan_time=10364
checkup
Results of screen317's Security Check version 0.99.71
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Computer Security
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 25
Adobe Flash Player 11.8.800.94
Adobe Reader XI
Mozilla Firefox (22.0)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
F-Secure apps ComputerSecurity Anti-Virus\FSGK32.EXE
F-Secure apps ComputerSecurity Anti-Virus\fssm32.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
Symantec Norton Online Backup NOBuAgent.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRSTlog
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-08-2013
Ran by Samsung (administrator) on 05-08-2013 08:41:01
Running from C:\Users\Samsung\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\fshoster32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\CCF_Reputation\fsorsp.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\FSGK32.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\windows\System32\alg.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\fssm32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSHDLL64.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\fshoster32.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
(Farbar) C:\Users\Samsung\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11895400 2011-06-25] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-13] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [F-Secure Manager] - C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE [310208 2013-03-28] (F-Secure Corporation)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ConnectionCenter] - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [305088 2011-04-25] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [F-Secure Hoster (666)] - C:\Program Files (x86)\F-Secure\fshoster32.exe [191424 2013-05-15] (F-Secure Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Samsung BHO Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\yn1lg684.default
FF Homepage: hxxp://www.ebay.de/itm/Vorwerk-EB-351-eb-351-TOP-Uberholt-Mwst-Rechnung-Neue-Bursten-/190657493065?pt=DE_Elektronik_Computer_Haushaltsger%C3%83%C2%A4te_Staubsaugerbeutel_PM&hash=item2c64127849|hxxp://www.ebay.de/itm/Vorwerk-Elektroburste-EB-351-m-NEUEN-Burstenwalzen-/200754329732?pt=DE_Elektronik_Computer_Haushaltsger%C3%A4te_Staubsaugerbeutel_PM&hash=item2ebde3f884
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\yn1lg684.default\searchplugins\ecosia.xml
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==================== Services (Whitelisted) =================
R2 fshoster; C:\Program Files (x86)\F-Secure\fshoster32.exe [191424 2013-05-15] (F-Secure Corporation)
R3 FSMA; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE [216000 2013-03-28] (F-Secure Corporation)
R2 FSORSPClient; C:\Program Files (x86)\F-Secure\apps\CCF_Reputation\fsorsp.exe [60352 2013-06-25] (F-Secure Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] ()
==================== Drivers (Whitelisted) ====================
R3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [202176 2013-08-02] (F-Secure Corporation)
R3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [202176 2013-08-02] (F-Secure Corporation)
R1 F-Secure HIPS; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\HIPS\drivers\fshs.sys [68928 2013-06-25] (F-Secure Corporation)
R1 F-Secure HIPS; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\HIPS\drivers\fshs.sys [68928 2013-06-25] (F-Secure Corporation)
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [56016 2013-08-02] ()
R0 fsbts; C:\Windows\SysWow64\Drivers\fsbts.sys [42248 2013-02-26] ()
R3 fsni; C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\fsni64.sys [80832 2013-04-25] (F-Secure Corporation)
R3 fsni; C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\fsni64.sys [80832 2013-04-25] (F-Secure Corporation)
R1 fsvista; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [13248 2013-03-28] ()
R1 fsvista; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [13248 2013-03-28] ()
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2011-12-01] (Windows (R) 2003 DDK 3790 provider)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2011-12-01] (Windows (R) 2003 DDK 3790 provider)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-05 08:39 - 2013-08-05 08:39 - 01788733 _____ (Farbar) C:\Users\Samsung\Downloads\FRST64(1).exe
2013-08-05 08:38 - 2013-08-05 08:38 - 00001018 _____ C:\Users\Samsung\Desktop\checkup.txt
2013-08-05 08:33 - 2013-08-05 08:33 - 00891098 _____ C:\Users\Samsung\Desktop\SecurityCheck.exe
2013-08-04 13:50 - 2013-08-04 13:51 - 02347384 _____ (ESET) C:\Users\Samsung\Downloads\esetsmartinstaller_enu.exe
2013-08-04 13:44 - 2013-08-04 13:44 - 00001422 _____ C:\Users\Samsung\Desktop\AdwCleaner[S1].txt
2013-08-04 13:41 - 2013-08-04 13:41 - 00001422 _____ C:\AdwCleaner[S1].txt
2013-08-04 13:38 - 2013-08-04 13:39 - 00666633 _____ C:\Users\Samsung\Downloads\adwcleaner.exe
2013-08-03 15:26 - 2013-08-03 15:26 - 00023399 _____ C:\Users\Samsung\Downloads\Addition.txt
2013-08-03 15:25 - 2013-08-03 15:25 - 00000000 ____D C:\FRST
2013-08-03 15:23 - 2013-08-03 15:23 - 01781485 _____ (Farbar) C:\Users\Samsung\Downloads\FRST64.exe
2013-08-03 13:29 - 2013-08-03 13:29 - 00001069 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-03 13:29 - 2013-08-03 13:29 - 00000000 ____D C:\Users\Samsung\AppData\Roaming\Malwarebytes
2013-08-03 13:29 - 2013-08-03 13:29 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-03 13:29 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-08-03 13:28 - 2013-08-03 13:29 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-03 13:27 - 2013-08-03 13:28 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Samsung\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-02 15:13 - 2013-08-02 15:13 - 00001903 _____ C:\Users\Public\Desktop\F-Secure.lnk
2013-07-19 21:11 - 2013-07-19 21:12 - 00000000 ____D C:\Users\Samsung\Desktop\Challenge Roth, 14072013
2013-07-17 18:57 - 2013-07-17 18:58 - 00000000 ____D C:\windows\system32\MRT
2013-07-16 21:47 - 2013-07-16 21:49 - 00000000 ____D C:\Users\Samsung\Desktop\triathlon 2013
2013-07-15 12:24 - 2013-07-15 12:24 - 01067456 _____ (Solid State Networks) C:\Users\Samsung\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe
2013-07-13 20:42 - 2013-07-13 20:42 - 00784856 _____ (Google Inc.) C:\Users\Samsung\Downloads\GoogleEarthPluginSetup.exe
2013-07-13 20:42 - 2013-07-13 20:42 - 00784856 _____ (Google Inc.) C:\Users\Samsung\Downloads\GoogleEarthPluginSetup(1).exe
2013-07-11 13:48 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-07-11 13:48 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-07-11 13:48 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-07-11 13:48 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-07-11 13:48 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-07-11 13:48 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-07-11 13:48 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-07-11 13:48 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-07-11 13:48 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-07-11 13:48 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-07-11 13:48 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-07-11 13:48 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-07-11 13:48 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-07-11 13:48 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-07-11 13:48 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-07-11 13:48 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-07-11 13:48 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-07-11 13:48 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-07-11 13:48 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-07-11 13:48 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-07-11 13:48 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-07-11 13:48 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-07-11 13:48 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-07-11 13:48 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-07-11 13:48 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-07-11 13:48 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-07-11 13:48 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-07-11 13:48 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-11 13:48 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-07-11 13:48 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-07-11 13:48 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-07-11 08:26 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-07-11 08:26 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2013-07-11 08:26 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2013-07-11 08:26 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-07-11 08:26 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2013-07-11 08:25 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2013-07-11 08:25 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
==================== One Month Modified Files and Folders =======
2013-08-05 08:39 - 2013-08-05 08:39 - 01788733 _____ (Farbar) C:\Users\Samsung\Downloads\FRST64(1).exe
2013-08-05 08:38 - 2013-08-05 08:38 - 00001018 _____ C:\Users\Samsung\Desktop\checkup.txt
2013-08-05 08:33 - 2013-08-05 08:33 - 00891098 _____ C:\Users\Samsung\Desktop\SecurityCheck.exe
2013-08-05 08:27 - 2009-07-14 06:45 - 00021200 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-05 08:27 - 2009-07-14 06:45 - 00021200 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-05 08:24 - 2011-10-31 22:39 - 01464624 _____ C:\windows\WindowsUpdate.log
2013-08-05 08:20 - 2012-10-20 11:20 - 00000374 _____ C:\windows\system32\Drivers\etc\hosts.ics
2013-08-05 08:20 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-05 08:20 - 2009-07-14 06:51 - 00134841 _____ C:\windows\setupact.log
2013-08-05 07:07 - 2012-03-30 13:57 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-08-04 20:43 - 2012-02-24 19:34 - 00000000 ____D C:\Users\Samsung\Documents\Outlook-Dateien
2013-08-04 13:59 - 2011-10-31 22:16 - 00657016 _____ C:\windows\system32\perfh007.dat
2013-08-04 13:59 - 2011-10-31 22:16 - 00131454 _____ C:\windows\system32\perfc007.dat
2013-08-04 13:59 - 2009-07-14 07:13 - 01506562 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-04 13:51 - 2013-08-04 13:50 - 02347384 _____ (ESET) C:\Users\Samsung\Downloads\esetsmartinstaller_enu.exe
2013-08-04 13:44 - 2013-08-04 13:44 - 00001422 _____ C:\Users\Samsung\Desktop\AdwCleaner[S1].txt
2013-08-04 13:41 - 2013-08-04 13:41 - 00001422 _____ C:\AdwCleaner[S1].txt
2013-08-04 13:39 - 2013-08-04 13:38 - 00666633 _____ C:\Users\Samsung\Downloads\adwcleaner.exe
2013-08-03 15:26 - 2013-08-03 15:26 - 00023399 _____ C:\Users\Samsung\Downloads\Addition.txt
2013-08-03 15:25 - 2013-08-03 15:25 - 00000000 ____D C:\FRST
2013-08-03 15:23 - 2013-08-03 15:23 - 01781485 _____ (Farbar) C:\Users\Samsung\Downloads\FRST64.exe
2013-08-03 13:29 - 2013-08-03 13:29 - 00001069 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-03 13:29 - 2013-08-03 13:29 - 00000000 ____D C:\Users\Samsung\AppData\Roaming\Malwarebytes
2013-08-03 13:29 - 2013-08-03 13:29 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-03 13:29 - 2013-08-03 13:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-03 13:28 - 2013-08-03 13:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Samsung\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-02 16:24 - 2012-02-24 15:13 - 00000000 ____D C:\Program Files (x86)\F-Secure
2013-08-02 16:24 - 2010-11-21 05:47 - 00982208 _____ C:\windows\PFRO.log
2013-08-02 15:21 - 2012-05-04 18:24 - 00056016 _____ C:\windows\system32\Drivers\fsbts.sys
2013-08-02 15:15 - 2012-02-24 16:02 - 00277622 _____ C:\windows\FSAVINST.LOG
2013-08-02 15:15 - 2012-02-24 16:02 - 00016478 _____ C:\windows\FSGKIAIN.log
2013-08-02 15:15 - 2012-02-24 16:02 - 00012390 _____ C:\windows\FSAVCSIN.LOG
2013-08-02 15:15 - 2012-02-24 16:02 - 00007326 _____ C:\windows\FSLDIN.LOG
2013-08-02 15:15 - 2012-02-24 16:02 - 00003483 _____ C:\windows\fsavunin.log
2013-08-02 15:15 - 2012-02-24 16:02 - 00002628 _____ C:\windows\fsav_db_setup.log
2013-08-02 15:15 - 2012-02-24 16:01 - 08023472 _____ C:\windows\FSISU.log
2013-08-02 15:15 - 2012-02-24 16:01 - 01774956 _____ C:\windows\FSSFM.log
2013-08-02 15:15 - 2012-02-24 16:01 - 01530657 _____ C:\windows\FSSETUP.log
2013-08-02 15:15 - 2012-02-24 16:01 - 00569508 _____ C:\windows\FSPROD.log
2013-08-02 15:15 - 2012-02-24 16:01 - 00494878 _____ C:\windows\RunSetup.log
2013-08-02 15:14 - 2012-02-24 16:02 - 00019829 _____ C:\windows\prodsett_copy.ini
2013-08-02 15:14 - 2012-02-24 16:02 - 00002380 _____ C:\windows\DAASINST.LOG
2013-08-02 15:14 - 2012-02-24 16:01 - 00677621 _____ C:\windows\FSDEPH.log
2013-08-02 15:13 - 2013-08-02 15:13 - 00001903 _____ C:\Users\Public\Desktop\F-Secure.lnk
2013-08-02 15:13 - 2012-02-24 16:02 - 00081886 _____ C:\windows\fspplugin.log
2013-07-31 20:50 - 2009-07-14 07:08 - 00032632 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-07-30 14:19 - 2012-06-09 22:56 - 00000000 ____D C:\Users\Samsung\AppData\Local\CrashDumps
2013-07-30 09:59 - 2012-03-30 13:57 - 00692104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-07-30 09:59 - 2012-03-30 13:57 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-07-30 09:59 - 2012-02-25 14:35 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-30 09:58 - 2012-02-22 14:50 - 00000000 ____D C:\Users\Samsung\AppData\Local\Adobe
2013-07-29 20:44 - 2012-08-16 22:24 - 00000000 ____D C:\Users\Samsung\AppData\Roaming\vlc
2013-07-29 20:17 - 2012-08-16 22:25 - 00000000 ____D C:\Users\Samsung\AppData\Roaming\dvdcss
2013-07-25 07:17 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\NDF
2013-07-19 21:12 - 2013-07-19 21:11 - 00000000 ____D C:\Users\Samsung\Desktop\Challenge Roth, 14072013
2013-07-19 18:12 - 2012-02-26 19:18 - 00000000 ____D C:\Users\Samsung\Documents\Vermögen
2013-07-19 17:41 - 2012-02-24 17:21 - 00000000 ____D C:\Users\Samsung\AppData\Local\Microsoft Help
2013-07-18 20:39 - 2012-12-08 10:38 - 00000000 ____D C:\Users\Samsung\Documents\Gebetsabende
2013-07-17 18:58 - 2013-07-17 18:57 - 00000000 ____D C:\windows\system32\MRT
2013-07-16 21:49 - 2013-07-16 21:47 - 00000000 ____D C:\Users\Samsung\Desktop\triathlon 2013
2013-07-16 10:35 - 2012-12-20 20:41 - 00000000 ____D C:\Program Files (x86)\WildTangent Games
2013-07-15 12:24 - 2013-07-15 12:24 - 01067456 _____ (Solid State Networks) C:\Users\Samsung\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe
2013-07-13 20:42 - 2013-07-13 20:42 - 00784856 _____ (Google Inc.) C:\Users\Samsung\Downloads\GoogleEarthPluginSetup.exe
2013-07-13 20:42 - 2013-07-13 20:42 - 00784856 _____ (Google Inc.) C:\Users\Samsung\Downloads\GoogleEarthPluginSetup(1).exe
2013-07-11 21:35 - 2009-07-14 06:45 - 00427072 _____ C:\windows\system32\FNTCACHE.DAT
2013-07-11 21:34 - 2011-10-31 22:07 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-11 21:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-11 21:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-11 13:56 - 2012-02-24 17:21 - 00000000 ____D C:\ProgramData\Microsoft Help
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-29 19:54
==================== End Of Log ============================
--- --- ---
Jetzt passt wieder alles, oder?