Hallo schrauber und danke.
Malware: Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.01.11.04
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Boppel :: BOPPEL-PC [Administrator]
Schutz: Aktiviert
11.01.2014 14:42:36
mbam-log-2014-01-11 (14-42-36).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 274838
Laufzeit: 4 Minute(n), 20 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bösartig: (0) Gut: (1) -> Erfolgreich ersetzt und in Quarantäne gestellt.
Infizierte Verzeichnisse: 4
C:\Users\Boppel\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Boppel\AppData\Roaming\OpenCandy\760299429AA94238A922149DB4983D57 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Boppel\AppData\Roaming\OpenCandy\92D588F5E34B4A458B23C9F3DB2D5B5E (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Boppel\AppData\Roaming\OpenCandy\OpenCandy_760299429AA94238A922149DB4983D57 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 6
C:\Users\Boppel\AppData\Roaming\OpenCandy\760299429AA94238A922149DB4983D57\2996.ico (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Boppel\AppData\Roaming\OpenCandy\760299429AA94238A922149DB4983D57\blekkotb_002Tb_1.0.0.20.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Boppel\AppData\Roaming\OpenCandy\760299429AA94238A922149DB4983D57\Blekko_Viscom_p1v3.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Boppel\AppData\Roaming\OpenCandy\760299429AA94238A922149DB4983D57\EBB77268-338F-4C6A-8590-AD88FED26F4A (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Boppel\AppData\Roaming\OpenCandy\760299429AA94238A922149DB4983D57\OCBrowserHelper_1.0.3.85.dll (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Boppel\AppData\Roaming\OpenCandy\92D588F5E34B4A458B23C9F3DB2D5B5E\TuneUpUtilities2013_2200217_de-DE.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) adwarecleaner: Code:
# AdwCleaner v3.016 - Bericht erstellt am 11/01/2014 um 14:58:01
# Aktualisiert 23/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Boppel - BOPPEL-PC
# Gestartet von : C:\Users\Boppel\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\blekko toolbars
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Program Files (x86)\Movier-media
Ordner Gelöscht : C:\Users\Boppel\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Boppel\AppData\LocalLow\Movier-media
Ordner Gelöscht : C:\Users\Boppel\AppData\Roaming\Mozilla\Firefox\Profiles\fcp69dsk.default\Smartbar
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2186473
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26C9E18C-3717-4BE1-A225-04E4471F5B6E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CE10BF86-DA68-441E-91FA-38336363E3CD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2ADFA15A-35FC-4DD4-B211-7D34868852BA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B481DDE0-20D6-4DAB-850C-3D1372BDEC87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CE10BF86-DA68-441E-91FA-38336363E3CD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{26C9E18C-3717-4BE1-A225-04E4471F5B6E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE10BF86-DA68-441E-91FA-38336363E3CD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{26C9E18C-3717-4BE1-A225-04E4471F5B6E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CE10BF86-DA68-441E-91FA-38336363E3CD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2ADFA15A-35FC-4DD4-B211-7D34868852BA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B481DDE0-20D6-4DAB-850C-3D1372BDEC87}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CE10BF86-DA68-441E-91FA-38336363E3CD}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CE10BF86-DA68-441E-91FA-38336363E3CD}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CE10BF86-DA68-441E-91FA-38336363E3CD}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{CE10BF86-DA68-441E-91FA-38336363E3CD}]
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Movier-media
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\PIP
Schlüssel Gelöscht : HKLM\Software\Movier-media
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Movier-media Toolbar
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v26.0 (de)
[ Datei : C:\Users\Boppel\AppData\Roaming\Mozilla\Firefox\Profiles\fcp69dsk.default\prefs.js ]
Zeile gelöscht : user_pref("CT2186473./9B-0?3G>D.enc", "PT5AbXNuP3V6dHBzdyB7e3l6JXpOTiUqKCUkKScmKSYuMC8r");
Zeile gelöscht : user_pref("CT2186473./9B5BA==9CJAG.enc", "PW1rb2o+cUV6RXZxdEd5e04heiB8");
Zeile gelöscht : user_pref("CT2186473./9B90E@8FF=EG.enc", "OT81Lz4=");
Zeile gelöscht : user_pref("CT2186473.1000082.isDisplayHidden", "true");
Zeile gelöscht : user_pref("CT2186473.1000082.isPlayDisplay", "true");
Zeile gelöscht : user_pref("CT2186473.1000082.state", "{\"state\":\"stopped\",\"text\":\"RNE Radio...\",\"description\":\"RNE Radio 1\",\"url\":\"hxxp://www.rtve.es/rne/audio/r1live.asx\"}");
Zeile gelöscht : user_pref("CT2186473.1000234.TWC_TMP_city", "BERLIN");
Zeile gelöscht : user_pref("CT2186473.1000234.TWC_TMP_country", "DE");
Zeile gelöscht : user_pref("CT2186473.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2186473.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2186473.FirstTime", "true");
Zeile gelöscht : user_pref("CT2186473.FirstTimeFF3", "true");
Zeile gelöscht : user_pref("CT2186473.LoginRevertSettingsEnabled", false);
Zeile gelöscht : user_pref("CT2186473.RevertSettingsEnabled", true);
Zeile gelöscht : user_pref("CT2186473.ShoppingApp.GK.Exipres.enc", "U2F0IE5vdiAyNCAyMDEyIDE5OjEyOjIyIEdNVCswMTAw");
Zeile gelöscht : user_pref("CT2186473.ShoppingApp.GK.GeoLocation.enc", "Z2VybWFueQ==");
Zeile gelöscht : user_pref("CT2186473.UserID", "UN88971236919425016");
Zeile gelöscht : user_pref("CT2186473.addressBarTakeOverEnabledInHidden", "true");
Zeile gelöscht : user_pref("CT2186473.embeddedsData", "[{\"appId\":\"128206941184375899\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
Zeile gelöscht : user_pref("CT2186473.enableAlerts", "never");
Zeile gelöscht : user_pref("CT2186473.firstTimeDialogOpened", "true");
Zeile gelöscht : user_pref("CT2186473.fixPageNotFoundErrorInHidden", "true");
Zeile gelöscht : user_pref("CT2186473.fixUrls", true);
Zeile gelöscht : user_pref("CT2186473.isCheckedStartAsHidden", true);
Zeile gelöscht : user_pref("CT2186473.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2186473.isFirstTimeToolbarLoading", "false");
Zeile gelöscht : user_pref("CT2186473.isNewTabEnabled", false);
Zeile gelöscht : user_pref("CT2186473.isPerformedSmartBarTransition", "true");
Zeile gelöscht : user_pref("CT2186473.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gelöscht : user_pref("CT2186473.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2186473.migrateAppsAndComponents", true);
Zeile gelöscht : user_pref("CT2186473.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about%3Aaddons\",\"EB_MAIN_FRAME_TITLE\":\"\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://Moviermedia.OurToolbar.c[...]
Zeile gelöscht : user_pref("CT2186473.search.searchAppId", "128206941184375899");
Zeile gelöscht : user_pref("CT2186473.search.searchCount", "0");
Zeile gelöscht : user_pref("CT2186473.searchInNewTabEnabled", "false");
Zeile gelöscht : user_pref("CT2186473.searchInNewTabEnabledInHidden", "true");
Zeile gelöscht : user_pref("CT2186473.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2186473\"}");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://Moviermedia.OurToolbar.com//xpi\"}");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Movier-media\"}");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1353348980544");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_appsMetadata_lastUpdate", "1353348867343");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1353348865591");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_login_10.10.27.6_lastUpdate", "1350502713850");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_login_10.13.40.15_lastUpdate", "1353349494286");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_optimizer_lastUpdate", "1350502714442");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1353348865814");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_searchAPI_lastUpdate", "1353348864293");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_serviceMap_lastUpdate", "1353348860332");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_toolbarContextMenu_lastUpdate", "1353348867505");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_toolbarSettings_lastUpdate", "1353348864237");
Zeile gelöscht : user_pref("CT2186473.serviceLayer_services_translation_lastUpdate", "1353348867310");
Zeile gelöscht : user_pref("CT2186473.settingsINI", true);
Zeile gelöscht : user_pref("CT2186473.smartbar.CTID", "CT2186473");
Zeile gelöscht : user_pref("CT2186473.smartbar.Uninstall", "0");
Zeile gelöscht : user_pref("CT2186473.smartbar.isHidden", false);
Zeile gelöscht : user_pref("CT2186473.smartbar.toolbarName", "Movier-media ");
Zeile gelöscht : user_pref("CT2186473.toolbarBornServerTime", "15-10-2012");
Zeile gelöscht : user_pref("CT2186473.toolbarCurrentServerTime", "19-11-2012");
Zeile gelöscht : user_pref("CT2186473.toolbarDisabled", "true");
Zeile gelöscht : user_pref("CT2186473.upgradeFromClearSBVersion", true);
Zeile gelöscht : user_pref("CT2186473_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1353350012610,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
*************************
AdwCleaner[R0].txt - [11263 octets] - [11/01/2014 14:56:52]
AdwCleaner[S0].txt - [10707 octets] - [11/01/2014 14:58:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10768 octets] ##########
JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows 7 Home Premium x64
Ran by Boppel on 11.01.2014 at 15:05:29,64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APN_ATU3__RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APN_ATU3__RASMANCS
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Boppel\appdata\local\cre"
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{066900C6-CBF9-46A3-AF47-C660A8BE0188}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{08F1A309-18AD-43B3-9BB4-D492579A8781}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{0A07CA1D-2123-4581-B3E1-AB68DF85275C}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{0C61D2D4-D5ED-44C7-8437-489D0CC8AAA3}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{151A56E5-36A0-416C-97EF-929A2A076A5B}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{1583E035-1DE9-4192-A87F-868BF78BD619}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{1A73D5EE-BD92-499C-9AEE-BE3312BE33B1}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{1B0B494D-8A6C-4AFF-B90C-E297E5F9230F}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{1CA47B73-7CE1-4EB9-B541-C374512C5472}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{1D28C5AF-4053-4746-8871-FFB9F393007D}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{2351659C-0C56-44C9-978D-8378224C11D1}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{247EF8B1-F155-4128-96AD-4B02023796F4}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{288756D1-3F15-4402-ABBF-59B40350C69A}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{2A5BCFD3-B987-454D-A3B2-38BBDD5798E3}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{2B203476-3AAF-4C4C-8D0E-414E12219B18}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{3891CD8E-A90A-4402-AD75-B303E83F1367}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{38E09F5B-4EC0-412E-87B8-99AB0E28793D}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{3BAA55AD-1006-4050-940C-0A9228578413}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{3E5582AE-B3BE-4A0F-9BA1-2AD6EF754E97}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{432A511A-96C5-4982-938A-297D7B2B86F5}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{49D36247-E501-4548-9449-9A249FDAAC8F}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{517E7017-607A-4C9A-B3AE-197E172EC122}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{55AD3A1E-F220-450B-BB48-72B9A584DC89}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{574E6FF0-29BC-460D-83D8-9E1F404C3E07}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{58CCCBBA-F5D8-4481-B125-3A82845E5DA1}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{5BC9A49E-E6AC-4A38-AA19-BE948582E204}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{5C0F6050-5202-489F-AEA0-D8A78211BDA1}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{5CF14BE7-1EC0-43FA-84F2-24AF8FC7F484}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{5E55E662-D385-4ABA-A4E1-5D6B25A63EE1}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{5EA2BC53-04A3-4057-934A-6CE6826B9413}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{62A90204-8DAC-43C3-B81F-64D92118BBB2}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{64AE249E-FEDD-483A-A5E0-AD9B452E52B8}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{66F113F9-6518-4B3F-B812-4DBC5FB0D85E}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{6775A2A6-9C10-49B6-97D1-84ABF3625BA5}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{69CABA14-89AD-43AB-88AF-9EFE73F23551}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{6B6F3802-CC56-4B84-8855-41D106492930}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{6D01C6A2-A1B3-4ED3-8C92-E0D6C3F08A46}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{6EE4D8EF-1D1A-4923-9B3C-388B82EAE807}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{7257655D-5E3E-4A0E-AD14-A6A94947C533}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{72D89F31-8454-4100-A8AD-827E9FB4AF20}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{74030C7F-69DE-4A77-A8D8-62421551E276}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{788AE695-4E39-4F2B-9CFA-DC8106736E3B}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{7BE82D63-699D-4EF3-A1DC-F3B074708CAA}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{7C732AE9-9C02-4E57-877C-BE20BBBA68C1}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{7C8C3FF4-99E3-464B-88A2-E2142063ED81}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{82D49EE9-565F-413A-A338-0FA5A178E848}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{866515B3-D620-428D-A652-5B67D2C69255}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{8C2708BA-3000-437A-A73F-E59ABAAC5F0C}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{8D680DC7-890E-441F-AE27-7E830193BC2D}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{9462A26B-1A92-454D-9FC0-590097CD45FC}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{9625F0B7-1195-47A7-9004-282B5C85BF79}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{991D0E26-5E9D-4459-990F-5B38D5B32E44}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{9FE2815B-5194-4243-A34F-CEDF9763FE8F}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{A1C6CD86-3252-4262-ABDE-9E05200CCD37}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{A1D28277-D018-49B0-9F53-AB6FD0FDB071}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{A59CF2D9-95C4-45DF-8CF5-882F3B7813AB}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{A760CD09-9FF1-474F-8626-6FBDC513A321}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{A8A79684-1D7B-4AD8-9EDA-A35E648C052D}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{A8DB3812-402F-402E-AF26-503E71169AB6}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{AD4D118F-21C2-472C-B77D-291F79AEC9EF}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{B2450173-1F19-4047-9156-3C8A403186D2}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{B2645E57-E054-477C-BBE6-8E5FE6FCE82A}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{B3336F22-E863-451B-BA8A-B625A6FB9341}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{B973495A-C998-4855-883B-6EE9B5CBD16A}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{BAFBA132-3945-4D3B-A9EF-9BF68B444F20}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{BB75964F-EBBB-429D-B314-B2F2C256BB88}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{BCA1F5E9-F30A-43DD-B7AC-FDAD78DCF06A}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{BD358C0E-CAE9-46A4-9683-86DF649A3DD6}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{BE9662CC-F1C5-421D-9936-8AF133CC44F2}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{C24B331B-A286-4B86-8AA1-C6774865A448}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{C6547AFE-50D0-4259-9F71-DE09252194B1}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{C8304FC8-5E3E-48AC-8624-1A0535910FC4}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{C88A1A28-9AF4-4F2D-9D6F-E159A834D8F0}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{CC733262-F714-4DB4-A631-CB07F1F960AE}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{CDA75440-ADD2-4AE8-A74E-8715791A42E2}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{D2AF5CAE-82FC-4382-A395-ABCF71F97491}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{D3D6C028-40F0-4A6D-B91E-C06067268F28}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{D4D66671-E5FD-4884-942F-ED9CA56E093B}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{D6500C96-F7A9-4BA9-9830-A87EE17B79A0}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{D89BA28E-6D27-486D-8CC3-6896F66A0921}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{DA180ADC-63AF-48CA-9906-F909A4BACA89}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{DC373AEF-3D3B-47D7-9E5B-F170E871B00F}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{E8C8A19A-0639-41F0-BFAB-69DD1C2A2875}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{E94E3C22-F5C1-4C42-931E-4A0030BBE10E}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{EED968DE-BFB7-4D58-9523-5BEFF2BA117B}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{F09672EE-8C00-4B8B-882A-A263AE683EF4}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{F2A526C5-4C45-4BC6-BF6A-C942971FACA7}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{F4B3EBA6-E433-4106-B196-7706A29C6797}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{F6249E18-4297-4BDE-BB49-3C9FB3824E68}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{FAE6D3A0-4365-43CD-8B98-0FD290217093}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{FDC85FDF-6063-47B6-9FBC-7E75DAFFB3A9}
Successfully deleted: [Empty Folder] C:\Users\Boppel\appdata\local\{FEB15C56-AD70-4E5F-BE8B-088A19021798}
~~~ FireFox
Failed to delete: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\blekkotb.xml"
Successfully deleted: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\blekkotb.xml"
Emptied folder: C:\Users\Boppel\AppData\Roaming\mozilla\firefox\profiles\fcp69dsk.default\minidumps [639 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.01.2014 at 15:12:06,04
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-01-2014 03
Ran by Boppel (administrator) on BOPPEL-PC on 11-01-2014 15:22:40
Running from C:\Users\Boppel\Desktop\Virenscan
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Users\Boppel\AppData\Roaming\IDriveSync\IDriveSyncService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe
(Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe
() C:\Users\Boppel\AppData\Roaming\IDriveSync\IDriveSyncTray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Users\Boppel\AppData\Roaming\IDriveSync\IDriveSync_Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [ProfilerU] - C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2013-01-31] (Saitek)
HKLM\...\Run: [SaiMfd] - C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2013-01-31] (Saitek)
HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [43608 2010-09-07] ()
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2014-01-06] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
Startup: C:\Users\Boppel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IDriveSync.lnk
ShortcutTarget: IDriveSync.lnk -> C:\Users\Boppel\AppData\Roaming\IDriveSync\IDriveSyncTray.exe ()
Startup: C:\Users\Boppel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Firefox.lnk
ShortcutTarget: Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{4B5E5FDD-64F0-4445-BE51-D0D9FEF33C88}: [NameServer]192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Boppel\AppData\Roaming\Mozilla\Firefox\Profiles\fcp69dsk.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Xmarks - C:\Users\Boppel\AppData\Roaming\Mozilla\Firefox\Profiles\fcp69dsk.default\Extensions\foxmarks@kei.com [2013-05-21]
FF Extension: Snip It! Button for eBay - C:\Users\Boppel\AppData\Roaming\Mozilla\Firefox\Profiles\fcp69dsk.default\Extensions\{aab35b56-0206-4472-9993-9cb5c09bb722} [2012-08-29]
FF Extension: Flash and Video Download - C:\Users\Boppel\AppData\Roaming\Mozilla\Firefox\Profiles\fcp69dsk.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2014-01-11]
FF Extension: Multi Links - C:\Users\Boppel\AppData\Roaming\Mozilla\Firefox\Profiles\fcp69dsk.default\Extensions\multilinks@plugin.xpi [2012-10-04]
FF Extension: Adblock Plus - C:\Users\Boppel\AppData\Roaming\Mozilla\Firefox\Profiles\fcp69dsk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-05-15]
FF Extension: DownThemAll! - C:\Users\Boppel\AppData\Roaming\Mozilla\Firefox\Profiles\fcp69dsk.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2013-10-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-01-06]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-01-06]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-01-06]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2014-01-06] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG)
R2 IDriveSyncService; C:\Users\Boppel\AppData\Roaming\IDriveSync\IDriveSyncService.exe [125064 2012-11-26] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
S3 61883; C:\Windows\System32\DRIVERS\61883.sys [60288 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-06] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-06] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
R1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 SaiK0CC3; C:\Windows\System32\DRIVERS\SaiK0CC3.sys [180584 2012-09-20] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-02-01] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-02-01] (Saitek)
S3 SaiU0CC3; C:\Windows\System32\DRIVERS\SaiU0CC3.sys [47208 2012-09-20] (Saitek)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-11 15:12 - 2014-01-11 15:12 - 00011098 _____ C:\Users\Boppel\Desktop\JRT.txt
2014-01-11 15:05 - 2014-01-11 15:05 - 00000000 ____D C:\Windows\ERUNT
2014-01-11 15:04 - 2014-01-08 04:36 - 01037068 _____ (Thisisu) C:\Users\Boppel\Desktop\JRT.exe
2014-01-11 14:56 - 2014-01-11 14:58 - 00000000 ____D C:\AdwCleaner
2014-01-11 14:51 - 2014-01-11 14:51 - 01233962 _____ C:\Users\Boppel\Desktop\adwcleaner.exe
2014-01-11 14:38 - 2014-01-11 14:38 - 00000000 ____D C:\Users\Boppel\AppData\Roaming\Malwarebytes
2014-01-11 14:38 - 2014-01-11 14:38 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-11 14:38 - 2014-01-11 14:38 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-11 14:38 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-10 12:54 - 2014-01-10 12:54 - 00132475 _____ C:\ComboFix.txt
2014-01-10 12:08 - 2014-01-10 12:54 - 00000000 ____D C:\Qoobox
2014-01-10 12:08 - 2014-01-10 12:50 - 00000000 ____D C:\Windows\erdnt
2014-01-10 12:08 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2014-01-10 12:08 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2014-01-10 12:08 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-10 12:08 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-10 12:08 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-10 12:08 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2014-01-10 12:08 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2014-01-10 12:08 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2014-01-10 12:06 - 2014-01-10 12:06 - 05162489 ____R (Swearware) C:\Users\Boppel\Desktop\ComboFix.exe
2014-01-09 21:53 - 2014-01-11 15:22 - 00000000 ____D C:\Users\Boppel\Desktop\Virenscan
2014-01-09 17:52 - 2014-01-09 17:52 - 00001208 _____ C:\Users\Boppel\Documents\Gmer.txt
2014-01-09 17:07 - 2014-01-11 15:22 - 00000000 ____D C:\FRST
2014-01-09 17:06 - 2014-01-09 17:06 - 00000000 _____ C:\Users\Boppel\defogger_reenable
2014-01-06 19:25 - 2014-01-06 19:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-12 01:35 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 01:35 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 01:35 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 01:35 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 01:34 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 01:34 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 01:34 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 01:34 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 01:34 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 01:34 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 01:34 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 01:34 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 01:34 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 01:34 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 01:34 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 01:34 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 01:34 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 01:34 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 01:34 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 01:34 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 01:34 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 01:34 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 01:34 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 01:34 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-12 01:34 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 01:34 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 01:34 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 01:34 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-12 01:34 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 01:34 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 01:34 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 01:34 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 01:34 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-12 01:34 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 01:34 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
==================== One Month Modified Files and Folders =======
2014-01-11 15:22 - 2014-01-09 21:53 - 00000000 ____D C:\Users\Boppel\Desktop\Virenscan
2014-01-11 15:22 - 2014-01-09 17:07 - 00000000 ____D C:\FRST
2014-01-11 15:12 - 2014-01-11 15:12 - 00011098 _____ C:\Users\Boppel\Desktop\JRT.txt
2014-01-11 15:09 - 2009-07-14 05:45 - 00013728 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-11 15:09 - 2009-07-14 05:45 - 00013728 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-11 15:05 - 2014-01-11 15:05 - 00000000 ____D C:\Windows\ERUNT
2014-01-11 15:02 - 2012-12-19 05:55 - 00000000 ____D C:\Users\Boppel\AppData\Roaming\IDriveSync
2014-01-11 15:01 - 2012-05-13 22:04 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-11 15:01 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-11 15:01 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-11 15:01 - 2009-07-14 05:51 - 00058750 _____ C:\Windows\setupact.log
2014-01-11 15:00 - 2012-05-13 19:20 - 01851845 _____ C:\Windows\WindowsUpdate.log
2014-01-11 14:58 - 2014-01-11 14:56 - 00000000 ____D C:\AdwCleaner
2014-01-11 14:52 - 2012-05-13 22:40 - 00097698 _____ C:\Windows\PFRO.log
2014-01-11 14:51 - 2014-01-11 14:51 - 01233962 _____ C:\Users\Boppel\Desktop\adwcleaner.exe
2014-01-11 14:42 - 2012-05-14 17:33 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-11 14:38 - 2014-01-11 14:38 - 00000000 ____D C:\Users\Boppel\AppData\Roaming\Malwarebytes
2014-01-11 14:38 - 2014-01-11 14:38 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-11 14:38 - 2014-01-11 14:38 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-11 14:34 - 2012-05-13 23:11 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{95855130-2DEC-4489-A04C-D3F028595DFC}
2014-01-10 12:54 - 2014-01-10 12:54 - 00132475 _____ C:\ComboFix.txt
2014-01-10 12:54 - 2014-01-10 12:08 - 00000000 ____D C:\Qoobox
2014-01-10 12:50 - 2014-01-10 12:08 - 00000000 ____D C:\Windows\erdnt
2014-01-10 12:50 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-10 12:24 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default
2014-01-10 12:06 - 2014-01-10 12:06 - 05162489 ____R (Swearware) C:\Users\Boppel\Desktop\ComboFix.exe
2014-01-10 12:02 - 2012-05-13 19:36 - 00000000 ____D C:\Users\Boppel
2014-01-09 18:18 - 2012-05-14 19:20 - 00000000 ____D C:\ProgramData\Zoom Player
2014-01-09 17:52 - 2014-01-09 17:52 - 00001208 _____ C:\Users\Boppel\Documents\Gmer.txt
2014-01-09 17:06 - 2014-01-09 17:06 - 00000000 _____ C:\Users\Boppel\defogger_reenable
2014-01-08 04:36 - 2014-01-11 15:04 - 01037068 _____ (Thisisu) C:\Users\Boppel\Desktop\JRT.exe
2014-01-07 09:56 - 2012-05-13 22:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-07 03:05 - 2013-08-15 00:07 - 00000000 ____D C:\Windows\system32\MRT
2014-01-07 03:02 - 2012-05-15 16:41 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-06 23:23 - 2012-05-14 22:53 - 00000000 ____D C:\Users\Boppel\AppData\Roaming\ICQ
2014-01-06 19:25 - 2014-01-06 19:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-06 18:40 - 2013-05-07 16:28 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-01-06 18:40 - 2013-05-03 12:49 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-01-06 18:40 - 2013-05-03 12:49 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-12 16:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-12 16:09 - 2009-07-14 18:58 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-12-12 16:09 - 2009-07-14 18:58 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-12-12 16:09 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-12 16:04 - 2009-07-14 05:45 - 00311480 _____ C:\Windows\system32\FNTCACHE.DAT
Some content of TEMP:
====================
C:\Users\Boppel\AppData\Local\Temp\avgnt.exe
C:\Users\Boppel\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-09 18:36
==================== End Of Log ============================ --- --- ---
--- --- ---
Michael |