Hallo! Hoffe, du bist noch da...
Hier logEset Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=f5ed3ad2422b4b4684279a890cefae1c
# engine=18204
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-05-10 05:24:38
# local_time=2014-05-10 07:24:38 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 12048024 151329328 0 0
# scanned=151837
# found=1
# cleaned=0
# scan_time=3460
sh=9C860E0B0EAFF9D2912642BC3940BA098C00BBCE ft=1 fh=41f2b86635803f1b vn="NSIS/StartPage.CC Trojaner" ac=I fn="C:\Users\BS-Lap\Downloads\vlc-2.1.0-win64.exe" Himmel nochmal :schrei: , wo hab ich nur diese Trojaner her...und kannst du mir sagen, was dieser Trojaner macht? Kann ich davon ausgehen, dass dann auch der dritte Rechner, der am Netzwerk hängt, infiziert ist - oder sogar der erste Rechner wieder, den wir bereits überprüft haben? Und warum findet das gekaufte Bitdefender-Virenprogramm diesen Trojaner nicht? Wer weiss, wie lange ich den schon mitrumschleppe?
Hier log securitycheck Code:
Results of screen317's Security Check version 0.99.82
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
Adobe Flash Player 13.0.0.206
Adobe Reader XI
Mozilla Firefox (28.0)
Mozilla Thunderbird (17.0.8) ````````Process Check: objlist.exe by Laurent````````
Bitdefender Bitdefender 2013 bdagent.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
Und nun noch FRST
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2014 01
Ran by BS-Lap (administrator) on BS-LAPTOP on 10-05-2014 07:32:06
Running from C:\Users\BS-Lap\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Super Flexible Software Ltd. & Co. KG) C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
() C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
( ) C:\Program Files (x86)\LockKey\LockKey.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe
() C:\Program Files (x86)\Syncovery\SyncoveryService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2866960 2011-12-16] (Synaptics Incorporated)
HKLM\...\Run: [SynLenovoGestureMgr] => C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [410896 2011-12-16] (Synaptics)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12343400 2011-12-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-15] (Realtek Semiconductor)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789856 2012-08-23] (Lenovo)
HKLM\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8079408 2012-08-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6202416 2012-08-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-08-23] (Lenovo)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1575192 2014-02-09] (Bitdefender)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-21] (Intel Corporation)
HKLM-x32\...\Run: [LockKey] => C:\Program Files (x86)\LockKey\LockKey.exe [337776 2011-08-25] ( )
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [152896 2012-06-25] (Intel Corporation)
HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2012-01-26] (Lenovo, Inc.)
HKLM-x32\...\Run: [Intelligent Touchpad] => C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe [291272 2011-12-08] ()
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-28] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-28] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-08-23] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-772892197-4109324267-2503982889-1000\...\Run: [Power2GoExpress] => NA
HKU\S-1-5-21-772892197-4109324267-2503982889-1001\...\Run: [Syncovery Background Scheduler] => C:\Program Files (x86)\Syncovery\SyncoveryService.exe [15304016 2012-12-06] ()
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [260928 2012-02-23] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [215360 2012-02-23] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Lenovo\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.google.com/ig/redirectdomain?brand=KMOH&bmod=KMOH
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - URL hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms}
SearchScopes: HKLM-x32 - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=43169&gid=40335331560044&dbCode=1&command={searchTerms}
SearchScopes: HKLM-x32 - TopResultURLFallback hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms}
SearchScopes: HKCU - URL hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms}
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=43169&gid=40335331560044&dbCode=1&command={searchTerms}
SearchScopes: HKCU - TopResultURLFallback hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7KMOH_deDE511DE512
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120823200948.dll No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20121126152057.dll No File
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Ghostery - C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default\Extensions\firefox@ghostery.com.xpi [2013-08-29]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15]
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15]
Chrome:
=======
CHR HomePage: about:newtab
CHR RestoreOnStartup: "about:newtab"], "restore_on_startup_migrated":true, "restore_on_startup":4}, "net":{"http_server_properties":{"toolbarqueries.google.com:443":{"settings":[{"value":100, "id":4}], "supports_spdy":true}}}, "countryid_at_install":17477, "download":{"directory_upgrade":true, "extensions_to_open":""}, "extensions":{"autoupdate":{"next_check":"12998413474678835"}, "settings":{"coobgpohoikkiipiblmjeljniedjpjpf":{"from_bookmark":true, "path":"coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.19_0", "ack_external":true, "location":1, "was_installed_by_default":true, "install_time":"12998412905687238", "page_ordinal":"n", "manifest":{"name":"Google-Suche", "app":{"urls":["*://www.google.com/search", "*://www.google.com/webhp", "*://www.google.com/imgres"], "launch":{"web_url":"hxxp://www.google.com/webhp?source=search_app"}}, "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIiso3Loy5VJHL40shGhUl6it5ZG55XB9q/2EX6aa88jAxwPutbCgy5d9bm1YmBzLfSgpX4xcpgTU08ydWbd7b50fbkLsqWl1mRhxoqnN01kuNfv9Hbz9dWWYd+O4ZfD3L2XZs0wQqo0y6k64n+qeLkUMd1MIhf6MR8Xz1SOA8pwIDAQAB", "default_locale":"en", "update_url":"hxxp://clients2.google.com/service/update2/crx", "current_locale":"de", "icons":{"128":"128.png", "48":"48.png", "32":"32.png", "16":"16.png"}, "version":"0.0.0.19", "description":"Die schnellste Suche im Web."}, "state":1, "from_webstore":true, "app_launcher_ordinal":"t"}, "ahfgeienlihckogmohjhadlkjgocpleb":{"page_ordinal":"n", "app_launcher_ordinal":"q"}, "pjkljhegncpnkpknbcohdijeoejaedia":{"from_bookmark":false, "active_permissions":{"api":["notifications"]}, "path":"pjkljhegncpnkpknbcohdijeoejaedia\\7_0", "ack_external":true, "location":1, "was_installed_by_default":true, "install_time":"12998412906122238", "page_ordinal":"n", "manifest":{"permissions":["notifications"], "name":"Google Mail", "app":{"urls":["*://mail.google.com/mail/ca"], "launch":{"web_url":"https://mail.google.com/mail/ca", "container":"tab"}}, "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB", "default_locale":"en", "update_url":"hxxp://clients2.google.com/service/update2/crx", "current_locale":"de", "icons":{"128":"128.png"}, "version":"7", "options_page":"https://mail.google.com/mail/ca/#settings", "description":"Schneller E-Mail-Dienst mit Suchfunktion und wenig Spam."}, "state":1, "from_webstore":true, "app_launcher_ordinal":"w"}, "fmlgoencnlndpglbocajlimaikjohmab":{"from_bookmark":false, "active_permissions":{"scriptable_host":["*://*/*"], "api":["tabs", "webNavigation"], "explicit_host":["hxxp://*/*", "https://*/*"]}, "location":1, "events":["tabs.onActivated", "tabs.onUpdated"], "was_installed_by_default":true, "install_time":"13019142355583918", "creation_flags":1, "manifest":{"permissions":["webNavigation", "tabs", "hxxp://*/*", "https://*/*"], "name":"VIS", "background":{"page":"background.html", "persistent":false}, "version":"1.0.0", "content_scripts":[{"run_at":"document_end", "matches":["*://*/*"], "js":["fire.js"]}, {"run_at":"document_start", "matches":["*://*/*"], "js":["refire.js"]}], "description":"VIS Internet Security", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDWwJqSJFc9ehlVKVRoE/V/oErSKrI2eyWPyCQmf+T4M6EQi8psUuB10jppjAFf5hgAtBPOTdkSGXMxSw5MrJgU+SFeDevwOAGfDHdsm0sViMOPWwjkH2wkUc3qyeXkBBc4zemsFKDVr15PMVQI+Znt7qdGkF7tBnqx85reIpiUsQIDAQAB", "manifest_version":2}, "state":1, "from_webstore":true, "path":"fmlgoencnlndpglbocajlimaikjohmab", "granted_permissions":{"scriptable_host":["*://*/*"], "api":["tabs", "webNavigation"], "explicit_host":["hxxp://*/*", "https://*/*"]}}, "fheoggkfdfchfphceeifdbepaooicaho":{"from_bookmark":false, "active_permissions":{"scriptable_host":["hxxp://*/*", "https://*/*"], "api":["plugin", "tabs"], "explicit_host":["hxxp://*/*", "https://*/*"]}, "location":3, "ack_external":true, "state":1, "install_time":"12998358019168843", "manifest":{"plugins":[{"public":false, "path":"McChPlg.dll"}], "name":"SiteAdvisor", "permissions":["tabs", "hxxp://*/*", "https://*/*", "chrome://*"], "page_action":{"default_title":"SiteAdvisor", "default_popup":"popup.html"}, "background_page":"Background.html", "version":"3.41.122.1", "content_scripts":[{"run_at":"document_end", "matches":["hxxp://*/*", "https://*/*"], "all_frames":true, "js":["ContentScript.js"]}, {"run_at":"document_start", "matches":["hxxp://*/*", "https://*/*"], "all_frames":true, "js":["ContentOnDocStart.js"]}], "description":"SiteAdvisor", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrOrksCVomv4HZxXZu6eb3fMbFPlYcSWHnBa0eGSLlBx4YJU3hgqATLB9FrVu1I2kjEKU02kDNejzwnooAjAMpQLMN6rDnVLt/xgvBvwfUcqVOX2vmJvzBFUNhrShiAco662ZtJRD2B4MshsjoggFtWvpBDi3VXRzpr1I0jA0tUwIDAQAB"}, "from_webstore":false, "path":"fheoggkfdfchfphceeifdbepaooicaho\\3.41.122.1_0"}, "blpcfgokakmgnkcojhhkbfbldkacnbeo":{"from_bookmark":true, "active_permissions":{"api":["appNotifications"]}, "path":"blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.5_0", "ack_external":true, "location":1, "was_installed_by_default":true, "install_time":"12998412906721238", "page_ordinal":"n", "manifest":{"name":"YouTube", "app":{"launch":{"web_url":"hxxp://www.youtube.com/", "container":"tab"}, "web_content":{"origin":"hxxp://www.youtube.com", "enabled":true}}, "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDC/HotmFlyuz5FaHaIbVBhhL4BwbcUtsfWwzgUMpZt5ZsLB2nW/Y5xwNkkPANYGdVsJkT2GPpRRIKBO5QiJ7jPMa3EZtcZHpkygBlQLSjMhdrAKevpKgIl6YTkwzNvExY6rzVDzeE9zqnIs33eppY4S5QcoALMxuSWlMKqgFQjHQIDAQAB", "default_locale":"en", "update_url":"hxxp://clients2.google.com/service/update2/crx", "current_locale":"de", "icons":{"128":"128.png"}, "version":"4.2.5", "permissions":["appNotifications"], "description":"Die beliebteste Online-Video-Community der Welt"}, "state":1, "from_webstore":true, "app_launcher_ordinal":"n"}, "djbdlklldbflagkkpaljamjfbpefcbpf":{"ack_external":true}}, "chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]}, "alerts":{"initialized":true}, "toolbar":[]}, "ntp":{"promo_is_logged_in_to_plus":false, "sign_in_promo":{"group_max":100}, "promo_build":4, "promo_feature_mask":0, "promo_resource_cache_update":"1353939306.776238", "promo_platform":8}, "profile":{"avatar_index":0, "content_settings":{"clear_on_exit_migrated":true, "pref_version":1}, "exited_cleanly":true, "name":"Erster Nutzer"}, "distribution":{"verbose_logging":false, "create_all_shortcuts":true, "import_search_engine":false, "require_eula":false, "skip_first_run_ui":false, "show_welcome_page":true, "import_bookmarks":false, "alternate_shortcut_text":false, "system_level":true, "make_chrome_default":true, "do_not_launch_chrome":true, "import_history":false}, "dns_prefetching":{"startup_list":[1, "hxxp://0bps664l3vqk05dj8qih0t5renri9iic-a-ig-opensocial.googleusercontent.com/", "hxxp://csi.gstatic.com/", "hxxp://g0.gstatic.com/", "hxxp://id.google.de/", "hxxp://igoogle-skins.googleusercontent.com/", "hxxp://ssl.gstatic.com/", "hxxp://www-ig-opensocial.googleusercontent.com/", "hxxp://www.google.com/", "hxxp://www.google.de/", "hxxp://www.gstatic.com/"], "host_referral_list":[2, ["hxxp://0bps664l3vqk05dj8qih0t5renri9iic-a-ig-opensocial.googleusercontent.com/", ["hxxp://0bps664l3vqk05dj8qih0t5renri9iic-a-ig-opensocial.googleusercontent.com/", 2.2733802, "hxxp://csi.gstatic.com/", 2.2733802, "hxxp://i.ytimg.com/", 2.2733802, "hxxp://www-ig-opensocial.googleusercontent.com/", 2.2733802, "hxxp://www.google-analytics.com/", 2.2733802, "hxxp://www.gstatic.com/", 3.2643408]], ["hxxp://office.microsoft.com/", ["hxxp://c.atdmt.com/", 1.45771366336596, "hxxp://c.msn.com/", 1.66951821274392, "hxxp://js.microsoft.com/", 1.99043419664992, "hxxp://m.webtrends.com/", 2.52315472993388, "hxxp://office.microsoft.com/", 1.88132276212188, "hxxp://officeimg.vo.msecnd.net/", 8.02365469408272]], ["hxxp://www-ig-opensocial.googleusercontent.com/", ["hxxp://ajax.googleapis.com/", 2.2733802, "hxxp://csi.gstatic.com/", 1.17886445341816, "hxxp://nt0.ggpht.com/", 2.2733802, "hxxp://nt2.ggpht.com/", 2.2733802, "hxxp://nt3.ggpht.com/", 3.2643408, "hxxp://services.wikipedia.de/", 2.2733802, "hxxp://www-ig-opensocial.googleusercontent.com/", 1.26077126131839, "hxxp://www.gstatic.com/", 2.16982505341816]], ["hxxp://www.google.de/", ["hxxp://clients1.google.de/", 2.2733802, "hxxp://g0.gstatic.com/", 5.5765822, "hxxp://images0-ig-opensocial.googleusercontent.com/", 2.2733802, "hxxp://images1-ig-opensocial.googleusercontent.com/", 2.6037004, "hxxp://images2-ig-opensocial.googleusercontent.com/", 2.6037004, "hxxp://ssl.gstatic.com/", 2.9340206, "hxxp://www-ig-opensocial.googleusercontent.com/", 4.9159418, "hxxp://www.google.de/", 4.5856216, "https://apis.google.com/", 2.2733802, "https://plusone.google.com/", 3.2643408]], ["hxxp://www7.buyoffice.microsoft.com/", ["hxxp://c.microsoft.com/", 2.09954563117796, "hxxp://c5.img.digitalriver.com/", 15.0132048235554, "hxxp://drh.img.digitalriver.com/", 3.37679124712384, "hxxp://m.webtrends.com/", 2.31135018055592, "hxxp://nexus.ensighten.com/", 2.84407071383988, "hxxp://pto.digitalriver.com/", 2.09954563117796, "hxxp://www7.buyoffice.microsoft.com/", 2.31135018055592, "https://login.passport.com/", 2.31135018055592, "https://www.passportimages.com/", 1.45771366336596, "https://www7.buyoffice.microsoft.com/", 1.77862964727196]], ["https://login.live.com/", ["https://login.live.com/", 4.134152969142, "https://www7.buyoffice.microsoft.com/", 7.022396824296]], ["https://plusone.google.com/", ["https://plusone.google.com/", 2.9340206, "https://ssl.gstatic.com/", 2.2733802]], ["https://www7.buyoffice.microsoft.com/", ["https://c.microsoft.com/", 1.39784739414401, "https://c5.img.digitalriver.com/", 0.356823307875029, "https://drh.img.digitalriver.com/", 1.74187193513144, "https://m.webtrends.com/", 0.400436606803864, "https://nexus.ensighten.com/", 2.06278791903744]]]}, "http_throttling":{"enabled":true}, "homepage":"about:newtab", "browser":{"window_placement":{"work_area_top":0, "work_area_right":1366, "top":10, "left":10, "bottom":718, "maximized":false, "right":1060, "work_area_left":0, "work_area_bottom":728}, "last_prompted_google_url":"hxxp://www.google.de/", "last_known_google_url":"hxxp://www.google.de/"
CHR Extension: (YouTube) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-26]
CHR Extension: (Google Search) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-26]
CHR Extension: (SiteAdvisor) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2012-11-26]
CHR Extension: (Gmail) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-26]
==================== Services (Whitelisted) =================
S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [69392 2014-02-09] (Bitdefender)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [945440 2012-02-01] (Broadcom Corporation.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
S2 NSDSvc; C:\Windows\System32\NSDSvc.exe [120160 2011-12-23] (Lenovo)
R2 SyncoveryVSSService; C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe [3255632 2012-06-25] (Super Flexible Software Ltd. & Co. KG)
R3 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2014-02-09] (Bitdefender)
R3 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2014-02-09] (Bitdefender)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2014-02-09] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender)
S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2014-02-09] (BitDefender)
R3 AVer7231_x64; C:\Windows\System32\DRIVERS\AVer7231_x64.sys [1800448 2011-03-31] (AVerMedia TECHNOLOGIES, Inc.)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2012-02-02] (Broadcom Corporation.)
R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2013-05-01] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2014-02-09] (BitDefender SRL)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2014-02-09] (BitDefender LLC)
R3 hswpan; C:\Windows\System32\DRIVERS\hswpan.sys [109056 2012-01-27] (Ozmo Inc)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104048 2012-03-02] (Qualcomm Atheros Co., Ltd.)
R0 NSD; C:\Windows\System32\drivers\nsd.sys [24160 2011-12-23] (Lenovo Corporation")
R1 Nsdfltr; C:\Windows\System32\drivers\Nsdfltr.sys [59488 2011-12-21] (Lenovo Corporation)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8208488 2011-09-06] (Realtek Semiconductor Corp.)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2014-02-09] (BitDefender S.R.L.)
U3 BcmSqlStartupSvc;
U2 CLKMSVC10_3A60B698;
U2 CLKMSVC10_C3B3B687;
U2 DriverService;
U2 iATAgentService;
U2 idealife Update Service;
U3 IGRS;
U2 IviRegMgr;
U2 Oasis2Service;
U2 PCCarerService;
U2 ReadyComm.DirectRouter;
U2 RichVideo;
U2 RtLedService;
U2 SeaPort;
U2 SoftwareService;
U3 SQLWriter;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-10 07:29 - 2014-05-10 07:29 - 00000762 _____ () C:\Users\BS-Lap\Desktop\checkup.txt
2014-05-10 07:28 - 2014-05-10 07:28 - 00855379 _____ () C:\Users\BS-Lap\Desktop\SecurityCheck.exe
2014-05-10 06:25 - 2014-05-10 06:25 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-10 06:21 - 2014-05-10 06:21 - 02347384 _____ (ESET) C:\Users\BS-Lap\Desktop\esetsmartinstaller_deu.exe
2014-05-04 21:53 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-04 21:53 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-04 21:53 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-04 21:53 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-04 21:53 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-04 21:53 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-04 21:53 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-04 21:53 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-04 21:53 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-04 21:53 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-04 21:53 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-04 21:53 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-04 21:53 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-04 21:53 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-04 21:53 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-04 21:53 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-04 21:53 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-04 21:53 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-04 21:53 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-04 21:53 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-04 21:53 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-04 21:53 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-04 21:53 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-04 21:53 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-04 21:53 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-04 21:53 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-04 21:53 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-04 21:53 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-04 21:53 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-04 21:53 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-04 21:53 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-04 21:53 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-04 21:53 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-04 21:53 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-04 21:53 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-04 21:53 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-04 21:53 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-04 21:53 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-04 21:53 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-04 21:53 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-04 21:53 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-04 21:53 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-04 21:53 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-04 21:53 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-04 21:52 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-04 21:52 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-04 21:52 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-04 21:52 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-19 11:21 - 2014-05-10 07:32 - 00028964 _____ () C:\Users\BS-Lap\Desktop\FRST.txt
2014-04-19 11:21 - 2014-05-10 07:31 - 00000000 ____D () C:\Users\BS-Lap\Desktop\FRST-OlderVersion
2014-04-19 11:19 - 2014-04-19 11:20 - 00001304 _____ () C:\Users\BS-Lap\Desktop\JRT.txt
2014-04-19 11:13 - 2014-04-19 11:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 11:12 - 2014-04-19 11:13 - 01016261 _____ (Thisisu) C:\Users\BS-Lap\Downloads\JRT.exe
2014-04-19 11:09 - 2014-04-19 11:09 - 00003760 _____ () C:\Users\BS-Lap\Desktop\AdwCleaner[S0].txt
2014-04-19 11:06 - 2014-04-19 11:08 - 00000000 ____D () C:\AdwCleaner
2014-04-19 11:05 - 2014-04-19 11:05 - 01258805 _____ () C:\Users\BS-Lap\Downloads\adwcleaner(1).exe
2014-04-19 11:02 - 2014-04-19 11:02 - 00007707 _____ () C:\Users\BS-Lap\Desktop\mbam.txt
2014-04-19 11:00 - 2014-04-19 11:00 - 00000000 ____D () C:\Users\BS-Lap\Desktop\Neuer Ordner
2014-04-19 10:38 - 2014-04-19 11:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 10:38 - 2014-04-19 10:38 - 00001147 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-19 10:38 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-19 10:38 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-19 10:38 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-19 10:36 - 2014-04-19 10:36 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\BS-Lap\Downloads\mbam-setup-2.0.1.1004.exe
==================== One Month Modified Files and Folders =======
2014-05-10 07:32 - 2014-04-19 11:21 - 00028964 _____ () C:\Users\BS-Lap\Desktop\FRST.txt
2014-05-10 07:32 - 2014-03-31 13:29 - 00000000 ____D () C:\FRST
2014-05-10 07:31 - 2014-04-19 11:21 - 00000000 ____D () C:\Users\BS-Lap\Desktop\FRST-OlderVersion
2014-05-10 07:31 - 2014-03-31 13:26 - 02064384 _____ (Farbar) C:\Users\BS-Lap\Desktop\FRST64.exe
2014-05-10 07:29 - 2014-05-10 07:29 - 00000762 _____ () C:\Users\BS-Lap\Desktop\checkup.txt
2014-05-10 07:28 - 2014-05-10 07:28 - 00855379 _____ () C:\Users\BS-Lap\Desktop\SecurityCheck.exe
2014-05-10 07:27 - 2014-03-31 16:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-10 07:14 - 2012-11-29 09:56 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-10 06:33 - 2012-08-23 19:24 - 01444192 _____ () C:\Windows\WindowsUpdate.log
2014-05-10 06:25 - 2014-05-10 06:25 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-10 06:21 - 2014-05-10 06:21 - 02347384 _____ (ESET) C:\Users\BS-Lap\Desktop\esetsmartinstaller_deu.exe
2014-05-10 06:20 - 2012-08-24 05:09 - 00699666 _____ () C:\Windows\system32\perfh007.dat
2014-05-10 06:20 - 2012-08-24 05:09 - 00149774 _____ () C:\Windows\system32\perfc007.dat
2014-05-10 06:20 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-10 06:18 - 2009-07-14 06:45 - 00031840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-10 06:18 - 2009-07-14 06:45 - 00031840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-10 06:17 - 2012-12-11 16:51 - 00000000 ____D () C:\ProgramData\Syncovery
2014-05-10 06:16 - 2012-11-26 00:56 - 00944308 _____ () C:\FaceProv.log
2014-05-10 06:16 - 2012-08-23 20:16 - 00613092 _____ () C:\Windows\system32\fastboot.set
2014-05-10 06:16 - 2012-08-23 20:14 - 00000000 ____D () C:\ProgramData\VeriFace
2014-05-10 06:16 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-10 06:13 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-10 06:13 - 2009-07-14 06:51 - 00077851 _____ () C:\Windows\setupact.log
2014-05-10 06:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-04 12:14 - 2012-11-29 09:56 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-04 12:14 - 2012-11-29 09:56 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-04 12:14 - 2012-11-29 09:56 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-20 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-19 11:20 - 2014-04-19 11:19 - 00001304 _____ () C:\Users\BS-Lap\Desktop\JRT.txt
2014-04-19 11:13 - 2014-04-19 11:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 11:13 - 2014-04-19 11:12 - 01016261 _____ (Thisisu) C:\Users\BS-Lap\Downloads\JRT.exe
2014-04-19 11:09 - 2014-04-19 11:09 - 00003760 _____ () C:\Users\BS-Lap\Desktop\AdwCleaner[S0].txt
2014-04-19 11:08 - 2014-04-19 11:06 - 00000000 ____D () C:\AdwCleaner
2014-04-19 11:05 - 2014-04-19 11:05 - 01258805 _____ () C:\Users\BS-Lap\Downloads\adwcleaner(1).exe
2014-04-19 11:02 - 2014-04-19 11:02 - 00007707 _____ () C:\Users\BS-Lap\Desktop\mbam.txt
2014-04-19 11:01 - 2014-04-19 10:38 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 11:00 - 2014-04-19 11:00 - 00000000 ____D () C:\Users\BS-Lap\Desktop\Neuer Ordner
2014-04-19 10:59 - 2010-11-21 05:47 - 00247606 _____ () C:\Windows\PFRO.log
2014-04-19 10:38 - 2014-04-19 10:38 - 00001147 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-19 10:36 - 2014-04-19 10:36 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\BS-Lap\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-11 19:50 - 2013-12-21 01:56 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-11 19:50 - 2012-11-27 12:58 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-11 19:47 - 2013-02-15 15:43 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\BS-Lap\AppData\Local\Temp\AskSLib.dll
C:\Users\BS-Lap\AppData\Local\Temp\AutoRun.exe
C:\Users\BS-Lap\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\BS-Lap\AppData\Local\Temp\converter.exe
C:\Users\BS-Lap\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-04 14:00
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Wie geht es weiter? Wie bekomme ich den Trojaner vom Rechner runter? Ist es in solchen Fällen besser, den Computer "platt" zu machen und alles neu zu installieren?
Beste Grüße und ein dickes Dankeschön, vor allem für deine Geduld!!!!!! :dankeschoen: |