Soooooo, ich hab meine Zeit wiedergefunden ;)
Revo ausgeführt und entsprechend gelöscht - es kann sein, dass noch einige Dateien manuell zu löschen sind???
mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 19.04.2014
Suchlauf-Zeit: 10:58:12
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.19.05
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: BS-Lap
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 306610
Verstrichene Zeit: 18 Min, 44 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 10
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=),Ersetzt,[e21e1ee2679910f061b887a0897bfd03]
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=),Ersetzt,[926eee12c53b7090b16a5bcc2ada758b]
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=),Ersetzt,[af5144bce51b907009115bcc09fb9d63]
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=),Ersetzt,[02fea15f9868a45cc15b96915da7728e]
Hijack.SearchPage, HKU\S-1-5-21-772892197-4109324267-2503982889-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=),Ersetzt,[8e7247b98779bb45f028e542a460d828]
Hijack.SearchPage, HKU\S-1-5-21-772892197-4109324267-2503982889-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=),Ersetzt,[bf4144bc04fcd72935e130f780847f81]
Hijack.SearchPage, HKU\S-1-5-21-772892197-4109324267-2503982889-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=),Ersetzt,[d82807f944bce21eb95e7fa831d31ee2]
Hijack.SearchPage, HKU\S-1-5-21-772892197-4109324267-2503982889-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=),Ersetzt,[22de01ff26da728e28f5a780c2426e92]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-772892197-4109324267-2503982889-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&q=%s, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&q=%s),Ersetzt,[55abb64ac43c11efd4726bbed2327987]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-772892197-4109324267-2503982889-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default), hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&q=%s, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&q=%s),Ersetzt,[966abd43c739c937c384e7422adae818]
Ordner: 2
PUP.Optional.DownloadGuide.A, C:\Users\BS-Lap\AppData\Local\DownloadGuide, In Quarantäne, [30d0ab55fd03946c84f2b4ecaf54d32d],
PUP.Optional.DownloadGuide.A, C:\Users\BS-Lap\AppData\Local\DownloadGuide\Offers, In Quarantäne, [30d0ab55fd03946c84f2b4ecaf54d32d],
Dateien: 10
PUP.Optional.BundleInstaller.A, C:\$Recycle.Bin\S-1-5-21-772892197-4109324267-2503982889-1001\$ROU85CB.exe, In Quarantäne, [fd037a86d82848b890a89594936d16ea],
PUP.Optional.HomeTab.A, C:\Users\BS-Lap\AppData\Local\Temp\tbu97BC.exe, In Quarantäne, [1ce4fc04b64a649c704672b33ec3857b],
PUP.Optional.HomeTab.A, C:\Users\BS-Lap\AppData\Local\DownloadGuide\Offers\hometab.exe, In Quarantäne, [b64a44bc46ba768a15a1c2638d7407f9],
PUP.Optional.Iminent.A, C:\Users\BS-Lap\AppData\Local\DownloadGuide\Offers\iminent.exe, In Quarantäne, [0cf4ae5246ba3cc483f1a6826a97ed13],
PUP.Optional.CrossRider, C:\Users\BS-Lap\AppData\Local\DownloadGuide\Offers\plus-hd-3-8.exe, In Quarantäne, [8e72e818d030a858e51f61bcb8497b85],
PUP.Optional.WebSearch.A, C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default\searchplugins\Web Search.xml, In Quarantäne, [956b6e9220e0d03013697cf8837fcd33],
PUP.Optional.DownloadGuide.A, C:\Users\BS-Lap\AppData\Local\DownloadGuide\amazon.ico, In Quarantäne, [30d0ab55fd03946c84f2b4ecaf54d32d],
PUP.Optional.DownloadGuide.A, C:\Users\BS-Lap\AppData\Local\DownloadGuide\vlc-2.1.0-win32.exe, In Quarantäne, [30d0ab55fd03946c84f2b4ecaf54d32d],
PUP.Optional.DownloadGuide.A, C:\Users\BS-Lap\AppData\Local\DownloadGuide\Offers\vis-pro.exe, In Quarantäne, [30d0ab55fd03946c84f2b4ecaf54d32d],
PUP.Optional.CertifiedTB.A, C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=");), Ersetzt,[06fad32d25dbae52dd06f65d877d4cb4]
Physische Sektoren: 0
(No malicious items detected)
(end)
adw-cleaner Code:
# AdwCleaner v3.024 - Bericht erstellt am 19/04/2014 um 11:08:01
# Aktualisiert 18/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : BS-Lap - BS-LAPTOP
# Gestartet von : C:\Users\BS-Lap\Downloads\adwcleaner(1).exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Youcam
Ordner Gelöscht : C:\Program Files (x86)\Browser Updater
Ordner Gelöscht : C:\Program Files (x86)\Protected Search
Ordner Gelöscht : C:\Users\BS-Lap\AppData\Roaming\SimplyTech
Ordner Gelöscht : C:\Users\BS-Lap\Documents\Youcam
Ordner Gelöscht : C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
Ordner Gelöscht : C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab
Datei Gelöscht : C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default\searchplugins\FBDownloader.xml
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\FBDownloader.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_photoscape_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_photoscape_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{671F1846-80F2-4ED8-B183-A921E6A4D5D4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E80943C-847C-4447-B830-F94E7DCBBD4E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{6E80943C-847C-4447-B830-F94E7DCBBD4E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Schlüssel Gelöscht : HKCU\Software\Protector
Schlüssel Gelöscht : HKCU\Software\simplytech
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultengine", "Web Search");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
Zeile gelöscht : user_pref("browser.search.order.1", "Web Search");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=43169&tid=3580&ts=1381653310834&tguid=43169-3580-1381653305486-316722&st=chrome&q=");
-\\ Google Chrome v
[ Datei : C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [4367 octets] - [19/04/2014 11:06:58]
AdwCleaner[S0].txt - [3620 octets] - [19/04/2014 11:08:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3680 octets] ##########
jrt.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by BS-Lap on 19.04.2014 at 11:13:50,60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\AboutURLs\\Tabs
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\BS-Lap\appdata\local\{056F89F9-15EF-49AA-ADF7-C72802AAF9A3}
Successfully deleted: [Empty Folder] C:\Users\BS-Lap\appdata\local\{2A830A86-76D2-4C8A-837F-E1F23BDE3E32}
Successfully deleted: [Empty Folder] C:\Users\BS-Lap\appdata\local\{8F278806-8379-451F-A81F-55CC8E2D0AD3}
Successfully deleted: [Empty Folder] C:\Users\BS-Lap\appdata\local\{EAD1C309-D626-4F70-9A7D-9E79798BEADF}
~~~ FireFox
Emptied folder: C:\Users\BS-Lap\AppData\Roaming\mozilla\firefox\profiles\6h0z3s5z.default\minidumps [54 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.04.2014 at 11:19:43,02
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
frst
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01
Ran by BS-Lap (administrator) on BS-LAPTOP on 19-04-2014 11:21:43
Running from C:\Users\BS-Lap\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Super Flexible Software Ltd. & Co. KG) C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe
() C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
( ) C:\Program Files (x86)\LockKey\LockKey.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Intel Corporation) C:\Windows\system32\hkcmd.exe
(Intel Corporation) C:\Windows\system32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe
() C:\Program Files (x86)\Syncovery\SyncoveryService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2866960 2011-12-16] (Synaptics Incorporated)
HKLM\...\Run: [SynLenovoGestureMgr] => C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [410896 2011-12-16] (Synaptics)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12343400 2011-12-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-15] (Realtek Semiconductor)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789856 2012-08-23] (Lenovo)
HKLM\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8079408 2012-08-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6202416 2012-08-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-08-23] (Lenovo)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1575192 2014-02-09] (Bitdefender)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-21] (Intel Corporation)
HKLM-x32\...\Run: [LockKey] => C:\Program Files (x86)\LockKey\LockKey.exe [337776 2011-08-25] ( )
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [152896 2012-06-25] (Intel Corporation)
HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2012-01-26] (Lenovo, Inc.)
HKLM-x32\...\Run: [Intelligent Touchpad] => C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe [291272 2011-12-08] ()
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-28] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-28] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-08-23] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-772892197-4109324267-2503982889-1000\...\Run: [Power2GoExpress] => NA
HKU\S-1-5-21-772892197-4109324267-2503982889-1001\...\Run: [Syncovery Background Scheduler] => C:\Program Files (x86)\Syncovery\SyncoveryService.exe [15304016 2012-12-06] ()
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [260928 2012-02-23] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [215360 2012-02-23] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Lenovo\Bluetooth Software\BtwProximityCP.dll
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.google.com/ig/redirectdomain?brand=KMOH&bmod=KMOH
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - URL hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms}
SearchScopes: HKLM-x32 - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=43169&gid=40335331560044&dbCode=1&command={searchTerms}
SearchScopes: HKLM-x32 - TopResultURLFallback hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms}
SearchScopes: HKCU - URL hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms}
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=43169&gid=40335331560044&dbCode=1&command={searchTerms}
SearchScopes: HKCU - TopResultURLFallback hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7KMOH_deDE511DE512
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120823200948.dll No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20121126152057.dll No File
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Ghostery - C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default\Extensions\firefox@ghostery.com.xpi [2013-08-29]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15]
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15]
Chrome:
=======
CHR HomePage: about:newtab
CHR RestoreOnStartup: "about:newtab"], "restore_on_startup_migrated":true, "restore_on_startup"
CHR Extension: (YouTube) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-26]
CHR Extension: (Google Search) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-26]
CHR Extension: (SiteAdvisor) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2012-11-26]
CHR Extension: (Gmail) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-26]
==================== Services (Whitelisted) =================
S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [69392 2014-02-09] (Bitdefender)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [945440 2012-02-01] (Broadcom Corporation.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
S2 NSDSvc; C:\Windows\System32\NSDSvc.exe [120160 2011-12-23] (Lenovo)
R2 SyncoveryVSSService; C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe [3255632 2012-06-25] (Super Flexible Software Ltd. & Co. KG)
R3 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2014-02-09] (Bitdefender)
R3 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2014-02-09] (Bitdefender)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2014-02-09] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender)
S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2014-02-09] (BitDefender)
R3 AVer7231_x64; C:\Windows\System32\DRIVERS\AVer7231_x64.sys [1800448 2011-03-31] (AVerMedia TECHNOLOGIES, Inc.)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2012-02-02] (Broadcom Corporation.)
R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2013-05-01] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2014-02-09] (BitDefender SRL)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2014-02-09] (BitDefender LLC)
R3 hswpan; C:\Windows\System32\DRIVERS\hswpan.sys [109056 2012-01-27] (Ozmo Inc)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104048 2012-03-02] (Qualcomm Atheros Co., Ltd.)
R0 NSD; C:\Windows\System32\drivers\nsd.sys [24160 2011-12-23] (Lenovo Corporation")
R1 Nsdfltr; C:\Windows\System32\drivers\Nsdfltr.sys [59488 2011-12-21] (Lenovo Corporation)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8208488 2011-09-06] (Realtek Semiconductor Corp.)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2014-02-09] (BitDefender S.R.L.)
U3 BcmSqlStartupSvc;
U2 CLKMSVC10_3A60B698;
U2 CLKMSVC10_C3B3B687;
U2 DriverService;
U2 iATAgentService;
U2 idealife Update Service;
U3 IGRS;
U2 IviRegMgr;
U2 Oasis2Service;
U2 PCCarerService;
U2 ReadyComm.DirectRouter;
U2 RichVideo;
U2 RtLedService;
U2 SeaPort;
U2 SoftwareService;
U3 SQLWriter;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-19 11:21 - 2014-04-19 11:21 - 00018218 _____ () C:\Users\BS-Lap\Desktop\FRST.txt
2014-04-19 11:21 - 2014-04-19 11:21 - 00000000 ____D () C:\Users\BS-Lap\Desktop\FRST-OlderVersion
2014-04-19 11:19 - 2014-04-19 11:20 - 00001304 _____ () C:\Users\BS-Lap\Desktop\JRT.txt
2014-04-19 11:13 - 2014-04-19 11:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 11:12 - 2014-04-19 11:13 - 01016261 _____ (Thisisu) C:\Users\BS-Lap\Downloads\JRT.exe
2014-04-19 11:09 - 2014-04-19 11:09 - 00003760 _____ () C:\Users\BS-Lap\Desktop\AdwCleaner[S0].txt
2014-04-19 11:06 - 2014-04-19 11:08 - 00000000 ____D () C:\AdwCleaner
2014-04-19 11:05 - 2014-04-19 11:05 - 01258805 _____ () C:\Users\BS-Lap\Downloads\adwcleaner(1).exe
2014-04-19 11:02 - 2014-04-19 11:02 - 00007707 _____ () C:\Users\BS-Lap\Desktop\mbam.txt
2014-04-19 11:00 - 2014-04-19 11:00 - 00000000 ____D () C:\Users\BS-Lap\Desktop\Neuer Ordner
2014-04-19 10:38 - 2014-04-19 11:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 10:38 - 2014-04-19 10:38 - 00001147 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-19 10:38 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-19 10:38 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-19 10:38 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-19 10:36 - 2014-04-19 10:36 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\BS-Lap\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-09 18:19 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-09 18:19 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-09 18:19 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-09 18:19 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-09 18:19 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 18:19 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 18:19 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 18:19 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 18:19 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 18:19 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 18:19 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 18:19 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 18:19 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 18:19 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 18:19 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 18:19 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 18:19 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 18:19 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 18:19 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 18:19 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 18:19 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-08 17:42 - 2014-04-08 17:42 - 00001309 _____ () C:\Users\BS-Lap\Desktop\Revo Uninstaller.lnk
2014-04-08 17:42 - 2014-04-08 17:42 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-08 17:41 - 2014-04-08 17:41 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\BS-Lap\Desktop\revosetup95.exe
2014-03-31 16:38 - 2014-03-31 16:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-31 13:29 - 2014-04-19 11:21 - 00000000 ____D () C:\FRST
2014-03-31 13:28 - 2014-03-31 13:28 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\BS-Lap\Desktop\mbam-setup-2.0.0.1000.exe
2014-03-31 13:26 - 2014-04-19 11:21 - 02158592 _____ (Farbar) C:\Users\BS-Lap\Desktop\FRST64.exe
2014-03-31 13:23 - 2014-04-08 11:40 - 00000000 ____D () C:\Users\BS-Lap\Desktop\sortieren
==================== One Month Modified Files and Folders =======
2014-04-19 11:21 - 2014-04-19 11:21 - 00018218 _____ () C:\Users\BS-Lap\Desktop\FRST.txt
2014-04-19 11:21 - 2014-04-19 11:21 - 00000000 ____D () C:\Users\BS-Lap\Desktop\FRST-OlderVersion
2014-04-19 11:21 - 2014-03-31 13:29 - 00000000 ____D () C:\FRST
2014-04-19 11:21 - 2014-03-31 13:26 - 02158592 _____ (Farbar) C:\Users\BS-Lap\Desktop\FRST64.exe
2014-04-19 11:20 - 2014-04-19 11:19 - 00001304 _____ () C:\Users\BS-Lap\Desktop\JRT.txt
2014-04-19 11:16 - 2009-07-14 06:45 - 00031840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-19 11:16 - 2009-07-14 06:45 - 00031840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-19 11:14 - 2012-11-29 09:56 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-19 11:13 - 2014-04-19 11:13 - 00000000 ____D () C:\Windows\ERUNT
2014-04-19 11:13 - 2014-04-19 11:12 - 01016261 _____ (Thisisu) C:\Users\BS-Lap\Downloads\JRT.exe
2014-04-19 11:13 - 2012-08-24 05:09 - 00699666 _____ () C:\Windows\system32\perfh007.dat
2014-04-19 11:13 - 2012-08-24 05:09 - 00149774 _____ () C:\Windows\system32\perfc007.dat
2014-04-19 11:13 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-19 11:10 - 2012-08-23 20:16 - 00889258 _____ () C:\Windows\system32\fastboot.set
2014-04-19 11:09 - 2014-04-19 11:09 - 00003760 _____ () C:\Users\BS-Lap\Desktop\AdwCleaner[S0].txt
2014-04-19 11:09 - 2012-12-11 16:51 - 00000000 ____D () C:\ProgramData\Syncovery
2014-04-19 11:09 - 2012-11-26 00:56 - 00925193 _____ () C:\FaceProv.log
2014-04-19 11:09 - 2012-08-23 20:14 - 00000000 ____D () C:\ProgramData\VeriFace
2014-04-19 11:08 - 2014-04-19 11:06 - 00000000 ____D () C:\AdwCleaner
2014-04-19 11:08 - 2012-08-23 19:24 - 01187299 _____ () C:\Windows\WindowsUpdate.log
2014-04-19 11:08 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-19 11:08 - 2009-07-14 06:51 - 00077067 _____ () C:\Windows\setupact.log
2014-04-19 11:05 - 2014-04-19 11:05 - 01258805 _____ () C:\Users\BS-Lap\Downloads\adwcleaner(1).exe
2014-04-19 11:02 - 2014-04-19 11:02 - 00007707 _____ () C:\Users\BS-Lap\Desktop\mbam.txt
2014-04-19 11:01 - 2014-04-19 10:38 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 11:00 - 2014-04-19 11:00 - 00000000 ____D () C:\Users\BS-Lap\Desktop\Neuer Ordner
2014-04-19 10:59 - 2010-11-21 05:47 - 00247606 _____ () C:\Windows\PFRO.log
2014-04-19 10:38 - 2014-04-19 10:38 - 00001147 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-19 10:36 - 2014-04-19 10:36 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\BS-Lap\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-11 19:50 - 2012-11-27 12:58 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-11 19:47 - 2013-12-21 01:56 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-11 19:47 - 2013-02-15 15:43 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-08 19:50 - 2013-09-25 14:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-04-08 17:42 - 2014-04-08 17:42 - 00001309 _____ () C:\Users\BS-Lap\Desktop\Revo Uninstaller.lnk
2014-04-08 17:42 - 2014-04-08 17:42 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-08 17:41 - 2014-04-08 17:41 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\BS-Lap\Desktop\revosetup95.exe
2014-04-08 14:38 - 2012-12-09 11:45 - 00000000 ____D () C:\Users\BS-Lap\AppData\Local\CutePDF Writer
2014-04-08 11:40 - 2014-03-31 13:23 - 00000000 ____D () C:\Users\BS-Lap\Desktop\sortieren
2014-04-03 17:07 - 2012-11-26 16:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-03 09:51 - 2014-04-19 10:38 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-19 10:38 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-19 10:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 16:38 - 2014-03-31 16:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-31 13:28 - 2014-03-31 13:28 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\BS-Lap\Desktop\mbam-setup-2.0.0.1000.exe
2014-03-31 03:16 - 2014-04-09 18:19 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-09 18:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-09 18:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-09 18:19 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
Some content of TEMP:
====================
C:\Users\BS-Lap\AppData\Local\Temp\AskSLib.dll
C:\Users\BS-Lap\AppData\Local\Temp\AutoRun.exe
C:\Users\BS-Lap\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\BS-Lap\AppData\Local\Temp\converter.exe
C:\Users\BS-Lap\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 01:15
==================== End Of Log ============================ --- --- ---
Ich glaub, das waren die gewünschten Infos?
Ein frohes Osterfest wünsch ich dir!!! |