Hallo schrauber,
vielen Dank für Deine Hilfe!
Ich habe alle Aktionen wie beschrieben ausgeführt. Hier sind die Logfiles:
MALWAREBYTES ANTI-MALWARE: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 08.04.2014 11:31:26, SYSTEM, NB001, Protection, Malware Protection, Starting,
Protection, 08.04.2014 11:31:26, SYSTEM, NB001, Protection, Malware Protection, Started,
Protection, 08.04.2014 11:31:26, SYSTEM, NB001, Protection, Malicious Website Protection, Starting,
Update, 08.04.2014 11:31:32, SYSTEM, NB001, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 08.04.2014 11:31:44, SYSTEM, NB001, Manual, Malware Database, 2014.3.4.9, 2014.4.8.2,
Protection, 08.04.2014 11:31:46, SYSTEM, NB001, Protection, Refresh, Starting,
Protection, 08.04.2014 11:32:08, SYSTEM, NB001, Protection, Malicious Website Protection, Started,
Protection, 08.04.2014 11:32:08, SYSTEM, NB001, Protection, Malicious Website Protection, Stopping,
Protection, 08.04.2014 11:32:08, SYSTEM, NB001, Protection, Malicious Website Protection, Stopped,
Protection, 08.04.2014 11:32:15, SYSTEM, NB001, Protection, Refresh, Success,
Protection, 08.04.2014 11:32:15, SYSTEM, NB001, Protection, Malicious Website Protection, Starting,
Protection, 08.04.2014 11:32:16, SYSTEM, NB001, Protection, Malicious Website Protection, Started,
Detection, 08.04.2014 12:09:14, SYSTEM, NB001, Protection, Malware Protection, File, PUP.Optional.Searchprotect, C:\Program Files\Amazon Browser Bar\search_protect.exe, Quarantine, [657d3ceb59221e18e681fc186a97af51]
Protection, 08.04.2014 12:19:30, SYSTEM, NB001, Protection, Malware Protection, Starting,
Protection, 08.04.2014 12:19:30, SYSTEM, NB001, Protection, Malware Protection, Started,
Protection, 08.04.2014 12:19:30, SYSTEM, NB001, Protection, Malicious Website Protection, Starting,
Protection, 08.04.2014 12:22:50, SYSTEM, NB001, Protection, Malicious Website Protection, Started,
Detection, 08.04.2014 12:26:56, SYSTEM, NB001, Protection, Malicious Website Protection, IP, 5.153.38.132, qop.frmclstr.net, 49335, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe,
Detection, 08.04.2014 12:26:57, SYSTEM, NB001, Protection, Malicious Website Protection, IP, 5.153.38.132, qop.frmclstr.net, 49335, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe,
Detection, 08.04.2014 12:26:57, SYSTEM, NB001, Protection, Malicious Website Protection, IP, 5.153.38.132, qop.frmclstr.net, 49342, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe,
Detection, 08.04.2014 12:27:01, SYSTEM, NB001, Protection, Malicious Website Protection, IP, 5.153.38.132, qop.frmclstr.net, 49374, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe,
Detection, 08.04.2014 12:28:24, SYSTEM, NB001, Protection, Malicious Website Protection, IP, 5.153.38.132, qop.frmclstr.net, 49634, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe,
Detection, 08.04.2014 12:28:30, SYSTEM, NB001, Protection, Malicious Website Protection, IP, 5.153.38.132, qop.frmclstr.net, 49677, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe,
Detection, 08.04.2014 12:28:31, SYSTEM, NB001, Protection, Malicious Website Protection, IP, 5.153.38.132, qop.frmclstr.net, 49679, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe,
Detection, 08.04.2014 12:28:40, SYSTEM, NB001, Protection, Malicious Website Protection, IP, 5.153.38.132, qop.frmclstr.net, 49711, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe,
Detection, 08.04.2014 12:28:41, SYSTEM, NB001, Protection, Malicious Website Protection, IP, 5.153.38.132, qop.frmclstr.net, 49712, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe,
(end) ADWCLEANER: Code:
# AdwCleaner v3.023 - Bericht erstellt am 08/04/2014 um 12:43:01
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : Administrator - NB001
# Gestartet von : C:\Users\Administrator\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox (2).lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [quick_start@gmail.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6EC10355-92E3-451C-A1A8-598F84D0020A}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EC10355-92E3-451C-A1A8-598F84D0020A}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78A7CC67-DD2D-433C-86B1-DA5622D20E1F}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{78A7CC67-DD2D-433C-86B1-DA5622D20E1F}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{775C9BFF-0006-4A0E-A8BF-F751CABE9816}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{775C9BFF-0006-4A0E-A8BF-F751CABE9816}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{73CBBDFA-C022-4F19-897B-1A407A15DEEA}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB7252E8-1C61-4BE0-A628-6E4FAB6344FD}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB7252E8-1C61-4BE0-A628-6E4FAB6344FD}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{73CBBDFA-C022-4F19-897B-1A407A15DEEA}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1B2185A4-F12D-4526-9A64-68985C62F4FF}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B2185A4-F12D-4526-9A64-68985C62F4FF}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1B3261E5-9809-4571-8517-CAFE7A980C8B}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B3261E5-9809-4571-8517-CAFE7A980C8B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\speedupmypc_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\speedupmypc_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0044150.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0044150.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0044150.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0044150.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051578.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051578.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051578.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051578.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051682.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051682.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051682.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051682.Sandbox.1
Schlüssel Gelöscht : HKCU\Software\968c8db369bf10
Schlüssel Gelöscht : HKLM\SOFTWARE\968c8db369bf10
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411411150}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511151178}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511161182}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422412250}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522152278}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522162282}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455415550}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555155578}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555165582}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466416650}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566156678}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566166682}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440444414450}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544154478}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544164482}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411411150}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511151178}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511161182}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\Alexa Internet
Schlüssel Gelöscht : HKCU\Software\DataMngr
[#] Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\distromatic
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\powerpack
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyrixeeker
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKLM\Software\BabylonToolbar
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Myfree Codec
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Tarma Installer
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DSite
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Amazon Browser Settings
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IePlugins
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\20maij8h.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.a13c471d96cbb4c089dd18dc16c66bb1fcf5065afca24464aa637af7582a82514com51578.51578.cookie.previous_page.value", "%22hxxp%3A//www.awesomehp.com/%3Ftype%3Dsc%26ts%3D1393531193%26from%[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "144ef06671dbb347601355ad49808046");
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.bbDpng", "6");
Zeile gelöscht : user_pref("extensions.delta.cntry", "DE");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gelöscht : user_pref("extensions.delta.hdrMd5", "3BA9B4D944838CA91285D573DD00828B");
Zeile gelöscht : user_pref("extensions.delta.id", "b0bd7eca0000000000000016cee7f750");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15954");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.lastVrsnTs", "1.8.24.622:15:21");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.sg", "azb");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.622:15:21");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=119357&tsp=4997");
Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
-\\ Google Chrome v33.0.1750.154
[ Datei : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht : search_url
Gelöscht : keyword
Gelöscht : homepage
*************************
AdwCleaner[R0].txt - [22608 octets] - [08/04/2014 12:32:40]
AdwCleaner[R1].txt - [18503 octets] - [08/04/2014 12:40:42]
AdwCleaner[S0].txt - [4711 octets] - [08/04/2014 12:35:46]
AdwCleaner[S1].txt - [15372 octets] - [08/04/2014 12:43:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [15433 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Professional x86
Ran by Administrator on 08.04.2014 at 13:05:34,99
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1518153914-1331252380-3142676199-500\Software\sweetim
~~~ Files
Successfully deleted: [File] "C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\speedupmypc.lnk"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Successfully deleted the following from C:\Users\Administrator\AppData\Roaming\mozilla\firefox\profiles\20maij8h.default\prefs.js
user_pref("extensions.a13c471d96cbb4c089dd18dc16c66bb1fcf5065afca24464aa637af7582a82514com51578.51578.cookie.previous_page.value", "%22hxxp%3A//www.awesomehp.com/%3Ftype%3Dsc%
Emptied folder: C:\Users\Administrator\AppData\Roaming\mozilla\firefox\profiles\20maij8h.default\minidumps [81 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08.04.2014 at 13:10:59,24
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 (ATTENTION: ====> FRST version is 26 days old and could be outdated)
Ran by Administrator (administrator) on NB001 on 08-04-2014 13:16:12
Running from C:\Users\Administrator\Downloads
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Lenovo) C:\Windows\system32\ibmpmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Windows\system32\AEADISRV.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.23.9\GoogleCrashHandler.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
(TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(TomTom) C:\Program Files\MyTomTom 3\MyTomTomSA.exe
(Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Teruten) C:\Windows\system32\FsUsbExService.Exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
() C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [TpShocks] - C:\Windows\system32\TpShocks.exe [180224 2012-06-21] (Lenovo.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2342200 2012-07-05] (Synaptics Incorporated)
HKLM\...\Run: [AgentMonitor] - C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe [365512 2012-06-28] ()
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-05-15] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-11-06] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-21] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1518153914-1331252380-3142676199-500\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-1518153914-1331252380-3142676199-500\...\Run: [AutoStartNPSAgent] - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [102400 2009-04-02] (Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-1518153914-1331252380-3142676199-500\...\Run: [TomTomHOME.exe] - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-03-22] (TomTom)
HKU\S-1-5-21-1518153914-1331252380-3142676199-500\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-11-06] (Samsung)
HKU\S-1-5-21-1518153914-1331252380-3142676199-500\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-11-06] (Samsung)
HKU\S-1-5-21-1518153914-1331252380-3142676199-500\...\Run: [MyTomTomSA.exe] - C:\Program Files\MyTomTom 3\MyTomTomSA.exe [458680 2013-08-01] (TomTom)
HKU\S-1-5-21-1518153914-1331252380-3142676199-500\...\Run: [Sony PC Companion] - C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [449760 2013-10-31] (Sony)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x321D48DB7D3CCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p07_serp_ie_de_display?ie=UTF8&tagbase=bds-p07&tbrId=v1_abb-channel-7_7d166af6715144058f905c7795ec972e_30_46_20131124_DE_ie_sp_IS0
SearchScopes: HKLM - DefaultScope value is missing.
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\20maij8h.default
FF NewTab: hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p07_serp_ff_de_display?ie=UTF8&tagbase=bds-p07&tbrId=v1_abb-channel-7_7d166af6715144058f905c7795ec972e_30_46_20131124_DE_ff_nt_IS0
FF SearchEngineOrder.1: Amazon
FF Homepage: hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p07_serp_ff_de_display?ie=UTF8&tagbase=bds-p07&tbrId=v1_abb-channel-7_7d166af6715144058f905c7795ec972e_30_46_20131124_DE_ff_sp_IS0
FF Keyword.URL: hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p07_serp_ff_de_display?ie=UTF8&tagbase=bds-p07&tag=bds-p07-serp-de-ff-21&tbrId=v1_abb-channel-7_7d166af6715144058f905c7795ec972e_30_46_20131124_DE_ff_ab_IS0&query=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\awesomehp.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: HQ-Video-Profession-1.3 - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\20maij8h.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com [2014-03-29]
FF Extension: DoNotTrackMe: Online Privacy Protection - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\20maij8h.default\Extensions\donottrackplus@abine.com [2014-03-29]
FF Extension: BrowserAdditions - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\20maij8h.default\Extensions\toolbarbutton@browseradditions.com [2013-09-06]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchProvider: awesomehp
CHR DefaultSearchURL: hxxp://www.google.com
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\33.0.1750.117\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files\McAfee Security Scan\3.0.313\npMcAfeeMss.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (McAfee Security Scan+) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-27]
CHR Extension: (Feven Pro 1.2) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcjbopemebdnolilndkpjfmhakccapkh [2014-03-04]
CHR Extension: (Google Wallet) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-24]
========================== Services (Whitelisted) =================
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [910416 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-21] (Avira Operations GmbH & Co. KG)
S2 Irmon; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [235696 2014-01-16] (McAfee, Inc.)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
S3 SUService; C:\Program Files\Lenovo\System Update\SUService.exe [22376 2013-06-26] ()
S2 APNMCP; "C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe" [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2014-01-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2014-01-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-10] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [69240 2014-01-03] (Avira Operations GmbH & Co. KG)
R3 BTHprint; C:\Windows\System32\DRIVERS\bthprint.sys [50688 2009-07-14] (Microsoft Corporation)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2009-03-31] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-04-08] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51416 2014-04-03] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-10-10] (Avira GmbH)
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 pppop; system32\DRIVERS\pppop.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-08 13:16 - 2014-04-08 13:16 - 00015767 _____ () C:\Users\Administrator\Downloads\FRST.txt
2014-04-08 12:54 - 2014-04-08 12:54 - 00000000 ____D () C:\Windows\ERUNT
2014-04-08 12:53 - 2014-04-08 12:53 - 01016261 _____ (Thisisu) C:\Users\Administrator\Downloads\JRT.exe
2014-04-08 12:31 - 2014-04-08 12:43 - 00000000 ____D () C:\AdwCleaner
2014-04-08 12:31 - 2014-04-08 12:31 - 01426178 _____ () C:\Users\Administrator\Downloads\adwcleaner.exe
2014-04-08 11:31 - 2014-04-08 13:01 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-08 11:31 - 2014-04-08 11:31 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-08 11:30 - 2014-04-08 11:31 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-08 11:30 - 2014-04-08 11:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-08 11:30 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-08 11:30 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-08 11:30 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-08 11:27 - 2014-04-08 11:28 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Administrator\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-08 10:25 - 2014-04-08 10:25 - 00001222 _____ () C:\Users\Administrator\Desktop\Revo Uninstaller.lnk
2014-04-08 10:25 - 2014-04-08 10:25 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-04-08 10:23 - 2014-04-08 10:23 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Administrator\Downloads\revosetup95.exe
2014-04-07 23:54 - 2014-04-08 13:12 - 00000000 ____D () C:\Users\Administrator\Desktop\Dokumente Trojaner
2014-04-07 23:33 - 2014-04-07 23:37 - 148281272 _____ () C:\Users\Administrator\Downloads\avira_antivirus_suite_de.exe
2014-04-07 22:24 - 2014-04-07 22:24 - 00380416 _____ () C:\Users\Administrator\Downloads\Gmer-19357.exe
2014-04-07 22:19 - 2014-04-08 13:16 - 00000000 ____D () C:\FRST
2014-04-07 22:17 - 2014-04-07 22:17 - 01145856 _____ (Farbar) C:\Users\Administrator\Downloads\FRST.exe
2014-04-07 22:11 - 2014-04-07 22:11 - 00000260 _____ () C:\Users\Administrator\Downloads\defogger_enable.log
2014-04-07 22:10 - 2014-04-07 22:10 - 00050477 _____ () C:\Users\Administrator\Downloads\Defogger(1).exe
2014-04-07 21:56 - 2014-04-07 21:56 - 00050477 _____ () C:\Users\Administrator\Downloads\Defogger.exe
2014-04-07 11:42 - 2014-04-07 11:42 - 00000000 ____D () C:\ProgramData\Sony
2014-04-04 13:52 - 2014-04-04 13:52 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Opera Software
2014-04-04 13:51 - 2014-04-04 13:51 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Opera Software
2014-04-04 13:26 - 2014-04-07 10:31 - 00000000 ____D () C:\Program Files\Opera
2014-03-23 15:35 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-23 15:35 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-23 15:35 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-23 15:35 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-23 15:35 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-23 15:35 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-23 15:35 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-23 15:35 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-23 15:35 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-23 15:35 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-23 15:35 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-23 15:35 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-23 15:35 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-23 15:35 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-23 15:35 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-23 15:35 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-23 15:35 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-23 15:35 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-23 15:35 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-23 15:35 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-23 15:35 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-23 15:35 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-23 15:35 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-23 15:35 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-23 15:34 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-23 15:34 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-23 15:33 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
==================== One Month Modified Files and Folders =======
2014-04-08 13:16 - 2014-04-08 13:16 - 00015767 _____ () C:\Users\Administrator\Downloads\FRST.txt
2014-04-08 13:16 - 2014-04-07 22:19 - 00000000 ____D () C:\FRST
2014-04-08 13:15 - 2012-09-24 22:05 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-08 13:12 - 2014-04-07 23:54 - 00000000 ____D () C:\Users\Administrator\Desktop\Dokumente Trojaner
2014-04-08 13:07 - 2009-07-14 06:34 - 00021808 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-08 13:07 - 2009-07-14 06:34 - 00021808 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-08 13:01 - 2014-04-08 11:31 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-08 12:57 - 2014-02-27 22:16 - 00001610 _____ () C:\Windows\Tasks\MediaPlayerEnhance-updater.job
2014-04-08 12:57 - 2014-02-27 22:15 - 00001584 _____ () C:\Windows\Tasks\HQ-Video-Profession-1.3-updater.job
2014-04-08 12:57 - 2014-02-27 22:15 - 00001524 _____ () C:\Windows\Tasks\Feven Pro 1.2-updater.job
2014-04-08 12:57 - 2014-02-27 22:14 - 00001464 _____ () C:\Windows\Tasks\MediaPlayerEnhance-enabler.job
2014-04-08 12:57 - 2014-02-27 22:13 - 00001566 _____ () C:\Windows\Tasks\MediaPlayerEnhance-codedownloader.job
2014-04-08 12:57 - 2014-02-27 22:10 - 00001438 _____ () C:\Windows\Tasks\HQ-Video-Profession-1.3-enabler.job
2014-04-08 12:57 - 2014-02-27 22:08 - 00001378 _____ () C:\Windows\Tasks\Feven Pro 1.2-enabler.job
2014-04-08 12:57 - 2014-02-27 22:05 - 00002398 _____ () C:\Windows\Tasks\MediaPlayerEnhance-firefoxinstaller.job
2014-04-08 12:57 - 2014-02-27 22:05 - 00001540 _____ () C:\Windows\Tasks\HQ-Video-Profession-1.3-codedownloader.job
2014-04-08 12:57 - 2014-02-27 22:03 - 00003124 _____ () C:\Windows\Tasks\MediaPlayerEnhance-chromeinstaller.job
2014-04-08 12:57 - 2014-02-27 22:03 - 00001480 _____ () C:\Windows\Tasks\Feven Pro 1.2-codedownloader.job
2014-04-08 12:57 - 2014-02-27 22:02 - 00002654 _____ () C:\Windows\Tasks\HQ-Video-Profession-1.3-firefoxinstaller.job
2014-04-08 12:57 - 2014-02-27 22:01 - 00002284 _____ () C:\Windows\Tasks\Feven Pro 1.2-firefoxinstaller.job
2014-04-08 12:57 - 2014-02-27 22:00 - 00003144 _____ () C:\Windows\Tasks\HQ-Video-Profession-1.3-chromeinstaller.job
2014-04-08 12:57 - 2014-02-27 22:00 - 00003104 _____ () C:\Windows\Tasks\Feven Pro 1.2-chromeinstaller.job
2014-04-08 12:57 - 2012-09-24 22:05 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-08 12:57 - 2012-09-23 21:43 - 00028697 _____ () C:\Windows\setupact.log
2014-04-08 12:57 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-08 12:56 - 2012-08-22 09:04 - 01129354 _____ () C:\Windows\WindowsUpdate.log
2014-04-08 12:54 - 2014-04-08 12:54 - 00000000 ____D () C:\Windows\ERUNT
2014-04-08 12:53 - 2014-04-08 12:53 - 01016261 _____ (Thisisu) C:\Users\Administrator\Downloads\JRT.exe
2014-04-08 12:43 - 2014-04-08 12:31 - 00000000 ____D () C:\AdwCleaner
2014-04-08 12:43 - 2013-09-17 14:54 - 00001037 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-08 12:43 - 2012-09-21 13:14 - 00001164 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-08 12:37 - 2012-09-24 22:06 - 00001236 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-08 12:37 - 2012-09-23 21:55 - 00001007 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-08 12:31 - 2014-04-08 12:31 - 01426178 _____ () C:\Users\Administrator\Downloads\adwcleaner.exe
2014-04-08 12:30 - 2012-09-24 22:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-08 12:18 - 2010-11-20 23:48 - 00379084 _____ () C:\Windows\PFRO.log
2014-04-08 11:31 - 2014-04-08 11:31 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-08 11:31 - 2014-04-08 11:30 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-08 11:30 - 2014-04-08 11:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-08 11:28 - 2014-04-08 11:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Administrator\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-08 10:25 - 2014-04-08 10:25 - 00001222 _____ () C:\Users\Administrator\Desktop\Revo Uninstaller.lnk
2014-04-08 10:25 - 2014-04-08 10:25 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-04-08 10:23 - 2014-04-08 10:23 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Administrator\Downloads\revosetup95.exe
2014-04-08 10:07 - 2012-09-23 21:55 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-04-08 00:04 - 2014-02-26 17:52 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-07 23:41 - 2013-10-27 14:15 - 00002012 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-04-07 23:37 - 2014-04-07 23:33 - 148281272 _____ () C:\Users\Administrator\Downloads\avira_antivirus_suite_de.exe
2014-04-07 22:24 - 2014-04-07 22:24 - 00380416 _____ () C:\Users\Administrator\Downloads\Gmer-19357.exe
2014-04-07 22:17 - 2014-04-07 22:17 - 01145856 _____ (Farbar) C:\Users\Administrator\Downloads\FRST.exe
2014-04-07 22:11 - 2014-04-07 22:11 - 00000260 _____ () C:\Users\Administrator\Downloads\defogger_enable.log
2014-04-07 22:11 - 2012-09-21 13:13 - 00000000 ____D () C:\Users\Administrator
2014-04-07 22:10 - 2014-04-07 22:10 - 00050477 _____ () C:\Users\Administrator\Downloads\Defogger(1).exe
2014-04-07 21:56 - 2014-04-07 21:56 - 00050477 _____ () C:\Users\Administrator\Downloads\Defogger.exe
2014-04-07 12:41 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2014-04-07 12:40 - 2012-09-24 22:21 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-04-07 12:40 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2014-04-07 12:09 - 2012-09-21 12:54 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-04-07 11:46 - 2012-09-21 12:05 - 00213776 _____ () C:\Windows\DPINST.LOG
2014-04-07 11:46 - 2010-11-20 23:01 - 01627884 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-07 11:42 - 2014-04-07 11:42 - 00000000 ____D () C:\ProgramData\Sony
2014-04-07 11:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-04-07 11:36 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-04-07 11:35 - 2014-02-27 22:00 - 00000000 ____D () C:\Program Files\Feven Pro 1.2
2014-04-07 11:35 - 2014-02-14 01:38 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-04-07 11:35 - 2013-11-25 00:37 - 00000000 ____D () C:\Program Files\Sony
2014-04-07 11:35 - 2012-11-20 18:41 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-04-07 11:35 - 2012-08-23 16:41 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-04-07 11:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2014-04-07 11:29 - 2012-09-24 22:21 - 00000000 ____D () C:\ProgramData\McAfee
2014-04-07 10:31 - 2014-04-04 13:26 - 00000000 ____D () C:\Program Files\Opera
2014-04-07 10:31 - 2011-04-12 03:39 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-04-04 15:07 - 2012-09-21 12:40 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-04-04 13:54 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\config\Journal
2014-04-04 13:52 - 2014-04-04 13:52 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Opera Software
2014-04-04 13:51 - 2014-04-04 13:51 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Opera Software
2014-04-03 09:51 - 2014-04-08 11:30 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-08 11:30 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-08 11:30 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 09:35 - 2012-08-22 09:52 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-26 04:37 - 2014-01-19 13:39 - 00001972 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-03-24 04:30 - 2009-07-14 06:33 - 00410064 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-24 04:08 - 2012-08-23 15:33 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-24 04:06 - 2013-08-16 07:16 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-24 04:02 - 2012-08-22 10:24 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.228.dll
Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\Administrator\AppData\Local\Temp\BackupSetup.exe
C:\Users\Administrator\AppData\Local\Temp\Quarantine.exe
C:\Users\Administrator\AppData\Local\Temp\uninst1.exe
C:\Users\Administrator\AppData\Local\Temp\vcredist_x86.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 01:32
==================== End Of Log ============================ --- --- ---
--- --- --- |