fisherman | 17.04.2015 14:37 | Hallo,
hab die Schritte durchgeführt und die logs dazu. Junkware Removal Tool ist bei mir leider abgestürzt, mehrfach.
MBAM Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 17.04.2015
Suchlauf-Zeit: 13:45:01
Logdatei: mbam-log-2015-04-17 (13-44-58).txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.04.17.03
Rootkit Datenbank: v2015.03.31.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows XP Service Pack 3
CPU: x86
Dateisystem: NTFS
Benutzer: Besitzer
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 300460
Verstrichene Zeit: 20 Min, 0 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 11
PUP.Optional.Snapdo.T, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [8126f37ae1a9122428cc88f2699ad828],
PUP.Optional.QuickShare.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [7a2d6b02cac0ba7cde1fc0b69e65ca36],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [7a2d6b02cac0ba7cde1fc0b69e65ca36],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, In Quarantäne, [2f780766d3b7162028af10348c7729d7],
PUP.Optional.Wajam.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, In Quarantäne, [2f780766d3b7162028af10348c7729d7],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, In Quarantäne, [2f780766d3b7162028af10348c7729d7],
Adware.GamePlayLab, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{11111111-1111-1111-1111-110011221158}, In Quarantäne, [e9bebab3fc8ec670ee1464ef7c870ef2],
Adware.GamePlayLab, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{11111111-1111-1111-1111-110011221158}, In Quarantäne, [e9bebab3fc8ec670ee1464ef7c870ef2],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\MICROSOFT\ESENT\PROCESS\WajamInternetEnhancer, In Quarantäne, [d9cec2ab830733035feaa2a2b253fe02],
PUP.Optional.SmartBar, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\SmartbarLog, In Quarantäne, [5552254845450a2c9d4c21198d789c64],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\INSTALLCORE, In Quarantäne, [07a05d10206a77bf73810e148580916f],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\INSTALLCORE|tb, 0N1P1Q2V1U1J1MtI0FtH0L, In Quarantäne, [07a05d10206a77bf73810e148580916f]
Registrierungsdaten: 12
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}),Ersetzt,[d8cfafbef79362d42b31d4221ce94ab6]
PUM.Hijack.StartMenu, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED|Start_ShowHelp, 0, Gut: (1), Schlecht: (0),Ersetzt,[9e09c9a45a30bb7b114e7d7f3ec710f0]
PUM.Hijack.Help, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|NoSMHelp, 1, Gut: (0), Schlecht: (1),Ersetzt,[0c9b5419e1a9bb7bb95ac239ce37b44c]
PUM.Hijack.StartMenu, HKU\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED|Start_ShowHelp, 0, Gut: (1), Schlecht: (0),Ersetzt,[cfd8ce9f7c0e3cfa0758f60651b47789]
PUM.Hijack.Help, HKU\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|NoSMHelp, 1, Gut: (0), Schlecht: (1),Ersetzt,[485f2b42addd7cba997a847734d1b54b]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}),Ersetzt,[7f2899d47c0e0630f36b787eea1b0df3]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}),Ersetzt,[eeb90d608901e84e65f9c92d85808977]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}),Ersetzt,[9d0a5c11ddad2412d78934c2b550639d]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}),Ersetzt,[872097d6b8d20c2abaa69c5a65a016ea]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DE&userid=11a58dfe-0baa-473a-800a-2371c7702b0d&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}),Ersetzt,[3077fa732466a19590cd09ed48bd44bc]
PUM.Hijack.StartMenu, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED|Start_ShowHelp, 0, Gut: (1), Schlecht: (0),Ersetzt,[55520e5f0e7ceb4b4c13807cc63ff50b]
PUM.Hijack.Help, HKU\S-1-5-21-1220945662-436374069-1801674531-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|NoSMHelp, 1, Gut: (0), Schlecht: (1),Ersetzt,[f5b280ed0c7e4fe7f41fcb307b8a25db]
Ordner: 3
PUP.Optional.OpenCandy, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\OpenCandy, In Quarantäne, [e7c0b6b78dfd2016d1eac4c78281629e],
PUP.Optional.OpenCandy, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\OpenCandy\2B22194DDABF4B98B562E727CBDA1DE1, In Quarantäne, [e7c0b6b78dfd2016d1eac4c78281629e],
PUP.Optional.OpenCandy, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\OpenCandy\OpenCandy_2B22194DDABF4B98B562E727CBDA1DE1, In Quarantäne, [e7c0b6b78dfd2016d1eac4c78281629e],
Dateien: 37
PUP.Optional.SmartBar, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\OpenCandy\2B22194DDABF4B98B562E727CBDA1DE1\LinkuryInstaller.msi, In Quarantäne, [0a9d1657593154e27cd1e749cf316a96],
PUP.Optional.SmartBar, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\OpenCandy\2B22194DDABF4B98B562E727CBDA1DE1\LinkuryInstaller_p1v13.exe, In Quarantäne, [12953835a1e90234113c67c9c7398c74],
PUP.Optional.SmartBar, C:\WINDOWS\Installer\81ece.msi, In Quarantäne, [c6e14b228bff54e2a7a6e848827e03fd],
PUP.Optional.WebSearch.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\searchplugins\Web Search.xml, In Quarantäne, [188fc4a96d1df442ebd3de25857f916f],
PUP.Optional.OpenCandy, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\OpenCandy\2B22194DDABF4B98B562E727CBDA1DE1\2787.ico, In Quarantäne, [e7c0b6b78dfd2016d1eac4c78281629e],
PUP.Optional.OpenCandy, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\OpenCandy\2B22194DDABF4B98B562E727CBDA1DE1\EBB77268-338F-4C6A-8590-AD88FED26F4A, In Quarantäne, [e7c0b6b78dfd2016d1eac4c78281629e],
PUP.Optional.OpenCandy, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\OpenCandy\2B22194DDABF4B98B562E727CBDA1DE1\OCBrowserHelper_1.0.3.81.dll, In Quarantäne, [e7c0b6b78dfd2016d1eac4c78281629e],
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), Ersetzt,[4b5c7fee9befca6c3d58fb449d6960a0]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (nces
/* Do not edit this file.
*
* If you mak), Ersetzt,[fdaa026b1c6e67cfddb8fb4490766e92]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (ferences
/* Do not edit this file.
*
* If you make changes ), Ersetzt,[624577f65e2cf0466b2af34c7c8a26da]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: ( Do not edit this file.
*
* If you make changes to this file while the applicati), Ersetzt,[c2e547264f3bb680a2f34af5b94d11ef]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (file.
*
* If you make changes to this file while the application is running,), Ersetzt,[8621cf9e6b1f85b1b7de2f1018eebc44]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (his file.
*
* If you make changes to this file while th), Ersetzt,[b2f575f8e7a36fc7e7ae80bfd23411ef]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (s
/* Do not edit this file.
*
* If you make change), Ersetzt,[4265d895d5b501358b0a77c85da97888]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (ces
/* Do not edit this file.
*
* If you make changes to t), Ersetzt,[6c3b1459deacb4829ef72e11e91d1ee2]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (* Do not edit this file.
*
* If you make changes to this), Ersetzt,[d2d5bbb25f2b9f97bdd880bf6c9ae41c]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (
/* Do not edit this file.
*
* If you make changes), Ersetzt,[4d5a303d26640f273d583c037e8858a8]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (ces
/* Do not edit this file.
*
* If you make c), Ersetzt,[1e89b2bb632771c57a1bfe410ef844bc]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (rences
/* Do not edit this file.
*
* If you make), Ersetzt,[dfc81e4f315971c52e6750efce3815eb]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (ences
/* Do not edit this file.
*
* If you make cha), Ersetzt,[70375518afdbd75fdabba6993fc7d927]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (es
/* Do not edit this file.
*
* If you make changes to this ), Ersetzt,[42652647bad0ae889104f54a976f2fd1]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\prefs.js, Gut: (), Schlecht: (o not edit this file.
*
* If you make changes to this f), Ersetzt,[5f48cba28dfd62d4a6ef1b24c93d0cf4]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819");), Ersetzt,[9116c3aab9d145f1fd374df210f63dc3]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (lbar_i.babTrack", "affID=110819");
user_pref("exten), Ersetzt,[4364125b6a20a78ff440c07ff214619f]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (ons.BabylonToolbar_i.babTrack", "affID=110819");
user), Ersetzt,[5c4b323b781292a459dbd56a5ea840c0]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (s.BabylonToolbar_i.babTrack", "affID=110819");
user_pref("extensions.BabylonToo), Ersetzt,[7d2aa0cd523855e13cf83a0539cdfb05]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (k", "affID=110819");
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_pre), Ersetzt,[9c0bfd703e4ce74f41f3d966a462629e]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: ("affID=110819");
user_pref("extensions.BabylonToolbar_i.ba), Ersetzt,[e9be9cd1325850e6d2620e31fc0a6a96]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (ylonToolbar_i.babTrack", "affID=110819");
user_pref("exte), Ersetzt,[2f785b12f1990b2bb183bf80a4621ce4]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (bylonToolbar_i.babTrack", "affID=110819");
user_pref("exte), Ersetzt,[e0c7b3ba4b3fac8a023289b648bed62a]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (ylonToolbar_i.babTrack", "affID=110819");
user_pref("extensions.Bab), Ersetzt,[a10624497d0d68ce0034fa450df9c43c]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (ar_i.babTrack", "affID=110819");
user_pref("extensions.Baby), Ersetzt,[1592bdb0b1d9ba7c8ba90639ee181ee2]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (lonToolbar_i.babTrack", "affID=110819");
user_pref("extensions.B), Ersetzt,[ced94a231872de58e94b1b2436d01be5]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (olbar_i.babTrack", "affID=110819");
user_pref("extensio), Ersetzt,[bdeaf9746a20b4824ce873cc0bfb0cf4]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (BabylonToolbar_i.babTrack", "affID=110819");
user_pref("), Ersetzt,[f3b4571675152610c07491aefa0c55ab]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (abylonToolbar_i.babTrack", "affID=110819");
user_pref(), Ersetzt,[fbacabc24743013572c2a69932d40af6]
PUP.Optional.Babylon.A, C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js, Gut: (), Schlecht: (.BabylonToolbar_i.babTrack", "affID=110819");
user_pref(), Ersetzt,[386ff17c3b4f72c449eb92ad4cba40c0]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) AdwCleaner Code:
# AdwCleaner v4.201 - Logfile created 17/04/2015 at 14:26:09
# Updated 08/04/2015 by Xplode
# Database : 2015-04-15.1 [Server]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : Besitzer - WORKSTATION
# Running from : C:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Downloads\AdwCleaner_4.201.exe
# Option : Cleaning
***** [ Services ] *****
[#] Service Deleted : APNMCP
[#] Service Deleted : vToolbarUpdater18.1.9
***** [ Files / Folders ] *****
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\apn
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AskPartnerNetwork
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AVG Secure Search
Folder Deleted : C:\Programme\AskPartnerNetwork
Folder Deleted : C:\Programme\AVG Secure Search
Folder Deleted : C:\Programme\AVG Security Toolbar
Folder Deleted : C:\Programme\Gemeinsame Dateien\AVG Secure Search
Folder Deleted : C:\DOKUME~1\Besitzer\LOKALE~1\Temp\apn
Folder Deleted : C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\AskPartnerNetwork
Folder Deleted : C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\AVG Secure Search
Folder Deleted : C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\AVG Secure Search
File Deleted : C:\END
File Deleted : C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\searchplugins\ask-search.xml
File Deleted : C:\Programme\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
File Deleted : C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\searchplugins\Linkury Smartbar Search.xml
File Deleted : C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\user.js
File Deleted : C:\Programme\Mozilla Firefox\defaults\pref\itms.js
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.apn.native_messaging_host_aaaaacalgebmfelllfiaoknifldpngjh
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{41564952-412D-5637-00A7-7A786E7484D7}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{41564952-412D-5637-00A7-7A786E7484D7}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D8278076-BC68-4484-9233-6E7F1628B56C}]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\OCS
Key Deleted : HKLM\SOFTWARE\AskPartnerNetwork
Key Deleted : HKLM\SOFTWARE\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork
Key Deleted : HKU\.DEFAULT\Software\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{41564952-412D-5637-00A7-A758B70C1200}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{41564952-412D-5637-00A7-A758B70C1200}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25946514D2147365007A7A857BC02100
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\25946514D2147365007A7A857BC02100
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\25946514D2147365007A7A857BC02100
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
Data Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:1085;hxxps=127.0.0.1:1085;
Data Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyEnable] - 1
Data Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
***** [ Web browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
-\\ Mozilla Firefox v37.0.1 (x86 de)
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("avg.install.installDirPath", "C:\\Dokumente und Einstellungen\\All Users\\Anwendungsdaten\\AVG Secure Search\\FireFoxExt\\18.1.9.799");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("avg.userPreferences.URLBarFocus.whiteList", "bing\\.comgoogle\\.\\w+yahoo\\.\\w+gmail\\.\\w+hotmail\\.\\w+live\\.\\w+isearch\\.avg\\.commysearch\\.avg\\.com");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-but[...]
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.AVIRA-V7.AUC_clientCache", "{\"AUC_CACHE\":{\"avira.com\":{\"c\":[1],\"ttl\":1376729493},\"ask.com\":{\"c\":[1],\"ttl\":1376729501},\"yr.no\":{\"c\":[1],\"ttl\":1376729506}}}");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.AVIRA-V7.com.avira.dnt.rules", "\"{\\\"Version\\\":44,\\\"Companies\\\":[{\\\"company\\\":\\\"Google Inc\\\",\\\"rules\\\":[{\\\"name\\\":\\\"Google Analytics\\\",\\\"category\\\[...]
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.AVIRA-V7.domain", "\"avira.search.ask.com\"");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.AVIRA-V7.hpr_ff", "\"hxxp://avira.search.ask.com/?tpid=AVIRA-V7&o=APN11080&pf=&trgb=ALL&p2=%5EB0Y%5EYYYYYY%5EYY%5ENO&gct=hp&apn_ptnrs=%5EB0Y&apn_dtid=%5EYYYYYY%5EYY%5ENO&apn_dbr=[...]
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.AVIRA-V7.newTabSearchURL", "\"hxxp://avira.search.ask.com/web?o=APN11080&p2=%5EB0Y%5EYYYYYY%5EYY%5ENO&tpid=AVIRA-V7&gct=tab&apn_uid=6331D101-0C43-493B-AFDC-E47D2C312C2B&apn_ptnrs[...]
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.AVIRA-V7.pref_tab_close", "[{\"title\":\"MultiC_JavaConnector_Arkiv%20-%20AttachmentDownloadServlet\",\"url\":\"hxxps://nettbank.sor.no/dialogue/attachment/AttachmentDownloadServ[...]
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.AVIRA-V7.searchURL", "\"hxxp://avira.search.ask.com/web?o=APN11080&p2=%5EB0Y%5EYYYYYY%5EYY%5ENO&tpid=AVIRA-V7&gct=bar&apn_uid=6331D101-0C43-493B-AFDC-E47D2C312C2B&apn_ptnrs=%5EB0[...]
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "f425dffa000000000000001a6b68c2cf");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.id", "f425dffa000000000000001a6b68c2cf");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15491");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1720:56:57");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.enabledAddons", "toolbar_AVIRA-V7%40apn.ask.com:108.20,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:37.0.1");
[ltsgi1im.default\prefs.js] - Line Deleted : user_pref("extensions.xpiState", "{\"app-profile\":{\"abs@avira.com\":{\"d\":\"C:\\\\Dokumente und Einstellungen\\\\Besitzer\\\\Anwendungsdaten\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ltsgi1im.default\\\[...]
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [15391 bytes] - [17/04/2015 14:23:57]
AdwCleaner[S0].txt - [15169 bytes] - [17/04/2015 14:26:09]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15229 bytes] ########## Junkware Removal Tool
==> ist abgestürtzt, auch nach mehrfachen neustart
FRST log:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-04-2015 04
Ran by Besitzer (administrator) on WORKSTATION on 17-04-2015 15:30:35
Running from C:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Downloads
Loaded Profiles: Besitzer (Available profiles: Besitzer)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\WINDOWS\system32\ibmpmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Programme\Bonjour\mDNSResponder.exe
(Sun Microsystems, Inc.) C:\Programme\Java\jre6\bin\jqs.exe
(Safer-Networking Ltd.) C:\Programme\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Programme\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Synaptics Incorporated) C:\Programme\Synaptics\SynTP\SynTPEnh.exe
(Brother Industries, Ltd.) C:\Programme\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Programme\Brother\ControlCenter3\BrccMCtl.exe
(Synaptics Incorporated) C:\Programme\Synaptics\SynTP\SynTPLpr.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avgnt.exe
(Safer-Networking Ltd.) C:\Programme\Spybot - Search & Destroy 2\SDTray.exe
(Microsoft Corporation) C:\Programme\Messenger\msmsgs.exe
(Skype Technologies S.A.) C:\Programme\Skype\Phone\Skype.exe
(Avanquest Software ) C:\Programme\Digital Line Detect\DLG.exe
(Dropbox, Inc.) C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox\bin\Dropbox.exe
() C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\My Avira\Avira.OE.ServiceHost.exe
(OpenOffice.org) C:\Programme\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Programme\OpenOffice.org 3\program\soffice.bin
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Brother Industries, Ltd.) C:\Programme\Browny02\BrYNSvc.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Mozilla Corporation) C:\Programme\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Adobe ARM] => C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [SynTPEnh] => C:\Programme\Synaptics\SynTP\SynTPEnh.exe [2350352 2012-04-09] (Synaptics Incorporated)
HKLM\...\Run: [UserFaultCheck] => %systemroot%\system32\dumprep 0 -u
HKLM\...\Run: [NeroFilterCheck] => C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [APSDaemon] => C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [ControlCenter3] => C:\Programme\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] => C:\Programme\Browny02\Brother\BrStMonW.exe [2621440 2010-02-09] (Brother Industries, Ltd.)
HKLM\...\Run: [avgnt] => C:\Programme\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-12] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [SDTray] => C:\Programme\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM\...\Run: [Avira Systray] => C:\Programme\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-1220945662-436374069-1801674531-1002\...\Run: [MSMSGS] => C:\Programme\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-1220945662-436374069-1801674531-1002\...\Run: [Skype] => C:\Programme\Skype\Phone\Skype.exe [17148552 2012-02-29] (Skype Technologies S.A.)
HKU\S-1-5-21-1220945662-436374069-1801674531-1002\...\MountPoints2: {7897241a-85b0-11e3-a80e-0013024662ff} - E:\AutoRun.exe
HKU\S-1-5-21-1220945662-436374069-1801674531-1002\...\MountPoints2: {8c90c104-2dba-11e2-a526-0013024662ff} - E:\LaunchU3.exe -a
HKU\S-1-5-21-1220945662-436374069-1801674531-1002\...\MountPoints2: {8c90c106-2dba-11e2-a526-0013024662ff} - E:\LaunchU3.exe
HKU\S-1-5-21-1220945662-436374069-1801674531-1002\...\MountPoints2: {98d406cc-84e5-11e3-a80d-0013024662ff} - F:\AutoRun.exe
HKU\S-1-5-21-1220945662-436374069-1801674531-1002\...\MountPoints2: {f67f0a1e-7ba1-11e3-a7fb-0013024662ff} - E:\AutoRun.exe
HKU\S-1-5-18\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Digital Line Detect.lnk
ShortcutTarget: Digital Line Detect.lnk -> C:\Programme\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Autostart\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Autostart\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Autostart\RocketDock.lnk
ShortcutTarget: RocketDock.lnk -> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe ()
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:1085;https=127.0.0.1:1085;
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "hxxp://www.google.com" <======= ATTENTION
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Programme\Java\jre6\bin\ssv.dll [2012-05-05] (Sun Microsystems, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Programme\Java\jre6\bin\jp2ssv.dll [2012-05-05] (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class -> {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -> C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-05-05] (Sun Microsystems, Inc.)
Toolbar: HKU\.DEFAULT -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKU\.DEFAULT -> No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL [2002-05-24] (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL [2002-05-24] (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL [2002-05-24] (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL [2002-05-24] (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL [2002-05-24] (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL [2002-05-24] (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL [2002-05-24] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies)
Winsock: Catalog5 04 C:\Programme\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 109.247.114.4 81.167.36.11
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default
FF SearchEngineOrder.1: Ask Search
FF SelectedSearchEngine: Ask Search
FF Homepage: www.zeit.de
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw.dll [2009-10-29] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Programme\iTunes\Mozilla Plugins\npitunes.dll [2012-10-31] ()
FF Plugin: @java.com/DTPlugin,version=1.6.0_32 -> C:\WINDOWS\system32\npdeployJava1.dll [2012-05-05] (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin -> C:\Programme\Java\jre6\bin\plugin2\npjp2.dll [2012-05-05] (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Programme\Microsoft Silverlight\3.0.40818.0\npctrl.dll [2009-08-17] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Extension: Segurança do navegador Avira - C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\Extensions\abs@avira.com [2015-04-01]
FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\ltsgi1im.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi [2013-07-26]
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Programme\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Programme\Java\jre6\lib\deploy\jqs\ff [2012-05-05]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-10-17]
Chrome:
=======
CHR Profile: C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Programme\Avira\AntiVir Desktop\avmailc.exe [815352 2015-04-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [434424 2015-04-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-12] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE [1004032 2015-04-12] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device; C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55184 2012-08-11] (Apple Inc.)
R2 Avira.OE.ServiceHost; C:\Programme\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
R2 Bonjour Service; C:\Programme\Bonjour\mDNSResponder.exe [390504 2011-08-31] (Apple Inc.)
R3 BrYNSvc; C:\Programme\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed]
S2 helpsvc; C:\WINDOWS\System32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
R2 IBMPMSVC; C:\WINDOWS\system32\ibmpmsvc.exe [57344 2003-07-03] ()
S3 iPod Service; C:\Programme\iPod\bin\iPodService.exe [553440 2012-12-12] (Apple Inc.)
R2 JavaQuickStarterService; C:\Programme\Java\jre6\bin\jqs.exe [153376 2012-05-05] (Sun Microsystems, Inc.)
S2 MBAMService; C:\Programme\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [148080 2015-04-15] (Mozilla Foundation)
S2 PEVSystemStart; C:\ComboFix\SWREG.3XE [518144 2000-08-31] (SteelWerX) [File not signed]
R2 SDScannerService; C:\Programme\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Programme\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Programme\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [158856 2012-02-29] (Skype Technologies)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [105864 2015-03-05] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [42784 2014-08-12] (AVG Technologies)
R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [136216 2015-03-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 BrScnUsb; C:\WINDOWS\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.)
R2 drhard; C:\WINDOWS\system32\Drivers\drhard.sys [23600 2005-12-01] (Licensed for Gebhard Software) [File not signed]
R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [217016 2010-06-02] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [993464 2010-06-02] (Conexant Systems, Inc.)
S3 hwusbfake; C:\WINDOWS\System32\DRIVERS\ewusbfake.sys [102656 2008-12-30] (Huawei Technologies Co., Ltd.)
R3 IBMPMDRV; C:\WINDOWS\System32\DRIVERS\ibmpmdrv.sys [11344 2003-07-03] (IBM Corp.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
R0 mv61xxmm; C:\WINDOWS\system32\Drivers\mv61xxmm.sys [5632 2011-01-17] (Marvell Semiconductor Inc.) [File not signed]
R0 mv64xxmm; C:\WINDOWS\system32\Drivers\mv64xxmm.sys [5632 2011-01-17] (Marvell Semiconductor Inc.) [File not signed]
R0 mvxxmm; C:\WINDOWS\system32\Drivers\mvxxmm.sys [5632 2011-01-17] (Marvell Semiconductor Inc.) [File not signed]
R3 NETwLx32; C:\WINDOWS\System32\DRIVERS\NETwLx32.sys [6607744 2010-08-16] (Intel Corporation)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2013-08-10] (Avira GmbH)
R3 tpm; C:\WINDOWS\System32\DRIVERS\tpm.sys [13824 2008-06-20] (Intel Corporation)
S4 IntelIde; No ImagePath
U3 TlntSvr; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-17 14:51 - 2015-04-17 14:51 - 00000000 ____D () C:\RegBackup
2015-04-17 14:23 - 2015-04-17 14:27 - 00000000 ____D () C:\AdwCleaner
2015-04-17 14:20 - 2015-04-17 14:07 - 00047128 _____ () C:\Dokumente und Einstellungen\Besitzer\Desktop\mbam-log-2015-04-17 (13-44-58).xml
2015-04-17 14:08 - 2015-04-17 14:08 - 00073128 _____ () C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
2015-04-17 13:43 - 2015-04-17 14:12 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-17 13:43 - 2015-04-17 13:43 - 00000749 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-17 13:43 - 2015-04-17 13:43 - 00000000 ____D () C:\Programme\Malwarebytes Anti-Malware
2015-04-17 13:43 - 2015-04-17 13:43 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes Anti-Malware
2015-04-17 13:43 - 2015-03-17 06:15 - 00120024 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-17 13:43 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-04-15 19:15 - 2015-04-15 19:15 - 00000265 _____ () C:\WINDOWS\wininit.ini
2015-04-15 15:20 - 2015-04-15 15:21 - 00000000 ___SD () C:\ComboFix
2015-04-15 12:41 - 2015-04-15 12:41 - 00000000 _RSHD () C:\cmdcons
2015-04-15 12:41 - 2015-01-07 19:01 - 00000211 _____ () C:\Boot.bak
2015-04-15 12:41 - 2004-08-03 23:00 - 00262448 __RSH () C:\cmldr
2015-04-15 12:40 - 2015-04-15 12:40 - 00000000 __SHD () C:\Dokumente und Einstellungen\NetworkService\IETldCache
2015-04-15 12:36 - 2015-04-15 12:36 - 00000000 ___SD () C:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Verwaltung
2015-04-15 12:36 - 2015-04-15 12:36 - 00000000 ____D () C:\Qoobox
2015-04-15 12:36 - 2011-06-26 08:45 - 00256000 _____ () C:\WINDOWS\PEV.exe
2015-04-15 12:36 - 2010-11-07 19:20 - 00208896 _____ () C:\WINDOWS\MBR.exe
2015-04-15 12:36 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2015-04-15 12:36 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2015-04-15 12:36 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2015-04-15 12:36 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2015-04-15 12:36 - 2000-08-31 02:00 - 00098816 _____ () C:\WINDOWS\sed.exe
2015-04-15 12:36 - 2000-08-31 02:00 - 00080412 _____ () C:\WINDOWS\grep.exe
2015-04-15 12:36 - 2000-08-31 02:00 - 00068096 _____ () C:\WINDOWS\zip.exe
2015-04-15 12:35 - 2015-04-15 12:35 - 00000000 ____D () C:\WINDOWS\erdnt
2015-04-15 12:29 - 2015-04-15 12:31 - 05618457 ____R (Swearware) C:\Dokumente und Einstellungen\Besitzer\Desktop\ComboFix.exe
2015-04-15 12:20 - 2015-04-15 12:20 - 00000889 _____ () C:\Dokumente und Einstellungen\Besitzer\Desktop\Revo Uninstaller.lnk
2015-04-15 12:20 - 2015-04-15 12:20 - 00000000 ____D () C:\Programme\VS Revo Group
2015-04-14 19:55 - 2015-04-17 15:30 - 00000000 ____D () C:\FRST
2015-04-14 19:52 - 2015-04-14 19:52 - 00000000 _____ () C:\Dokumente und Einstellungen\Besitzer\defogger_reenable
2015-04-13 13:50 - 2015-04-13 15:33 - 00023795 _____ () C:\Dokumente und Einstellungen\Besitzer\Desktop\Silvi.odt
2015-04-12 20:17 - 2015-04-12 20:17 - 00088088 _____ () C:\Dokumente und Einstellungen\LocalService\Eigene Dateien\AVSCAN-20150412-183957-AA43E91F.LOG
2015-04-07 11:36 - 2015-04-07 11:36 - 00000832 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Avira.lnk
2015-03-30 19:27 - 2015-03-30 19:27 - 00114688 _____ () C:\WINDOWS\Minidump\Mini033015-01.dmp
2015-03-18 18:26 - 2015-03-18 18:26 - 00114688 _____ () C:\WINDOWS\Minidump\Mini031815-01.dmp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-17 15:30 - 2012-05-10 06:10 - 00000000 ____D () C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Temp
2015-04-17 14:46 - 2012-10-29 14:19 - 00000000 ___RD () C:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Dropbox
2015-04-17 14:46 - 2012-10-29 14:10 - 00000000 ____D () C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Dropbox
2015-04-17 14:46 - 2012-05-10 05:54 - 01934192 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-17 14:44 - 2014-10-26 20:52 - 00000636 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
2015-04-17 14:44 - 2012-05-10 06:49 - 00000259 _____ () C:\WINDOWS\wiadebug.log
2015-04-17 14:43 - 2014-03-12 19:25 - 00000228 _____ () C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Benachrichtigung – Anmeldung.job
2015-04-17 14:43 - 2013-06-07 21:42 - 00000350 _____ () C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job
2015-04-17 14:43 - 2013-06-03 22:26 - 00000350 _____ () C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2015-04-17 14:43 - 2012-05-10 06:49 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2015-04-17 14:43 - 2012-05-10 06:06 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-04-17 14:42 - 2012-05-31 15:33 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-04-17 14:42 - 2012-05-10 06:10 - 00000190 ___SH () C:\Dokumente und Einstellungen\Besitzer\ntuser.ini
2015-04-17 14:42 - 2012-05-10 06:10 - 00000000 ____D () C:\Dokumente und Einstellungen\Besitzer
2015-04-17 14:42 - 2012-05-10 06:06 - 00032256 _____ () C:\WINDOWS\SchedLgU.Txt
2015-04-17 14:27 - 2012-05-10 06:44 - 00000000 ___RD () C:\Programme
2015-04-17 14:23 - 2013-08-23 20:39 - 02189312 ___SH () C:\Dokumente und Einstellungen\Besitzer\Desktop\Thumbs.db
2015-04-17 14:09 - 2004-08-04 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2015-04-17 14:07 - 2012-05-04 17:07 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2647518$
2015-04-17 13:43 - 2012-05-10 06:44 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme
2015-04-17 13:43 - 2012-05-04 17:56 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2015-04-17 10:25 - 2012-05-10 05:58 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2015-04-15 15:14 - 2012-06-11 01:41 - 00000000 ____D () C:\Programme\Mozilla Maintenance Service
2015-04-15 12:41 - 2012-05-10 07:37 - 00000327 __RSH () C:\boot.ini
2015-04-15 12:40 - 2014-02-12 22:01 - 00100567 _____ () C:\WINDOWS\setupapi.log
2015-04-15 12:40 - 2012-05-10 06:44 - 00217774 _____ () C:\WINDOWS\iis6.log
2015-04-15 12:40 - 2012-05-10 06:06 - 00000000 __SHD () C:\Dokumente und Einstellungen\NetworkService
2015-04-15 12:36 - 2012-05-10 06:10 - 00000000 ___RD () C:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme
2015-04-15 12:28 - 2012-05-10 06:10 - 00000000 ___RD () C:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Autostart
2015-04-15 12:27 - 2012-10-29 14:19 - 00001045 _____ () C:\Dokumente und Einstellungen\Besitzer\Desktop\Dropbox.lnk
2015-04-15 12:27 - 2012-10-29 14:10 - 00000000 ____D () C:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Dropbox
2015-04-15 12:07 - 2012-05-10 06:43 - 00193489 _____ () C:\WINDOWS\setupact.log
2015-04-15 12:06 - 2014-06-18 21:06 - 00000000 ____D () C:\Programme\Mozilla Firefox
2015-04-14 21:42 - 2013-08-10 15:50 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-14 21:34 - 2012-05-04 17:00 - 125832184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-14 20:45 - 2012-05-31 15:33 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-14 20:45 - 2012-05-04 17:39 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-14 19:31 - 2012-06-10 17:17 - 00000000 ____D () C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Skype
2015-04-14 19:25 - 2014-01-16 14:58 - 00000000 ____D () C:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Zimmer_Schanze
2015-04-12 20:17 - 2012-05-10 05:59 - 00000000 __SHD () C:\Dokumente und Einstellungen\LocalService
2015-04-12 19:57 - 2013-02-01 10:51 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2015-04-12 18:40 - 2012-05-10 05:52 - 00000000 ____D () C:\WINDOWS\Registration
2015-04-12 18:37 - 2013-08-10 10:49 - 00000000 ____D () C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Avira
2015-04-12 18:37 - 2013-08-10 10:43 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira
2015-04-12 18:36 - 2013-08-10 10:42 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira
2015-04-12 13:10 - 2012-05-10 06:11 - 00000000 ___RD () C:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Eigene Bilder
2015-04-11 18:29 - 2012-08-31 12:14 - 00000069 _____ () C:\WINDOWS\NeroDigital.ini
2015-04-10 18:47 - 2014-03-12 19:25 - 00000222 _____ () C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Monatliche Benachrichtigung.job
2015-04-08 08:10 - 2014-08-07 12:00 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Package Cache
2015-04-07 22:22 - 2013-06-12 13:28 - 00000664 _____ () C:\WINDOWS\system32\d3d9caps.dat
2015-04-07 11:36 - 2013-08-10 10:42 - 00000000 ____D () C:\Programme\Avira
2015-03-30 19:27 - 2014-02-11 18:09 - 00000000 ____D () C:\WINDOWS\Minidump
==================== Files in the root of some directories =======
2013-07-13 11:35 - 2014-06-22 22:08 - 0003730 _____ () C:\Programme\Mozilla Firefoxavg-secure-search.xml
2012-06-01 18:47 - 2015-03-15 18:09 - 0017920 _____ () C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some content of TEMP:
====================
C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Temp\avgnt.exe
C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Temp\catchme.dll
C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Temp\DataCard_Setup.exe
C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpp2x8f3.dll
C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Temp\Quarantine.exe
C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Temp\ResetDevice.exe
C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Temp\sqlite3.dll
C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Temp\_is4.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0979456 ____A (Microsoft Corporation) bb8e0ae6833a774f4792cb8892ca92e6
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================ --- --- --- |