Space Pope | 01.06.2015 09:49 | So, mal sehen ob ich das, was ich gelesen habe, auch verstanden habe und anwenden kann:
Hier kommen die Logs:
1. AdwCleaner Code:
# AdwCleaner v4.206 - Logfile created 01/06/2015 at 10:07:36
# Updated 01/06/2015 by Xplode
# Database : 2015-05-31.5 [Server]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : XXXXXXX - WOLF-43E12FFCCD
# Running from : C:\Dokumente und Einstellungen\XXXXXXX\Eigene Dateien\Downloads\AdwCleaner_4.206(1).exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\w3i
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\driver whiz
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\FinalMediaPlayer
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\RegClean Pro
Folder Deleted : C:\Programme\Conduit
Folder Deleted : C:\Programme\FinalMediaPlayer
Folder Deleted : C:\Programme\GamesBar
Folder Deleted : C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Anwendungsdaten\Conduit
Folder Deleted : C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Anwendungsdaten\FinalMediaPlayer
Folder Deleted : C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Anwendungsdaten\OpenCandy
Folder Deleted : C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\FinalMediaPlayer
Folder Deleted : C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\Systweak
Folder Deleted : C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\Uniblue
Folder Deleted : C:\Dokumente und Einstellungen\XXXXXXX\Eigene Dateien\PC Speed Maximizer
File Deleted : C:\Dokumente und Einstellungen\All Users\Startmenü\FinalMediaPlayer.lnk
File Deleted : C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\FinalMediaPlayer.lnk
File Deleted : C:\Dokumente und Einstellungen\XXXXXXX\Desktop\FinalMediaPlayer.lnk
File Deleted : C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\Mozilla\Firefox\Profiles\306433of.default\searchplugins\safesearch.xml
***** [ Scheduled tasks ] *****
Task Deleted : Final Media Player Update Checker
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [pcspeedup]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [RegistryBooster]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SearchEngineProtection]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\50c9e684700d0.ocx.50c9e684700d0.ocx
Key Deleted : HKLM\SOFTWARE\Classes\50c9e684700d0.ocx.50c9e684700d0.ocx.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{16BE6EB5-924D-8142-1DB9-4AD0D111F083}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{16BE6EB5-924D-8142-1DB9-4AD0D111F083}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{16BE6EB5-924D-8142-1DB9-4AD0D111F083}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{16BE6EB5-924D-8142-1DB9-4AD0D111F083}
Key Deleted : HKCU\Software\Bitberry Software
Key Deleted : HKCU\Software\Bitberry
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\pdfforge
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\Uniblue
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FinalMediaPlayer_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BatBrowse
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\FinalMediaPlayer_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RegClean Pro_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF
***** [ Web browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v38.0.1 (x86 de)
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT2319825&SearchSource=13");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.InstallationId", "ConduitNSISIntegration");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.InstallationType", "ConduitXPEIntegration");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.SearchCaption", "Winload Customized Web Search");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.SearchEngineBeforeUnload", "Winload Customized Web Search");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2319825&SearchSource=13");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2319825");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.backendstorage.autocompletepro_enable", "31");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.backendstorage.autocompletepro_enable_auto", "31");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[306433of.default\prefs.js] - Line Deleted : user_pref("CT2319825.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2319825&SearchSource=13");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ConduitSearchList", "Winload Customized Web Search");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=de", "xVl2ui1iX6CDJwlhoXazeQ==");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=de", "WiZSpHJzJ/uTUKvfHHyj/w==");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=de", "U5mhHQKIYvMC666+kpF/Lw==");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=de", "eJfMrdrGnhGHiiPiYjgAww==");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Dokumente und Einstellungen\\XXXXXXX\\Anwendungsdaten\\Mozilla\\Firefox\\Profiles\\306433of.default\\conduitCommon\\modules\\3.10.0.1");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.10.0.1");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=302398&p=");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2319825");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2319825");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2319825");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Tue May 29 2012 11:31:01 GMT+0200");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.globalUserId", "75477236-da86-4cd4-8c3d-90998c01c9ef");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2319825");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue May 29 2012 11:31:02 GMT+0200");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 60);
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue May 29 2012 11:31:08 GMT+0200");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue May 29 2012 11:31:01 GMT+0200");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.userId", "04e0ea32-4b6b-448f-bfe1-dd625d37469a");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.spiegel.de/");
[306433of.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties");
[306433of.default\prefs.js] - Line Deleted : user_pref("extensions.irmysearch.aflt", "irmsd103");
[306433of.default\prefs.js] - Line Deleted : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtD0EtDyE0Czy0E0FtBzyyEtCyC0E0CtN0D0Tzu0CyCyCtAtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA");
[306433of.default\prefs.js] - Line Deleted : user_pref("extensions.irmysearch.cr", "1645532461");
[306433of.default\prefs.js] - Line Deleted : user_pref("extensions.irmysearch.instlRef", "");
*************************
AdwCleaner[R0].txt - [13328 bytes] - [01/06/2015 09:55:37]
AdwCleaner[S0].txt - [13629 bytes] - [01/06/2015 10:07:36]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13689 bytes] ########## 2. Junkware Removal Tool Log Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.8.6 (05.31.2015:1)
OS: Microsoft Windows XP x86
Ran by XXXXXXX on 01.06.2015 at 10:19:45,60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\WINDOWS\tasks\RegClean Prosch.job
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{43C7EB82-B8DD-8C0A-20B5-25E19720A0B9}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update BatBrowse
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util BatBrowse
~~~ Files
Successfully deleted: [File] C:\WINDOWS\wininit.ini
~~~ Folders
Successfully deleted: [Folder] C:\ai_recyclebin
Successfully deleted: [Folder] C:\WINDOWS\System32\ai_recyclebin
~~~ FireFox
Successfully deleted: [Folder] C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\mozilla\firefox\profiles\306433of.default\conduitcommon
Successfully deleted the following from C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\mozilla\firefox\profiles\306433of.default\prefs.js
user_pref(CT2319825..clientLogIsEnabled, false);
user_pref(CT2319825.ALLOW_SHOWING_HIDDEN_TOOLBAR, false);
user_pref(CT2319825.BrowserCompStateIsOpen_129714600517272937, true);
user_pref(CT2319825.CTID, CT2319825);
user_pref(CT2319825.CurrentServerDate, 29-5-2012);
user_pref(CT2319825.DSInstall, true);
user_pref(CT2319825.DialogsAlignMode, LTR);
user_pref(CT2319825.DialogsGetterLastCheckTime, Tue May 29 2012 11:31:02 GMT+0200);
user_pref(CT2319825.DownloadReferralCookieData, );
user_pref(CT2319825.EMailNotifierPollDate, Tue May 29 2012 12:06:02 GMT+0200);
user_pref(CT2319825.FeedPollDate11908299, Tue May 29 2012 12:01:03 GMT+0200);
user_pref(CT2319825.FirstServerDate, 12-3-2012);
user_pref(CT2319825.FirstTime, true);
user_pref(CT2319825.FirstTimeFF3, true);
user_pref(CT2319825.FixPageNotFoundErrors, true);
user_pref(CT2319825.GroupingServerCheckInterval, 1440);
user_pref(CT2319825.HPInstall, true);
user_pref(CT2319825.HasUserGlobalKeys, true);
user_pref(CT2319825.HomePageProtectorEnabled, true);
user_pref(CT2319825.Initialize, true);
user_pref(CT2319825.InitializeCommonPrefs, true);
user_pref(CT2319825.InstallationAndCookieDataSentCount, 3);
user_pref(CT2319825.InstalledDate, Mon Mar 12 2012 11:44:11 GMT+0100);
user_pref(CT2319825.InvalidateCache, false);
user_pref(CT2319825.IsAlertDBUpdated, true);
user_pref(CT2319825.IsGrouping, false);
user_pref(CT2319825.IsInitSetupIni, true);
user_pref(CT2319825.IsMulticommunity, false);
user_pref(CT2319825.IsOpenThankYouPage, false);
user_pref(CT2319825.IsOpenUninstallPage, true);
user_pref(CT2319825.IsProtectorsInit, true);
user_pref(CT2319825.LanguagePackLastCheckTime, Tue May 29 2012 11:31:01 GMT+0200);
user_pref(CT2319825.LanguagePackReloadIntervalMM, 1440);
user_pref(CT2319825.LastLogin_3.10.0.1, Tue May 29 2012 11:31:01 GMT+0200);
user_pref(CT2319825.LatestVersion, 3.12.2.3);
user_pref(CT2319825.Locale, de);
user_pref(CT2319825.MCDetectTooltipHeight, 83);
user_pref(CT2319825.MCDetectTooltipUrl, hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1);
user_pref(CT2319825.MCDetectTooltipWidth, 295);
user_pref(CT2319825.MyStuffEnabledAtInstallation, true);
user_pref(CT2319825.OriginalFirstVersion, 3.10.0.1);
user_pref(CT2319825.RadioIsPodcast, false);
user_pref(CT2319825.RadioLastCheckTime, Tue May 29 2012 11:31:02 GMT+0200);
user_pref(CT2319825.RadioLastUpdateIPServer, 3);
user_pref(CT2319825.RadioLastUpdateServer, 129224641269630000);
user_pref(CT2319825.RadioMediaID, 11949532);
user_pref(CT2319825.RadioMediaType, Media Player);
user_pref(CT2319825.RadioMenuSelectedID, EBRadioMenu_CT231982511949532);
user_pref(CT2319825.RadioShrinkedFromSetup, false);
user_pref(CT2319825.RadioStationName, 1Live);
user_pref(CT2319825.RadioStationURL, hxxp://gffstream.ic.llnwd.net/stream/gffstream_stream_wdr_einslive_a);
user_pref(CT2319825.SavedHomepage, hxxp://www.spiegel.de/);
user_pref(CT2319825.SearchFromAddressBarIsInit, true);
user_pref(CT2319825.SearchInNewTabEnabled, true);
user_pref(CT2319825.SearchInNewTabIntervalMM, 1440);
user_pref(CT2319825.SearchInNewTabLastCheckTime, Tue May 29 2012 11:30:58 GMT+0200);
user_pref(CT2319825.SearchProtectorEnabled, true);
user_pref(CT2319825.SearchProtectorToolbarDisabled, false);
user_pref(CT2319825.SendProtectorDataViaLogin, true);
user_pref(CT2319825.ServiceMapLastCheckTime, Tue May 29 2012 11:31:00 GMT+0200);
user_pref(CT2319825.SettingsLastCheckTime, Tue May 29 2012 11:30:58 GMT+0200);
user_pref(CT2319825.SettingsLastUpdate, 1337169810);
user_pref(CT2319825.ThirdPartyComponentsInterval, 504);
user_pref(CT2319825.ThirdPartyComponentsLastCheck, Tue May 29 2012 11:30:57 GMT+0200);
user_pref(CT2319825.ThirdPartyComponentsLastUpdate, 1331806000);
user_pref(CT2319825.ToolbarShrinkedFromSetup, false);
user_pref(CT2319825.UserID, UN84463045727168524);
user_pref(CT2319825.ValidationData_Toolbar, 1);
user_pref(CT2319825.WeatherNetwork, );
user_pref(CT2319825.WeatherPollDate, Tue May 29 2012 12:01:04 GMT+0200);
user_pref(CT2319825.WeatherUnit, C);
user_pref(CT2319825.alertChannelId, 715912);
user_pref(CT2319825.backendstorage.id, 3339363735393836);
user_pref(CT2319825.globalFirstTimeInfoLastCheckTime, Tue May 29 2012 11:31:02 GMT+0200);
user_pref(CT2319825.homepageProtectorEnableByLogin, true);
user_pref(CT2319825.initDone, true);
user_pref(CT2319825.isAppTrackingManagerOn, true);
user_pref(CT2319825.isFirstRadioInstallation, false);
user_pref(CT2319825.myStuffEnabled, true);
user_pref(CT2319825.myStuffPublihserMinWidth, 400);
user_pref(CT2319825.myStuffServiceIntervalMM, 1440);
user_pref(CT2319825.navigateToUrlOnSearch, false);
user_pref(CT2319825.oldAppsList, 128898076802619665,128898076802619666,111,1000082,129769053852558608,129453462855350877,129309281463312841,129264494738128351,1289032489178
user_pref(CT2319825.revertSettingsEnabled, true);
user_pref(CT2319825.searchProtectorDialogDelayInSec, 10);
user_pref(CT2319825.searchProtectorEnableByLogin, true);
user_pref(CT2319825.testingCtid, );
user_pref(CT2319825.toolbarAppMetaDataLastCheckTime, Tue May 29 2012 11:31:02 GMT+0200);
user_pref(CT2319825.toolbarContextMenuLastCheckTime, Tue May 29 2012 11:31:02 GMT+0200);
user_pref(CT2319825.usagesFlag, 2);
Emptied folder: C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\mozilla\firefox\profiles\306433of.default\minidumps [9 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.06.2015 at 10:29:57,62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 3. FRST log, allerdings gab es kein Addition log (bzw. ich hab dieses Log nicht gefunden): Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-05-2015
Ran by XXXXXXX (administrator) on WOLF-43E12FFCCD on 01-06-2015 10:32:58
Running from C:\Dokumente und Einstellungen\XXXXXXX\Eigene Dateien\Downloads
Loaded Profiles: XXXXXXX (Available Profiles: XXXXXXX & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avast Software s.r.o.) C:\Programme\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
(TeamViewer GmbH) C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe
(Avast Software s.r.o.) C:\Programme\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [VTPreset] => C:\WINDOWS\system32\VTPreset.exe [45056 2004-02-24] (S3 Graphics, Inc.)
HKLM\...\Run: [AudioDeck] => C:\Programme\VIA\VIAudioi\SBADeck\ADeck.exe [528384 2007-08-09] (VIA Technologies, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [PDFPrint] => C:\Programme\PDF24\pdf24.exe [186408 2013-12-12] (Geek Software GmbH)
HKLM\...\Run: [IndexSearch] => C:\Programme\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PaperPort PTD] => C:\Programme\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PPort12reminder] => C:\Programme\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PDFHook] => C:\Programme\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] => C:\Programme\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [ControlCenter4] => C:\Programme\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] => C:\Programme\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKLM\...\Run: [AvastUI.exe] => C:\Programme\AVAST Software\Avast\AvastUI.exe [5535048 2015-05-12] (Avast Software s.r.o.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-299502267-527237240-725345543-1003\...\Run: [WMPNSCFG] => C:\Programme\Windows Media Player\WMPNSCFG.exe [204288 2006-11-03] (Microsoft Corporation)
HKU\S-1-5-21-299502267-527237240-725345543-1003\...\Run: [ISUSPM] => C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-299502267-527237240-725345543-1003\...\Run: [WISE-FTP Task Planner] => C:\Programme\AceBIT\WISE-FTP 4\wf_tp.exe [965632 2007-02-12] (AceBIT GmbH)
HKU\S-1-5-21-299502267-527237240-725345543-1003\...\Run: [MSMSGS] => C:\Programme\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-299502267-527237240-725345543-1003\...\MountPoints2: {61d99f44-bbb4-11e3-af8c-001333b7bca9} - F:\ting.exe
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan Plus.lnk [2014-10-28]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Programme\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\REALTEK 11n USB Wireless LAN Utility.lnk [2014-01-21]
ShortcutTarget: REALTEK 11n USB Wireless LAN Utility.lnk -> C:\Programme\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Programme\AVAST Software\Avast\ashShell.dll [2015-05-12] (Avast Software s.r.o.)
BootExecute: autocheck autochk * sprestrt
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com/?fr=hp-avast&type=avastbcl
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-299502267-527237240-725345543-1003\Software\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com/?fr=hp-avast&type=avastbcl
HKU\S-1-5-21-299502267-527237240-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Page = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKU\S-1-5-21-299502267-527237240-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = https://de.yahoo.com/?fr=hp-avast&type=avastbcl
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "about:newtab" <======= ATTENTION
SearchScopes: HKLM -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-299502267-527237240-725345543-1003 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL =
SearchScopes: HKU\S-1-5-21-299502267-527237240-725345543-1003 -> {43C7EB82-B8DD-8C0A-20B5-25E19720A0B9} URL = hxxp://start.gamesagogo.iplay.com/searchresultsredirect.aspx?o=chrome&q={searchTerms}
SearchScopes: HKU\S-1-5-21-299502267-527237240-725345543-1003 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
BHO: No Name -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> No File
BHO: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Programme\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll No File
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Programme\Java\jre1.8.0_45\bin\ssv.dll [2015-05-21] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Programme\AVAST Software\Avast\aswWebRepIE.dll [2015-04-12] (Avast Software s.r.o.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Programme\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-21] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-299502267-527237240-725345543-1003 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} hxxp://support.asus.de/common/asusTek_sys_ctrl.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_67-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0067-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_67-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_67-windows-i586.cab
DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} hxxp://yahoode.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} hxxp://driveragent.com/files/driveragent.cab
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2005-09-20] (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2005-09-20] (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2005-09-20] (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2005-09-20] (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2005-09-20] (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2005-09-20] (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2005-09-20] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\Mozilla\Firefox\Profiles\306433of.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-16] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Programme\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-21] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Programme\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-21] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Programme\Microsoft Silverlight\4.0.60310.0\npctrl.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Programme\VideoLAN\VLC\npvlc.dll [2012-06-28] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\NPOFFICE.DLL [2007-03-22] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF SearchPlugin: C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\Mozilla\Firefox\Profiles\306433of.default\searchplugins\yahoo-avast.xml [2014-11-05]
FF Extension: Adblock Plus - C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\Mozilla\Firefox\Profiles\306433of.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-06]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-05-08]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Programme\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Programme\AVAST Software\Avast\WebRep\FF [2014-11-05]
FF HKU\S-1-5-21-299502267-527237240-725345543-1003\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Programme\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-03-23]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Programme\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-23]
CHR HKLM\...\Chrome\Extension: [hjjfbcfodpfbfhgmjpiapmljapjopjfc] - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SaveByclick\hjjfbcfodpfbfhgmjpiapmljapjopjfc.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Programme\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-12] (Avast Software s.r.o.)
S3 BrYNSvc; C:\Programme\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
S2 JavaQuickStarterService; C:\Programme\Java\jre7\bin\jqs.exe [182696 2015-01-01] (Oracle Corporation)
S2 MBAMScheduler; C:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Programme\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Programme\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 MDM; C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE [322120 2003-06-19] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [148080 2015-05-18] (Mozilla Foundation)
S2 NMSAccess; C:\Programme\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [89136 2003-07-28] (Microsoft Corporation)
S2 PDFProFiltSrvPP; C:\Programme\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [160944 2012-11-09] (Skype Technologies)
R2 TeamViewer8; C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe [5095264 2014-08-04] (TeamViewer GmbH)
S2 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2014-01-21] (Cisco Systems, Inc.) [File not signed]
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24144 2015-05-12] ()
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [74976 2015-05-12] (Avast Software s.r.o.)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-05-12] (Avast Software s.r.o.)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49904 2015-05-12] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [787760 2015-05-12] (Avast Software s.r.o.)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [427992 2015-05-12] (Avast Software s.r.o.)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-05-12] (Avast Software s.r.o.)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [209048 2015-05-12] ()
R3 BrScnUsb; C:\WINDOWS\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.)
S3 BS_Flash; C:\Programme\Tseries BIOS Update\Award\BS_Flash.sys [3604 2007-08-16] () [File not signed]
R1 BS_I2cIo; C:\WINDOWS\system32\drivers\BS_I2cIo.sys [17024 2008-06-16] (BIOSTAR Group) [File not signed]
R3 FET5X86V; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [47104 2011-01-23] (VIA Technologies, Inc. )
S3 FETND5BV; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [47104 2011-01-23] (VIA Technologies, Inc. )
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-14] (Microsoft Corporation)
R1 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [120024 2015-04-14] (Malwarebytes Corporation)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-01] (Malwarebytes Corporation)
R3 ms_mpu401; C:\WINDOWS\System32\drivers\msmpu401.sys [2944 2001-08-17] (Microsoft Corporation)
R3 S3Psddr; C:\WINDOWS\System32\DRIVERS\s3gnbm.sys [167168 2004-08-13] (S3 Graphics, Inc.)
S3 S3SavageNB; C:\WINDOWS\System32\DRIVERS\s3gnbm.sys [167168 2004-08-13] (S3 Graphics, Inc.)
R2 StarOpen; C:\WINDOWS\system32\Drivers\StarOpen.sys [5504 2012-06-03] () [File not signed]
R0 viaagp1; C:\WINDOWS\System32\DRIVERS\viaagp1.sys [27904 2014-01-19] (VIA Technologies, Inc.)
R3 VIAudio; C:\WINDOWS\System32\drivers\vinyl97.sys [207488 2007-06-27] (VIA Technologies, Inc.)
R0 videX32; C:\WINDOWS\System32\DRIVERS\videX32.sys [13976 2009-05-05] (VIA Technologies, Inc.)
S3 DrvAgent32; \??\C:\WINDOWS\system32\Drivers\DrvAgent32.sys [X]
S3 FETNDIS; system32\DRIVERS\fetnd5.sys [X]
S4 IntelIde; No ImagePath
S3 RTL8192cu; system32\DRIVERS\RTL8192cu.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-01 10:29 - 2015-06-01 10:29 - 00007089 _____ () C:\Dokumente und Einstellungen\XXXXXXX\Desktop\JRT.txt
2015-06-01 10:19 - 2015-06-01 10:19 - 00000000 ____D () C:\RegBackup
2015-06-01 09:51 - 2015-06-01 10:08 - 00000000 ____D () C:\AdwCleaner
2015-06-01 09:40 - 2015-06-01 09:40 - 00000889 _____ () C:\Dokumente und Einstellungen\XXXXXXX\Desktop\Revo Uninstaller.lnk
2015-06-01 09:40 - 2015-06-01 09:40 - 00000000 ____D () C:\Programme\VS Revo Group
2015-05-31 08:08 - 2015-05-12 10:27 - 00291312 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\aswBoot.exe
2015-05-30 22:26 - 2015-05-30 22:26 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\AVAST Software
2015-05-30 09:00 - 2015-05-30 09:00 - 00000000 _____ () C:\Dokumente und Einstellungen\XXXXXXX\defogger_reenable
2015-05-30 08:45 - 2015-06-01 09:52 - 00000000 ____D () C:\Dokumente und Einstellungen\XXXXXXX\Eigene Dateien\Virenbefall
2015-05-30 07:54 - 2015-06-01 10:33 - 00000000 ____D () C:\FRST
2015-05-12 10:27 - 2015-05-12 10:27 - 00043112 _____ (Avast Software s.r.o.) C:\WINDOWS\avastSS.scr
2015-05-08 08:30 - 2015-05-08 08:30 - 00000000 ____D () C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Macromedia
2015-05-08 08:30 - 2015-05-08 08:30 - 00000000 ____D () C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Adobe
2015-05-08 08:24 - 2015-05-08 08:25 - 00000000 ____D () C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Mozilla
2015-05-08 08:24 - 2015-05-08 08:24 - 00000000 ____D () C:\Dokumente und Einstellungen\LocalService\Startmenü\Programme
2015-05-08 08:24 - 2015-05-08 08:24 - 00000000 ____D () C:\Dokumente und Einstellungen\LocalService\Startmenü
2015-05-08 08:24 - 2015-05-08 08:24 - 00000000 ____D () C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Mozilla
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-01 10:33 - 2010-07-01 16:15 - 00000000 ____D () C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp
2015-06-01 10:31 - 2012-04-12 09:14 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-06-01 10:20 - 2014-11-05 09:55 - 00000358 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-06-01 10:19 - 2012-09-06 12:23 - 00000000 ____D () C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\vlc
2015-06-01 10:17 - 2010-07-01 16:01 - 01187188 _____ () C:\WINDOWS\WindowsUpdate.log
2015-06-01 10:15 - 2014-01-13 18:40 - 00000000 _____ () C:\WINDOWS\RTacDbg.txt
2015-06-01 10:14 - 2010-07-01 16:51 - 00000000 ___RD () C:\Programme
2015-06-01 10:12 - 2014-03-11 07:58 - 00000226 _____ () C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Benachrichtigung – Anmeldung.job
2015-06-01 10:12 - 2010-07-01 16:54 - 00000157 _____ () C:\WINDOWS\wiadebug.log
2015-06-01 10:12 - 2006-02-28 14:00 - 00012598 _____ () C:\WINDOWS\system32\wpa.dbl
2015-06-01 10:11 - 2010-07-01 16:54 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2015-06-01 10:11 - 2010-07-01 16:08 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-06-01 10:09 - 2010-07-01 16:15 - 00000300 ___SH () C:\Dokumente und Einstellungen\XXXXXXX\ntuser.ini
2015-06-01 10:09 - 2010-07-01 16:08 - 00032360 _____ () C:\WINDOWS\SchedLgU.Txt
2015-06-01 10:08 - 2010-07-01 16:50 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü
2015-06-01 10:07 - 2010-07-01 16:50 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme
2015-06-01 10:05 - 2013-10-25 11:05 - 00000422 _____ () C:\WINDOWS\Tasks\At1.job
2015-06-01 09:40 - 2010-07-01 16:15 - 00000000 ___RD () C:\Dokumente und Einstellungen\XXXXXXX\Startmenü\Programme
2015-06-01 09:05 - 2014-06-28 09:10 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-05-31 20:56 - 2014-01-19 15:01 - 00550391 _____ () C:\WINDOWS\setupapi.log
2015-05-31 12:38 - 2014-10-07 12:38 - 00000000 ____D () C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\FileTypeAssistant
2015-05-31 08:10 - 2014-11-05 09:56 - 00001653 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Avast Free Antivirus.lnk
2015-05-31 07:37 - 2010-07-01 16:50 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Dokumente
2015-05-30 22:32 - 2014-01-17 16:07 - 00000190 ___SH () C:\Dokumente und Einstellungen\Administrator\ntuser.ini
2015-05-30 09:00 - 2010-07-01 16:15 - 00000000 ____D () C:\Dokumente und Einstellungen\XXXXXXX
2015-05-29 13:37 - 2010-07-01 17:58 - 00002537 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Excel 2003.lnk
2015-05-27 06:54 - 2010-07-01 17:58 - 00002607 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Outlook 2003.lnk
2015-05-26 06:10 - 2014-01-22 13:08 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862152$
2015-05-21 14:21 - 2015-02-06 12:26 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Oracle
2015-05-21 14:16 - 2015-01-01 23:51 - 00096352 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2015-05-21 14:16 - 2011-06-22 10:04 - 00146432 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2015-05-21 14:15 - 2010-07-15 16:35 - 00000000 ____D () C:\Programme\Java
2015-05-18 22:50 - 2014-09-12 22:17 - 00000000 ____D () C:\Programme\Mozilla Firefox
2015-05-18 22:50 - 2012-11-09 12:36 - 00000000 ____D () C:\Programme\Mozilla Maintenance Service
2015-05-18 14:35 - 2010-07-01 16:15 - 00000000 ___HD () C:\Dokumente und Einstellungen\XXXXXXX\Netzwerkumgebung
2015-05-13 09:03 - 2013-08-15 03:16 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-05-13 08:53 - 2010-07-02 16:24 - 137310008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-05-12 10:27 - 2014-11-05 09:52 - 00427992 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-05-12 10:27 - 2014-11-05 09:52 - 00209048 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-05-12 10:27 - 2014-11-05 09:52 - 00074976 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-05-12 10:27 - 2014-11-05 09:52 - 00057888 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswTdi.sys
2015-05-12 10:27 - 2014-11-05 09:52 - 00055200 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswRdr.sys
2015-05-12 10:27 - 2014-11-05 09:52 - 00049904 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-05-12 10:27 - 2014-11-05 09:52 - 00024144 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-05-12 10:26 - 2014-11-05 09:52 - 00787760 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-05-12 08:59 - 2012-03-09 14:13 - 00000000 ____D () C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\XnView
2015-05-12 08:56 - 2010-07-06 11:32 - 00000000 ____D () C:\Dokumente und Einstellungen\XXXXXXX\Download
2015-05-12 08:54 - 2010-07-05 23:17 - 00051712 _____ () C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-11 21:57 - 2014-10-06 12:36 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\FreeFileViewer
2015-05-08 17:35 - 2011-01-23 22:01 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2015-05-08 15:00 - 2014-03-11 07:57 - 00000220 _____ () C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Monatliche Benachrichtigung.job
2015-05-08 08:27 - 2010-07-01 16:08 - 00000000 __SHD () C:\Dokumente und Einstellungen\LocalService
2015-05-05 22:30 - 2010-07-01 15:59 - 00166437 _____ () C:\WINDOWS\wmsetup.log
==================== Files in the root of some directories =======
2011-10-21 11:24 - 2011-10-21 11:25 - 9852544 _____ (Malwarebytes Corporation ) C:\Programme\mbam-setup-1.51.2.1300.exe
2011-10-21 09:56 - 2011-10-21 09:56 - 2563800 _____ (Symantec Corporation) C:\Programme\NPE.exe
2014-11-09 10:48 - 2014-11-09 10:48 - 0038445 _____ () C:\Dokumente und Einstellungen\XXXXXXX\Anwendungsdaten\Microsoft Excel.ADR
2010-07-05 23:17 - 2015-05-12 08:54 - 0051712 _____ () C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-09-30 13:31 - 2014-09-30 13:31 - 0000822 _____ () C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Anwendungsdaten\recently-used.xbel
Files to move or delete:
====================
C:\Windows\Tasks\At1.job
Some files in TEMP:
====================
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\86438uninstall.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\AMPing.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\contentDATs.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpde847h.dll
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\InstallManager_BAB_BAB.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\install_flashplayer11x32au_gtbd_chrd_dn_aih[1].exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-6u21-windows-i586-iftw-rv.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-6u22-windows-i586-iftw-rv.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-6u23-windows-i586-iftw-rv.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-7u13-windows-i586-iftw.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-7u15-windows-i586-iftw.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-7u21-windows-i586-iftw.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-7u25-windows-i586-iftw.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-7u45-windows-i586-iftw.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-7u51-windows-i586-iftw.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-7u55-windows-i586-iftw.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-7u67-windows-i586-iftw.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-7u71-windows-i586-iftw.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-7u9-windows-i586-iftw.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\jre-8u31-windows-au.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\pcspeedmaxsetup.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\Quarantine.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\SecurityScan_Release.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\setup_wm.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\SkypeSetup.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\Sqlite3.dll
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\TFRC1.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\vcredist_x86.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\vlc-2.2.1-win32.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\XnView-win.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\_is175.exe
C:\Dokumente und Einstellungen\XXXXXXX\Lokale Einstellungen\Temp\{620A5D3C-3342-4ED1-950B-CCD89F60941A}-26.0.1410.43_25.0.1364.172_chrome_updater.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================ Soweit mein aktueller Stand.
Malwarebyte weigert sich noch immer standhaft, eingeschaltet zu werden und Definitionen von heute zu laden. |