Saatkrähe | 13.12.2013 10:04 | Hallo Schrauber,
hier der Report von mbam:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.12.13.03
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16750
annabird :: ANNABIRD-PC [Administrator]
13.12.2013 08:48:49
mbam-log-2013-12-13 (08-48-49).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 197632
Laufzeit: 11 Minute(n), 40 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende)
ich fahre nun mit dem AdwCleaner
AdwareCleaner report:AdwCleaner Logfile: Code:
# AdwCleaner v3.015 - Bericht erstellt am 13/12/2013 um 09:25:33
# Updated 10/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Basic Service Pack 1 (32 bits)
# Benutzername : annabird - ANNABIRD-PC
# Gestartet von : C:\Users\annabird\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\AVG Security Toolbar
Ordner Gelöscht : C:\Users\annabird\AppData\Local\AVG Security Toolbar
Datei Gelöscht : C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\2w5ftyys.default\searchplugins\askcomsearch.xml
Datei Gelöscht : C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\2w5ftyys.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askchecker_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askchecker_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_getdataback_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_getdataback_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CCC7A320-B3CA-4199-B1A6-9F516DD69829}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Schlüssel Gelöscht : HKCU\Software\IGearSettings
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AVG Security Toolbar
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16750
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
-\\ Mozilla Firefox v26.0 (de)
[ Datei : C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\2w5ftyys.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultengine", "Search-Results");
Zeile gelöscht : user_pref("browser.search.order.1", "Search-Results");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://isearch.glarysoft.com/?src=ffhome");
Zeile gelöscht : user_pref("extensions.asktb.InstallDir", "C:\\Program Files\\Ask.com\\");
Zeile gelöscht : user_pref("extensions.asktb.abar-war-timeout", "4000");
Zeile gelöscht : user_pref("extensions.asktb.autofill-competitor-query-enabled", true);
Zeile gelöscht : user_pref("extensions.asktb.autofill-text-highlight-enabled", true);
Zeile gelöscht : user_pref("extensions.asktb.cbid", "96");
Zeile gelöscht : user_pref("extensions.asktb.config-updated", false);
Zeile gelöscht : user_pref("extensions.asktb.count", "35");
Zeile gelöscht : user_pref("extensions.asktb.crumb", "2011.09.12+07.18.34-toolbar007iad-DE-QmVybGluLEdlcm1hbnk%3D");
Zeile gelöscht : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.search-results.com/web?q={query}&o={o}&l={l}&qsrc={qsrc}");
Zeile gelöscht : user_pref("extensions.asktb.displaybehavior", "1");
Zeile gelöscht : user_pref("extensions.asktb.displaytext", "Musik%20h%F6ren");
Zeile gelöscht : user_pref("extensions.asktb.dtid", "YYYYYYYYDE");
Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://isearch.avg.com/search?cid=%7B5353df0a-80a4-4d09-a07d-d72c84aa3247%7D&mid=cfbf5d3cca1c47d1b978d15a31d8d37a-2a33260a482023f7fb6033a502b9d02[...]
Zeile gelöscht : user_pref("extensions.asktb.fresh-install", false);
Zeile gelöscht : user_pref("extensions.asktb.guid", "128669B7-AB9A-41F4-AA36-BAECCF1DADE6");
Zeile gelöscht : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \"WWW.google.com\", \"hxxps://websearch.ask.com\", [...]
Zeile gelöscht : user_pref("extensions.asktb.if", "first");
Zeile gelöscht : user_pref("extensions.asktb.l", "dis");
Zeile gelöscht : user_pref("extensions.asktb.last-config-req", "1339404163064");
Zeile gelöscht : user_pref("extensions.asktb.last-search-timestamp", "1338749382975");
Zeile gelöscht : user_pref("extensions.asktb.last-v", "3.12.2.16752");
Zeile gelöscht : user_pref("extensions.asktb.locale", "de_DE");
Zeile gelöscht : user_pref("extensions.asktb.location", "Berlin,Germany");
Zeile gelöscht : user_pref("extensions.asktb.lstation", "s117322");
Zeile gelöscht : user_pref("extensions.asktb.o", "41648033");
Zeile gelöscht : user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Zeile gelöscht : user_pref("extensions.asktb.pstate", "");
Zeile gelöscht : user_pref("extensions.asktb.qsrc", "2871");
Zeile gelöscht : user_pref("extensions.asktb.r", "2");
Zeile gelöscht : user_pref("extensions.asktb.sa", "YES");
Zeile gelöscht : user_pref("extensions.asktb.saguid", "F59C6370-0D20-4F99-B01E-2D86A3AB0C51");
Zeile gelöscht : user_pref("extensions.asktb.silent-upgrade", true);
Zeile gelöscht : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Zeile gelöscht : user_pref("extensions.asktb.socialmini-first", true);
Zeile gelöscht : user_pref("extensions.asktb.socialmini-interval", "1200000");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-max-items", "30");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-native-on", true);
Zeile gelöscht : user_pref("extensions.asktb.socialmini-speed", "5000");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-transition-first-open", false);
Zeile gelöscht : user_pref("extensions.asktb.themeid", "");
Zeile gelöscht : user_pref("extensions.asktb.to", "");
Zeile gelöscht : user_pref("extensions.asktb.v", "3.13.1.100007");
Zeile gelöscht : user_pref("extensions.asktb.volume", "40");
Zeile gelöscht : user_pref("extensions.enabledAddons", "firefox@ghostery.com:2.7.2,TFToolbarX@torrent-finder:1.3,trackmenot@mrl.nyu.edu:0.6.728,{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.21,{64161300-e22b-11db-8314-08[...]
Zeile gelöscht : user_pref("extensions.foxlingo.addit.defaultAddons", "{ \"software\": {\"20\": {\"id\": \"20\",\"title\": \"Babylon\",\"type\": \"EXE\",\"url\": \"hxxps://www.addonfox.com/downloads/babylon.exe\",\"ho[...]
Zeile gelöscht : user_pref("extensions.toolbar@ask.com.install-event-fired", true);
[ Datei : C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\prefs.js ]
Zeile gelöscht : user_pref("extensions.personas.lastselected4", "{\"id\":\"251369\",\"name\":\"BLISS OF SPRING\",\"headerURL\":\"hxxps://addons.mozilla.org/_files/251369/purple.jpg?1288905732\",\"footerURL\":\"hxxps:/[...]
Zeile gelöscht : user_pref("lightweightThemes.usedThemes", "[{\"id\":\"472399\",\"name\":\"Red Birds of Winter\",\"headerURL\":\"hxxps://addons.mozilla.org/_files/472399/header.png?1384730435\",\"footerURL\":\"hxxps:/[...]
*************************
AdwCleaner[R0].txt - [8976 octets] - [13/12/2013 09:22:33]
AdwCleaner[S0].txt - [8835 octets] - [13/12/2013 09:25:33]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8895 octets] ########## --- --- ---
Logfile JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Basic x86
Ran by annabird on 13.12.2013 at 9:43:51,83
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{13189051-CB6F-4B16-907E-4F1FB1CFC0EF}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F8318B10-97C5-4207-94B8-0D8C11BB9DCF}
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Users\annabird\AppData\Roaming\mozilla\firefox\profiles\2w5ftyys.default\extensions\toolbar@web.de
Successfully deleted the following from C:\Users\annabird\AppData\Roaming\mozilla\firefox\profiles\2w5ftyys.default\prefs.js
user_pref("extensions.speeddial.thumbnail-2-label", "Search-results Suche");
user_pref("extensions.speeddial.thumbnail-2-url", "hxxp://de.search-results.com/?l=dis&o=41648036");
Emptied folder: C:\Users\annabird\AppData\Roaming\mozilla\firefox\profiles\q34j5t7j.default-1339490348969\minidumps [393 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13.12.2013 at 9:49:17,37
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-12-2013 01
Ran by annabird (administrator) on ANNABIRD-PC on 13-12-2013 09:59:07
Running from C:\Users\annabird\Downloads
Microsoft Windows 7 Home Basic Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe
(Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesApp32.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
(Glarysoft Ltd) C:\Program Files\Glary Utilities\memdefrag.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.)
HKLM\...\Runonce: [AvgUninstallURL] - cmd.exe /c start hxxp://www.avg.de/de.special-uninstallation-feedback-lsf?lic=OUxTRlJFRS1WUFVaNy1HMkNNWC1SWFBXQS1QM05aSC05RDIwQy0zN1RT"&"inst=NzctMTE5MTE3NjE2My1GTDEwKzEtRERUKzYyNTY0LVRVRyszLVNUMTBGQVBQKzEtREQxMEYrMS1GMTBUQisyLVNUMTBUQkYrMQ"&"prod=55"&"ver=10.0.1424
HKCU\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKCU\...\Run: [PeerBlock] - C:\Program Files\PeerBlock\peerblock.exe [1866864 2010-11-06] (PeerBlock, LLC)
HKCU\...\Run: [Glary Memory Optimizer] - C:\Program Files\Glary Utilities\memdefrag.exe [108384 2012-09-11] (Glarysoft Ltd)
MountPoints2: {1d862051-6f69-11e1-9e7a-0013773c3a89} - E:\DPFMate.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7C9710700A68CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
URLSearchHook: HKCU - (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch
SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969
FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF NetworkProxy: "ftp", "188.165.249.205"
FF NetworkProxy: "ftp_port", 3128
FF NetworkProxy: "gopher", ""
FF NetworkProxy: "gopher_port", 0
FF NetworkProxy: "http", "188.165.249.205"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "188.165.249.205"
FF NetworkProxy: "socks_port", 3128
FF NetworkProxy: "ssl", "188.165.249.205"
FF NetworkProxy: "ssl_port", 3128
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\annabird\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
FF Plugin HKCU: @www.flatcast.com/FlatViewer 5.2 - C:\Users\annabird\AppData\Roaming\Flatcast\NpFv522.dll (1 mal 1 Software GmbH)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\glarysearch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Visualisateur 3D de 20-20 - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\2020Player_IKEA@2020Technologies.com
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\ich@maltegoetz.de
FF Extension: Flashblock - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF Extension: WOT - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF Extension: firefox - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\firefox@ghostery.com.xpi
FF Extension: personas - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\personas@christopher.beard.xpi
FF Extension: savedpasswordeditor - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\savedpasswordeditor@daniel.dawson.xpi
FF Extension: stealthyextension - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\stealthyextension@gmail.com.xpi
FF Extension: TFToolbarX - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\TFToolbarX@torrent-finder.xpi
FF Extension: toolbar - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\toolbar@web.de.xpi
FF Extension: SmoothWheel - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}.xpi
FF Extension: speeddial - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi
FF Extension: ImTranslator - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
FF Extension: Adblock Plus - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: bprivacyprefs - C:\Users\annabird\AppData\Roaming\Mozilla\Firefox\Profiles\q34j5t7j.default-1339490348969\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe [1739576 2013-10-30] (TuneUp Software)
==================== Drivers (Whitelisted) ====================
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [120600 2013-11-05] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [209176 2013-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147768 2013-10-24] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22840 2013-09-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [176952 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [222520 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [102712 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27448 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [193848 2013-08-01] (AVG Technologies CZ, s.r.o.)
R2 DOSMEMIO; C:\Windows\system32\MEMIO.SYS [4300 2000-08-24] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [22560 2013-09-25] (REALiX(tm))
S3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [20080 2010-11-06] ()
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26624 2011-12-15] (The OpenVPN Project)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesDriver32.sys [12320 2013-08-21] (TuneUp Software)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-13 09:58 - 2013-12-13 09:58 - 00000000 ____D C:\Users\annabird\Downloads\FRST-OlderVersion
2013-12-13 09:49 - 2013-12-13 09:49 - 00001510 _____ C:\Users\annabird\Desktop\JRT.txt
2013-12-13 09:43 - 2013-12-13 09:43 - 00000000 ____D C:\Windows\ERUNT
2013-12-13 09:41 - 2013-12-13 09:41 - 00001062 _____ C:\Users\annabird\Desktop\JRT - Verknüpfung.lnk
2013-12-13 09:40 - 2013-12-13 09:41 - 01034531 _____ (Thisisu) C:\Users\annabird\Downloads\JRT.exe
2013-12-13 09:22 - 2013-12-13 09:25 - 00000000 ____D C:\AdwCleaner
2013-12-13 09:21 - 2013-12-13 09:21 - 00001135 _____ C:\Users\annabird\Desktop\adwcleaner - Verknüpfung.lnk
2013-12-13 09:16 - 2013-12-13 09:18 - 01226802 _____ C:\Users\annabird\Downloads\adwcleaner.exe
2013-12-12 15:41 - 2013-12-12 15:42 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\annabird\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-12-11 13:00 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-11 13:00 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-11 12:58 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 12:58 - 2013-10-25 05:45 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-11 12:58 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 12:58 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 12:58 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 12:58 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 12:58 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-11 12:58 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-11 12:58 - 2013-10-25 05:43 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 12:58 - 2013-10-25 05:43 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-11 12:58 - 2013-10-25 05:43 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-11 12:58 - 2013-10-25 05:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 12:58 - 2013-10-25 05:43 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-11 12:58 - 2013-10-25 04:41 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 12:58 - 2013-10-25 03:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-11 12:57 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 12:01 - 2013-12-13 09:59 - 00010950 _____ C:\Users\annabird\Downloads\FRST.txt
2013-12-11 12:01 - 2013-12-11 12:02 - 00023067 _____ C:\Users\annabird\Downloads\Addition.txt
2013-12-11 12:00 - 2013-12-13 09:58 - 00000000 ____D C:\FRST
2013-12-11 11:59 - 2013-12-11 11:59 - 00001077 _____ C:\Users\annabird\Desktop\FRST - Verknüpfung.lnk
2013-12-11 11:58 - 2013-12-13 09:58 - 01060575 _____ (Farbar) C:\Users\annabird\Downloads\FRST.exe
2013-12-11 10:07 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-12-11 10:07 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-12-11 10:07 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-12-11 10:06 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 10:06 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 10:06 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 10:06 - 2013-10-30 02:27 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 10:06 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 10:06 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 10:06 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-12-11 10:06 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 10:06 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-12-11 10:06 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-12-11 10:06 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 10:06 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 10:06 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-12-11 10:06 - 2013-10-04 02:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 10:06 - 2013-10-04 02:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 10:06 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-12-11 10:06 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-12-11 10:06 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-12-11 10:06 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-12-11 10:06 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-12-11 10:06 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-12-11 10:06 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-12-11 10:06 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-12-11 10:06 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-12-11 10:06 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-12-11 10:06 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-12-11 10:04 - 2013-12-11 10:04 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-11 09:09 - 2013-12-11 09:09 - 00103680 _____ (GMER) C:\kxdyqkow.sys
2013-12-11 09:08 - 2013-12-11 09:08 - 00377856 _____ C:\Users\annabird\Downloads\gmer_2.1.19163.exe
2013-11-25 10:44 - 2013-11-25 11:06 - 00014401 _____ C:\Users\annabird\Documents\IKEA Küche.odt
==================== One Month Modified Files and Folders =======
2013-12-13 10:00 - 2013-12-11 12:01 - 00010950 _____ C:\Users\annabird\Downloads\FRST.txt
2013-12-13 09:58 - 2013-12-13 09:58 - 00000000 ____D C:\Users\annabird\Downloads\FRST-OlderVersion
2013-12-13 09:58 - 2013-12-11 12:00 - 00000000 ____D C:\FRST
2013-12-13 09:58 - 2013-12-11 11:58 - 01060575 _____ (Farbar) C:\Users\annabird\Downloads\FRST.exe
2013-12-13 09:49 - 2013-12-13 09:49 - 00001510 _____ C:\Users\annabird\Desktop\JRT.txt
2013-12-13 09:43 - 2013-12-13 09:43 - 00000000 ____D C:\Windows\ERUNT
2013-12-13 09:41 - 2013-12-13 09:41 - 00001062 _____ C:\Users\annabird\Desktop\JRT - Verknüpfung.lnk
2013-12-13 09:41 - 2013-12-13 09:40 - 01034531 _____ (Thisisu) C:\Users\annabird\Downloads\JRT.exe
2013-12-13 09:36 - 2009-07-14 05:34 - 00020800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-13 09:36 - 2009-07-14 05:34 - 00020800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-13 09:35 - 2012-04-04 17:00 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-13 09:35 - 2011-08-31 20:12 - 00000000 ____D C:\ProgramData\MFAData
2013-12-13 09:29 - 2011-09-07 09:47 - 00000320 _____ C:\Windows\Tasks\GlaryInitialize.job
2013-12-13 09:29 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-13 09:28 - 2012-06-16 22:16 - 00046200 _____ C:\Windows\setupact.log
2013-12-13 09:27 - 2011-08-31 19:04 - 01929114 _____ C:\Windows\WindowsUpdate.log
2013-12-13 09:25 - 2013-12-13 09:22 - 00000000 ____D C:\AdwCleaner
2013-12-13 09:21 - 2013-12-13 09:21 - 00001135 _____ C:\Users\annabird\Desktop\adwcleaner - Verknüpfung.lnk
2013-12-13 09:18 - 2013-12-13 09:16 - 01226802 _____ C:\Users\annabird\Downloads\adwcleaner.exe
2013-12-12 15:42 - 2013-12-12 15:41 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\annabird\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-12-11 15:35 - 2012-04-04 17:00 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-12-11 15:35 - 2011-09-06 13:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-12-11 15:19 - 2011-08-31 19:20 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-11 15:14 - 2009-07-14 05:33 - 00292496 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-11 15:10 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-12-11 15:09 - 2012-04-30 11:14 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-12-11 13:02 - 2013-08-07 21:51 - 00000000 ____D C:\Windows\system32\MRT
2013-12-11 12:02 - 2013-12-11 12:01 - 00023067 _____ C:\Users\annabird\Downloads\Addition.txt
2013-12-11 11:59 - 2013-12-11 11:59 - 00001077 _____ C:\Users\annabird\Desktop\FRST - Verknüpfung.lnk
2013-12-11 10:04 - 2013-12-11 10:04 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-11 09:09 - 2013-12-11 09:09 - 00103680 _____ (GMER) C:\kxdyqkow.sys
2013-12-11 09:08 - 2013-12-11 09:08 - 00377856 _____ C:\Users\annabird\Downloads\gmer_2.1.19163.exe
2013-12-10 19:28 - 2012-10-05 10:26 - 00032394 _____ C:\Windows\PFRO.log
2013-12-10 19:28 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\PLA
2013-12-05 13:35 - 2013-11-12 15:37 - 00145581 _____ C:\Users\annabird\Documents\cecilia aka Aliesa Formatseiten.odt
2013-12-05 11:41 - 2011-09-16 14:03 - 00000000 ____D C:\Users\annabird\Documents\Krempelkram
2013-12-02 11:39 - 2013-07-10 13:26 - 00000000 ____D C:\Users\annabird\AppData\Roaming\HpUpdate
2013-12-01 14:42 - 2011-08-31 20:18 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-30 12:14 - 2012-07-30 08:05 - 00000000 ____D C:\Users\annabird\AppData\Local\Paint.NET
2013-11-26 12:57 - 2013-09-25 20:41 - 00000951 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2013-11-25 11:06 - 2013-11-25 10:44 - 00014401 _____ C:\Users\annabird\Documents\IKEA Küche.odt
2013-11-23 19:26 - 2013-12-11 10:06 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-11-18 08:32 - 2011-09-04 13:04 - 00000000 ____D C:\Users\annabird\AppData\Local\Adobe
Some content of TEMP:
====================
C:\Users\annabird\AppData\Local\Temp\Quarantine.exe
C:\Users\annabird\AppData\Local\Temp\vlc-2.0.8-win32.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-10 14:55
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
Bitteschön..
Grüße,
Saatkrähe |