Driver23 | 18.04.2014 18:44 | Hallo Schrauber,
der erste Erfolg ist bereits eingetreten, Firefox hat wieder Google als Startseite. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.04.2014
Suchlauf-Zeit: 18:54:01
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.18.07
Rootkit Datenbank: v2014.03.27.01
Lizenz: Premium
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Pod
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 256481
Verstrichene Zeit: 9 Min, 45 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 4
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\rrsavings, In Quarantäne, [22addb504b3041f5548ba7c3c53de11f],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3960197758-2477925476-223839332-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\RrSavings, In Quarantäne, [9936de4dcab1c5710ad7d892847e36ca],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3960197758-2477925476-223839332-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Rr Savings, In Quarantäne, [5679fa311e5de84e3ea792d8ad55e11f],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3960197758-2477925476-223839332-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\rrsavings, In Quarantäne, [ae2146e57efdba7c13d10e5c54aef20e],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 2
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-3960197758-2477925476-223839332-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69&q={searchTerms}),Ersetzt,[e2ed9398cab167cfd9522fef4fb502fe]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-3960197758-2477925476-223839332-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1397571067&from=amt&uid=ST500DM002-1BD142_Z3TRAW69XXXXZ3TRAW69),Ersetzt,[567970bbe9922511161365b9f50fe11f]
Ordner: 3
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter, In Quarantäne, [6a65b57672099d99d5a29dcd29d9c040],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\SSL, In Quarantäne, [6a65b57672099d99d5a29dcd29d9c040],
Dateien: 15
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\background.js, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\CustomActionInstall, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\CustomActionUninstall, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon128.png, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon16.png, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon32.png, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon48.png, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon64.png, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\icon8.png, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\iwalyk.js, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\manifest.json, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\marcopolo.js, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\Microsoft.Deployment.WindowsInstaller.dll, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\Microsoft.Deployment.WindowsInstaller.xml, In Quarantäne, [d5faf239afccc472e195d8927191837d],
PUP.Optional.RRSavings.A, C:\Program Files (x86)\RrSavings\SendJson.dll, In Quarantäne, [d5faf239afccc472e195d8927191837d],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.023 - Bericht erstellt am 18/04/2014 um 19:34:59
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Pod - POD-PC
# Gestartet von : C:\Users\Pod\Desktop\Downloads\Sicherheits-Tools\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\prefs.js ]
-\\ Google Chrome v
[ Datei : C:\Users\Pod\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [26173 octets] - [11/11/2013 18:44:59]
AdwCleaner[R1].txt - [16766 octets] - [11/11/2013 18:52:19]
AdwCleaner[R2].txt - [19899 octets] - [12/11/2013 20:12:58]
AdwCleaner[S0].txt - [27430 octets] - [12/11/2013 20:15:33]
AdwCleaner[S1].txt - [1041 octets] - [18/04/2014 19:34:59]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1101 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Pod on 18.04.2014 at 19:13:18,72
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BC73C780-0926-4885-8602-33442E1C6EF9}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files (x86)\free video converter"
~~~ FireFox
Emptied folder: C:\Users\Pod\AppData\Roaming\mozilla\firefox\profiles\n7yu7958.default\minidumps [7 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.04.2014 at 19:22:21,49
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2013 01 (ATTENTION: ====> FRST version is 159 days old and could be outdated)
Ran by Pod (administrator) on POD-PC on 18-04-2014 19:39:57
Running from C:\Users\Pod\Downloads\Sicherheit
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe
() C:\Windows\SysWOW64\PSIService.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Dropbox, Inc.) C:\Users\Pod\AppData\Roaming\Dropbox\bin\Dropbox.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-14] (Samsung)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-14] (Samsung)
HKCU\...\Run: [Messenger (Yahoo!)] - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.)
HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ReminderApp_EEAC3053-7055-4143-B8A0-306758055099] - C:\Program Files (x86)\Nova Development\Print Artist Gold 25\ReminderApp.exe [146080 2013-08-06] ()
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [97280 2009-07-14] ()
Startup: C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Pod\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC3322628F9C1CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKCU - {9BD27B24-13BE-4DDD-9586-61254659E6CD} URL = hxxp://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: Browser Guard - {02a0d829-4393-46fc-a37e-126263035883} - C:\Program Files (x86)\Browser Guard\browserguard.dll (Browser Guard)
BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
Toolbar: HKLM - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent64.dll (soft Xpansion)
Toolbar: HKLM-x32 - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent32.dll (soft Xpansion)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Hosts: 127.0.0.1 d3oxij66pru1i3.cloudfront.net
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: webssearches
FF SelectedSearchEngine: webssearches
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @soft-xpansion/npsxpdf - C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\searchplugins\yahoo_ff.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\Extensions\WTB_GLOBAL.sqlite
FF Extension: Adblock Plus - C:\Users\Pod\AppData\Roaming\Mozilla\Firefox\Profiles\n7yu7958.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi
FF Extension: No Name - C:\Program Files (x86)\Browser Guard\browserguard.xpi
FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF HKLM-x32\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [kfepagcelbegkpkcjgfeecmlnmkedjin] - C:\Program Files (x86)\Browser Guard\browserguard.crx
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-22] (Advanced Micro Devices, Inc.)
R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [506288 2011-02-08] (REINER SCT)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-02-18] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [529704 2008-02-28] (Nero AG)
R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.)
R2 ProtexisLicensing; C:\Windows\SysWOW64\PSIService.exe [177704 2007-06-05] ()
R2 StarMoney Business 6.0 OnlineUpdate; C:\Program Files (x86)\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-10-08] (soft Xpansion)
S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe" [x]
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices)
S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2010-11-27] (REINER SCT)
S3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-19] (Siliten)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-18] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
S1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [90960 2013-03-15] (Windows (R) 2000 DDK provider)
S1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633680 2013-03-15] (Paragon)
S1 Uim_VIM; C:\Windows\System32\Drivers\uim_vimx64.sys [390352 2013-03-15] (Paragon)
S3 MSICDSetup; \??\F:\CDriver64.sys [x]
S3 NTIDrvr; System32\Drivers\NTIDrvr.sys [x]
S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-18 19:22 - 2014-04-18 19:22 - 00001108 _____ C:\Users\Pod\Desktop\JRT.txt
2014-04-18 19:00 - 2014-04-18 19:00 - 00004997 _____ C:\mbam.txt
2014-04-17 15:27 - 2014-04-17 15:27 - 00000000 ____D C:\Users\Pod\AppData\Local\PAShell
2014-04-17 15:24 - 2014-04-17 15:24 - 00000000 ____D C:\Users\Pod\AppData\Local\Nova Development
2014-04-17 15:23 - 2014-04-17 15:23 - 00002937 _____ C:\Users\Public\Desktop\Print Artist Gold 25.lnk
2014-04-17 15:22 - 2014-04-17 15:22 - 00000000 ____D C:\Program Files (x86)\Nova Development
2014-04-16 20:29 - 2014-04-16 20:29 - 00001298 _____ C:\Users\Pod\Desktop\Revo Uninstaller.lnk
2014-04-16 20:29 - 2014-04-16 20:29 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2014-04-16 07:23 - 2014-04-16 07:23 - 00015102 _____ C:\Users\Pod\Downloads\Defogger (1).exe
2014-04-15 20:00 - 2014-04-15 20:01 - 00000000 ____D C:\FRST
2014-04-15 18:52 - 2014-04-15 18:52 - 00000000 _____ C:\Users\Pod\defogger_reenable
2014-04-15 18:51 - 2014-04-15 18:51 - 00000000 ____D C:\Users\Pod\AppData\Roaming\IDM2
2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D C:\MININT
2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D C:\Users\Pod\AppData\Local\cache
2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 _____ C:\Users\Pod\daemonprocess.txt
2014-04-15 16:12 - 2014-04-15 16:44 - 00000000 ____D C:\Program Files\002
2014-04-15 16:10 - 2014-04-15 16:26 - 00000000 ____D C:\Users\Pod\AppData\Local\41
2014-04-12 15:14 - 2014-04-18 19:36 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-12 15:14 - 2014-04-12 15:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-12 15:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-12 15:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-10 19:06 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-10 19:06 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-10 19:06 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-10 19:06 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-10 19:05 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-10 19:05 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-10 19:05 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-10 19:05 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-10 19:05 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-10 19:05 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-10 19:05 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-10 19:05 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-10 19:05 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-10 19:05 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-10 19:05 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-10 19:05 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-10 19:05 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-10 19:05 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-10 19:05 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-10 19:05 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-10 19:05 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-03-29 14:15 - 2014-03-29 14:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-03-21 11:05 - 2014-03-21 15:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
==================== One Month Modified Files and Folders =======
2014-04-18 19:39 - 2013-11-12 21:44 - 00000000 ____D C:\Users\Pod\Downloads\Sicherheit
2014-04-18 19:36 - 2014-04-12 15:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-18 19:36 - 2013-12-07 12:28 - 00000000 ___RD C:\Users\Pod\Dropbox
2014-04-18 19:36 - 2013-12-07 12:23 - 00000000 ____D C:\Users\Pod\AppData\Roaming\Dropbox
2014-04-18 19:36 - 2013-10-26 10:56 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-18 19:36 - 2013-10-10 13:23 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2014-04-18 19:36 - 2013-10-09 09:33 - 00039134 _____ C:\Windows\setupact.log
2014-04-18 19:36 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-04-18 19:35 - 2013-11-11 18:44 - 00000000 ____D C:\AdwCleaner
2014-04-18 19:35 - 2013-10-09 09:35 - 01864143 _____ C:\Windows\WindowsUpdate.log
2014-04-18 19:22 - 2014-04-18 19:22 - 00001108 _____ C:\Users\Pod\Desktop\JRT.txt
2014-04-18 19:18 - 2013-10-26 10:56 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-18 19:15 - 2009-07-14 06:45 - 00022240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-18 19:15 - 2009-07-14 06:45 - 00022240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-18 19:12 - 2011-04-12 09:43 - 00699416 _____ C:\Windows\system32\perfh007.dat
2014-04-18 19:12 - 2011-04-12 09:43 - 00149556 _____ C:\Windows\system32\perfc007.dat
2014-04-18 19:12 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI
2014-04-18 19:06 - 2013-10-06 17:15 - 00001113 _____ C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-18 19:06 - 2013-10-05 21:20 - 00001083 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-18 19:06 - 2013-10-05 20:24 - 00001025 _____ C:\Users\Pod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-18 19:00 - 2014-04-18 19:00 - 00004997 _____ C:\mbam.txt
2014-04-18 18:55 - 2010-11-21 05:47 - 00444622 _____ C:\Windows\PFRO.log
2014-04-18 11:41 - 2013-10-08 14:21 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-17 18:38 - 2013-10-05 20:31 - 00117408 _____ C:\Users\Pod\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-17 18:36 - 2013-10-06 20:54 - 00000000 ____D C:\Program Files (x86)\StarMoney Business 6.0
2014-04-17 18:30 - 2009-07-14 06:45 - 00419856 _____ C:\Windows\system32\FNTCACHE.DAT
2014-04-17 15:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\tracing
2014-04-17 15:27 - 2014-04-17 15:27 - 00000000 ____D C:\Users\Pod\AppData\Local\PAShell
2014-04-17 15:24 - 2014-04-17 15:24 - 00000000 ____D C:\Users\Pod\AppData\Local\Nova Development
2014-04-17 15:23 - 2014-04-17 15:23 - 00002937 _____ C:\Users\Public\Desktop\Print Artist Gold 25.lnk
2014-04-17 15:22 - 2014-04-17 15:22 - 00000000 ____D C:\Program Files (x86)\Nova Development
2014-04-17 13:03 - 2013-10-22 12:15 - 00000000 ____D C:\Users\Pod\Desktop\Tour neu
2014-04-17 12:14 - 2014-03-01 22:04 - 00007168 ___SH C:\Users\Pod\Desktop\Thumbs.db
2014-04-16 20:29 - 2014-04-16 20:29 - 00001298 _____ C:\Users\Pod\Desktop\Revo Uninstaller.lnk
2014-04-16 20:29 - 2014-04-16 20:29 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2014-04-16 17:26 - 2013-10-05 21:44 - 00000000 ____D C:\Users\Pod\Documents\PhraseExpress
2014-04-16 07:23 - 2014-04-16 07:23 - 00015102 _____ C:\Users\Pod\Downloads\Defogger (1).exe
2014-04-15 20:01 - 2014-04-15 20:00 - 00000000 ____D C:\FRST
2014-04-15 18:52 - 2014-04-15 18:52 - 00000000 _____ C:\Users\Pod\defogger_reenable
2014-04-15 18:52 - 2013-10-05 20:24 - 00000000 ____D C:\Users\Pod
2014-04-15 18:51 - 2014-04-15 18:51 - 00000000 ____D C:\Users\Pod\AppData\Roaming\IDM2
2014-04-15 18:48 - 2014-04-15 18:48 - 00000000 ____D C:\MININT
2014-04-15 18:48 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Resources
2014-04-15 17:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\LiveKernelReports
2014-04-15 16:44 - 2014-04-15 16:12 - 00000000 ____D C:\Program Files\002
2014-04-15 16:44 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\DigitalLocker
2014-04-15 16:26 - 2014-04-15 16:10 - 00000000 ____D C:\Users\Pod\AppData\Local\41
2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 ____D C:\Users\Pod\AppData\Local\cache
2014-04-15 16:18 - 2014-04-15 16:18 - 00000000 _____ C:\Users\Pod\daemonprocess.txt
2014-04-12 15:14 - 2014-04-12 15:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-12 15:14 - 2013-11-12 19:52 - 00001136 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D C:\Users\Pod\AppData\Roaming\Malwarebytes
2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-04-12 15:14 - 2013-11-12 19:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-04-11 17:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2014-04-11 03:04 - 2013-10-08 13:50 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-04-11 03:03 - 2013-10-28 18:00 - 00000000 ____D C:\Windows\system32\MRT
2014-04-11 03:02 - 2013-10-28 18:00 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-07 08:40 - 2013-10-22 13:30 - 00000964 _____ C:\Windows\Tasks\Paragon Archive name arc_221013112910391.job
2014-04-07 08:40 - 2013-10-17 13:04 - 00000964 _____ C:\Windows\Tasks\Paragon Archive name arc_171013110200181.job
2014-04-03 14:13 - 2013-10-26 10:56 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-03 14:13 - 2013-10-26 10:56 - 00003848 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-03 09:51 - 2014-04-12 15:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-12 15:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2013-11-12 19:52 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-31 03:16 - 2014-04-10 19:06 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-10 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-10 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-10 19:06 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-30 16:12 - 2013-10-05 21:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-29 14:15 - 2014-03-29 14:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-03-27 11:02 - 2013-10-07 13:30 - 00002828 ___SH C:\Windows\SysWOW64\KGyGaAvL.sys
2014-03-27 11:02 - 2013-10-07 13:30 - 00000000 ____D C:\Users\Pod\AppData\Local\Corel
2014-03-21 15:18 - 2014-03-21 11:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
Some content of TEMP:
====================
C:\Users\Pod\AppData\Local\Temp\avgnt.exe
C:\Users\Pod\AppData\Local\Temp\instract.exe
C:\Users\Pod\AppData\Local\Temp\nsc883D.exe
C:\Users\Pod\AppData\Local\Temp\nsx7D73.exe
C:\Users\Pod\AppData\Local\Temp\nsxFF43.exe
C:\Users\Pod\AppData\Local\Temp\Quarantine.exe
C:\Users\Pod\AppData\Local\Temp\repair4.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-09 15:13
==================== End Of Log ============================ --- --- ---
So, alles erledigt, dabei ist mir aufgefallen, dass Du mir im November schon mal geholfen hast. Hat gut gewirkt, bis ich wieder beim Herunterladen Mist gemacht habe.
Bin mal gespannt, ob es jetzt OK ist.
Ist AVG Antivirus gut? Habe ich im Moment.
Viele Grüsse,
Driver23 |