Perserkatze | 23.07.2014 21:14 | Hallo, Danke für die Antwort und den Hinweis!
zuerst die MBAM Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 23.07.2014
Suchlauf-Zeit: 20:54:00
Logdatei: Suchlaufprotokoll.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.23.07
Rootkit Datenbank: v2014.07.17.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: ASUS
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 294984
Verstrichene Zeit: 20 Min, 21 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 9
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [c23130724b30d46295967be008fa2cd4],
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\LevelQualityWatcher, In Quarantäne, [9261633fdaa1ac8ae352319b6b978a76],
PUP.Optional.SavingsBull.A, HKLM\SOFTWARE\Savings Bull, In Quarantäne, [1ed51f83502b2511418bb3386d9518e8],
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{813BA625-B0FA-48D8-9B75-59759C88C219}, In Quarantäne, [787ba8fa57245adc546cd70222e04cb4],
PUP.Optional.SavingsBull.A, HKLM\SOFTWARE\WOW6432NODE\SavingsbullFilter, In Quarantäne, [22d1317183f874c2c30bf6f5d9297d83],
PUP.Optional.SavingsBull.A, HKU\S-1-5-21-1697896229-4048069815-419722118-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SavingsBull, In Quarantäne, [11e2c1e17b0065d1f8a98d916b998a76],
PUP.Optional.SavingsBull.A, HKU\S-1-5-21-1697896229-4048069815-419722118-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Savings Bull, In Quarantäne, [945f237f83f8fc3afecd4c9f58aaf10f],
PUP.Optional.SavingsBull.A, HKU\S-1-5-21-1697896229-4048069815-419722118-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\SavingsBull, In Quarantäne, [d221b7ebc1ba52e468380e108381748c],
PUP.Optional.PassShow.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\711b30bb-9a27-492e-96b8-946705ab6197, In Quarantäne, [9b58c2e0e6952412706609aa0df534cc],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 33
PUP.Optional.SavingsBull.A, C:\PROGRAM FILES\SAVINGSBULLFILTER, In Quarantäne, [9261584a96e532049733cc1f9f637090],
PUP.Optional.SavingsBull.A, C:\PROGRAM FILES (X86)\SAVINGSBULL, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\defaults, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\defaults\preferences, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\locale, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\resources, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\addon-kit, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\ADDON-KIT\data, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\ADDON-KIT\lib, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\api-utils, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\data, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\addon, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\content, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\dom, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\event, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\events, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\l10n, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\private-browsing, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\system, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\tabs, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\traits, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\utils, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\window, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\API-UTILS\lib\windows, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\SavingsBull, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\SAVINGSBULL\data, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\SAVINGSBULL\lib, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\Z40BNESM.DEFAULT\EXTENSIONS\SAVINGSBULL@JETPACK\RESOURCES\SAVINGSBULL\tests, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.PassShow.A, C:\PROGRAM FILES (X86)\PassShow, In Quarantäne, [9b58c2e0e6952412706609aa0df534cc],
PUP.Optional.Adpeak, C:\PROGRAM FILES\LEVEL QUALITY WATCHER, In Quarantäne, [f4ff287a27540a2c36ed8c3224dea45c],
PUP.Optional.Adpeak, C:\PROGRAM FILES\LEVEL QUALITY WATCHER\v1.01, In Quarantäne, [f4ff287a27540a2c36ed8c3224dea45c],
Dateien: 116
PUP.Optional.SavingsBull.A, C:\Program Files\SavingsbullFilter\sample.dll, In Quarantäne, [9261584a96e532049733cc1f9f637090],
PUP.Optional.SavingsBull.A, C:\Program Files\SavingsbullFilter\Installbat64.dll, In Quarantäne, [9261584a96e532049733cc1f9f637090],
PUP.Optional.SavingsBull.A, C:\Program Files\SavingsbullFilter\Microsoft.Deployment.WindowsInstaller.dll, In Quarantäne, [9261584a96e532049733cc1f9f637090],
PUP.Optional.SavingsBull.A, C:\Program Files\SavingsbullFilter\Microsoft.Deployment.WindowsInstaller.xml, In Quarantäne, [9261584a96e532049733cc1f9f637090],
PUP.Optional.SavingsBull.A, C:\Program Files\SavingsbullFilter\nfapi.dll, In Quarantäne, [9261584a96e532049733cc1f9f637090],
PUP.Optional.SavingsBull.A, C:\Program Files\SavingsbullFilter\nfregdrv.exe, In Quarantäne, [9261584a96e532049733cc1f9f637090],
PUP.Optional.SavingsBull.A, C:\Program Files\SavingsbullFilter\ProtocolFilters.dll, In Quarantäne, [9261584a96e532049733cc1f9f637090],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\background.js, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\bootstrap.js, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\bootstrap.js.old, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\CustomActionInstall, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\CustomActionUninstall, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\ff_main.js.old, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\icon128.png, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\icon16.png, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\icon32.png, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\icon48.png, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\icon64.png, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\icon8.png, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\manifest.json, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\marcopolo.js, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\Microsoft.Deployment.WindowsInstaller.dll, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\Microsoft.Deployment.WindowsInstaller.xml, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Program Files (x86)\SavingsBull\SendJson.dll, In Quarantäne, [1dd6346ed5a69a9c58178f1b56ace11f],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\bootstrap.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\harness-options.json, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\icon.png, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\install.rdf, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\locales.json, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\defaults\preferences\prefs.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\addon-kit\lib\page-mod.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\addon-kit\lib\private-browsing.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\addon-kit\lib\request.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\addon-kit\lib\windows.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\heritage.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\api-utils.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\base64.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\byte-streams.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\collection.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\content.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\cortex.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\cuddlefish.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\deprecate.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\environment.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\errors.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\events.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\file.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\functional.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\globals.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\hidden-frame.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\light-traits.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\list.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\loader.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\match-pattern.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\memory.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\namespace.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\observer-service.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\plain-text-console.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\preferences-service.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\promise.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\querystring.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\runtime.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\sandbox.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\self.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\system.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\text-streams.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\timer.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\traceback.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\traits.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\unload.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\url.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\uuid.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\window-utils.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\xhr.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\xpcom.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\xul-app.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\addon\runner.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\content\content-proxy.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\content\content-worker.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\content\loader.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\content\symbiont.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\content\worker.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\dom\events.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\event\core.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\event\target.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\events\assembler.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\l10n\core.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\l10n\html.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\l10n\loader.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\l10n\locale.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\l10n\prefs.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\private-browsing\utils.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\system\events.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\tabs\events.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\tabs\observer.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\tabs\tab.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\tabs\utils.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\traits\core.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\utils\data.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\utils\object.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\utils\registry.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\utils\thumbnail.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\window\utils.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\windows\dom.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\windows\loader.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\windows\observer.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\api-utils\lib\windows\tabs.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\SavingsBull\data\icon64.png, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.SavingsBull.A, C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\extensions\SavingsBull@jetpack\resources\SavingsBull\lib\main.js, In Quarantäne, [ee053c6619622d09dd67affd8a78d828],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow\154.crx, In Quarantäne, [9b58c2e0e6952412706609aa0df534cc],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow\154.dat, In Quarantäne, [9b58c2e0e6952412706609aa0df534cc],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow\154.xpi, In Quarantäne, [9b58c2e0e6952412706609aa0df534cc],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow\a.db, In Quarantäne, [9b58c2e0e6952412706609aa0df534cc],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow\b.db, In Quarantäne, [9b58c2e0e6952412706609aa0df534cc],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow\Sqlite3.dll, In Quarantäne, [9b58c2e0e6952412706609aa0df534cc],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow\Uninstall.exe, In Quarantäne, [9b58c2e0e6952412706609aa0df534cc],
Physische Sektoren: 0
(No malicious items detected)
(end) ADW Cleaner Code:
# AdwCleaner v3.216 - Bericht erstellt am 23/07/2014 um 21:33:06
# Aktualisiert 17/07/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : ASUS - ASUS-PC
# Gestartet von : C:\Users\ASUS\Desktop\adwcleaner_3.216.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\windows\Installer\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
Ordner Gelöscht : C:\windows\Installer\{813BA625-B0FA-48D8-9B75-59759C88C219}
Datei Gelöscht : C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\1708EDD6AB4EB164A86999D0AF0ABE1D
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\1708EDD6AB4EB164A86999D0AF0ABE1D
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17207
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\prefs.js ]
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [1801 octets] - [23/07/2014 21:25:01]
AdwCleaner[S0].txt - [1722 octets] - [23/07/2014 21:33:06]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1782 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by ASUS on 23.07.2014 at 21:40:18,26
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\windows\Tasks\wise care 365.job"
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\ASUS\AppData\Roaming\mozilla\firefox\profiles\z40bnesm.default\minidumps [97 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.07.2014 at 22:04:09,07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ eine neue FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-07-2014 01
Ran by ASUS (administrator) on ASUS-PC on 23-07-2014 22:07:06
Running from C:\Users\ASUS\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(WiseCleaner.com) C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUS) C:\Windows\AsScrPro.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-10-14] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322176 2012-02-16] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-24] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-02] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-07-18] (AVAST Software)
HKU\S-1-5-21-1697896229-4048069815-419722118-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21446272 2014-05-08] (Skype Technologies S.A.)
HKU\S-1-5-21-1697896229-4048069815-419722118-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: No Name -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
BHO-x32: No Name -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> No File
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\z40bnesm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-02-24]
FF HKCU\...\Firefox\Extensions: [{8492baab-62ca-4e2c-983b-dfef7cae8082}] - C:\Program Files (x86)\PassShow\154.xpi
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2011-07-14] (Advanced Micro Devices, Inc.) [File not signed]
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-03-13] (Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-13] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-18] (AVAST Software)
S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]
S2 McOobeSv; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [X]
==================== Drivers (Whitelisted) ====================
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2011-09-06] (Google Inc)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2011-09-06] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [35840 2011-09-06] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93184 2011-09-16] (LG Electronics Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-18] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-18] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-18] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-18] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-18] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-18] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-18] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-18] ()
R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
S3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-23] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S0 mfewfpk; system32\drivers\mfewfpk.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-23 22:06 - 2014-07-23 22:06 - 00000000 ____D () C:\Users\ASUS\Desktop\FRST-OlderVersion
2014-07-23 22:04 - 2014-07-23 22:04 - 00000824 _____ () C:\Users\ASUS\Desktop\JRT.txt
2014-07-23 21:40 - 2014-07-23 21:40 - 00000000 ____D () C:\windows\ERUNT
2014-07-23 21:39 - 2014-07-23 21:39 - 01016261 _____ (Thisisu) C:\Users\ASUS\Desktop\JRT.exe
2014-07-23 21:37 - 2014-07-23 21:37 - 00001862 _____ () C:\Users\ASUS\Desktop\AdwCleaner[S0].txt
2014-07-23 21:26 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-07-23 21:24 - 2014-07-23 21:33 - 00000000 ____D () C:\AdwCleaner
2014-07-23 21:23 - 2014-07-23 21:23 - 01354223 _____ () C:\Users\ASUS\Desktop\adwcleaner_3.216.exe
2014-07-23 21:21 - 2014-07-23 21:21 - 00031957 _____ () C:\Users\ASUS\Desktop\mbam.txt
2014-07-23 20:52 - 2014-07-23 21:19 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-23 20:51 - 2014-07-23 20:51 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-23 20:51 - 2014-07-23 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-23 20:51 - 2014-07-23 20:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-23 20:51 - 2014-07-23 20:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-23 20:51 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-07-23 20:51 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-07-23 20:51 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-07-18 12:48 - 2014-07-18 12:48 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-07-16 20:06 - 2014-07-16 20:06 - 00017525 _____ () C:\ComboFix.txt
2014-07-16 19:39 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2014-07-16 19:39 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2014-07-16 19:39 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-07-16 19:39 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-07-16 19:39 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-07-16 19:39 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2014-07-16 19:39 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2014-07-16 19:39 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2014-07-16 19:38 - 2014-07-16 20:06 - 00000000 ____D () C:\Qoobox
2014-07-16 19:38 - 2014-07-16 20:02 - 00000000 ____D () C:\windows\erdnt
2014-07-16 19:35 - 2014-07-16 19:36 - 05221447 ____R (Swearware) C:\Users\ASUS\Desktop\ComboFix.exe
2014-07-16 19:32 - 2014-07-16 19:32 - 00001294 _____ () C:\Users\ASUS\Desktop\Revo Uninstaller.lnk
2014-07-16 19:32 - 2014-07-16 19:32 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-14 21:38 - 2014-07-23 22:07 - 00013056 _____ () C:\Users\ASUS\Desktop\FRST.txt
2014-07-14 21:38 - 2014-07-23 22:07 - 00000000 ____D () C:\FRST
2014-07-14 21:37 - 2014-07-23 22:06 - 02091520 _____ (Farbar) C:\Users\ASUS\Desktop\FRST64.exe
2014-07-13 13:13 - 2014-07-13 13:13 - 00002216 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Digital Editions 3.0.lnk
2014-07-13 13:13 - 2014-07-13 13:13 - 00000000 ____D () C:\Users\ASUS\Documents\My Digital Editions
2014-07-13 13:13 - 2014-07-13 13:13 - 00000000 ____D () C:\Users\ASUS\AppData\Local\Adobe_Systems_Incorporate
2014-07-13 13:13 - 2014-07-13 13:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2014-07-11 19:57 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-07-11 19:57 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-07-11 19:57 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-07-11 19:57 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2014-07-11 19:57 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-07-11 19:57 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-07-11 19:57 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-07-11 19:57 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2014-07-11 19:57 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-07-11 19:57 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-07-11 19:57 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2014-07-11 19:57 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-07-11 19:57 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-07-11 19:57 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-07-11 19:53 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-07-11 19:53 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-07-11 19:53 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2014-07-11 19:53 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe
2014-07-11 19:53 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-07-11 19:53 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-07-11 19:53 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2014-07-11 19:53 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2014-07-11 19:51 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-07-11 19:51 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-07-11 19:51 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-07-11 19:51 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-07-11 19:51 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-07-11 19:51 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-07-11 19:51 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-07-11 19:51 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-07-11 19:51 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-07-11 19:51 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-07-11 19:51 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-07-11 19:51 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-07-11 19:51 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-07-11 19:51 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-11 19:51 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-07-11 19:51 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-07-11 19:51 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-07-11 19:51 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-07-11 19:51 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-07-11 19:50 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-07-11 19:50 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-07-11 19:50 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-07-11 19:50 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-07-11 19:50 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-07-11 19:50 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-07-11 19:50 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-07-11 19:50 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-07-11 19:50 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-07-11 19:50 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-07-11 19:50 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-07-11 19:50 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-07-11 19:50 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-07-11 19:50 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-07-11 19:50 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-07-11 19:50 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-07-11 19:50 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-07-11 19:50 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-07-11 19:50 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-07-11 19:50 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-07-11 19:50 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-07-11 19:50 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-07-11 19:50 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-07-11 19:50 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-07-11 19:50 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-07-11 19:50 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-07-11 19:50 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-07-11 19:50 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-07-11 19:50 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-07-11 19:50 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-07-11 19:50 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-07-11 19:50 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-07-11 19:50 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-07-11 19:50 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-07-11 19:50 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-07-11 19:50 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-07-11 19:50 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-07-11 19:49 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2014-07-11 19:48 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2014-07-11 19:48 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2014-07-08 18:49 - 2014-07-08 18:49 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\No Company Name
2014-07-08 18:38 - 2014-07-08 18:38 - 01057176 _____ (Adobe) C:\Users\ASUS\Desktop\install_flashplayer14x32_mssd_aaa_aih.exe
2014-06-30 19:35 - 2014-07-11 20:14 - 00000000 ____D () C:\Users\ASUS\Desktop\wohnung
==================== One Month Modified Files and Folders =======
2014-07-23 22:08 - 2014-07-14 21:38 - 00013056 _____ () C:\Users\ASUS\Desktop\FRST.txt
2014-07-23 22:07 - 2014-07-14 21:38 - 00000000 ____D () C:\FRST
2014-07-23 22:06 - 2014-07-23 22:06 - 00000000 ____D () C:\Users\ASUS\Desktop\FRST-OlderVersion
2014-07-23 22:06 - 2014-07-14 21:37 - 02091520 _____ (Farbar) C:\Users\ASUS\Desktop\FRST64.exe
2014-07-23 22:04 - 2014-07-23 22:04 - 00000824 _____ () C:\Users\ASUS\Desktop\JRT.txt
2014-07-23 21:41 - 2009-07-14 06:45 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-23 21:41 - 2009-07-14 06:45 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-23 21:40 - 2014-07-23 21:40 - 00000000 ____D () C:\windows\ERUNT
2014-07-23 21:39 - 2014-07-23 21:39 - 01016261 _____ (Thisisu) C:\Users\ASUS\Desktop\JRT.exe
2014-07-23 21:38 - 2013-06-02 14:20 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\Skype
2014-07-23 21:37 - 2014-07-23 21:37 - 00001862 _____ () C:\Users\ASUS\Desktop\AdwCleaner[S0].txt
2014-07-23 21:34 - 2014-02-24 09:41 - 00210262 _____ () C:\windows\PFRO.log
2014-07-23 21:34 - 2014-02-24 09:41 - 00020846 _____ () C:\windows\setupact.log
2014-07-23 21:34 - 2013-02-14 21:48 - 00000380 _____ () C:\Users\ASUS\AppData\Roaming\sp_data.sys
2014-07-23 21:34 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-07-23 21:33 - 2014-07-23 21:24 - 00000000 ____D () C:\AdwCleaner
2014-07-23 21:33 - 2014-02-24 09:45 - 01719725 _____ () C:\windows\WindowsUpdate.log
2014-07-23 21:23 - 2014-07-23 21:23 - 01354223 _____ () C:\Users\ASUS\Desktop\adwcleaner_3.216.exe
2014-07-23 21:21 - 2014-07-23 21:21 - 00031957 _____ () C:\Users\ASUS\Desktop\mbam.txt
2014-07-23 21:19 - 2014-07-23 20:52 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-23 21:16 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\LiveKernelReports
2014-07-23 20:51 - 2014-07-23 20:51 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-23 20:51 - 2014-07-23 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-23 20:51 - 2014-07-23 20:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-23 20:51 - 2014-07-23 20:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-23 20:47 - 2012-02-24 04:28 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-23 20:39 - 2011-02-19 06:24 - 00699666 _____ () C:\windows\system32\perfh007.dat
2014-07-23 20:39 - 2011-02-19 06:24 - 00149774 _____ () C:\windows\system32\perfc007.dat
2014-07-23 20:39 - 2009-07-14 07:13 - 01620612 _____ () C:\windows\system32\PerfStringBackup.INI
2014-07-23 20:36 - 2013-12-23 14:59 - 00000400 _____ () C:\windows\Tasks\Wise Turbo Checker.job
2014-07-23 20:36 - 2012-02-24 04:29 - 00000912 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-18 12:48 - 2014-07-18 12:48 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-07-18 12:48 - 2014-05-08 14:43 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys
2014-07-18 12:48 - 2014-02-24 22:55 - 01041168 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys
2014-07-18 12:48 - 2014-02-24 22:55 - 00427360 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys
2014-07-18 12:48 - 2014-02-24 22:55 - 00224896 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-07-18 12:48 - 2014-02-24 22:55 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-07-18 12:48 - 2014-02-24 22:55 - 00092008 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys
2014-07-18 12:48 - 2014-02-24 22:55 - 00079184 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-07-18 12:48 - 2014-02-24 22:55 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-07-18 12:48 - 2014-02-24 22:55 - 00003924 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2014-07-18 12:48 - 2014-02-24 22:55 - 00001978 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-07-18 12:48 - 2014-02-24 22:54 - 00307344 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-07-16 20:06 - 2014-07-16 20:06 - 00017525 _____ () C:\ComboFix.txt
2014-07-16 20:06 - 2014-07-16 19:38 - 00000000 ____D () C:\Qoobox
2014-07-16 20:02 - 2014-07-16 19:38 - 00000000 ____D () C:\windows\erdnt
2014-07-16 19:59 - 2009-07-14 04:34 - 00000215 _____ () C:\windows\system.ini
2014-07-16 19:57 - 2009-07-14 04:34 - 89653248 _____ () C:\windows\system32\config\software.bak
2014-07-16 19:57 - 2009-07-14 04:34 - 20709376 _____ () C:\windows\system32\config\system.bak
2014-07-16 19:57 - 2009-07-14 04:34 - 00524288 _____ () C:\windows\system32\config\default.bak
2014-07-16 19:57 - 2009-07-14 04:34 - 00262144 _____ () C:\windows\system32\config\security.bak
2014-07-16 19:57 - 2009-07-14 04:34 - 00262144 _____ () C:\windows\system32\config\sam.bak
2014-07-16 19:36 - 2014-07-16 19:35 - 05221447 ____R (Swearware) C:\Users\ASUS\Desktop\ComboFix.exe
2014-07-16 19:32 - 2014-07-16 19:32 - 00001294 _____ () C:\Users\ASUS\Desktop\Revo Uninstaller.lnk
2014-07-16 19:32 - 2014-07-16 19:32 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-16 19:28 - 2013-12-23 14:48 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\Wise Care 365
2014-07-14 21:37 - 2012-02-24 04:28 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-07-13 13:13 - 2014-07-13 13:13 - 00002216 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Digital Editions 3.0.lnk
2014-07-13 13:13 - 2014-07-13 13:13 - 00000000 ____D () C:\Users\ASUS\Documents\My Digital Editions
2014-07-13 13:13 - 2014-07-13 13:13 - 00000000 ____D () C:\Users\ASUS\AppData\Local\Adobe_Systems_Incorporate
2014-07-13 13:13 - 2014-07-13 13:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2014-07-13 00:45 - 2009-07-14 06:45 - 01658584 _____ () C:\windows\system32\FNTCACHE.DAT
2014-07-13 00:42 - 2014-05-01 11:43 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-07-13 00:42 - 2009-07-14 09:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-13 00:42 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2014-07-13 00:42 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\Dism
2014-07-11 20:48 - 2013-08-15 06:46 - 00000000 ____D () C:\windows\system32\MRT
2014-07-11 20:43 - 2013-01-31 16:45 - 96441528 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-07-11 20:14 - 2014-06-30 19:35 - 00000000 ____D () C:\Users\ASUS\Desktop\wohnung
2014-07-10 07:00 - 2014-02-22 18:33 - 00065104 _____ () C:\Users\ASUS\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-08 18:52 - 2012-02-24 04:28 - 00000000 ____D () C:\ProgramData\Adobe
2014-07-08 18:49 - 2014-07-08 18:49 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\No Company Name
2014-07-08 18:38 - 2014-07-08 18:38 - 01057176 _____ (Adobe) C:\Users\ASUS\Desktop\install_flashplayer14x32_mssd_aaa_aih.exe
2014-07-06 09:34 - 2013-02-05 22:19 - 00000000 ____D () C:\Users\ASUS\AppData\Local\Adobe
2014-07-05 10:48 - 2009-07-14 07:08 - 00032640 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-07-04 19:26 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\NDF
2014-07-01 17:53 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache
2014-06-30 04:09 - 2014-07-11 19:53 - 00519168 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-11 19:53 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
Some content of TEMP:
====================
C:\Users\ASUS\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-18 13:04
==================== End Of Log ============================ --- --- ---
Vielen Dank für die Hilfe :)
Lieben Gruß
Julia |