Hi,
mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.01.2015
Suchlauf-Zeit: 17:39:15
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.29.08
Rootkit Datenbank: v2015.01.14.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Katja Kohlhase
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 394594
Verstrichene Zeit: 15 Min, 42 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe, 3228, Löschen bei Neustart, [5fcd57a6b0d92214e8a66719d033a65a]
PUP.Optional.AdPeak.A, C:\Program Files\004\rqpbhevlkc64.exe, 2892, Löschen bei Neustart, [f834e11c5d2c54e2018d19eb3fc62bd5]
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 17
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}, In Quarantäne, [f23a78855c2d999d587470c44ab952ae],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, In Quarantäne, [f23a78855c2d999d587470c44ab952ae],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [f23a78855c2d999d587470c44ab952ae],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [f23a78855c2d999d587470c44ab952ae],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, In Quarantäne, [f23a78855c2d999d587470c44ab952ae],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-3527590482-2007125430-3922928400-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [da52a8557811b6803d8c1420e12238c8],
PUP.Optional.CompatibilityVerifier.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Verifies and fixes application compatibility issues, In Quarantäne, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.AdPeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rqpbhevlkc64, In Quarantäne, [f834e11c5d2c54e2018d19eb3fc62bd5],
Adware.EoRezo, HKLM\SOFTWARE\WOW6432NODE\FREESOFTTODAY, In Quarantäne, [b8742cd13257fa3c470e865bbb493ac6],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [0c20d825038639fdd076c5363dc701ff],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [c468c23b7d0cd56169a778417c875ba5],
PUP.Optional.FocusBase.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update focusbase, In Quarantäne, [200c36c7107964d22d2d20dac73dbc44],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [da52e914afda4beb05669bf0679c9868],
PUP.Optional.ClicUp.A, HKU\S-1-5-21-3527590482-2007125430-3922928400-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\clicup, In Quarantäne, [3eee25d8abde3006857090edd82bde22],
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-3527590482-2007125430-3922928400-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TutoTag, In Quarantäne, [0e1e12ebdfaa79bd4b28ba44b153ad53],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3527590482-2007125430-3922928400-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [2dff1fde4742e5514214517416eddd23],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3527590482-2007125430-3922928400-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [200c54a98aff4ee89dcd974433d16a96],
Registrierungswerte: 4
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [d6563cc185040135cd149df79c675ea2]
PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [54d8738a3d4c999d845d23713ac97b85]
PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|fst_de_153, In Quarantäne, [e9436b927c0de6503d1caf03d2318c74],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3527590482-2007125430-3922928400-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 1T1M1E2X1H1LtO1S1H1E1J1K1H1O1T, In Quarantäne, [200c54a98aff4ee89dcd974433d16a96]
Registrierungsdaten: 5
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1408787259&from=obw&uid=HGSTXHTS725050A7E630_TF0500WJ0UUNBL0UUNBLX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1408787259&from=obw&uid=HGSTXHTS725050A7E630_TF0500WJ0UUNBL0UUNBLX&q={searchTerms}),Ersetzt,[e7456895761368ce8ef1425e32d36a96]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1408787259&from=obw&uid=HGSTXHTS725050A7E630_TF0500WJ0UUNBL0UUNBLX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1408787259&from=obw&uid=HGSTXHTS725050A7E630_TF0500WJ0UUNBL0UUNBLX&q={searchTerms}),Ersetzt,[45e756a73950ae88c830aeef9273d729]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-3527590482-2007125430-3922928400-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbPGr6Jy1Ks2e111hOmaVHQAxQHSlVfcqvikmWF5fOt6xqIb9QnJ4iSSMbega4nk3wkQFcSUjZMhp0vDdDCgNft--63A66RXlNzIG8rffcmi4o5fW329VNluRUclOXVWtJGDvRLRPQEV262b1PgXi-DSLnm1XT3HdBrqPBvb-IgajW3T6gvQpg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbPGr6Jy1Ks2e111hOmaVHQAxQHSlVfcqvikmWF5fOt6xqIb9QnJ4iSSMbega4nk3wkQFcSUjZMhp0vDdDCgNft--63A66RXlNzIG8rffcmi4o5fW329VNluRUclOXVWtJGDvRLRPQEV262b1PgXi-DSLnm1XT3HdBrqPBvb-IgajW3T6gvQpg,,&q={searchTerms}),Ersetzt,[86a6609dd4b5310536551d830ff64eb2]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-3527590482-2007125430-3922928400-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbPGr6Jy1Ks2e111hOmaVHQAxQHSlVfcqvikmWF5fOt6xqIb9QnJ4iSSMbega4nk3wkQFcSUjZMhp0vDdDCgNft--63A66RXlNzIG8rffcmi4o5fW329VNluRUclOXVWtJGDvRLRPQEV262b1PgXi-DSLnm1XT3HdBrqPBvb-IgajW3T6gvQpg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbPGr6Jy1Ks2e111hOmaVHQAxQHSlVfcqvikmWF5fOt6xqIb9QnJ4iSSMbega4nk3wkQFcSUjZMhp0vDdDCgNft--63A66RXlNzIG8rffcmi4o5fW329VNluRUclOXVWtJGDvRLRPQEV262b1PgXi-DSLnm1XT3HdBrqPBvb-IgajW3T6gvQpg,,&q={searchTerms}),Ersetzt,[93992dd089006bcbbfcda7f9ed18ab55]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-3527590482-2007125430-3922928400-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbPGr6Jy1Ks2e111hOmaVHQAxQHSlVfcqvikmWF5fOt6xqIb9QnJ4iSSMbega4nk3wkQFcSUjZMhp0vDdDCgNft--63A66RXlNzIG8rffcmi4o5fW329VNluRUclOXVWtJGDvRLRPQEV262b1PgXi-DSLnm1XT3HdBrqPBvb-IgajW3T6gvQpg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbPGr6Jy1Ks2e111hOmaVHQAxQHSlVfcqvikmWF5fOt6xqIb9QnJ4iSSMbega4nk3wkQFcSUjZMhp0vDdDCgNft--63A66RXlNzIG8rffcmi4o5fW329VNluRUclOXVWtJGDvRLRPQEV262b1PgXi-DSLnm1XT3HdBrqPBvb-IgajW3T6gvQpg,,&q={searchTerms}),Ersetzt,[9f8dad50becb4ceab9ce6d330cf98e72]
Ordner: 15
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\locales, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier, Löschen bei Neustart, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\locales, In Quarantäne, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.AdPeak.A, C:\Program Files\004, Löschen bei Neustart, [f834e11c5d2c54e2018d19eb3fc62bd5],
PUP.Optional.WeatherAlerts, C:\Users\Katja Kohlhase\AppData\Local\WeatherAlerts, In Quarantäne, [42ead825cbbe81b5c89972d5689b28d8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\code, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\log, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader, In Quarantäne, [b67624d91079e74f674d4e04010211ef],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\SSL, In Quarantäne, [b67624d91079e74f674d4e04010211ef],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, In Quarantäne, [5fcd14e9692069cd927f69f482815ea2],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [5fcd14e9692069cd927f69f482815ea2],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [5fcd14e9692069cd927f69f482815ea2],
Dateien: 58
PUP.Optional.OpenCandy, C:\Users\Katja Kohlhase\Downloads\DTLite4491-0356.exe, In Quarantäne, [5bd1e01dbfcaa393574f369acc39dc24],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\cef.pak, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\cef_100_percent.pak, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\cef_200_percent.pak, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\debug.log, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\icudtl.dat, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\libEGL.dll, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\vcredist_x86.exe, In Quarantäne, [f93386772b5ed561612dc7b9838019e7],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\cef.pak, Löschen bei Neustart, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\cef_100_percent.pak, Löschen bei Neustart, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\cef_200_percent.pak, In Quarantäne, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, Löschen bei Neustart, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe, Löschen bei Neustart, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, In Quarantäne, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\debug.log, Löschen bei Neustart, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, In Quarantäne, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\icudtl.dat, Löschen bei Neustart, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\libEGL.dll, In Quarantäne, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, In Quarantäne, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, In Quarantäne, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Katja Kohlhase\AppData\Roaming\Compatibility Verifier\vcredist_x86.exe, In Quarantäne, [5fcd57a6b0d92214e8a66719d033a65a],
PUP.Optional.BrowserSafeGuard.A, C:\Windows\System32\Tasks\BrowserSafeguard Update Task, In Quarantäne, [2705a35acdbc191d9100604391724db3],
PUP.Optional.AdPeak.A, C:\Program Files\004\rqpbhevlkc64.exe, Löschen bei Neustart, [f834e11c5d2c54e2018d19eb3fc62bd5],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\201.json, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\MessageBox.xml, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\un.ini, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\uninstallDlg2.xml, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\UninstallManager.exe, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\bg.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\bg1.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\bk_shadow.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\button.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\button1.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\checkbox.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\checkbox_select.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\checked.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\close.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\loading_bg.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\loading_light.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\min.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\scrollbar.bmp, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\Thumbs.db, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\unchecked.png, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\code\code1.jpg, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\code\code2.jpg, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\code\code3.jpg, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\code\code4.jpg, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\code\code5.jpg, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\code\code6.jpg, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\images\code\Thumbs.db, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WebsSearches.A, C:\Users\Katja Kohlhase\AppData\Roaming\webssearches\log\UninstallManager_2014-08-24[14-13-52-817].log, In Quarantäne, [ba7241bc2b5e4fe7a92750fbe41f38c8],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-08-23[11-47-49-537].log, In Quarantäne, [5fcd14e9692069cd927f69f482815ea2],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) AdwCleaner[s0].txt Code:
# AdwCleaner v4.109 - Bericht erstellt am 29/01/2015 um 18:08:37
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-01-26.1 [Live]
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Katja Kohlhase - KATJAKOHLHASE
# Gestartet von : C:\Users\Katja Kohlhase\Desktop\AdwCleaner_4.109.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : AddonsHelper
Dienst Gelöscht : netfilter64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\DNSErrorHelper
Ordner Gelöscht : C:\Program Files (x86)\predm
Ordner Gelöscht : C:\Users\Katja Kohlhase\AppData\Roaming\ap_logs
Ordner Gelöscht : C:\Users\Katja Kohlhase\AppData\Roaming\OCS
Datei Gelöscht : C:\Windows\System32\drivers\netfilter64.sys
Datei Gelöscht : C:\Users\Katja Kohlhase\AppData\Roaming\aps.uninstall.scan.results
***** [ Tasks ] *****
Task Gelöscht : BrowserSafeguard Update Task
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [dnshelp@dnshelp.com]
Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9B6B03F1-16CF-4491-BBBB-E872802DD717}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9B6B03F1-16CF-4491-BBBB-E872802DD717}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{721061FB-EB79-4568-A03C-3CE26D68DAE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{721061fb-eb79-4568-a03c-3ce26d68dae9}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Tutorials
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v35.0.1 (x86 de)
[feVxXkkO.default\prefs.js] - Zeile gelöscht : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-but[...]
[feVxXkkO.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"14919a78a2d11b-017409a058c3ca8-40524136-0-14919a78a2e2dc\"");
[feVxXkkO.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.SAUTH_expires_at", "1423137086");
[feVxXkkO.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.SAUTH_rndsnr", "\"beba3f4810e8c515e240be08fe7ea0d42f8d9463\"");
[feVxXkkO.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.SAUTH_userid", "5628426140");
[feVxXkkO.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.SAUTH_utoken", "\"0dcf8d6a7e49b6bdba3d453aee0ab9ed595dddd4\"");
[feVxXkkO.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.install", "1413474650677");
[feVxXkkO.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.search_offer_disabled", "true");
[feVxXkkO.default\prefs.js] - Zeile gelöscht : user_pref("extensions.xpiState", "{\"app-profile\":{\"abs@avira.com\":{\"d\":\"C:\\\\Users\\\\Katja Kohlhase\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\feVxXkkO.default\\\\extensions\\[...]
*************************
AdwCleaner[R0].txt - [5878 octets] - [29/01/2015 18:06:05]
AdwCleaner[S0].txt - [5515 octets] - [29/01/2015 18:08:37]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5575 octets] ########## JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Professional x64
Ran by Katja Kohlhase on 29.01.2015 at 18:15:57,67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [File] C:\Users\Katja Kohlhase\AppData\Roaming\mozilla\firefox\profiles\feVxXkkO.default\searchplugins\avira-safesearch.xml
Successfully deleted: [Folder] C:\Users\Katja Kohlhase\AppData\Roaming\mozilla\firefox\profiles\feVxXkkO.default\extensions\safesearch@avira.com
Successfully deleted the following from C:\Users\Katja Kohlhase\AppData\Roaming\mozilla\firefox\profiles\feVxXkkO.default\prefs.js
user_pref("avira.safe_search.search_was_active", "false");
user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-
user_pref("extensions.bootstrappedAddons", "{\"abs@avira.com\":{\"version\":\"1.4.3\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Katja Kohlhase\\\\AppData\\\\Roami
user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"14919a78a2d11b-017409a058c3ca8-40524136-0-14919a78a2e2dc\"");
user_pref("extensions.safesearch.SAUTH_expires_at", "1423156420");
user_pref("extensions.safesearch.SAUTH_rndsnr", "\"1cb65c28bb185756962e63c951944d0a0eb2baf4\"");
user_pref("extensions.safesearch.SAUTH_userid", "5814902826");
user_pref("extensions.safesearch.SAUTH_utoken", "\"80f59873f17780fe704b61285863365a7853eb40\"");
user_pref("extensions.safesearch.install", "1422551616603");
user_pref("extensions.xpiState", "{\"app-profile\":{\"abs@avira.com\":{\"d\":\"C:\\\\Users\\\\Katja Kohlhase\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\feVxXkk
Emptied folder: C:\Users\Katja Kohlhase\AppData\Roaming\mozilla\firefox\profiles\feVxXkkO.default\minidumps [31 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.01.2015 at 18:19:39,94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST.txt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by Katja Kohlhase (administrator) on KATJAKOHLHASE on 29-01-2015 18:21:08
Running from C:\Users\Katja Kohlhase\Desktop
Loaded Profiles: Katja Kohlhase (Available profiles: Katja Kohlhase)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpCardEngine.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CryptoMill Technologies Ltd.) C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\CreoSvc.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Spotify Ltd) C:\Users\Katja Kohlhase\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(AkkuLine.de) C:\Program Files (x86)\AkkuLine.de\AkkuLine Batterie-Tool\AL-Batterie-Tool.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe
(Dropbox, Inc.) C:\Users\Katja Kohlhase\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Windows\SysWOW64\flcdlock.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPConnectionManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184112 2012-09-17] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [CryptoMill Refresh] => C:\Program Files\Hewlett-Packard\HP Trust Circles\ceflauncher -m refresh
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-09-27] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2816240 2014-10-13] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2014-10-13] (IDT, Inc.)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [683656 2013-07-18] (PDF Complete Inc)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296208 2014-12-22] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2014-11-09] (Intel Corporation)
HKLM-x32\...\Run: [HP File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2213592 2013-08-07] (Hewlett-Packard)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-09] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [336672 2014-05-16] (Hewlett-Packard Company)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM-x32\...\Run: [HPConnectionManager] => C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [185144 2014-04-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [126240 2014-04-01] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707472 2014-03-12] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-12-18] (Oracle Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-3527590482-2007125430-3922928400-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1942720 2015-01-23] (Valve Corporation)
HKU\S-1-5-21-3527590482-2007125430-3922928400-1001\...\Run: [Spotify] => C:\Users\Katja Kohlhase\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-09] (Spotify Ltd)
HKU\S-1-5-21-3527590482-2007125430-3922928400-1001\...\Run: [Spotify Web Helper] => C:\Users\Katja Kohlhase\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-09] (Spotify Ltd)
HKU\S-1-5-21-3527590482-2007125430-3922928400-1001\...\Run: [ALBATTTOOL] => C:\Program Files (x86)\AkkuLine.de\AkkuLine Batterie-Tool\AL-Batterie-Tool.exe [391680 2009-12-27] (AkkuLine.de)
HKU\S-1-5-21-3527590482-2007125430-3922928400-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk
ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
Startup: C:\Users\Katja Kohlhase\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Katja Kohlhase\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [+1TBIcon] -> {B9C55E85-DED6-4911-82F3-83CF1CAB2898} => C:\Program Files\Hewlett-Packard\HP Trust Circles\tbicon.dll (CryptoMill Technologies Ltd.)
ShellIconOverlayIdentifiers-x32: [+1TBIcon] -> {B9C55E85-DED6-4911-82F3-83CF1CAB2898} => C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\tbicon.dll (CryptoMill Technologies Ltd.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3527590482-2007125430-3922928400-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3527590482-2007125430-3922928400-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKU\S-1-5-21-3527590482-2007125430-3922928400-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: HP File Sanitizer -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Microsoft Web Test Recorder 12.0 Helper -> {432dd630-7e03-4c97-9d62-b99f52df4fc2} -> C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Katja Kohlhase\AppData\Roaming\Mozilla\Firefox\Profiles\feVxXkkO.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.75.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.75.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\components\npChromeDPAgent.dll (DigitalPersona, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF SearchPlugin: C:\Users\Katja Kohlhase\AppData\Roaming\Mozilla\Firefox\Profiles\feVxXkkO.default\searchplugins\c5634bfc-d2d8-4ec6-8082-c5938640c0a1.xml
FF Extension: Avira Browser Safety - C:\Users\Katja Kohlhase\AppData\Roaming\Mozilla\Firefox\Profiles\feVxXkkO.default\Extensions\abs@avira.com [2014-12-11]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Katja Kohlhase\AppData\Roaming\Mozilla\Firefox\Profiles\feVxXkkO.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-12-09]
FF Extension: Adblock Plus - C:\Users\Katja Kohlhase\AppData\Roaming\Mozilla\Firefox\Profiles\feVxXkkO.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-25]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2015-01-27]
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2014-06-07]
FF HKU\S-1-5-21-3527590482-2007125430-3922928400-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-12-09]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\dpchrome.crx [2013-08-05]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-09] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG)
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation)
R2 CreoService; C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\CreoSvc.exe [1366488 2013-08-23] (CryptoMill Technologies Ltd.)
R2 CtAgentService; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [7168 2014-03-31] () [File not signed]
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [500048 2013-08-05] (DigitalPersona, Inc.)
R2 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [558392 2013-08-06] (Hewlett-Packard Company)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2013-08-22] (Microsoft Corporation) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [683296 2014-05-16] (Hewlett-Packard Company)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-09-27] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [317032 2014-11-09] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-11-09] (Intel Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-09-06] ()
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2014-11-09] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-17] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1143432 2013-07-18] (PDF Complete Inc)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [340480 2014-10-13] (IDT, Inc.) [File not signed]
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-12-18] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-01-17] (Intel® Corporation)
S3 OracleMTSRecoveryService; C:\oraclexe\app\oracle\product\11.2.0\server\bin\omtsreco.exe OracleMTSRecoveryService [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-08-15] (Avira Operations GmbH & Co. KG)
S3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [132920 2013-04-23] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [1385272 2013-08-08] (Motorola Solutions, Inc.)
S3 btmlehid; C:\Windows\system32\drivers\btmlehid.sys [76088 2013-01-22] (Motorola Solutions, Inc.)
R2 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [65752 2013-06-13] (Hewlett-Packard Company)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-10-22] (Disc Soft Ltd)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [489752 2014-07-23] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28008 2013-09-27] (Intel Corporation)
S3 ibtusb; C:\Windows\System32\DRIVERS\ibtusb.sys [113096 2013-08-07] (Intel Corporation)
R3 IceKore; C:\Windows\System32\DRIVERS\IceKore.sys [397784 2013-08-19] (CryptoMill Technologies Inc.)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21408 2013-08-08] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21920 2013-08-08] ()
R3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-08-07] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-07-23] ()
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2014-11-09] (Intel Corporation)
R3 NETwNs64; C:\Windows\System32\DRIVERS\NETwsw02.sys [3434976 2014-04-16] (Intel Corporation)
R0 PinFile; C:\Windows\System32\DRIVERS\PinFile.sys [49856 2013-08-22] (WinMagic Inc.)
S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [476888 2014-10-13] (Realsil Semiconductor Corporation)
R0 SDDisk2K; C:\Windows\System32\DRIVERS\SDDisk2K.sys [228544 2013-08-22] (WinMagic Inc.)
R0 SDDToki; C:\Windows\System32\DRIVERS\SDDToki.sys [131264 2013-08-22] (WinMagic Inc.)
S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver_AMDASF.sys [30448 2013-08-19] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [34544 2014-10-13] (Synaptics Incorporated)
R3 usb3Hub; C:\Windows\System32\DRIVERS\usb3Hub.sys [206744 2013-06-21] (Windows (R) Win 7 DDK provider)
S3 usbohci; C:\Windows\system32\drivers\usbohci.sys [25600 2013-12-18] (Microsoft Corporation) [File not signed]
S3 usbuhci; C:\Windows\system32\drivers\usbuhci.sys [30720 2013-12-18] (Microsoft Corporation) [File not signed]
R3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [76480 2014-11-17] (VMware, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-29 18:19 - 2015-01-29 18:19 - 00002299 _____ () C:\Users\Katja Kohlhase\Desktop\JRT.txt
2015-01-29 18:15 - 2015-01-29 18:15 - 00000000 ____D () C:\Windows\ERUNT
2015-01-29 18:12 - 2015-01-29 18:12 - 00005687 _____ () C:\Users\Katja Kohlhase\Desktop\AdwCleaner[S0].txt
2015-01-29 18:05 - 2015-01-29 18:08 - 00000000 ____D () C:\AdwCleaner
2015-01-29 17:59 - 2015-01-29 18:11 - 00001078 _____ () C:\Windows\system32dbgraw.bmp
2015-01-29 17:58 - 2015-01-29 17:58 - 00019328 _____ () C:\Users\Katja Kohlhase\Desktop\mbam.txt
2015-01-29 17:38 - 2015-01-29 17:38 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-29 17:37 - 2015-01-29 17:37 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-29 17:37 - 2015-01-29 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-29 17:37 - 2015-01-29 17:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-29 17:37 - 2015-01-29 17:37 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-29 17:37 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-29 17:37 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-29 17:37 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-29 17:35 - 2015-01-29 17:35 - 01707939 _____ (Thisisu) C:\Users\Katja Kohlhase\Desktop\JRT.exe
2015-01-29 17:34 - 2015-01-29 17:35 - 02194432 _____ () C:\Users\Katja Kohlhase\Desktop\AdwCleaner_4.109.exe
2015-01-29 17:34 - 2015-01-29 17:34 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Katja Kohlhase\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-29 13:44 - 2015-01-29 18:21 - 00026521 _____ () C:\Users\Katja Kohlhase\Desktop\FRST.txt
2015-01-29 13:44 - 2015-01-29 13:45 - 00049802 _____ () C:\Users\Katja Kohlhase\Desktop\Addition.txt
2015-01-29 12:58 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-01-29 12:58 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-01-29 12:58 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-01-29 12:58 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-01-29 12:58 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-01-29 12:58 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-01-29 12:58 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-01-29 12:58 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-01-29 12:57 - 2015-01-29 13:32 - 00000000 ____D () C:\Qoobox
2015-01-29 12:57 - 2015-01-29 13:32 - 00000000 ____D () C:\ComboFix
2015-01-29 12:57 - 2015-01-29 13:28 - 00000000 ____D () C:\Windows\erdnt
2015-01-29 12:52 - 2015-01-29 12:53 - 05610841 ____R (Swearware) C:\Users\Katja Kohlhase\Desktop\ComboFix.exe
2015-01-28 18:05 - 2015-01-28 18:06 - 00049832 _____ () C:\Users\Katja Kohlhase\Downloads\Addition.txt
2015-01-28 18:04 - 2015-01-28 18:06 - 00040338 _____ () C:\Users\Katja Kohlhase\Downloads\FRST.txt
2015-01-28 18:03 - 2015-01-29 18:21 - 00000000 ____D () C:\FRST
2015-01-28 18:02 - 2015-01-28 18:02 - 02130432 _____ (Farbar) C:\Users\Katja Kohlhase\Desktop\FRST64.exe
2015-01-27 14:20 - 2015-01-27 14:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-26 17:58 - 2015-01-26 17:58 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2015-01-26 17:58 - 2015-01-26 17:58 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2015-01-26 17:58 - 2015-01-26 17:58 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2015-01-26 17:58 - 2015-01-26 17:58 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-26 17:58 - 2015-01-26 17:58 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-26 16:28 - 2015-01-29 17:59 - 00000368 _____ () C:\Windows\Tasks\HPCeeScheduleForKatja Kohlhase.job
2015-01-26 16:28 - 2015-01-29 17:35 - 00003240 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForKatja Kohlhase
2015-01-20 15:01 - 2015-01-20 15:05 - 00005128 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KatjaKohlhase-Katja Kohlhase KatjaKohlhase
2015-01-17 16:57 - 2015-01-17 16:57 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-01-17 16:57 - 2015-01-17 16:57 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-01-17 16:57 - 2015-01-17 16:57 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-01-17 16:57 - 2015-01-17 16:57 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-01-14 18:38 - 2015-01-29 17:53 - 00000112 _____ () C:\ProgramData\4q643EG.dat
2015-01-14 16:37 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 16:37 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 16:37 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 16:37 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 16:37 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 16:37 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 16:37 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 16:37 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 16:37 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 16:37 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 16:37 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 16:37 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 16:37 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-02 17:24 - 2015-01-02 17:24 - 00000000 __SHD () C:\Users\Katja Kohlhase\AppData\Local\EmieBrowserModeList
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-29 18:20 - 2009-07-14 05:45 - 00037184 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-29 18:20 - 2009-07-14 05:45 - 00037184 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-29 18:13 - 2014-08-26 12:37 - 00000000 ____D () C:\Users\Katja Kohlhase\AppData\Roaming\Spotify
2015-01-29 18:13 - 2013-12-18 07:04 - 00000000 ____D () C:\ProgramData\PDFC
2015-01-29 18:12 - 2014-10-30 13:43 - 00000000 ___RD () C:\Users\Katja Kohlhase\Dropbox
2015-01-29 18:12 - 2014-10-30 13:36 - 00000000 ____D () C:\Users\Katja Kohlhase\AppData\Roaming\Dropbox
2015-01-29 18:11 - 2014-12-07 21:06 - 00000000 ____D () C:\ProgramData\VMware
2015-01-29 18:11 - 2014-08-24 14:30 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-29 18:11 - 2009-07-14 05:51 - 00244712 _____ () C:\Windows\setupact.log
2015-01-29 18:10 - 2014-06-07 11:30 - 00000225 _____ () C:\Windows\CryptoMill_CreoService.log
2015-01-29 18:10 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-29 18:09 - 2014-08-22 20:34 - 01998604 _____ () C:\Windows\WindowsUpdate.log
2015-01-29 18:09 - 2010-11-21 04:47 - 00314690 _____ () C:\Windows\PFRO.log
2015-01-29 17:59 - 2014-06-07 11:30 - 00000225 _____ () C:\Windows\CryptoMill_CreoService.001
2015-01-29 17:57 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Speech
2015-01-29 17:27 - 2014-06-07 11:30 - 00000225 _____ () C:\Windows\CryptoMill_CreoService.002
2015-01-29 17:16 - 2014-06-07 11:30 - 00000225 _____ () C:\Windows\CryptoMill_CreoService.003
2015-01-29 13:34 - 2014-06-07 11:30 - 00000225 _____ () C:\Windows\CryptoMill_CreoService.004
2015-01-29 13:18 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-01-29 13:17 - 2014-06-07 11:30 - 00000225 _____ () C:\Windows\CryptoMill_CreoService.005
2015-01-29 13:03 - 2014-10-13 15:21 - 00000000 ____D () C:\Users\Katja Kohlhase\AppData\Local\CrashDumps
2015-01-28 19:40 - 2014-08-24 14:28 - 00000000 ____D () C:\Users\Katja Kohlhase\AppData\Roaming\vlc
2015-01-28 18:02 - 2014-06-07 10:56 - 00703102 _____ () C:\Windows\system32\perfh007.dat
2015-01-28 18:02 - 2014-06-07 10:56 - 00151234 _____ () C:\Windows\system32\perfc007.dat
2015-01-28 18:02 - 2009-07-14 06:13 - 01631048 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-28 16:55 - 2014-08-22 20:37 - 00003986 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{A4844669-D79E-4131-B38F-9F31117A425F}
2015-01-28 16:48 - 2014-08-23 10:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-26 17:59 - 2014-08-23 12:05 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-26 16:25 - 2014-08-24 13:24 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2015-01-26 16:24 - 2014-08-24 13:24 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2015-01-26 14:12 - 2014-08-26 12:37 - 00000000 ____D () C:\Users\Katja Kohlhase\AppData\Local\Spotify
2015-01-19 16:10 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-14 23:45 - 2014-08-23 12:54 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 23:42 - 2014-08-23 12:54 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-14 18:30 - 2013-12-18 06:59 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-08 09:55 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
==================== Files in the root of some directories =======
2014-09-08 17:19 - 2014-09-17 13:56 - 0000624 _____ () C:\Users\Katja Kohlhase\AppData\Roaming\All CPU MeterV3_Settings.ini
2014-08-24 13:28 - 2014-09-11 10:42 - 0007598 _____ () C:\Users\Katja Kohlhase\AppData\Local\Resmon.ResmonCfg
2015-01-14 18:38 - 2015-01-29 17:53 - 0000112 _____ () C:\ProgramData\4q643EG.dat
Files to move or delete:
====================
C:\ProgramData\4q643EG.dat
Some content of TEMP:
====================
C:\Users\Katja Kohlhase\AppData\Local\Temp\avgnt.exe
C:\Users\Katja Kohlhase\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpj2dbu6.dll
C:\Users\Katja Kohlhase\AppData\Local\Temp\Quarantine.exe
C:\Users\Katja Kohlhase\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-19 18:20
==================== End Of Log ============================ --- --- ---
Liebe Grüße
Katja |