Hallo und Guten Abend,
das geht ja total wie am Schnürchen.
Ich habe die Programme durchlaufen lassen, das Symbol in der Taskleiste ist weg, Firefox sieht plötzlich wieder ganz frisch aus - toll.
Jetzt bin ich wieder ein bißchen entspannter ;-))))
Ich schicke dir jetzt noch die Dateien:
Zuerst mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 06.02.2015
Suchlauf-Zeit: 15:53:43
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.02.06.04
Rootkit Datenbank: v2015.02.03.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: cmc_HP
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 390772
Verstrichene Zeit: 26 Min, 32 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 4
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1836, Löschen bei Neustart, [56e6f5264941b87ed0f93a2cc0407090]
PUP.Optional.XTab.A, C:\Program Files\XTab\ProtectService.exe, 1564, Löschen bei Neustart, [201c0f0c34563bfb6d0fa564be44e020]
PUP.Optional.XTab.A, C:\Program Files\XTab\CmdShell.exe, 896, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937]
PUP.Optional.XTab.A, C:\Program Files\XTab\HPNotify.exe, 2728, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937]
Module: 9
PUP.Optional.XTab.A, C:\Program Files\XTab\BrowerWatchFF.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\BrowserAction.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\IeWatchDog.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\msvcp110.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\msvcp110.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\msvcp110.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\msvcr110.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\msvcr110.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\msvcr110.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
Registrierungsschlüssel: 9
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [56e6f5264941b87ed0f93a2cc0407090],
PUP.Optional.XTab.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IHProtect Service, In Quarantäne, [201c0f0c34563bfb6d0fa564be44e020],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\IHProtect, In Quarantäne, [99a357c4deac092ddc60bccd877cf907],
PUP.Optional.WPM.A, HKLM\SOFTWARE\supWindowsMangerProtect, In Quarantäne, [e9538e8d4e3cdf57e3bf23e0ef16a858],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\webssearchesSoftware, In Quarantäne, [e25a1b001971e650235adbe6b64da060],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [9ca068b38208f73fadb4b13eda2a3ac6],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\SUPTAB, In Quarantäne, [cb7169b23a504aec37d33f6055aed12f],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [6bd163b8bcce0b2b59e6593b689b20e0],
PUP.Optional.Qone8, HKU\S-1-5-21-682379189-956013972-3949525639-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [f04cd645dab0142284dc24cb26dedc24],
Registrierungswerte: 3
PUP.Optional.FFToolbar.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|fftoolbar2014@etech.com, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\fftoolbar2014@etech.com, In Quarantäne, [053772a91773f93d23b33652b25101ff]
PUP.Optional.FastStart.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\faststartff@gmail.com, In Quarantäne, [5ce09883abdfdf5705bc18eaaf56a759]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\SUPTAB|ptid, cvs1, In Quarantäne, [cb7169b23a504aec37d33f6055aed12f]
Registrierungsdaten: 4
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "D:\Internet\Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1423077010&from=cvs1&uid=HitachiXHTS547550A9E384_J2510051GKUHBEGKUHBEX, Gut: (firefox.exe), Schlecht: ("D:\Internet\Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1423077010&from=cvs1&uid=HitachiXHTS547550A9E384_J2510051GKUHBEGKUHBEX),Ersetzt,[e854e13a97f359dda1a104a630d536ca]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hppp&ts=1423077074&from=cvs1&uid=HitachiXHTS547550A9E384_J2510051GKUHBEGKUHBEX, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hppp&ts=1423077074&from=cvs1&uid=HitachiXHTS547550A9E384_J2510051GKUHBEGKUHBEX),Ersetzt,[1329be5dd3b7ca6ce067feac09fcd828]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[3309ee2d1b6fa19532f2f4c04abb0df3]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-682379189-956013972-3949525639-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hppp&ts=1423077074&from=cvs1&uid=HitachiXHTS547550A9E384_J2510051GKUHBEGKUHBEX, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hppp&ts=1423077074&from=cvs1&uid=HitachiXHTS547550A9E384_J2510051GKUHBEGKUHBEX),Ersetzt,[201c3edda2e8af87a53df0c4fa0bf20e]
Ordner: 41
PUP.Optional.XTab.A, C:\Program Files\XTab, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\image, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\weather, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\en-US, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\es-419, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\es-ES, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-BE, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-CA, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-CH, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-FR, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-LU, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\it-CH, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\it-IT, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pl, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pt, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pt-BR, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\ru, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\ru-MO, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\tr-TR, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\vi-VI, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\zh-CN, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\zh-TW, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\code, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\log, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.SearchProtect.A, C:\Users\cmc_HP\AppData\Local\SearchProtect, In Quarantäne, [25178a9186048aac7594b0b2fb086d93],
PUP.Optional.SearchProtect.A, C:\Users\cmc_HP\AppData\Local\SearchProtect\Logs, In Quarantäne, [25178a9186048aac7594b0b2fb086d93],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [77c5d744afdb9b9b2f05481c669d55ab],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [77c5d744afdb9b9b2f05481c669d55ab],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, In Quarantäne, [68d4a17a5a30c76feeef5c24e320a45c],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, In Quarantäne, [68d4a17a5a30c76feeef5c24e320a45c],
PUP.Optional.FFToolbar.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\fftoolbar2014@etech.com, In Quarantäne, [8eae78a3a3e714228e7df28ffb088c74],
PUP.Optional.FFToolbar.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\fftoolbar2014@etech.com\chrome, In Quarantäne, [8eae78a3a3e714228e7df28ffb088c74],
PUP.Optional.FFToolbar.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\fftoolbar2014@etech.com\chrome\content, In Quarantäne, [8eae78a3a3e714228e7df28ffb088c74],
PUP.Optional.FFToolbar.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\fftoolbar2014@etech.com\chrome\skin, In Quarantäne, [8eae78a3a3e714228e7df28ffb088c74],
Dateien: 117
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [56e6f5264941b87ed0f93a2cc0407090],
PUP.Optional.XTab.A, C:\Program Files\XTab\ProtectService.exe, Löschen bei Neustart, [201c0f0c34563bfb6d0fa564be44e020],
PUP.Optional.SupTab.A, C:\Program Files\XTab\SupTab.dll, In Quarantäne, [64d8b269f6944ee8487ac66f728e54ac],
PUP.Optional.Breitschopp, C:\Users\cmc_HP\Downloads\agsetup183se_v3.0.0.67(1).exe, In Quarantäne, [f64651ca8efc39fddd31096fe2230af6],
PUP.Optional.Breitschopp, C:\Users\cmc_HP\Downloads\agsetup183se_v3.0.0.67(2).exe, In Quarantäne, [84b862b9503a6bcb30de8eea1aeb16ea],
PUP.Optional.Breitschopp, C:\Users\cmc_HP\Downloads\agsetup183se_v3.0.0.67.exe, In Quarantäne, [2319b9622a604cea2ae4cdab0afbb24e],
PUP.Optional.XTab.A, C:\Program Files\XTab\uninstall.exe, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\BrowerWatchCH.dll, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\BrowerWatchFF.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\BrowserAction.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\CmdShell.exe, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\conf, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\ffsearch_toolbar!1.0.0.1025.xpi, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\HPNotify.exe, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\IeWatchDog.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\install.data, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\msvcp110.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\msvcr110.dll, Löschen bei Neustart, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\searchProvider.xml, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\about.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\about_bk.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\btn.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\btn_apply.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\close.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\conf.xml, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\conf_back.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\input_bk.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\logo.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\main.xml, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\radio_1.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\radio_2.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\rigth_arrow.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\settings.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\data.html, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\indexIE.html, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\indexIE8.html, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\main.css, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\ver.txt, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\arrow.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\default_add_logo.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\default_add_logo_hover.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\default_logo.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\googlelogo.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\googlelogo2.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\google_trends.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\icon128.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\icon16.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\icon48.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\loading.gif, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\logo32.ico, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\weather\0.png, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\common.js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\ga.js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\ie8.js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\jquery.autocomplete.js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\js.js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\library.js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\xagainit-ie8.js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\xagainit.js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\xagainit2.0.js, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\en-US\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\es-419\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\es-ES\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-BE\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-CA\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-CH\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-FR\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-LU\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\it-CH\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\it-IT\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pl\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pt\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pt-BR\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\ru\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\ru-MO\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\tr-TR\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\vi-VI\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\zh-CN\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\zh-TW\messages.json, In Quarantäne, [2c108695800a74c25ce128614fb4c937],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\searchplugins\webssearches.xml, In Quarantäne, [95a7809bef9b5adcd6aa7948a55e6997],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\426.json, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\MessageBox.xml, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\uninstallDlg2.xml, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\UninstallManager.exe, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\bg.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\bg1.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\bk_shadow.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\button.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\button1.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\checkbox.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\checkbox_select.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\checked.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\close.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\loading_bg.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\loading_light.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\min.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\scrollbar.bmp, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\Thumbs.db, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\unchecked.png, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\code\code1.jpg, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\code\code2.jpg, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\code\code3.jpg, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\code\code4.jpg, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\code\code5.jpg, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\code\code6.jpg, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\images\code\Thumbs.db, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\webssearches\log\UninstallManager_2015-02-04[20-29-18-781].log, In Quarantäne, [b18b8c8fdbafd95d8deda7aca162db25],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [77c5d744afdb9b9b2f05481c669d55ab],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update\conf, In Quarantäne, [68d4a17a5a30c76feeef5c24e320a45c],
PUP.Optional.FFToolbar.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\fftoolbar2014@etech.com\chrome.manifest, In Quarantäne, [8eae78a3a3e714228e7df28ffb088c74],
PUP.Optional.FFToolbar.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\fftoolbar2014@etech.com\install.rdf, In Quarantäne, [8eae78a3a3e714228e7df28ffb088c74],
PUP.Optional.FFToolbar.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\fftoolbar2014@etech.com\chrome\content\toolbar.js, In Quarantäne, [8eae78a3a3e714228e7df28ffb088c74],
PUP.Optional.FFToolbar.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\fftoolbar2014@etech.com\chrome\content\toolbar.xul, In Quarantäne, [8eae78a3a3e714228e7df28ffb088c74],
PUP.Optional.FFToolbar.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\fftoolbar2014@etech.com\chrome\skin\icon.png, In Quarantäne, [8eae78a3a3e714228e7df28ffb088c74],
PUP.Optional.QuickStart.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), Ersetzt,[d06cfd1e6327d75fd414be30f90c857b]
PUP.Optional.WebsSearches.A, C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hppp&ts=1423077074&from=cvs1&uid=HitachiXHTS547550A9E384_J2510051GKUHBEGKUHBEX");), Ersetzt,[1e1eaa710c7ef1452837c12f7f860af6]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end)
Dann die Datei zu AdwCleaner: Code:
# AdwCleaner v4.110 - Bericht erstellt 06/02/2015 um 18:25:49
# Aktualisiert 05/02/2015 von Xplode
# Datenbank : 2015-02-05.2 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86)
# Benutzername : cmc_HP - CMC_HP-PC
# Gestarted von : C:\Users\cmc_HP\Downloads\AdwCleaner_4.110(1).exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\cmc_HP\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\Users\cmc_HP\AppData\LocalLow\Check Point Software Technologies LTD
Ordner Gelöscht : C:\Users\cmc_HP\AppData\Roaming\CheckPoint\ZoneAlarm LTD Toolbar
Ordner Gelöscht : C:\Users\cmc_HP\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\cmc_HP\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\cmc_HP\AppData\Roaming\Tobit
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\user.js
***** [ Geplante Tasks ] *****
Task Gelöscht : Run_Bobby_Browser
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\cmc_HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\cmc_HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\cmc_HP\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi
Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{908106AF-E5B0-4764-A627-AAFFA18C605C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Myfree Codec
Schlüssel Gelöscht : HKLM\SOFTWARE\SupDp
Schlüssel Gelöscht : HKLM\SOFTWARE\Clara
Schlüssel Gelöscht : HKLM\SOFTWARE\DriverTuner_Init
Schlüssel Gelöscht : HKLM\SOFTWARE\DriverTuner
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v23.0.1 (de)
[xfbj3s6j.default-1392757257819\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultenginename", "Ixquick hxxpS - Deutsch");
[xfbj3s6j.default-1392757257819\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.alias", "webssearches");
[xfbj3s6j.default-1392757257819\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.iconURL", "hxxp://istart.webssearches.com/web/favicon.ico");
[xfbj3s6j.default-1392757257819\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.name", "webssearches");
[xfbj3s6j.default-1392757257819\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.url", "hxxp://istart.webssearches.com/web/?type=dspp&ts=1423077074&from=cvs1&uid=HitachiXHTS547550A9E384_J2510051GKUHBEGKUHBEX&q={searchTerms}");
[xfbj3s6j.default-1392757257819\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "webssearches");
[xfbj3s6j.default-1392757257819\prefs.js] - Zeile Gelöscht : user_pref("extensions.quick_start.enable_search1", false);
[xfbj3s6j.default-1392757257819\prefs.js] - Zeile Gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [5113 Bytes] - [06/02/2015 17:12:50]
AdwCleaner[S0].txt - [5696 Bytes] - [06/02/2015 18:25:49]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5755 Bytes] ##########
Und dann jrt.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x86
Ran by cmc_HP on 06.02.2015 at 18:32:32,87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.02.2015 at 18:37:09,03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Sieht etwas unspektakulär aus für mich als Laien, ist aber sicherlich auch besser, nicht wahr?!
Und zuletzt kommt das neue Frst.log
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-02-2015 01
Ran by cmc_HP (administrator) on CMC_HP-PC on 06-02-2015 19:12:18
Running from C:\Users\cmc_HP\Desktop
Loaded Profiles: cmc_HP (Available profiles: cmc_HP)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AVAST Software) D:\Security\avast\AvastSvc.exe
(AVAST Software) D:\Security\avast\avastui.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Ellora Assets Corp.) D:\Medien\Video\Freemake\CaptureLib\CaptureLibService.exe
(Safer-Networking Ltd.) D:\Security\Spybot - Search & Destroy2\SDFSSvc.exe
(Safer-Networking Ltd.) D:\Security\Spybot - Search & Destroy2\SDUpdSvc.exe
(Safer-Networking Ltd.) D:\Security\Spybot - Search & Destroy2\SDWSCSvc.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [AvastUI.exe] => D:\Security\avast\AvastUI.exe [5227112 2015-02-02] (AVAST Software)
HKU\S-1-5-21-682379189-956013972-3949525639-1000\...\Run: [GUDelayStartup] => D:\Security\Glary Utilities 5\StartupManager.exe [37152 2014-11-24] (Glarysoft Ltd)
HKU\S-1-5-21-682379189-956013972-3949525639-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-682379189-956013972-3949525639-1000\...\Policies\Explorer: [NoSimpleStartMenu] 1
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => D:\Security\avast\ashShell.dll (AVAST Software)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-682379189-956013972-3949525639-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-682379189-956013972-3949525639-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> D:\Security\Spybot - Search & Destroy2\SDHelper.dll (Safer-Networking Ltd.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> D:\Security\avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Office\Office 2010\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-682379189-956013972-3949525639-1000 -> No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819
FF DefaultSearchEngine: Ixquick HTTPS - Deutsch
FF DefaultSearchUrl: https://startpage.com/do/metasearch.pl
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1214154.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> D:\Medien\musik\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> D:\Office\PdfViewer\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> D:\Office\OFFICE~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> D:\Office\OFFICE~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> D:\Medien\Bilder\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> D:\Medien\Bilder\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> D:\Medien\Bilder\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\searchplugins\das-rtliche.xml
FF SearchPlugin: C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\searchplugins\google-maps.xml
FF SearchPlugin: C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\searchplugins\ixquick-https---deutsch.xml
FF Extension: YouTube Unblocker - C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\Extensions\youtubeunblocker@unblocker.yt [2014-11-23]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-12-14]
FF Extension: NoScript - C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-02-18]
FF Extension: Easy Youtube Video Downloader Express - C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2014-11-10]
FF Extension: Adblock Plus - C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-12-17]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files\Mozilla Firefox\browser\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2014-12-14]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - D:\Security\avast\WebRep\FF
FF Extension: Avast Online Security - D:\Security\avast\WebRep\FF [2011-11-03]
FF HKU\S-1-5-21-682379189-956013972-3949525639-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\cmc_HP\AppData\Roaming\Mozilla\Firefox\Profiles\xfbj3s6j.default-1392757257819\extensions\cliqz@cliqz.com
FF HKU\S-1-5-21-682379189-956013972-3949525639-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff [2014-12-14]
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR Profile: C:\Users\cmc_HP\AppData\Local\Google\Chrome\User Data\default
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - D:\Security\avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-22]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; D:\Security\avast\AvastSvc.exe [50344 2014-11-22] (AVAST Software)
R2 FreemakeVideoCapture; D:\Medien\Video\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-12-12] (Ellora Assets Corp.) [File not signed]
R2 SDScannerService; D:\Security\Spybot - Search & Destroy2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; D:\Security\Spybot - Search & Destroy2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
R2 SDWSCService; D:\Security\Spybot - Search & Destroy2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amd_sata; C:\Windows\System32\DRIVERS\amd_sata.sys [66688 2011-04-16] (Advanced Micro Devices)
R0 amd_xata; C:\Windows\System32\DRIVERS\amd_xata.sys [33408 2011-04-16] (Advanced Micro Devices)
R3 AR5416; C:\Windows\System32\DRIVERS\athw.sys [1982112 2011-08-21] (Atheros Communications, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-11-22] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2014-11-22] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-11-22] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-11-22] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787800 2014-11-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423784 2014-11-22] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [91496 2014-11-22] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [206248 2014-11-22] ()
S3 athr; C:\Windows\System32\DRIVERS\athr.sys [2957312 2012-06-20] (Qualcomm Atheros Communications, Inc.)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14920 2012-12-21] () [File not signed]
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9160 2012-12-21] () [File not signed]
R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [17344 2014-11-29] (Glarysoft Ltd)
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\cmc_HP\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-06 18:37 - 2015-02-06 18:37 - 00000626 _____ () C:\Users\cmc_HP\Desktop\JRT.txt
2015-02-06 18:31 - 2015-02-06 18:31 - 01388274 _____ (Thisisu) C:\Users\cmc_HP\Downloads\JRT.exe
2015-02-06 18:30 - 2015-02-06 18:30 - 00005835 _____ () C:\Users\cmc_HP\Desktop\AdwCleaner[S0].txt
2015-02-06 17:12 - 2015-02-06 18:25 - 00000000 ____D () C:\AdwCleaner
2015-02-06 17:12 - 2015-02-06 17:12 - 02112512 _____ () C:\Users\cmc_HP\Downloads\AdwCleaner_4.110(1).exe
2015-02-06 17:10 - 2015-02-06 17:10 - 02112512 _____ () C:\Users\cmc_HP\Downloads\AdwCleaner_4.110.exe
2015-02-06 17:08 - 2015-02-06 17:08 - 00027129 _____ () C:\Users\cmc_HP\Desktop\mbam.txt
2015-02-06 15:51 - 2015-02-06 15:51 - 00000735 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-06 15:50 - 2015-02-06 15:50 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\cmc_HP\Downloads\mbam-setup-2.0.4.1028(1).exe
2015-02-05 16:20 - 2015-02-05 16:20 - 00014785 _____ () C:\ComboFix.txt
2015-02-05 15:58 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-05 15:58 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-05 15:58 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-05 15:58 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-05 15:58 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-05 15:58 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-05 15:58 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-05 15:58 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-05 15:49 - 2015-02-05 16:20 - 00000000 ____D () C:\Qoobox
2015-02-05 15:48 - 2015-02-05 16:17 - 00000000 ____D () C:\Windows\erdnt
2015-02-05 15:46 - 2015-02-05 15:46 - 05611380 ____R (Swearware) C:\Users\cmc_HP\Desktop\ComboFix.exe
2015-02-05 12:26 - 2015-02-05 12:28 - 00043771 _____ () C:\Users\cmc_HP\Desktop\Addition.txt
2015-02-05 12:25 - 2015-02-06 19:12 - 00011490 _____ () C:\Users\cmc_HP\Desktop\FRST.txt
2015-02-05 12:25 - 2015-02-06 19:12 - 00000000 ____D () C:\FRST
2015-02-05 12:24 - 2015-02-05 12:24 - 01123328 _____ (Farbar) C:\Users\cmc_HP\Desktop\FRST.exe
2015-02-04 20:20 - 2015-02-04 20:20 - 00619080 _____ () C:\Users\cmc_HP\Downloads\download_audiograbber_mp3_plugin.exe
2015-02-04 20:16 - 2015-02-04 20:23 - 00000452 _____ () C:\Windows\cdplayer.ini
2015-02-04 20:12 - 2015-02-04 20:12 - 00000000 ____D () C:\Users\cmc_HP\AppData\Roaming\dlg
2015-01-21 17:30 - 2015-02-06 19:10 - 00003371 _____ () C:\Windows\setupact.log
2015-01-21 17:30 - 2015-02-06 18:26 - 00049102 _____ () C:\Windows\PFRO.log
2015-01-21 17:30 - 2015-01-21 17:30 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-21 17:01 - 2015-02-06 17:05 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-21 17:00 - 2015-02-06 15:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-21 17:00 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-21 17:00 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-21 16:58 - 2015-01-21 16:58 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\cmc_HP\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-21 16:23 - 2015-01-21 16:23 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-01-21 16:23 - 2015-01-21 16:22 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2015-01-21 16:23 - 2015-01-21 16:22 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2015-01-21 16:23 - 2015-01-21 16:22 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-01-21 16:21 - 2015-01-21 16:21 - 03402176 _____ (Check Point Software Technologies Ltd.) C:\Users\cmc_HP\Downloads\zaSetupWeb_133_052_000.exe
2015-01-18 17:14 - 2015-01-18 21:34 - 1628226542 _____ () C:\Users\cmc_HP\Downloads\Zeit der Krähen.zip
2015-01-18 11:00 - 2015-01-18 15:33 - 1803775449 _____ () C:\Users\cmc_HP\Downloads\Die dunkle Königin.zip
2015-01-14 08:03 - 2015-01-14 08:01 - 00450892 ____R () C:\Windows\system32\Drivers\etc\hosts.20150114-080326.backup
2015-01-14 07:47 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-01-14 07:47 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 07:42 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 07:42 - 2014-12-11 18:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 07:42 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 07:42 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 07:42 - 2012-10-03 17:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 07:41 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-06 19:11 - 2014-06-14 18:10 - 00000312 _____ () C:\Windows\Tasks\GlaryInitialize 5.job
2015-02-06 19:10 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-06 19:09 - 2011-10-31 18:08 - 01963038 _____ () C:\Windows\WindowsUpdate.log
2015-02-06 19:07 - 2014-06-09 21:14 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-06 18:34 - 2009-07-14 05:34 - 00019776 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-06 18:34 - 2009-07-14 05:34 - 00019776 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-06 18:25 - 2013-09-16 16:15 - 00000654 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-06 18:25 - 2013-09-16 16:15 - 00000654 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-06 18:25 - 2011-10-31 18:29 - 00001164 _____ () C:\Users\cmc_HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-06 16:25 - 2009-07-14 03:37 - 00000000 __RSD () C:\Windows\Media
2015-02-06 16:01 - 2012-09-10 18:11 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-02-06 16:01 - 2012-09-10 18:11 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-02-05 17:09 - 2011-10-31 18:30 - 01612484 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-05 16:20 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2015-02-05 16:16 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2015-02-04 19:31 - 2013-02-01 17:43 - 00000000 ____D () C:\Users\cmc_HP\AppData\Roaming\DVDVideoSoft
2015-02-04 19:06 - 2013-09-14 18:45 - 00000000 ____D () C:\Users\cmc_HP\AppData\Roaming\vlc
2015-01-24 20:47 - 2012-01-05 22:26 - 00000000 ____D () C:\Users\cmc_HP\Desktop\Wichtig
2015-01-24 20:46 - 2011-11-03 18:16 - 00000000 ____D () C:\Users\cmc_HP\Desktop\Security
2015-01-21 17:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\tracing
2015-01-21 17:00 - 2011-12-20 11:13 - 00000000 ____D () C:\Users\cmc_HP\AppData\Roaming\Malwarebytes
2015-01-21 17:00 - 2011-12-20 11:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-21 16:29 - 2013-09-16 18:04 - 00000000 ____D () C:\Program Files\CheckPoint
2015-01-21 16:24 - 2013-09-29 11:08 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-21 16:24 - 2011-12-22 11:16 - 00000000 ____D () C:\Program Files\Java
2015-01-21 16:22 - 2014-10-21 17:58 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2015-01-21 16:22 - 2014-10-21 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-19 17:11 - 2014-11-10 18:27 - 00000000 ____D () C:\Users\cmc_HP\.mediathek3
2015-01-19 11:38 - 2009-07-14 05:53 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-14 07:55 - 2013-07-22 08:36 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 07:48 - 2011-12-03 10:40 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Files in the root of some directories =======
2013-05-09 08:45 - 2014-01-09 19:11 - 0000822 _____ () C:\Users\cmc_HP\AppData\Roaming\Safer-Networking.log
2011-11-03 18:36 - 2011-11-03 18:40 - 0000623 ____H () C:\Users\cmc_HP\AppData\Roaming\xpy.ini
2006-12-11 18:13 - 2006-12-11 18:13 - 0097336 _____ (Un4seen Developments) C:\Users\cmc_HP\AppData\Local\bass.dll
2006-12-11 18:13 - 2006-12-11 18:13 - 0013872 _____ (Un4seen Developments) C:\Users\cmc_HP\AppData\Local\basscd.dll
2007-08-13 16:46 - 2007-08-13 16:46 - 0102912 _____ (Albert L Faber) C:\Users\cmc_HP\AppData\Local\CDRip.dll
2011-12-23 18:05 - 2014-06-11 11:19 - 0008192 _____ () C:\Users\cmc_HP\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-01-11 17:22 - 2012-09-20 06:40 - 0000173 _____ () C:\Users\cmc_HP\AppData\Local\msmathematics.qat.cmc_HP
2007-01-18 20:09 - 2007-01-18 20:09 - 0623616 _____ (Ivan Bischof ©2003 - 2005) C:\Users\cmc_HP\AppData\Local\No23 Recorder.exe
2013-04-21 15:50 - 2014-01-05 15:53 - 0001463 _____ () C:\Users\cmc_HP\AppData\Local\RecConfig.xml
Some content of TEMP:
====================
C:\Users\cmc_HP\AppData\Local\Temp\Quarantine.exe
C:\Users\cmc_HP\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-05 20:40
==================== End Of Log ============================ --- --- ---
--- --- ---
Es klang bei deiner letzten Antwort so, als ob der PC jetzt einigermaßen frei von irgendwelchen Schädlingen ist?!
Muss ich jetzt noch etwas tun, außer vielleicht doch noch besser und sorgfältiger beim Installieren von Programmen zu sein?!
Auf jeden Fall erst mal vielen Dank für die schnelle und tolle Hilfe - ich fühle mich hier sehr gut aufgehoben.
Danke!
JonasP |