![]() |
TR/Firehooker.1825 Infektion gefunden von Avira Hallo zusammen, nach längerer Pause hats mein Tablet jetzt erwischt. Avira meldet trotz Quarantäne und Löschversuchen oben genannten Virus. Ich möchte Euch um Eure Hilfe bitten. Hier wie in der Anleitung beschrieben die Logs: Avira: Avira Professional Security Report file date: Sonntag, 13. Dezember 2015 19:46 The program is running as an unrestricted full version. Online services are available. Licensee : Serial number : Platform : Windows 8.1 Enterprise Windows version : (plain) [6.2.9200] Boot mode : Normally booted Username : User Computer name : ELITEPAD1000 Version information: BUILD.DAT : 14.0.13.106 91073 Bytes 9/17/2015 15:42:00 AVSCAN.EXE : 14.0.13.104 1110608 Bytes 10/24/2015 10:58:59 AVSCANRC.DLL : 14.0.13.90 57912 Bytes 10/24/2015 10:58:59 LUKE.DLL : 14.0.13.103 66664 Bytes 10/24/2015 10:59:16 AVSCPLR.DLL : 14.0.13.104 100136 Bytes 10/24/2015 10:58:59 REPAIR.DLL : 14.0.13.103 515256 Bytes 10/24/2015 10:58:57 REPAIR.RDF : 1.0.12.98 1395721 Bytes 12/8/2015 19:32:27 AVREG.DLL : 14.0.13.90 287608 Bytes 10/24/2015 10:58:56 AVLODE.DLL : 14.0.13.103 618744 Bytes 10/24/2015 10:58:54 AVLODE.RDF : 14.0.5.18 88653 Bytes 12/9/2015 14:10:46 XBV00030.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:03 XBV00031.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:04 XBV00032.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:06 XBV00033.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:06 XBV00034.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:08 XBV00035.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:16 XBV00036.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:16 XBV00037.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:17 XBV00038.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:18 XBV00039.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:20 XBV00040.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:23 XBV00041.VDF : 8.11.165.190 2048 Bytes 8/7/2014 17:09:54 XBV00094.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:14 XBV00095.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:14 XBV00096.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:14 XBV00097.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:14 XBV00098.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:14 XBV00099.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:14 XBV00100.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:14 XBV00101.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:14 XBV00102.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:14 XBV00103.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:14 XBV00104.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00105.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00106.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00107.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00108.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00109.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00110.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00111.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00112.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00113.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00114.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00115.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00116.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00117.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00118.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00119.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00120.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:15 XBV00121.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00122.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00123.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00124.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00125.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00126.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00127.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00128.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00129.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00130.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00131.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00132.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00133.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00134.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00135.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00136.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00137.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00138.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00139.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00140.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:16 XBV00141.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00142.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00143.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00144.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00145.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00146.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00147.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00148.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00149.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00150.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00151.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00152.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00153.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00154.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00155.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00156.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00157.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:17 XBV00158.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00159.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00160.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00161.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00162.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00163.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00164.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00165.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00166.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00167.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00168.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00169.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00170.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00171.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00172.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00173.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:18 XBV00174.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00175.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00176.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00177.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00178.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00179.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00180.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00181.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00182.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00183.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00184.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00185.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00186.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00187.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00188.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00189.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00190.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00191.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00192.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00193.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00194.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00195.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:19 XBV00196.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00197.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00198.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00199.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00200.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00201.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00202.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00203.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00204.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00205.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00206.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00207.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:20 XBV00208.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00209.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00210.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00211.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00212.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00213.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00214.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00215.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00216.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00217.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00218.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00219.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00220.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00221.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00222.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00223.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00224.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00225.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00226.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00227.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:21 XBV00228.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00229.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00230.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00231.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00232.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00233.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00234.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00235.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00236.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00237.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00238.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00239.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00240.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00241.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00242.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00243.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00244.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00245.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00246.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00247.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00248.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:22 XBV00249.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:23 XBV00250.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:23 XBV00251.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:23 XBV00252.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:23 XBV00253.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:23 XBV00254.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:23 XBV00255.VDF : 8.12.34.234 2048 Bytes 12/8/2015 19:32:23 XBV00000.VDF : 7.11.70.0 66736640 Bytes 4/4/2013 11:40:31 XBV00001.VDF : 7.11.74.226 2201600 Bytes 4/30/2013 11:40:31 XBV00002.VDF : 7.11.80.60 2751488 Bytes 5/28/2013 11:40:31 XBV00003.VDF : 7.11.85.214 2162688 Bytes 6/21/2013 11:40:31 XBV00004.VDF : 7.11.91.176 3903488 Bytes 7/23/2013 11:40:31 XBV00005.VDF : 7.11.98.186 6822912 Bytes 8/29/2013 11:40:31 XBV00006.VDF : 7.11.139.38 15708672 Bytes 3/27/2014 17:07:54 XBV00007.VDF : 7.11.152.100 4193792 Bytes 6/2/2014 17:07:58 XBV00008.VDF : 8.11.165.192 4251136 Bytes 8/7/2014 17:08:03 XBV00009.VDF : 8.11.172.30 2094080 Bytes 9/15/2014 17:08:05 XBV00010.VDF : 8.11.178.32 1581056 Bytes 10/14/2014 17:08:07 XBV00011.VDF : 8.11.184.50 2178560 Bytes 11/11/2014 17:08:10 XBV00012.VDF : 8.11.190.32 1876992 Bytes 12/3/2014 11:50:59 XBV00013.VDF : 8.11.201.28 2973696 Bytes 1/14/2015 11:50:59 XBV00014.VDF : 8.11.206.252 2695680 Bytes 2/4/2015 11:50:59 XBV00015.VDF : 8.11.213.84 3175936 Bytes 3/3/2015 11:50:59 XBV00016.VDF : 8.11.213.176 212480 Bytes 3/5/2015 11:50:59 XBV00017.VDF : 8.11.219.166 2033664 Bytes 3/25/2015 11:50:59 XBV00018.VDF : 8.11.225.88 2367488 Bytes 4/22/2015 11:50:59 XBV00019.VDF : 8.11.230.186 1674752 Bytes 5/13/2015 11:50:59 XBV00020.VDF : 8.11.237.30 4711936 Bytes 6/2/2015 22:08:52 XBV00021.VDF : 8.11.243.12 2747904 Bytes 6/26/2015 22:08:53 XBV00022.VDF : 8.11.248.172 2350592 Bytes 7/17/2015 18:57:35 XBV00023.VDF : 8.11.254.112 2570752 Bytes 8/7/2015 18:57:39 XBV00024.VDF : 8.12.3.6 2196480 Bytes 8/27/2015 18:57:42 XBV00025.VDF : 8.12.8.238 1951232 Bytes 9/16/2015 18:57:45 XBV00026.VDF : 8.12.16.180 2211328 Bytes 10/7/2015 11:31:17 XBV00027.VDF : 8.12.21.126 2252288 Bytes 10/27/2015 06:48:31 XBV00028.VDF : 8.12.28.114 2935296 Bytes 11/17/2015 14:28:54 XBV00029.VDF : 8.12.34.234 2203648 Bytes 12/8/2015 19:32:11 XBV00042.VDF : 8.12.34.242 3584 Bytes 12/8/2015 19:32:11 XBV00043.VDF : 8.12.34.244 2048 Bytes 12/8/2015 19:32:11 XBV00044.VDF : 8.12.34.248 3584 Bytes 12/8/2015 19:32:11 XBV00045.VDF : 8.12.34.252 6656 Bytes 12/8/2015 19:32:11 XBV00046.VDF : 8.12.34.254 12800 Bytes 12/8/2015 19:32:11 XBV00047.VDF : 8.12.35.0 2048 Bytes 12/8/2015 19:32:11 XBV00048.VDF : 8.12.35.2 2048 Bytes 12/8/2015 19:32:11 XBV00049.VDF : 8.12.35.6 10752 Bytes 12/8/2015 19:32:11 XBV00050.VDF : 8.12.35.8 7680 Bytes 12/8/2015 19:32:11 XBV00051.VDF : 8.12.35.10 4608 Bytes 12/8/2015 19:32:11 XBV00052.VDF : 8.12.35.12 4608 Bytes 12/8/2015 06:25:07 XBV00053.VDF : 8.12.35.14 7680 Bytes 12/8/2015 06:25:07 XBV00054.VDF : 8.12.35.20 35328 Bytes 12/9/2015 06:25:07 XBV00055.VDF : 8.12.35.22 2048 Bytes 12/9/2015 06:25:07 XBV00056.VDF : 8.12.35.24 7680 Bytes 12/9/2015 08:10:43 XBV00057.VDF : 8.12.35.26 8192 Bytes 12/9/2015 10:10:44 XBV00058.VDF : 8.12.35.28 3584 Bytes 12/9/2015 10:10:44 XBV00059.VDF : 8.12.35.32 97280 Bytes 12/9/2015 11:20:38 XBV00060.VDF : 8.12.35.40 6656 Bytes 12/9/2015 11:20:38 XBV00061.VDF : 8.12.35.46 5120 Bytes 12/9/2015 11:20:38 XBV00062.VDF : 8.12.35.52 4608 Bytes 12/9/2015 11:20:38 XBV00063.VDF : 8.12.35.58 3072 Bytes 12/9/2015 11:20:38 XBV00064.VDF : 8.12.35.60 3072 Bytes 12/9/2015 11:20:38 XBV00065.VDF : 8.12.35.62 3072 Bytes 12/9/2015 11:20:38 XBV00066.VDF : 8.12.35.64 9216 Bytes 12/10/2015 11:20:38 XBV00067.VDF : 8.12.35.66 2048 Bytes 12/10/2015 11:20:38 XBV00068.VDF : 8.12.35.68 2048 Bytes 12/10/2015 11:20:38 XBV00069.VDF : 8.12.35.70 2048 Bytes 12/10/2015 11:20:38 XBV00070.VDF : 8.12.35.72 7168 Bytes 12/10/2015 11:20:38 XBV00071.VDF : 8.12.35.74 7168 Bytes 12/10/2015 11:20:38 XBV00072.VDF : 8.12.35.76 7680 Bytes 12/10/2015 11:20:38 XBV00073.VDF : 8.12.35.92 59392 Bytes 12/10/2015 22:01:40 XBV00074.VDF : 8.12.35.94 2048 Bytes 12/10/2015 22:01:40 XBV00075.VDF : 8.12.35.104 13312 Bytes 12/10/2015 22:01:40 XBV00076.VDF : 8.12.35.114 6144 Bytes 12/10/2015 22:01:40 XBV00077.VDF : 8.12.35.124 10240 Bytes 12/10/2015 23:02:49 XBV00078.VDF : 8.12.35.136 40960 Bytes 12/11/2015 13:59:55 XBV00079.VDF : 8.12.35.146 2048 Bytes 12/11/2015 13:59:55 XBV00080.VDF : 8.12.35.156 9216 Bytes 12/11/2015 13:59:55 XBV00081.VDF : 8.12.35.166 28672 Bytes 12/11/2015 13:59:55 XBV00082.VDF : 8.12.35.176 2048 Bytes 12/11/2015 13:59:55 XBV00083.VDF : 8.12.35.188 8192 Bytes 12/11/2015 13:59:55 XBV00084.VDF : 8.12.35.198 2048 Bytes 12/11/2015 13:59:55 XBV00085.VDF : 8.12.35.200 2048 Bytes 12/11/2015 13:59:55 XBV00086.VDF : 8.12.35.210 27136 Bytes 12/11/2015 18:05:13 XBV00087.VDF : 8.12.35.220 7168 Bytes 12/11/2015 18:05:13 XBV00088.VDF : 8.12.35.224 84992 Bytes 12/12/2015 18:05:13 XBV00089.VDF : 8.12.35.242 37888 Bytes 12/12/2015 18:05:13 XBV00090.VDF : 8.12.35.250 51712 Bytes 12/13/2015 18:05:13 XBV00091.VDF : 8.12.36.2 2048 Bytes 12/13/2015 18:05:13 XBV00092.VDF : 8.12.36.12 20992 Bytes 12/13/2015 18:05:13 XBV00093.VDF : 8.12.36.26 8192 Bytes 12/13/2015 18:05:13 LOCAL000.VDF : 8.12.36.26 147118592 Bytes 12/13/2015 18:05:51 Engine version : 8.3.34.88 AEBB.DLL : 8.1.3.0 59296 Bytes 11/26/2015 14:28:47 AECORE.DLL : 8.3.9.0 249920 Bytes 11/15/2015 18:21:08 AEDROID.DLL : 8.4.3.348 1800104 Bytes 11/6/2015 13:10:36 AEEMU.DLL : 8.1.3.6 404328 Bytes 11/26/2015 14:28:47 AEEXP.DLL : 8.4.2.136 289920 Bytes 12/4/2015 13:33:51 AEGEN.DLL : 8.1.8.10 491576 Bytes 12/4/2015 13:33:49 AEHELP.DLL : 8.3.2.6 284584 Bytes 11/26/2015 14:28:48 AEHEUR.DLL : 8.1.4.2078 9939824 Bytes 12/4/2015 13:33:51 AEMOBILE.DLL : 8.1.8.10 301936 Bytes 11/26/2015 14:28:52 AEOFFICE.DLL : 8.3.1.56 408432 Bytes 10/24/2015 10:58:48 AEPACK.DLL : 8.4.1.20 801920 Bytes 12/4/2015 13:33:51 AERDL.DLL : 8.2.1.38 813928 Bytes 11/6/2015 13:10:32 AESBX.DLL : 8.2.21.2 1629032 Bytes 11/6/2015 13:10:34 AESCN.DLL : 8.3.4.0 141216 Bytes 11/15/2015 18:21:10 AESCRIPT.DLL : 8.3.0.6 542632 Bytes 12/4/2015 13:33:51 AEVDF.DLL : 8.3.2.4 141216 Bytes 11/26/2015 14:28:52 AVWINLL.DLL : 14.0.13.90 29600 Bytes 10/24/2015 10:58:41 AVPREF.DLL : 14.0.13.90 55864 Bytes 10/24/2015 10:58:56 AVREP.DLL : 14.0.13.90 225320 Bytes 10/24/2015 10:58:56 AVARKT.DLL : 14.0.13.90 232000 Bytes 10/24/2015 10:58:50 AVEVTLOG.DLL : 14.0.13.103 189752 Bytes 10/24/2015 10:58:52 SQLITE3.DLL : 14.0.13.90 461672 Bytes 10/24/2015 10:59:21 AVSMTP.DLL : 14.0.13.90 82120 Bytes 10/24/2015 10:58:59 NETNT.DLL : 14.0.13.90 18792 Bytes 10/24/2015 10:59:16 rcimage.dll : 14.0.13.103 5101304 Bytes 10/24/2015 10:58:41 rctext.dll : 14.0.13.90 78000 Bytes 10/24/2015 10:58:41 Configuration settings for the scan: Jobname.............................: Complete system scan Configuration file..................: C:\program files (x86)\avira\antivir desktop\sysscan.avp Reporting...........................: default Primary action......................: Interactive Secondary action....................: Ignore Scan master boot sector.............: on Scan boot sector....................: on Boot sectors........................: C:, D:, Process scan........................: on Extended process scan...............: on Scan registry.......................: on Search for rootkits.................: on Integrity checking of system files..: off Scan all files......................: All files Scan archives.......................: on Limit recursion depth...............: 20 Smart extensions....................: on Macrovirus heuristic................: on File heuristic......................: extended Start of the scan: Sonntag, 13. Dezember 2015 19:46 Start scanning boot sectors: Boot sector 'HDD0(C:, D:)' [INFO] No virus was found! Starting search for hidden objects. Error in ARK library The scan of running processes will be started: Scan process 'svchost.exe' - '45' Module(s) have been scanned Scan process 'svchost.exe' - '28' Module(s) have been scanned Scan process 'dwm.exe' - '40' Module(s) have been scanned Scan process 'svchost.exe' - '106' Module(s) have been scanned Scan process 'svchost.exe' - '183' Module(s) have been scanned Scan process 'svchost.exe' - '76' Module(s) have been scanned Scan process 'svchost.exe' - '111' Module(s) have been scanned Scan process 'svchost.exe' - '69' Module(s) have been scanned Scan process 'svchost.exe' - '90' Module(s) have been scanned Scan process 'WLANExt.exe' - '36' Module(s) have been scanned Scan process 'conhost.exe' - '12' Module(s) have been scanned Scan process 'spoolsv.exe' - '93' Module(s) have been scanned Scan process 'sched.exe' - '82' Module(s) have been scanned Scan process 'avguard.exe' - '118' Module(s) have been scanned Scan process 'svchost.exe' - '62' Module(s) have been scanned Scan process 'dashost.exe' - '43' Module(s) have been scanned Scan process 'DnsBlockUpdateSvc.exe' - '71' Module(s) have been scanned Scan process 'DptfParticipantProcessorService.exe' - '17' Module(s) have been scanned Scan process 'DptfPolicyCriticalService.exe' - '17' Module(s) have been scanned Scan process 'DptfPolicyLpmService.exe' - '16' Module(s) have been scanned Scan process 'ihpmServer.exe' - '54' Module(s) have been scanned Scan process 'HeciServer.exe' - '26' Module(s) have been scanned Scan process 'svchost.exe' - '39' Module(s) have been scanned Scan process 'avshadow.exe' - '29' Module(s) have been scanned Scan process 'avmailc7.exe' - '44' Module(s) have been scanned Scan process 'avwebg7.exe' - '63' Module(s) have been scanned Scan process 'WUDFHost.exe' - '34' Module(s) have been scanned Scan process 'svchost.exe' - '63' Module(s) have been scanned Scan process 'taskhostex.exe' - '49' Module(s) have been scanned Scan process 'Explorer.EXE' - '198' Module(s) have been scanned Scan process 'TabTip.exe' - '45' Module(s) have been scanned Scan process 'TabTip32.exe' - '21' Module(s) have been scanned Scan process 'SearchIndexer.exe' - '61' Module(s) have been scanned Scan process 'DptfPolicyLpmServiceHelper.exe' - '13' Module(s) have been scanned Scan process 'RtkNGUI64.exe' - '43' Module(s) have been scanned Scan process 'igfxtray.exe' - '33' Module(s) have been scanned Scan process 'igfxsrvc.exe' - '34' Module(s) have been scanned Scan process 'hkcmd.exe' - '31' Module(s) have been scanned Scan process 'igfxpers.exe' - '34' Module(s) have been scanned Scan process 'InputPersonalization.exe' - '50' Module(s) have been scanned Scan process 'avgnt.exe' - '125' Module(s) have been scanned Scan process 'RuntimeBroker.exe' - '28' Module(s) have been scanned Scan process 'jusched.exe' - '47' Module(s) have been scanned Scan process 'DnsBlockTray.exe' - '32' Module(s) have been scanned Scan process 'firefox.exe' - '160' Module(s) have been scanned Scan process 'plugin-container.exe' - '79' Module(s) have been scanned Scan process 'FlashPlayerPlugin_20_0_0_235.exe' - '50' Module(s) have been scanned Scan process 'FlashPlayerPlugin_20_0_0_235.exe' - '69' Module(s) have been scanned Scan process 'jhi_service.exe' - '35' Module(s) have been scanned Scan process 'wmiprvse.exe' - '28' Module(s) have been scanned Scan process 'SearchProtocolHost.exe' - '37' Module(s) have been scanned Scan process 'svchost.exe' - '36' Module(s) have been scanned Scan process 'avcenter.exe' - '133' Module(s) have been scanned Scan process 'avscan.exe' - '114' Module(s) have been scanned Scan process 'vssvc.exe' - '39' Module(s) have been scanned Scan process 'SearchFilterHost.exe' - '26' Module(s) have been scanned Scan process 'wininit.exe' - '15' Module(s) have been scanned Scan process 'winlogon.exe' - '28' Module(s) have been scanned Scan process 'lsass.exe' - '59' Module(s) have been scanned Starting to scan executable files (registry): The registry was scanned ( '1230' files ). Starting the file scan: Begin scan in 'C:\' C:\swapfile.sys [WARNING] The file could not be opened! C:\Windows\SysWOW64\MQG4DECD.DLL [DETECTION] Is the TR/FireHooker.1825 Trojan Begin scan in 'D:\' Search path D:\ could not be opened! Unknown error <-2144272384> Beginning disinfection: C:\Windows\SysWOW64\MQG4DECD.DLL [DETECTION] Is the TR/FireHooker.1825 Trojan [NOTE] The file was moved to the quarantine directory under the name '4b9d4108.qua'! End of the scan: Sonntag, 13. Dezember 2015 20:14 Used time: 27:34 Minute(s) The scan has been done completely. 35168 Scanned directories 475120 Files were scanned 1 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 Files were deleted 0 Viruses and unwanted programs were repaired 1 Files were moved to quarantine 0 Files were renamed 1 Files cannot be scanned 475118 Files not concerned 6666 Archives were scanned 1 Warnings 1 Notes 919 Objects were scanned with rootkit scan 0 Hidden objects were found FRST: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-12-2015 01 Ran by User (administrator) on ELITEPAD1000 (13-12-2015 19:41:36) Running from C:\Users\User\Downloads Loaded Profiles: User (Available Profiles: User) Platform: Windows 8.1 Enterprise (X64) Language: Englisch (Vereinigte Staaten) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Windows\System32\DnsBlockUpdateSvc.exe (Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe (Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe (Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe () C:\Program Files (x86)\RayDld\ihpmServer.exe (Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe (Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\AP\RtkNGUI64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\DnsBlock\DnsBlockTray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_20_0_0_235.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_20_0_0_235.exe (Intel Corporation) C:\Program Files (x86)\Intel\TXE Components\DAL\jhi_service.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [hpdfe] => C:\Program Files\Hewlett-Packard\Shared\hpdfe.exe [325816 2014-01-03] (Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [70656 2014-01-20] (Intel Corporation) HKLM\...\Run: [RtkNGUI] => C:\Program Files\Realtek\Audio\AP\RtkNGUI64.exe [3318488 2014-01-13] (Realtek Semiconductor) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [738224 2015-10-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation) HKLM-x32\...\Run: [DnsBlock] => C:\Program Files (x86)\DnsBlock\DnsBlockTray.exe [826912 2015-11-15] () Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <======= ATTENTION (Restriction - ProxySettings) Winsock: Catalog5 05 C:\Windows\SysWOW64\DnsBlockA.dll [343584 2015-11-15] (DnsBlock) Winsock: Catalog5 09 C:\Windows\SysWOW64\DnsBlockB.dll [343584 2015-11-15] (DnsBlock) Winsock: Catalog5-x64 05 C:\Windows\system32\DnsBlockA.dll [434208 2015-11-15] (DnsBlock) Winsock: Catalog5-x64 09 C:\Windows\system32\DnsBlockB.dll [433696 2015-11-15] (DnsBlock) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{956F45A2-A224-4257-9411-009FC141564F}: [DhcpNameServer] 192.168.2.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKU\S-1-5-21-2038875719-2975076231-4046231055-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartpageing.com/?type=hp&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartpageing.com/?type=hp&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartpageing.com/web/?type=ds&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartpageing.com/web/?type=ds&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartpageing.com/?type=hp&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartpageing.com/?type=hp&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartpageing.com/web/?type=ds&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartpageing.com/web/?type=ds&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1&q={searchTerms} HKU\S-1-5-21-2038875719-2975076231-4046231055-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartpageing.com/?type=hp&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1 HKU\S-1-5-21-2038875719-2975076231-4046231055-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartpageing.com/?type=hp&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKLM -> {6374D37B-8A33-4EFF-A0E8-6B989841AAEB} URL = hxxp://www.startseite24.net/?q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartpageing.com/web/?type=ds&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartpageing.com/web/?type=ds&ts=1447612330&z=2230cbfe353bc0d263ccc07g9zdz3m4qbg9oac0c9e&from=cvs2&uid=3219913727_198264_5cc4e3a1&q={searchTerms} SearchScopes: HKU\S-1-5-21-2038875719-2975076231-4046231055-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKU\S-1-5-21-2038875719-2975076231-4046231055-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKU\S-1-5-21-2038875719-2975076231-4046231055-1001 -> {6374D37B-8A33-4EFF-A0E8-6B989841AAEB} URL = hxxp://www.startseite24.net/?q={searchTerms} BHO: DownloadProtect Extension -> {C654F3FE-8E84-4BB7-87CF-8D9171FC3C73} -> C:\Program Files\{4DDEF163-FE2A-4ACF-A182-B88A178C8B95}\{D82673AE-001A-4382-A7EE-672D11F49BD6}.bin [2015-12-13] (Download Protect) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-28] (Oracle Corporation) BHO-x32: DownloadProtect Extension -> {C654F3FE-8E84-4BB7-87CF-8D9171FC3C73} -> C:\Program Files (x86)\{C94231EC-66A5-4320-B097-484B32511BAD}\{43BCE9FD-310B-48A4-8BE8-70E7EC3EECCE}.bin [2015-12-13] (Download Protect) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-28] (Oracle Corporation) FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\zhkchf5r.default-1447613874437 FF DefaultSearchEngine: google FF DefaultSearchUrl: hxxp://www.google.de/search?hl=de&gl=de&lr=&ie=utf-8&oe=utf-8&meta=lr=lang_de&q= FF SelectedSearchEngine: Google FF SelectedSearchEngine: google FF Homepage: hxxp://www.google.de?hl=de&gl=de FF Keyword.URL: hxxp://www.google.de/search?hl=de&gl=de&lr=&ie=UTF-8&oe=UTF-8&meta=lr=lang_de&q= FF Keyword.URL: hxxp://www.google.de/search?hl=de&gl=de&lr=&ie=utf-8&oe=utf-8&meta=lr=lang_de&q= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-08] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-08] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\TXE Components\IPT\npIntelWebAPIIPT.dll [2013-07-12] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\TXE Components\IPT\npIntelWebAPIUpdater.dll [2013-07-12] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-28] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-28] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF user.js: detected! => C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\zhkchf5r.default-1447613874437\user.js [2015-12-13] FF HKLM-x32\...\Firefox\Extensions: [{08B7BA11-BBB8-4481-949B-4C83D76A431A}] - C:\Windows\Installer\{69F373F3-5013-4B60-913E-15559F252C35}\{08B7BA11-BBB8-4481-949B-4C83D76A431A}.xpi FF Extension: Download Protect - C:\Windows\Installer\{69F373F3-5013-4B60-913E-15559F252C35}\{08B7BA11-BBB8-4481-949B-4C83D76A431A}.xpi [2015-12-11] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [835616 2015-10-24] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [456528 2015-10-24] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [456528 2015-10-24] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1014288 2015-10-24] (Avira Operations GmbH & Co. KG) S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2013-11-14] (Broadcom Corporation.) R2 DnsBlockUpdateSvc; C:\Windows\system32\DnsBlockUpdateSvc.exe [151072 2015-11-15] () R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [80384 2014-01-20] (Intel Corporation) R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [92672 2014-01-20] (Intel Corporation) R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [88064 2014-01-20] (Intel Corporation) R2 ihpmServer; C:\Program Files (x86)\RayDld\ihpmServer.exe [271464 2015-11-10] () R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\TXE Components\DAL\jhi_service.exe [168216 2014-01-15] (Intel Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation) S3 hpqwmiex; "C:\Users\User\AppData\Roaming\Hewlett-Packard\hpqwmiex.exe" [X] ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [137800 2015-10-24] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [148632 2015-09-28] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43576 2015-05-29] (Avira Operations GmbH & Co. KG) R3 BCMSDH43XX; C:\Windows\system32\DRIVERS\bcmdhd63.sys [366808 2013-10-16] (Broadcom Corp) R3 BthMini; C:\Windows\System32\Drivers\BTHMINI.sys [31744 2014-10-29] (Microsoft Corporation) R3 BtwSerialBus; C:\Windows\system32\DRIVERS\BtwSerialBus.sys [150744 2013-09-10] (Broadcom Corporation.) R3 camera; C:\Windows\system32\DRIVERS\camera.sys [479232 2014-01-20] (Intel Corporation) R3 DASL; C:\Windows\system32\DRIVERS\DASL64.sys [86200 2014-01-03] (Hewlett-Packard) R3 DptfDevDisplay; C:\Windows\system32\DRIVERS\DptfDevDisplay.sys [29424 2014-01-20] (Intel Corporation) R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [42224 2014-01-20] (Intel Corporation) R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [94960 2014-01-20] (Intel Corporation) R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [234736 2014-01-20] (Intel Corporation) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation) R3 GPIO; C:\Windows\System32\drivers\iaiogpioe.sys [31232 2014-01-20] (Intel Corporation) R3 GpioVirtual; C:\Windows\System32\drivers\iaiogpiovirtual.sys [21504 2014-01-20] (Intel Corporation) S3 gwiopm; C:\Program Files (x86)\Slotman\gwiopm.sys [3904 1998-06-03] () [File not signed] R3 iaioi2c; C:\Windows\System32\drivers\iaioi2ce.sys [69632 2014-01-20] (Intel Corporation) R3 iaiospi; C:\Windows\System32\drivers\iaiospi.sys [65024 2014-01-20] (Intel Corporation) R3 iaiouart; C:\Windows\System32\drivers\iaiouart.sys [101376 2014-01-20] (Intel Corporation) R3 imx175; C:\Windows\system32\DRIVERS\imx175.sys [73728 2014-01-20] (Intel Corporation) R3 IntelSST; C:\Windows\system32\drivers\isstrtc.sys [312320 2014-01-20] (Intel(R) Corporation) S3 LAN9500; C:\Windows\system32\DRIVERS\lan9500-x64-n630f.sys [83968 2014-08-19] (SMSC) R3 Lm3554; C:\Windows\System32\drivers\lm3554.sys [31232 2014-01-20] (Intel Corporation) R0 MBI; C:\Windows\System32\drivers\MBI.sys [27600 2014-01-20] (Intel Corporation) R3 ov2722; C:\Windows\System32\drivers\ov2722.sys [53760 2014-01-20] (Intel Corporation) R3 PMIC; C:\Windows\System32\drivers\PMIC.sys [57344 2014-01-20] (Intel Corporation) R3 rtii2sac; C:\Windows\system32\DRIVERS\rtii2sac.sys [192216 2014-01-13] (Realtek Semiconductor Corp.) R3 SensorsServiceDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation) R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88080 2014-01-20] (Intel Corporation) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation) R3 wmbclass; C:\Windows\system32\DRIVERS\wmbclass.sys [268288 2014-03-18] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-12-13 19:41 - 2015-12-13 19:41 - 00018051 _____ C:\Users\User\Downloads\FRST.txt 2015-12-13 19:41 - 2015-12-13 19:41 - 00000000 ____D C:\FRST 2015-12-13 19:40 - 2015-12-13 19:41 - 02369536 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe 2015-12-13 19:39 - 2015-12-13 19:39 - 01720320 _____ (Farbar) C:\Users\User\Downloads\FRST.exe 2015-12-13 19:37 - 2015-12-13 19:37 - 00000000 ____D C:\Program Files\{4DDEF163-FE2A-4ACF-A182-B88A178C8B95} 2015-12-13 19:37 - 2015-12-13 19:37 - 00000000 ____D C:\Program Files (x86)\{C94231EC-66A5-4320-B097-484B32511BAD} 2015-12-11 15:00 - 2015-12-11 15:00 - 00005120 _____ C:\Windows\SysWOW64\RotMgr32.dll 2015-12-08 21:25 - 2015-12-08 21:26 - 00608470 _____ C:\Users\User\Downloads\Slotman_1131a_Help_e.zip 2015-12-08 20:58 - 2015-12-08 21:00 - 00000000 ____D C:\Program Files (x86)\Slotman 2015-12-08 20:58 - 2015-12-08 20:58 - 02063652 _____ C:\Users\User\Downloads\Slotman_1131a_e.exe 2015-12-08 20:58 - 2015-12-08 20:58 - 00001007 _____ C:\Users\User\Desktop\Slotman.lnk 2015-12-08 20:58 - 2015-12-08 20:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Slotman 2015-12-08 20:37 - 2015-12-08 20:37 - 00499994 _____ C:\Users\User\Downloads\Slotman608_Doku.zip 2015-12-08 20:37 - 2015-12-08 20:37 - 00000000 ____D C:\Users\User\Downloads\Slotman608_Doku 2015-12-08 20:37 - 2015-11-05 09:59 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2015-12-08 20:36 - 2015-11-11 17:21 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-12-08 20:36 - 2015-11-11 17:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-12-08 20:36 - 2015-11-11 16:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-12-08 20:36 - 2015-11-11 16:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2015-12-08 20:36 - 2015-11-11 16:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-12-08 20:36 - 2015-11-11 16:12 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-12-08 20:36 - 2015-11-10 01:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-12-08 20:36 - 2015-11-10 01:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-12-08 20:36 - 2015-11-10 01:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-12-08 20:36 - 2015-11-10 01:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-12-08 20:36 - 2015-11-10 01:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-12-08 20:36 - 2015-11-10 00:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-12-08 20:36 - 2015-11-10 00:41 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2015-12-08 20:36 - 2015-11-10 00:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-12-08 20:36 - 2015-11-10 00:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-12-08 20:36 - 2015-11-10 00:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-12-08 20:36 - 2015-11-10 00:36 - 00325632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-12-08 20:36 - 2015-11-10 00:25 - 01048576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2015-12-08 20:36 - 2015-11-10 00:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-12-08 20:36 - 2015-11-10 00:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-12-08 20:36 - 2015-11-10 00:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-12-08 20:36 - 2015-11-08 23:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-12-08 20:36 - 2015-11-08 23:15 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-12-08 20:36 - 2015-11-08 23:04 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-12-08 20:36 - 2015-11-08 23:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-12-08 20:36 - 2015-11-08 23:01 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-12-08 20:36 - 2015-11-08 22:32 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-12-08 20:36 - 2015-11-08 22:32 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2015-12-08 20:36 - 2015-11-08 22:25 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-12-08 20:36 - 2015-11-08 22:18 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-12-08 20:36 - 2015-11-08 22:16 - 00372224 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-12-08 20:36 - 2015-11-08 22:15 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-12-08 20:36 - 2015-11-08 22:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-12-08 20:36 - 2015-11-08 22:14 - 14456832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-12-08 20:36 - 2015-11-08 22:13 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-12-08 20:36 - 2015-11-08 21:53 - 02880000 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2015-12-08 20:36 - 2015-11-08 21:53 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-12-08 20:36 - 2015-11-08 21:41 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-12-08 20:36 - 2015-11-08 21:30 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-12-08 20:35 - 2015-11-22 07:59 - 07455064 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-12-08 20:35 - 2015-11-22 07:59 - 01735000 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-12-08 20:35 - 2015-11-22 07:59 - 01659568 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2015-12-08 20:35 - 2015-11-22 07:59 - 01519592 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-12-08 20:35 - 2015-11-22 07:59 - 01487008 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2015-12-08 20:35 - 2015-11-22 07:59 - 01355848 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-12-08 20:35 - 2015-11-22 07:58 - 01499920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-12-08 20:35 - 2015-11-21 19:32 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-12-08 20:35 - 2015-11-21 18:50 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-12-08 20:35 - 2015-11-21 17:59 - 01706496 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2015-12-08 20:35 - 2015-11-21 17:49 - 01344000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll 2015-12-08 20:35 - 2015-11-21 17:47 - 00522240 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll 2015-12-08 20:35 - 2015-11-21 17:40 - 00414208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll 2015-12-08 20:35 - 2015-11-20 23:47 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-12-08 20:35 - 2015-11-20 19:18 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-12-08 20:35 - 2015-11-20 17:58 - 03706880 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-12-08 20:35 - 2015-11-20 17:47 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-12-08 20:35 - 2015-11-20 17:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-12-08 20:35 - 2015-11-20 17:44 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2015-12-08 20:35 - 2015-11-20 17:44 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-12-08 20:35 - 2015-11-20 17:43 - 00897024 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-12-08 20:35 - 2015-11-20 17:42 - 02243584 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-12-08 20:35 - 2015-11-20 17:30 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-12-08 20:35 - 2015-11-20 17:29 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-12-08 20:35 - 2015-11-20 17:28 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-12-08 20:35 - 2015-11-20 17:27 - 00726528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-12-08 20:35 - 2015-11-09 01:41 - 01540728 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2015-12-08 20:35 - 2015-11-08 23:30 - 04176384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-12-08 20:35 - 2015-11-08 22:23 - 01994752 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-12-08 20:35 - 2015-11-08 22:13 - 01383936 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-12-08 20:35 - 2015-11-08 22:01 - 01753600 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2015-12-08 20:35 - 2015-11-08 21:52 - 01559552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2015-12-08 20:35 - 2015-11-08 21:48 - 01376256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2015-12-08 20:35 - 2015-11-08 21:42 - 01490944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2015-12-08 20:35 - 2015-10-28 16:49 - 02775552 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-12-08 20:35 - 2015-10-28 16:29 - 02462720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2015-12-08 20:35 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll 2015-12-08 20:35 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZST.DLL 2015-12-08 20:35 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL 2015-12-08 20:35 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL 2015-12-08 20:35 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll 2015-12-08 20:35 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZST.DLL 2015-12-08 20:35 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL 2015-12-08 20:35 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL 2015-12-08 20:35 - 2015-10-22 17:21 - 01200128 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll 2015-12-08 20:35 - 2015-10-22 17:21 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\GlobCollationHost.dll 2015-12-08 20:35 - 2015-10-22 16:58 - 00868864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll 2015-12-08 20:35 - 2015-10-22 16:58 - 00200704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GlobCollationHost.dll 2015-12-08 20:35 - 2015-10-22 15:08 - 00513456 _____ C:\Windows\SysWOW64\locale.nls 2015-12-08 20:35 - 2015-10-22 15:08 - 00513456 _____ C:\Windows\system32\locale.nls 2015-12-08 20:35 - 2015-10-11 07:34 - 00468824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2015-12-08 20:35 - 2015-10-11 07:34 - 00462168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2015-12-08 20:35 - 2015-10-11 07:34 - 00443224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2015-12-08 20:35 - 2015-10-11 07:34 - 00092504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2015-12-08 20:35 - 2015-10-11 07:34 - 00027992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2015-12-08 20:35 - 2015-10-10 19:41 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2015-12-08 20:35 - 2015-10-10 19:41 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2015-12-08 20:35 - 2015-10-10 19:40 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winusb.sys 2015-12-08 20:35 - 2015-10-10 18:20 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll 2015-12-08 20:35 - 2015-10-08 17:11 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\PCPKsp.dll 2015-12-08 20:35 - 2015-10-08 16:50 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PCPKsp.dll 2015-12-08 20:35 - 2015-10-03 20:41 - 01385280 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-12-08 20:35 - 2015-10-03 20:41 - 01124384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2015-12-08 20:34 - 2015-10-05 19:28 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\wininit.exe 2015-12-08 20:34 - 2015-10-05 19:25 - 00572928 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2015-12-08 20:30 - 2015-12-08 20:38 - 00000000 ____D C:\Users\User\Documents\Slotman608 2015-12-05 14:14 - 2015-12-05 14:27 - 00044544 _____ C:\Users\User\Desktop\Mitgliederliste f Startliste.xls 2015-12-02 09:12 - 2015-12-02 09:12 - 02298424 ____T C:\Users\User\Documents\Weihnachtsfeier 2015.oxps 2015-12-02 09:12 - 2015-12-02 09:12 - 00000000 ____D C:\Users\User\AppData\LocalLow\Temp 2015-11-29 13:41 - 2015-11-29 13:42 - 00061440 _____ C:\Users\User\Desktop\Mitgliederliste master.xls 2015-11-29 08:41 - 2015-11-29 08:41 - 05626824 _____ C:\Users\User\Downloads\Update SEPA Account Converter.exe 2015-11-29 08:41 - 2015-11-29 08:41 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Star Finanz 2015-11-29 08:41 - 2015-11-29 08:41 - 00000000 ____D C:\Users\User\AppData\Local\Downloaded Installations 2015-11-29 08:40 - 2015-11-29 08:41 - 00002429 _____ C:\Users\User\Desktop\SEPA Account Converter.lnk 2015-11-29 08:40 - 2015-11-29 08:40 - 00000000 ____D C:\Program Files (x86)\BIVG Hannover 2015-11-29 08:39 - 2015-11-29 08:39 - 01734144 _____ C:\Users\User\Downloads\sepa_account_converter.msi 2015-11-15 20:07 - 2015-11-15 20:07 - 00000000 ____D C:\Users\User\AppData\Local\Macromedia 2015-11-15 20:06 - 2015-12-13 19:04 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-11-15 20:06 - 2015-12-08 21:01 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-11-15 20:05 - 2015-11-23 18:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-11-15 19:57 - 2015-11-15 19:57 - 00000000 ____D C:\Users\User\Desktop\Alte Firefox-Daten 2015-11-15 19:37 - 2015-11-15 19:37 - 00005120 _____ C:\Windows\SysWOW64\MQG4DECD.DLL 2015-11-15 19:35 - 2015-11-15 20:07 - 00000000 ____D C:\Users\User\AppData\Local\Adobe 2015-11-15 19:35 - 2015-11-15 19:35 - 00000000 ____D C:\Users\User\AppData\Roaming\dlg 2015-11-15 19:34 - 2015-12-13 19:37 - 00000680 __RSH C:\ProgramData\ntuser.pol 2015-11-15 19:34 - 2015-12-06 14:57 - 00000000 ____D C:\Users\User\AppData\Roaming\AVG 2015-11-15 19:34 - 2015-12-06 14:57 - 00000000 ____D C:\Program Files (x86)\AVG 2015-11-15 19:33 - 2015-12-06 14:57 - 00000000 ____D C:\Users\User\AppData\Local\Avg 2015-11-15 19:33 - 2015-12-06 14:57 - 00000000 ____D C:\ProgramData\AVG 2015-11-15 19:32 - 2015-11-15 20:00 - 00000000 ____D C:\Users\User\AppData\Roaming\istartpageing 2015-11-15 19:32 - 2015-11-15 19:34 - 00151072 _____ C:\Windows\system32\DnsBlockUpdateSvc.exe 2015-11-15 19:32 - 2015-11-15 19:32 - 00471968 _____ C:\Windows\SysWOW64\dns.block 2015-11-15 19:32 - 2015-11-15 19:32 - 00471968 _____ C:\Windows\system32\dns.block 2015-11-15 19:32 - 2015-11-15 19:32 - 00434208 _____ (DnsBlock) C:\Windows\system32\DnsBlockA.dll 2015-11-15 19:32 - 2015-11-15 19:32 - 00433696 _____ (DnsBlock) C:\Windows\system32\DnsBlockB.dll 2015-11-15 19:32 - 2015-11-15 19:32 - 00343584 _____ (DnsBlock) C:\Windows\SysWOW64\DnsBlockB.dll 2015-11-15 19:32 - 2015-11-15 19:32 - 00343584 _____ (DnsBlock) C:\Windows\SysWOW64\DnsBlockA.dll 2015-11-15 19:32 - 2015-11-15 19:32 - 00000000 ____D C:\Users\User\AppData\Local\DnsBlock 2015-11-15 19:32 - 2015-11-15 19:32 - 00000000 ____D C:\Program Files (x86)\RayDld 2015-11-15 19:32 - 2015-11-15 19:32 - 00000000 ____D C:\Program Files (x86)\DnsBlock 2015-11-15 19:30 - 2015-11-15 19:30 - 00569488 _____ C:\Users\User\Downloads\Adobe-Flash-Player_091.exe 2015-11-15 19:25 - 2015-09-29 13:24 - 00155480 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys 2015-11-15 19:25 - 2015-09-04 20:24 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys 2015-11-15 19:25 - 2015-08-28 23:20 - 00183368 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe 2015-11-15 19:25 - 2015-08-20 21:45 - 01380048 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-11-15 19:25 - 2015-08-20 18:48 - 01096704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-11-15 19:25 - 2014-11-05 02:41 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll 2015-11-15 19:25 - 2014-11-05 02:18 - 00507392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-12-13 19:41 - 2013-08-22 14:36 - 00000000 ____D C:\Windows 2015-12-13 19:40 - 2015-09-28 21:49 - 00764970 _____ C:\Windows\system32\perfh007.dat 2015-12-13 19:40 - 2015-09-28 21:49 - 00159884 _____ C:\Windows\system32\perfc007.dat 2015-12-13 19:40 - 2014-03-18 11:01 - 01776918 _____ C:\Windows\system32\PerfStringBackup.INI 2015-12-13 19:40 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\Inf 2015-12-13 19:35 - 2014-11-12 21:15 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2015-12-13 19:35 - 2014-11-12 21:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2015-12-13 19:35 - 2013-08-22 15:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-13 19:35 - 2013-08-22 15:44 - 00362544 _____ C:\Windows\system32\FNTCACHE.DAT 2015-12-13 19:26 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\BBI 2015-12-13 19:05 - 2014-03-18 12:24 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C6306504-C39E-4BE8-AF4F-BCBF392B09A0} 2015-12-10 12:20 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\AppReadiness 2015-12-08 21:52 - 2014-03-18 12:15 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2038875719-2975076231-4046231055-1001 2015-12-08 21:45 - 2013-08-22 16:20 - 00000000 ____D C:\Windows\CbsTemp 2015-12-08 21:44 - 2014-11-12 21:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-12-08 21:40 - 2014-11-12 20:52 - 00000000 ____D C:\Windows\system32\MRT 2015-12-08 21:37 - 2014-11-12 20:52 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-12-01 18:22 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\rescache 2015-12-01 18:19 - 2014-11-13 02:11 - 00826872 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-12-01 18:19 - 2014-11-13 02:11 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-12-01 17:51 - 2015-09-28 21:03 - 00000000 ____D C:\FCM 2015-11-23 18:05 - 2015-09-28 20:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-11-15 19:34 - 2013-08-22 16:36 - 00000000 ___HD C:\Windows\system32\GroupPolicy ==================== Files in the root of some directories ======= 2015-07-12 08:29 - 2015-07-12 08:30 - 0000010 _____ () C:\ProgramData\system_image_date.txt Some files in TEMP: ==================== C:\Users\User\AppData\Local\Temp\avgnt.exe C:\Users\User\AppData\Local\Temp\DseShExt-x64.dll C:\Users\User\AppData\Local\Temp\DseShExt-x86.dll C:\Users\User\AppData\Local\Temp\OpenOffice_4.1.1_Win_x86_install_de.exe C:\Users\User\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\User\AppData\Local\Temp\SDShelEx-x64.dll ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-12-05 13:41 ==================== End of FRST.txt ============================ Addition:FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version:12-12-2015 01 Vielen Dank schon mal. Gruß M. |
:hallo: Mein Name ist Dennis und ich werde dir bei der Bereinigung helfen. Bitte beachte, dass es ein paar Regeln gibt:
![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Schritt # 1: AttentionUninstaller Bitte lade dir die passende Version von AttentionUninstaller auf deinen Desktop: http://trojanerboard.eig14830.webspa.../icon/icon.png AttentionUninstaller 32-Bit | AttentionUninstaller 64-Bit Deaktiviere deinen Virenscanner, damit AttentionUninstaller sauber durchläuft! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: DNSBlock (HKLM\...\{7b5da7f5-de7d-4e00-b330-a2e08e460095}) (Version: 1.0.0 - NETNS GMBH)
Schritt # 2: AdwCleaner Downloade Dir bitte ![]()
Schritt # 3: FRST Und noch ein frisches FRST Log bitte. Schritt # 4: Bitte Posten
|
Hallo Dennis, vielen Dank für Deine Hilfe. Hier die Logs: AU: Code: 14.12.2015 09:24:07: Deinstallation gestartet... AdwCleaner: Code: # AdwCleaner v5.025 - Logfile created 14/12/2015 at 09:37:57 FRST: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-12-2015 01 Vielen Dank nochmal. Gruß M. |
Hi, Schritt # 1: ESET ESET Online Scanner
Schritt # 2: Frage Besteht das Problem immer noch? Schritt # 3: Bitte Posten
|
Hallo nochmal, hier das ESET-Log: Code: ESETSmartInstaller@High as downloader log: ja das Problem besteht leider immer noch. Avira hat den Trojaner während des ESET-Scans wieder gemeldet. gruß M. Hier der Report von Avira: Virus or unwanted program 'TR/FireHooker.1825 [trojan]' detected in file 'C:\Windows\SysWOW64\RotMgr32.dll. Action performed: Deny access |
Hi, Schritt # 1: FRST-Fix Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: Winsock: Catalog5 05 C:\Windows\system32\DnsBlockA.dll No File Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt # 2: Virustotal Bitte lasse die Datei aus der Code-Box bei Virustotal überprüfen.
Schritt # 3: TDSS-Killer Downloade dir bitte ![]()
Schritt # 4: FRST Und noch ein frisches FRST-Log bitte. Schritt # 5: Bitte Posten
|
Hi, hier das Fixlog von FRST: Code: Fix result of Farbar Recovery Scan Tool (x64) Version:12-12-2015 01 Zu Virustotal: Die dll-Datei kann nicht gefunden werden. Hab jetzt erstmal nicht weitergemacht |
Hi, wahrscheinlich hat Avira die gelöscht. Mach mal weiter bitte. |
Ok, hier der TDSS Killer Report. Er hat kein Rootkit gefunden. Code: 09:16:13.0683 0x01e8 TDSS rootkit removing tool 3.1.0.9 Dec 11 2015 22:49:12 FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-12-2015 01 Vielen Dank für Deine Mühe (muss man immer mal wieder sagen) Gruß M. |
Hi, kommt die Meldung immer noch? |
Hi, heute kam die Meldung bis jetzt nicht mehr. Gruß M. |
Hi, wart noch ein bisschen, gib mir morgen oder übermorgen bescheid obs endgültig weg ist :) |
ok, mach ich. Nochmal danke! |
Hi, wie schauts aus? :) |
Hi, also bis jetzt ist die Meldung nicht mehr gekommen. Ich geh mal davon aus, dass das Tablet geheilt ist. Vielen Dank nochmal Gruß M |
Alle Zeitangaben in WEZ +1. Es ist jetzt 05:50 Uhr. |
Copyright ©2000-2025, Trojaner-Board