Plagegeister aller Art und deren Bekämpfung: snapdo und searchnu nerven extrem

snapdo und searchnu nerven extrem

snapdo und searchnu nerven extrem

Hallo Forum,

ich habe mir beim Runterladen eines Dateikonvertierungsprogramms was eingefangen. Öffne ich meinen Chrome- Browser, öffnen sich ungefragt in einem jeweils neuen Reiter die Seiten "search.snapdo.com" und "www.searchnu.com".
Habe mein System mit Avira gescannt und nichts gefunden. Habe auch versucht, das System auf einen früheren Zustandspunkt zurück zu setzen. Das hat wohl geklappt, aber searchnu und snapdo sind geblieben.
Was kann ich tun? Vielen Dank schonmal im Voraus für die Hilfe.

/// TB-Ausbilder
snapdo und searchnu nerven extrem

snapdo und searchnu nerven extrem


starte bitte mit einem OTL-Scan wie folgt:

Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
  • Doppelklick auf die OTL.exe.
  • Unter Extra Registry, wähle bitte Use SafeList.
  • Setze den Haken bei Scan all Users.
  • Klicke nun auf Run Scan.
  • Wenn der Scan beendet ist, werden 2 Logfiles (OTL.txt und Extras.txt) erstellt.
  • Poste den Inhalt dieser Logfiles hier in den Thread.


snapdo und searchnu nerven extrem

snapdo und searchnu nerven extrem

OTL Logfile:
OTL logfile created on: 01.06.2013 11:47:39 - Run 2
OTL by OldTimer - Version     Folder = C:\Users\Familie B\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,91 Gb Total Physical Memory | 1,85 Gb Available Physical Memory | 47,28% Memory free
7,82 Gb Paging File | 5,49 Gb Available in Paging File | 70,18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 657,54 Gb Total Space | 567,96 Gb Free Space | 86,38% Space Free | Partition Type: NTFS
Drive D: | 37,99 Gb Total Space | 0,33 Gb Free Space | 0,86% Space Free | Partition Type: NTFS
Computer Name: FAMILIEB-PC | User Name: Familie B | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.05.30 16:19:11 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Familie B\Downloads\OTL.exe
PRC - [2013.05.24 20:57:47 | 000,047,896 | ---- | M] (WebCake LLC) -- C:\Users\Familie B\AppData\Roaming\WebCake\WebCakeDesktop.exe
PRC - [2013.05.24 20:57:47 | 000,023,552 | ---- | M] (WebCake LLC) -- C:\Program Files (x86)\WebCake\WebCakeDesktop.Updater.exe
PRC - [2013.05.23 20:10:52 | 028,712,088 | ---- | M] (Dropbox, Inc.) -- C:\Users\Familie B\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013.05.23 07:44:09 | 000,825,808 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013.05.15 18:58:47 | 000,389,016 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
PRC - [2013.05.10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.05.02 11:20:20 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013.04.01 19:57:53 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2013.04.01 19:57:39 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2013.03.15 16:32:11 | 000,542,800 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\taxaktuell.exe
PRC - [2012.10.09 00:36:45 | 001,433,600 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\KeePassX.exe
PRC - [2011.04.30 09:32:54 | 000,013,592 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011.04.14 18:17:18 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
PRC - [2011.02.24 03:04:54 | 003,402,760 | ---- | M] (Pegatron Corporation) -- C:\Program Files (x86)\PHotkey\POSD.exe
PRC - [2011.02.24 03:04:50 | 000,819,720 | ---- | M] (Pegatron Corporation) -- C:\Program Files (x86)\PHotkey\PHotkey.exe
PRC - [2011.02.22 22:20:21 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2011.02.22 22:20:17 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2011.02.15 18:01:48 | 000,019,968 | ---- | M] (Fork Ltd.) -- C:\Prey\platform\windows\cronsvc.exe
PRC - [2011.02.11 21:40:00 | 000,997,712 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2011.02.11 21:39:58 | 001,304,912 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2011.02.11 21:39:54 | 000,985,424 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
PRC - [2011.02.11 21:39:54 | 000,907,600 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2010.08.04 00:39:38 | 000,107,816 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
PRC - [2010.01.13 02:36:00 | 000,117,256 | R--- | M] () -- C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
PRC - [2009.12.19 00:40:48 | 000,104,968 | R--- | M] () -- C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
PRC - [2009.12.19 00:38:18 | 000,345,608 | R--- | M] (TODO: <Company name>) -- C:\Program Files (x86)\PHotkey\HCSynApi.exe
========== Modules (No Company Name) ==========
MOD - [2013.05.23 07:44:07 | 000,393,168 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
MOD - [2013.05.23 07:44:06 | 013,136,336 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
MOD - [2013.05.23 07:43:59 | 004,051,408 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll
MOD - [2013.05.23 07:43:06 | 000,599,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libglesv2.dll
MOD - [2013.05.23 07:43:05 | 000,124,368 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libegl.dll
MOD - [2013.05.23 07:43:03 | 001,597,392 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ffmpegsumo.dll
MOD - [2013.05.16 00:43:32 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll
MOD - [2013.05.16 00:43:06 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll
MOD - [2013.05.15 18:58:47 | 002,244,504 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
MOD - [2013.05.15 18:58:47 | 000,158,104 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
MOD - [2013.05.15 18:58:47 | 000,022,424 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
MOD - [2013.03.19 16:31:28 | 002,170,960 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wfvie13.dll
MOD - [2013.03.19 15:48:09 | 008,921,680 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wgui13.dll
MOD - [2013.03.18 17:13:09 | 001,492,048 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wmain13.dll
MOD - [2013.03.15 16:33:03 | 002,997,840 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wcore13.dll
MOD - [2013.03.15 16:33:01 | 006,761,552 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wkont13.dll
MOD - [2013.03.15 16:32:55 | 004,158,544 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wauff13.dll
MOD - [2013.03.15 16:32:55 | 001,313,872 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wfabu13.dll
MOD - [2013.03.15 16:32:48 | 001,245,184 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wimp13.dll
MOD - [2013.03.15 16:32:46 | 001,310,800 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wwerb13.dll
MOD - [2013.03.15 16:32:46 | 001,215,568 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\whau213.dll
MOD - [2013.03.15 16:32:41 | 001,559,120 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wbae413.dll
MOD - [2013.03.15 16:32:41 | 001,146,448 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\whau113.dll
MOD - [2013.03.15 16:32:40 | 004,940,368 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wbae113.dll
MOD - [2013.03.15 16:32:35 | 001,747,536 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wbae313.dll
MOD - [2013.03.15 16:32:32 | 001,367,632 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wbae213.dll
MOD - [2013.03.15 16:32:27 | 001,724,496 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wreli13.dll
MOD - [2013.03.15 16:32:26 | 001,607,248 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wsteu13.dll
MOD - [2013.03.15 16:32:25 | 000,321,104 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\rsguiwinapi48.dll
MOD - [2013.03.15 16:32:22 | 000,308,816 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\rscorewinapi48.dll
MOD - [2013.03.15 16:32:11 | 000,542,800 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\taxaktuell.exe
MOD - [2013.03.15 16:31:57 | 000,136,272 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\rsodbc48.dll
MOD - [2013.03.15 16:31:54 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\rsdcom48.dll
MOD - [2013.03.15 16:09:38 | 001,041,408 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\clucene-core.dll
MOD - [2013.03.13 22:48:52 | 024,978,944 | ---- | M] () -- C:\Users\Familie B\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2013.02.12 12:03:49 | 000,251,392 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\clucene-contribs-lib.dll
MOD - [2013.02.12 12:03:49 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\clucene-shared.dll
MOD - [2013.01.10 11:13:29 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013.01.10 11:13:07 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013.01.10 11:13:01 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013.01.10 11:12:52 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2012.11.14 01:32:50 | 003,558,400 | ---- | M] () -- C:\Users\Familie B\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2012.10.09 00:36:45 | 009,515,520 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\QtGui4.dll
MOD - [2012.10.09 00:36:45 | 002,415,104 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\QtCore4.dll
MOD - [2012.10.09 00:36:45 | 001,433,600 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\KeePassX.exe
MOD - [2012.10.09 00:36:45 | 000,398,336 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\QtXml4.dll
MOD - [2012.10.09 00:36:45 | 000,350,720 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\imageformats\qmng4.dll
MOD - [2012.10.09 00:36:45 | 000,192,000 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\imageformats\qjpeg4.dll
MOD - [2012.10.09 00:36:45 | 000,082,944 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\imageformats\qgif4.dll
MOD - [2012.10.09 00:36:45 | 000,081,920 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\imageformats\qico4.dll
MOD - [2012.10.09 00:36:45 | 000,043,008 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\libgcc_s_dw2-1.dll
MOD - [2012.10.09 00:36:45 | 000,011,362 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\mingwm10.dll
MOD - [2012.10.05 12:53:24 | 003,198,976 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System\\System.dll
MOD - [2010.11.21 05:24:32 | 000,425,984 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration\\System.Configuration.dll
MOD - [2010.11.21 05:23:48 | 002,048,000 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml\\System.Xml.dll
MOD - [2010.11.13 01:26:08 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\\mscorlib.resources.dll
MOD - [2010.08.04 00:39:38 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2010.08.04 00:39:32 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
--- --- ---

OTL Logfile:
OTL Extras logfile created on: 01.06.2013 11:47:39 - Run 2
OTL by OldTimer - Version     Folder = C:\Users\Familie B\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,91 Gb Total Physical Memory | 1,85 Gb Available Physical Memory | 47,28% Memory free
7,82 Gb Paging File | 5,49 Gb Available in Paging File | 70,18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 657,54 Gb Total Space | 567,96 Gb Free Space | 86,38% Space Free | Partition Type: NTFS
Drive D: | 37,99 Gb Total Space | 0,33 Gb Free Space | 0,86% Space Free | Partition Type: NTFS
Computer Name: FAMILIEB-PC | User Name: Familie B | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
/// TB-Ausbilder
snapdo und searchnu nerven extrem

snapdo und searchnu nerven extrem


mach bitte mal das:

Schritt 1

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.
FF - prefs.js..browser.startup.homepage: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=hp&installDate=25/05/2013"
FF - prefs.js..keyword.URL: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=ds&installDate=25/05/2013&q="
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\..\SearchScopes\{1697AD61-0E75-4EDA-AAF4-77D13F362209}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=bdf2d80e-7f17-4267-9f9e-d84ef484a69e&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\..\SearchScopes\{5745C29C-E057-4BB2-BB00-000407154C49}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=bdf2d80e-7f17-4267-9f9e-d84ef484a69e&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\..\SearchScopes\{5AF26995-A704-4810-87F3-5EF2F5D96C84}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=bdf2d80e-7f17-4267-9f9e-d84ef484a69e&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\..\SearchScopes\{5FDDD75A-D2D7-4FA0-88FD-3F9828DF5BCB}: "URL" = hxxp://www.google.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E676F6F676C652E636F6D2F7365617263683F713D7B7365617263685465726D737D26726C733D636F6D2E6D6963726F736F66743A7B6C616E67756167657D3A7B72656665727265723A736F757263653F7D2669653D7B696E707574456E636F64696E677D266F653D7B6F7574707574456E636F64696E677D26736F7572636569643D69653726726C7A3D3149374D444E435F656E4445333933&st={searchTerms}&clid=bdf2d80e-7f17-4267-9f9e-d84ef484a69e&pid=fotofreeware&k=0
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\..\SearchScopes\{8CF37F23-4809-47A0-843F-95C598520ADC}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=bdf2d80e-7f17-4267-9f9e-d84ef484a69e&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\..\SearchScopes\{B57F6711-428C-4725-877E-D7BF71AEEF9E}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=bdf2d80e-7f17-4267-9f9e-d84ef484a69e&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\..\SearchScopes\{E5F75748-D279-4E30-B0E4-20ED0BE28E65}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=bdf2d80e-7f17-4267-9f9e-d84ef484a69e&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=ds&q={searchTerms}&installDate={installDate}
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=ds&q={searchTerms}&installDate={installDate}
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=hp&installDate={installDate}
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=ds&q={searchTerms}&installDate={installDate}
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=ds&q={searchTerms}&installDate={installDate}

  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread

Schritt 2
  • Öffne Google Chrome.
  • Klicke rechts oben auf Google Chrome anpassen.
  • Wähle Einstellungen.
  • Unter Beim Start > Wähle "Bestimmte Seite oder Seiten öffnen" aus und klicke auf Seiten festlegen.
  • Gib die gewünschte Startseite ein und bestätige mit Ok.
  • Schliesse den Google Chrome.

Schritt 3

Starte bitte die OTL.exe.
  • Setze den Haken bei Scan all Users.
  • Drücke auf den Quick Scan Button.
  • Poste den Inhalt von OTL.txt hier in den Thread.

Bitte poste in deiner nächsten Antwort:
  • Fixlog von OTL
  • Log von OTL

Alt 02.06.2013, 18:38   #5
snapdo und searchnu nerven extrem

snapdo und searchnu nerven extrem

All processes killed
========== OTL ==========
Prefs.js: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=hp&installDate=25/05/2013" removed from browser.startup.homepage
Prefs.js: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=ds&installDate=25/05/2013&q=" removed from keyword.URL
Registry key HKEY_USERS\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1697AD61-0E75-4EDA-AAF4-77D13F362209}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1697AD61-0E75-4EDA-AAF4-77D13F362209}\ not found.
Registry key HKEY_USERS\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Internet Explorer\SearchScopes\{5745C29C-E057-4BB2-BB00-000407154C49}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5745C29C-E057-4BB2-BB00-000407154C49}\ not found.
Registry key HKEY_USERS\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Internet Explorer\SearchScopes\{5AF26995-A704-4810-87F3-5EF2F5D96C84}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AF26995-A704-4810-87F3-5EF2F5D96C84}\ not found.
Registry key HKEY_USERS\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Internet Explorer\SearchScopes\{5FDDD75A-D2D7-4FA0-88FD-3F9828DF5BCB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDDD75A-D2D7-4FA0-88FD-3F9828DF5BCB}\ not found.
Registry key HKEY_USERS\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Internet Explorer\SearchScopes\{8CF37F23-4809-47A0-843F-95C598520ADC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CF37F23-4809-47A0-843F-95C598520ADC}\ not found.
Registry key HKEY_USERS\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B57F6711-428C-4725-877E-D7BF71AEEF9E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B57F6711-428C-4725-877E-D7BF71AEEF9E}\ not found.
Registry key HKEY_USERS\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E5F75748-D279-4E30-B0E4-20ED0BE28E65}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E5F75748-D279-4E30-B0E4-20ED0BE28E65}\ not found.
HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\SearchDefaultBranded| /E : value set successfully!
HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
========== COMMANDS ==========


User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56466 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Familie B
->Temp folder emptied: 85786238 bytes
->Temporary Internet Files folder emptied: 28292493 bytes
->Java cache emptied: 149910216 bytes
->FireFox cache emptied: 37062185 bytes
->Google Chrome cache emptied: 338278651 bytes
->Flash cache emptied: 57388 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3648 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67832 bytes
RecycleBin emptied: 464905 bytes

Total Files Cleaned = 610,00 mb

OTL by OldTimer - Version log created on 06022013_190630

Files\Folders moved on Reboot...
C:\Users\Familie B\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

OTL Logfile:
OTL logfile created on: 02.06.2013 19:19:57 - Run 3
OTL by OldTimer - Version     Folder = C:\Users\Familie B\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,91 Gb Total Physical Memory | 1,72 Gb Available Physical Memory | 43,96% Memory free
7,82 Gb Paging File | 5,44 Gb Available in Paging File | 69,51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 657,54 Gb Total Space | 568,22 Gb Free Space | 86,42% Space Free | Partition Type: NTFS
Drive D: | 37,99 Gb Total Space | 0,02 Gb Free Space | 0,04% Space Free | Partition Type: NTFS
Computer Name: FAMILIEB-PC | User Name: Familie B | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: {eadb1184-3305-4914-9490-1d074f61546d}:1.0
FF - prefs.js..extensions.enabledAddons: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:
FF - prefs.js..browser.startup.homepage: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=hp&installDate=25/05/2013"
FF - prefs.js..keyword.URL: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=ds&installDate=25/05/2013&q="
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.08 18:37:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.16 14:46:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.05.15 18:58:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.05.15 18:58:43 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2013.05.27 01:09:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie B\AppData\Roaming\mozilla\Extensions
[2013.05.30 15:50:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions
[2013.05.30 15:38:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions\{eadb1184-3305-4914-9490-1d074f61546d}
[2013.05.30 15:38:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions\plugin@getwebcake.com
[2012.10.19 13:42:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.03.21 01:58:45 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.06.28 10:28:54 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.09.07 08:57:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.10.19 13:42:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2011.10.21 15:21:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.11.11 01:40:27 | 000,001,937 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
========== Chrome  ==========
CHR - default_search_provider: Ixquick HTTPS - Deutsch (Enabled)
CHR - default_search_provider: search_url = https://ixquick.com/do/search?query={searchTerms}&cat=web&pl=chrome&language=deutsch
CHR - default_search_provider: suggest_url = ,
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\
CHR - Extension: Ghostery = C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.1_0\
CHR - Extension: Picasa = C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb\6.2.2_0\
CHR - Extension: Google Mail = C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (WebCake) - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files (x86)\WebCake\WebCakeIEClient.dll (WebCake LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Preispilot) - {C4415769-1588-4AD6-9624-B2E69DB78D1A} - C:\Program Files (x86)\preispilot\Internet Explorer\preispilot.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Familie B\AppData\Roaming\OCS\SM\SearchAnonymizer.exe File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe (Conexant systems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [Dolby Home Theater v4] C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Dolby Laboratories Inc.)
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000..\Run: [WebCake Desktop] C:\Users\Familie B\AppData\Roaming\WebCake\WebCakeDesktop.exe (WebCake LLC)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AeroFS.lnk = C:\Users\Familie B\AppData\Roaming\AeroFSExec\aerofs.exe ()
O4 - Startup: C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Familie B\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9:64bit: - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9:64bit: - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 10.17.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8068FE7C-7296-400B-9019-82B7F3A7BDB2}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1AEB345-498B-4D3D-A2B8-DB5469020C02}: DhcpNameServer =
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{9372c1ea-864e-11e1-940e-bc77371ff891}\Shell - "" = AutoRun
O33 - MountPoints2\{9372c1ea-864e-11e1-940e-bc77371ff891}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.06.02 19:06:30 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.05.30 16:41:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013.05.30 16:07:43 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.05.30 16:07:33 | 000,000,000 | ---D | C] -- C:\JRT
[2013.05.27 00:29:48 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\FreeFLVConverter
[2013.05.27 00:29:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free FLV Converter
[2013.05.25 09:10:58 | 000,719,872 | -HS- | C] (Abysmal Software) -- C:\Windows\SysWow64\devil.dll
[2013.05.25 09:10:57 | 000,369,152 | -HS- | C] (The Public) -- C:\Windows\SysWow64\avisynth.dll
[2013.05.25 09:10:56 | 000,070,656 | -HS- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll
[2013.05.25 09:10:55 | 000,070,656 | -HS- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\i420vfw.dll
[2013.05.25 09:10:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5
[2013.05.25 09:06:01 | 000,000,000 | ---D | C] -- C:\Users\Familie B\Documents\eRightSoft
[2013.05.25 09:05:44 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2013.05.25 09:05:44 | 000,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) -- C:\Windows\SysWow64\nbDX.dll
[2013.05.25 09:05:44 | 000,186,880 | RHS- | C] (RadLight) -- C:\Windows\SysWow64\RLOgg.ax
[2013.05.25 09:05:44 | 000,179,200 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\DiracSplitter.ax
[2013.05.25 09:05:44 | 000,163,328 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\flvDX.dll
[2013.05.25 09:05:44 | 000,161,792 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\RealMediaDX.ax
[2013.05.25 09:05:44 | 000,123,904 | RHS- | C] (CoreCodec) -- C:\Windows\SysWow64\AVCDX.ax
[2013.05.25 09:05:44 | 000,092,672 | RHS- | C] (RadLight) -- C:\Windows\SysWow64\RLVorbisDec.ax
[2013.05.25 09:05:44 | 000,090,112 | RHS- | C] (-) -- C:\Windows\SysWow64\TTADSSplitter.ax
[2013.05.25 09:05:44 | 000,090,112 | RHS- | C] (-) -- C:\Windows\SysWow64\TTADSDecoder.ax
[2013.05.25 09:05:44 | 000,067,584 | RHS- | C] (RadLight, LLC) -- C:\Windows\SysWow64\RLTheoraDec.ax
[2013.05.25 09:05:44 | 000,031,232 | RHS- | C] (Hans Mayerl) -- C:\Windows\SysWow64\msfDX.dll
[2013.05.25 09:05:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © - by eRightSoft
[2013.05.25 09:05:43 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\WebCake
[2013.05.25 09:05:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WebCake
[2013.05.25 09:04:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eRightSoft
[2013.05.25 01:17:47 | 000,000,000 | ---D | C] -- C:\Users\Familie B\Documents\StreamTransport
[2013.05.25 00:56:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StreamTransport
[2013.05.25 00:56:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\StreamTransport
[2013.05.25 00:12:36 | 000,000,000 | ---D | C] -- C:\Users\Familie B\Desktop\Handy
[2013.05.22 21:58:29 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\KeePass
[2013.05.22 21:56:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KeePass Password Safe 2
[2013.05.22 21:56:00 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Local\Programs
[2013.05.15 18:58:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2013.05.13 16:33:54 | 000,000,000 | R--D | C] -- C:\Users\Familie B\Documents\AeroFS
[2013.05.13 16:33:54 | 000,000,000 | -HSD | C] -- C:\Users\Familie B\Documents\.aerofs.aux.fd6a7d
[2013.05.13 16:33:19 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\AeroFS
[2013.05.13 16:33:11 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeroFS
[2013.05.13 16:33:08 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\AeroFSExec
========== Files - Modified Within 30 Days ==========
[2013.06.02 19:19:01 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.06.02 19:19:01 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.06.02 19:15:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.06.02 19:09:39 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.06.02 19:09:34 | 000,000,029 | ---- | M] () -- C:\Windows\SysWow64\TempWmicBatchFile.bat
[2013.06.02 19:09:29 | 000,000,022 | ---- | M] () -- C:\Windows\S.dirmngr
[2013.06.02 19:09:23 | 000,067,584 | -H-- | M] () -- C:\Windows\bootstat.dat
[2013.06.02 19:09:20 | 3151,327,232 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.02 18:58:03 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.01 14:02:41 | 000,001,060 | ---- | M] () -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.05.30 21:42:45 | 000,000,747 | ---- | M] () -- C:\Windows\wiso.ini
[2013.05.30 15:50:57 | 000,000,194 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013.05.30 15:50:00 | 000,632,031 | ---- | M] () -- C:\Users\Familie B\Desktop\adwcleaner.exe
[2013.05.27 11:42:04 | 391,156,380 | ---- | M] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD! - Terra X - ZDFmediathek - ZDF Mediathek.mp4
[2013.05.27 01:02:53 | 120,545,306 | ---- | M] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek_1.flv
[2013.05.27 00:46:43 | 288,854,567 | ---- | M] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD - Terra X - ZDFmediathek - ZDF Mediathek.mp4
[2013.05.26 12:30:37 | 001,434,340 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.05.26 12:30:37 | 000,629,594 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.05.26 12:30:37 | 000,595,198 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.05.26 12:30:37 | 000,120,434 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.05.26 12:30:37 | 000,099,568 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.05.25 09:22:49 | 345,066,172 | ---- | M] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek.flv
[2013.05.25 09:03:42 | 002,463,093 | ---- | M] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek_0.flv
[2013.05.25 01:42:18 | 523,524,896 | ---- | M] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD! - Terra X - ZDFmediathek - ZDF Mediathek.flv
[2013.05.23 00:54:56 | 000,001,012 | ---- | M] () -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AeroFS.lnk
[2013.05.16 14:38:46 | 000,380,664 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2013.06.02 19:09:29 | 000,000,022 | ---- | C] () -- C:\Windows\S.dirmngr
[2013.05.30 15:50:49 | 000,000,194 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013.05.30 15:50:00 | 000,632,031 | ---- | C] () -- C:\Users\Familie B\Desktop\adwcleaner.exe
[2013.05.27 10:38:23 | 391,156,380 | ---- | C] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD! - Terra X - ZDFmediathek - ZDF Mediathek.mp4
[2013.05.27 00:52:52 | 120,545,306 | ---- | C] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek_1.flv
[2013.05.27 00:32:01 | 288,854,567 | ---- | C] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD - Terra X - ZDFmediathek - ZDF Mediathek.mp4
[2013.05.27 00:30:22 | 000,001,183 | ---- | C] () -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free FLV Converter.lnk
[2013.05.25 09:10:57 | 000,032,256 | -HS- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2013.05.25 09:08:18 | 000,002,566 | ---- | C] () -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2013.05.25 09:05:44 | 000,195,584 | RHS- | C] () -- C:\Windows\SysWow64\MatroskaDX.ax
[2013.05.25 09:05:44 | 000,188,416 | RHS- | C] () -- C:\Windows\SysWow64\winDCE32.dll
[2013.05.25 09:05:44 | 000,175,104 | RHS- | C] () -- C:\Windows\SysWow64\CoreAAC.ax
[2013.05.25 09:05:44 | 000,121,344 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.ax
[2013.05.25 09:05:44 | 000,120,832 | RHS- | C] () -- C:\Windows\SysWow64\MPCDx.ax
[2013.05.25 09:05:44 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2013.05.25 09:05:44 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\RLMPCDec.ax
[2013.05.25 09:05:44 | 000,097,280 | RHS- | C] () -- C:\Windows\SysWow64\FLACDX.ax
[2013.05.25 09:05:44 | 000,070,656 | RHS- | C] () -- C:\Windows\SysWow64\RLAPEDec.ax
[2013.05.25 09:05:44 | 000,051,712 | RHS- | C] () -- C:\Windows\SysWow64\RLSpeexDec.ax
[2013.05.25 09:05:43 | 000,227,328 | RHS- | C] () -- C:\Windows\SysWow64\ac3DX.ax
[2013.05.25 09:05:43 | 000,081,920 | RHS- | C] () -- C:\Windows\SysWow64\aac_parser.ax
[2013.05.25 09:03:30 | 002,463,093 | ---- | C] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek_0.flv
[2013.05.25 08:57:44 | 523,524,896 | ---- | C] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD! - Terra X - ZDFmediathek - ZDF Mediathek.flv
[2013.05.25 08:54:04 | 345,066,172 | ---- | C] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek.flv
[2013.05.22 21:56:32 | 000,001,125 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk
[2013.05.13 16:33:11 | 000,001,012 | ---- | C] () -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AeroFS.lnk
[2013.04.05 12:15:22 | 000,002,833 | ---- | C] () -- C:\Users\Familie B\.recently-used.xbel
[2013.02.08 00:29:45 | 000,001,374 | ---- | C] () -- C:\Windows\SysWow64\bash.exe.stackdump
[2012.12.28 01:24:01 | 000,007,635 | ---- | C] () -- C:\Users\Familie B\AppData\Local\Resmon.ResmonCfg
[2012.12.14 02:42:30 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012.10.10 03:22:28 | 000,272,928 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng600.bin
[2012.10.10 03:22:20 | 000,963,452 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng600.bin
[2012.07.24 15:12:18 | 000,001,477 | ---- | C] () -- C:\Users\Familie B\AppData\Local\recently-used.xbel
[2012.07.24 15:10:05 | 000,003,540 | ---- | C] () -- C:\Users\Familie B\AppData\Local\ING Diba Jens.gnucash.20120724151005.gnucash
[2012.07.24 15:00:48 | 000,003,669 | ---- | C] () -- C:\Users\Familie B\AppData\Local\ING Diba Jens.gnucash
[2012.07.12 17:17:58 | 000,003,531 | ---- | C] () -- C:\Users\Familie B\AppData\Local\GnuCash.gnucash
[2012.03.19 23:31:16 | 000,963,912 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2012.03.19 23:31:16 | 000,261,208 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.11.23 23:07:32 | 000,000,747 | ---- | C] () -- C:\Windows\wiso.ini
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.05.29 19:02:15 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\AeroFS
[2013.05.30 15:38:20 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\AeroFSExec
[2012.02.28 12:16:08 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Buhl Data Service
[2013.01.08 23:53:03 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Canneverbe Limited
[2013.06.02 19:12:22 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Dropbox
[2013.05.30 15:37:32 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\FreeFLVConverter
[2013.05.30 22:48:45 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\gnupg
[2013.04.05 11:59:05 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\gtk-2.0
[2013.05.27 21:16:12 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\KeePass
[2013.05.30 15:38:21 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\KeePassX
[2011.09.01 14:20:14 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\LibreOffice
[2012.08.13 00:37:21 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\MakeMusic
[2011.09.01 13:54:02 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\MusE
[2011.11.11 01:40:27 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Opera
[2011.09.15 23:39:59 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Thunderbird
[2011.11.13 23:52:56 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Titanium
[2012.01.31 19:08:26 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\TrueCrypt
[2013.06.02 19:12:44 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\WebCake
[2013.05.30 15:38:27 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\XMedia Recode
========== Purity Check ==========

< End of report >
--- --- ---

snapdo und searchnu nerven extrem


wie siehts jetzt im Chrome aus?

Schritt 1

Lade SystemLook (von jpshortstuff) herunter und speichere das Tool auf dem Desktop.
  • Doppelklicke auf die SystemLook_x64.exe, um das Tool zu starten.
    Vista und Win7 User: Rechtsklick und "als Administrator starten".
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:

  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Wenn der Suchlauf beendet ist, wird sich dein Editor mit den Ergebnissen öffnen. Poste diese in deinen Thread.
  • Das Log-File wird auch auf dem Desktop als SystemLook.txt gespeichert.

Bitte poste in deiner nächsten Antwort:
  • Log von SystemLook
--> snapdo und searchnu nerven extrem

snapdo und searchnu nerven extrem

SystemLook 30.07.11 by jpshortstuff
Log created at 20:15 on 02/06/2013 by Familie B
Administrator - Elevation successful

========== filefind ==========

Searching for "*webcake*"
C:\Program Files (x86)\WebCake\WebCakeDesktop.Updater.exe --a---- 23552 bytes [07:05 25/05/2013] [18:57 24/05/2013] E89D463AB373CFACCCBB0645E9AE8154
C:\Program Files (x86)\WebCake\WebCakeIEClient.dll --a---- 197912 bytes [07:05 25/05/2013] [18:58 24/05/2013] 07A532C6044B985507A37EB80AF98B30
C:\Users\Familie B\AppData\Roaming\Mozilla\Firefox\Profiles\82e4ucv2.default\extensions\plugin@getwebcake.com\defaults\preferences\webcake.js --a---- 304 bytes [07:05 25/05/2013] [09:58 24/05/2013] 244B4874C7BD744EC6C1FB02360DE6A4
C:\Users\Familie B\AppData\Roaming\Mozilla\Firefox\Profiles\82e4ucv2.default\extensions\plugin@getwebcake.com\locale\en-US\webcake.properties --a---- 139 bytes [07:05 25/05/2013] [09:58 24/05/2013] 604FEEC3D7CC1A86DC469B2DBB86E944
C:\Users\Familie B\AppData\Roaming\WebCake\WebCakeDesktop.exe --a---- 47896 bytes [07:05 25/05/2013] [18:57 24/05/2013] 9EEE55B742B65439A0A45BF895E5CEA1

========== folderfind ==========

Searching for "*webcake*"
C:\Program Files (x86)\WebCake d------ [07:05 25/05/2013]
========== regfind ==========

Searching for "webcake"
"WebCake Desktop"=""C:\Users\Familie B\AppData\Roaming\WebCake\WebCakeDesktop.exe""
@="WebCakeIEClient 1.0 Type Library"
@="C:\Program Files (x86)\WebCake\WebCakeIEClient.dll"
@="C:\Program Files (x86)\WebCake"
@="WebCake Api"
@="WebCake Api"
@="C:\Program Files (x86)\WebCake\WebCakeIEClient.dll"
@="WebCake Api"
@="C:\Program Files (x86)\WebCake\WebCakeIEClient.dll"
@="C:\Program Files (x86)\WebCake\WebCakeIEClient.dll"
@="WebCakeIEClient 1.0 Type Library"
@="C:\Program Files (x86)\WebCake\WebCakeIEClient.dll"
@="C:\Program Files (x86)\WebCake"
"InstallLocation"="C:\Program Files (x86)\WebCake"
"DisplayName"="WebCake 3.00"
"Publisher"="WebCake LLC"
"path"="C:\Program Files (x86)\WebCake\WebCakeLayers.crx"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}]
@="WebCake Layers"
@="C:\Program Files (x86)\WebCake\WebCakeIEClient.dll"
@="WebCake Api"
@="C:\Program Files (x86)\WebCake\WebCakeIEClient.dll"
@="C:\Program Files (x86)\WebCake\WebCakeIEClient.dll"
@="WebCakeIEClient 1.0 Type Library"
@="C:\Program Files (x86)\WebCake\WebCakeIEClient.dll"
@="C:\Program Files (x86)\WebCake"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebCake Desktop Updater]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebCake Desktop Updater]
"ImagePath"=""C:\Program Files (x86)\WebCake\WebCakeDesktop.Updater.exe" "C:\Users\Familie B\AppData\Roaming\WebCake\WebCakeDesktop.exe""
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebCake Desktop Updater]
"DisplayName"="WebCake Desktop Updater"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebCake Desktop Updater]
"Description"="Provides limited updating assistance for WebCake Desktop"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\WebCake Desktop Updater]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\WebCake Desktop Updater]
"ImagePath"=""C:\Program Files (x86)\WebCake\WebCakeDesktop.Updater.exe" "C:\Users\Familie B\AppData\Roaming\WebCake\WebCakeDesktop.exe""
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\WebCake Desktop Updater]
"DisplayName"="WebCake Desktop Updater"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\WebCake Desktop Updater]
"Description"="Provides limited updating assistance for WebCake Desktop"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WebCake Desktop Updater]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WebCake Desktop Updater]
"ImagePath"=""C:\Program Files (x86)\WebCake\WebCakeDesktop.Updater.exe" "C:\Users\Familie B\AppData\Roaming\WebCake\WebCakeDesktop.exe""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WebCake Desktop Updater]
"DisplayName"="WebCake Desktop Updater"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WebCake Desktop Updater]
"Description"="Provides limited updating assistance for WebCake Desktop"
"WebCake Desktop"=""C:\Users\Familie B\AppData\Roaming\WebCake\WebCakeDesktop.exe""

Searching for " "
"ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res
"ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/>

-= EOF =-

bitte auch die Fragen beantworten:

Öffne ich meinen Chrome- Browser, öffnen sich ungefragt in einem jeweils neuen Reiter die Seiten "search.snapdo.com" und "www.searchnu.com".
Ist das immer noch so?

Schritt 1

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.
[2013.05.25 09:05:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WebCake
[2013.06.02 19:12:44 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\WebCake
O4 - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000..\Run: [WebCake Desktop] C:\Users\Familie B\AppData\Roaming\WebCake\WebCakeDesktop.exe (WebCake LLC)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Familie B\AppData\Roaming\OCS\SM\SearchAnonymizer.exe File not found
O2 - BHO: (WebCake) - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files (x86)\WebCake\WebCakeIEClient.dll (WebCake LLC)
[2013.05.30 15:38:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions\plugin@getwebcake.com
FF - prefs.js..browser.startup.homepage: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=hp&installDate=25/05/2013"
FF - prefs.js..keyword.URL: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=ds&installDate=25/05/2013&q="

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WebCake Desktop Updater]

  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread

Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

Schritt 3

Starte bitte die OTL.exe.
  • Setze den Haken bei Scan all Users.
  • Drücke auf den Quick Scan Button.
  • Poste den Inhalt von OTL.txt hier in den Thread.

Bitte poste in deiner nächsten Antwort:
  • Fixlog von OTL
  • Log von JRT
  • Log von OTL

Wenn ich jetzt den Chrome- Browser öffne, bin ich das Problem scheinbar los. Habe allerdings auch zusätzlich zu den vorgeschlagenen Anweisungen snapdo als Suchmaschine händisch aus den Suchmaschinenvorschlägen gelöscht. (Unter Einstellungen --> Beim Start Seiten festlegen)

Soll ich nun noch einmal Fixlog von OTL; Log von JRT und Log von OTL posten?

Falls ich den "ungebetenen Gast" nun endgültig losgeworden bin, bedanke ich mich recht herzlich für die kompetente Unterstützung.

snapdo und searchnu nerven extrem

Wenn ich jetzt den Chrome- Browser öffne, bin ich das Problem scheinbar los.

Soll ich nun noch einmal Fixlog von OTL; Log von JRT und Log von OTL posten?
Ja, wir sind noch nicht fertig. Diese Schritte adressieren noch weitere ungebetene Gäste.

All processes killed
========== OTL ==========
C:\Program Files (x86)\WebCake folder moved successfully.
C:\Users\Familie B\AppData\Roaming\WebCake\dat\update folder moved successfully.
C:\Users\Familie B\AppData\Roaming\WebCake\dat folder moved successfully.
Folder move failed. C:\Users\Familie B\AppData\Roaming\WebCake scheduled to be moved on reboot.
Registry value HKEY_USERS\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WebCake Desktop deleted successfully.
C:\Users\Familie B\AppData\Roaming\WebCake\WebCakeDesktop.exe moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Ocs_SM deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}\ deleted successfully.
File C:\Program Files (x86)\WebCake\WebCakeIEClient.dll not found.
C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions\plugin@getwebcake.com\locale\en-US folder moved successfully.
C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions\plugin@getwebcake.com\locale folder moved successfully.
C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions\plugin@getwebcake.com\defaults\preferences folder moved successfully.
C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions\plugin@getwebcake.com\defaults folder moved successfully.
C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions\plugin@getwebcake.com\content folder moved successfully.
C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions\plugin@getwebcake.com folder moved successfully.
Prefs.js: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=hp&installDate=25/05/2013" removed from browser.startup.homepage
Prefs.js: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=ds&installDate=25/05/2013&q=" removed from keyword.URL
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\WebCakeIEClient.DLL\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EFDF368C-8DD9-4E05-87CD-16AA5CB03CB8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EFDF368C-8DD9-4E05-87CD-16AA5CB03CB8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebCakeIEClient.Api\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebCakeIEClient.Api.1\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebCakeIEClient.Layers\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebCakeIEClient.Layers.1\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AF6B0594-6008-4327-93E5-608AD710A6FA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF6B0594-6008-4327-93E5-608AD710A6FA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\WebCakeIEClient.DLL\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EFDF368C-8DD9-4E05-87CD-16AA5CB03CB8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EFDF368C-8DD9-4E05-87CD-16AA5CB03CB8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebCakeDesktop_RASAPI32\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebCakeDesktop_RASMANCS\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{AF6B0594-6008-4327-93E5-608AD710A6FA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF6B0594-6008-4327-93E5-608AD710A6FA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\WebCakeIEClient.DLL\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{EFDF368C-8DD9-4E05-87CD-16AA5CB03CB8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EFDF368C-8DD9-4E05-87CD-16AA5CB03CB8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\WebCakeUpdaterService\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WebCake Desktop Updater\ deleted successfully.
========== COMMANDS ==========


User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Familie B
->Temp folder emptied: 3344 bytes
->Temporary Internet Files folder emptied: 1390295 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 23311912 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 608 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 24,00 mb

OTL by OldTimer - Version log created on 06022013_233053

Files\Folders moved on Reboot...
C:\Users\Familie B\AppData\Roaming\WebCake folder moved successfully.
C:\Users\Familie B\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Junkware Removal Tool (JRT) by Thisisu
~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ FireFox

OTL Logfile:
OTL logfile created on: 02.06.2013 23:46:59 - Run 4
OTL by OldTimer - Version     Folder = C:\Users\Familie B\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,91 Gb Total Physical Memory | 2,16 Gb Available Physical Memory | 55,11% Memory free
7,82 Gb Paging File | 5,87 Gb Available in Paging File | 74,99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 657,54 Gb Total Space | 567,80 Gb Free Space | 86,35% Space Free | Partition Type: NTFS
Drive D: | 37,99 Gb Total Space | 0,02 Gb Free Space | 0,04% Space Free | Partition Type: NTFS
Computer Name: FAMILIEB-PC | User Name: Familie B | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.05.30 16:19:11 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Familie B\Downloads\OTL.exe
PRC - [2013.05.25 02:47:30 | 027,776,968 | ---- | M] (Dropbox, Inc.) -- C:\Users\Familie B\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013.05.23 07:44:09 | 000,825,808 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013.05.10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.05.02 11:20:20 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013.04.01 19:57:53 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2013.04.01 19:57:39 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2013.03.15 16:32:11 | 000,542,800 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\taxaktuell.exe
PRC - [2012.10.09 00:36:45 | 001,433,600 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\KeePassX.exe
PRC - [2011.04.30 09:32:54 | 000,013,592 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011.04.14 18:17:18 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
PRC - [2011.02.24 03:04:54 | 003,402,760 | ---- | M] (Pegatron Corporation) -- C:\Program Files (x86)\PHotkey\POSD.exe
PRC - [2011.02.24 03:04:50 | 000,819,720 | ---- | M] (Pegatron Corporation) -- C:\Program Files (x86)\PHotkey\PHotkey.exe
PRC - [2011.02.22 22:20:21 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2011.02.22 22:20:17 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2011.02.15 18:01:48 | 000,019,968 | ---- | M] (Fork Ltd.) -- C:\Prey\platform\windows\cronsvc.exe
PRC - [2011.02.11 21:40:00 | 000,997,712 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2011.02.11 21:39:58 | 001,304,912 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2011.02.11 21:39:54 | 000,985,424 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
PRC - [2011.02.11 21:39:54 | 000,907,600 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2010.08.04 00:39:38 | 000,107,816 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
PRC - [2010.01.13 02:36:00 | 000,117,256 | R--- | M] () -- C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
PRC - [2009.12.19 00:40:48 | 000,104,968 | R--- | M] () -- C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
PRC - [2009.12.19 00:38:18 | 000,345,608 | R--- | M] (TODO: <Company name>) -- C:\Program Files (x86)\PHotkey\HCSynApi.exe
========== Modules (No Company Name) ==========
MOD - [2013.05.23 07:44:07 | 000,393,168 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
MOD - [2013.05.23 07:43:59 | 004,051,408 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll
MOD - [2013.05.23 07:43:06 | 000,599,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libglesv2.dll
MOD - [2013.05.23 07:43:05 | 000,124,368 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libegl.dll
MOD - [2013.05.23 07:43:03 | 001,597,392 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ffmpegsumo.dll
MOD - [2013.03.19 16:31:28 | 002,170,960 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wfvie13.dll
MOD - [2013.03.19 15:48:09 | 008,921,680 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wgui13.dll
MOD - [2013.03.18 17:13:09 | 001,492,048 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wmain13.dll
MOD - [2013.03.15 16:33:03 | 002,997,840 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wcore13.dll
MOD - [2013.03.15 16:33:01 | 006,761,552 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wkont13.dll
MOD - [2013.03.15 16:32:55 | 004,158,544 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wauff13.dll
MOD - [2013.03.15 16:32:55 | 001,313,872 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wfabu13.dll
MOD - [2013.03.15 16:32:48 | 001,245,184 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wimp13.dll
MOD - [2013.03.15 16:32:46 | 001,310,800 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wwerb13.dll
MOD - [2013.03.15 16:32:46 | 001,215,568 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\whau213.dll
MOD - [2013.03.15 16:32:41 | 001,559,120 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wbae413.dll
MOD - [2013.03.15 16:32:41 | 001,146,448 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\whau113.dll
MOD - [2013.03.15 16:32:40 | 004,940,368 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wbae113.dll
MOD - [2013.03.15 16:32:35 | 001,747,536 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wbae313.dll
MOD - [2013.03.15 16:32:32 | 001,367,632 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wbae213.dll
MOD - [2013.03.15 16:32:27 | 001,724,496 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wreli13.dll
MOD - [2013.03.15 16:32:26 | 001,607,248 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\wsteu13.dll
MOD - [2013.03.15 16:32:25 | 000,321,104 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\rsguiwinapi48.dll
MOD - [2013.03.15 16:32:22 | 000,308,816 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\rscorewinapi48.dll
MOD - [2013.03.15 16:32:11 | 000,542,800 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\taxaktuell.exe
MOD - [2013.03.15 16:31:57 | 000,136,272 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\rsodbc48.dll
MOD - [2013.03.15 16:31:54 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\rsdcom48.dll
MOD - [2013.03.15 16:09:38 | 001,041,408 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\clucene-core.dll
MOD - [2013.03.13 22:48:52 | 024,978,944 | ---- | M] () -- C:\Users\Familie B\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2013.02.12 12:03:49 | 000,251,392 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\clucene-contribs-lib.dll
MOD - [2013.02.12 12:03:49 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2013\clucene-shared.dll
MOD - [2012.11.14 01:32:50 | 003,558,400 | ---- | M] () -- C:\Users\Familie B\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2012.10.09 00:36:45 | 009,515,520 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\QtGui4.dll
MOD - [2012.10.09 00:36:45 | 002,415,104 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\QtCore4.dll
MOD - [2012.10.09 00:36:45 | 001,433,600 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\KeePassX.exe
MOD - [2012.10.09 00:36:45 | 000,398,336 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\QtXml4.dll
MOD - [2012.10.09 00:36:45 | 000,350,720 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\imageformats\qmng4.dll
MOD - [2012.10.09 00:36:45 | 000,192,000 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\imageformats\qjpeg4.dll
MOD - [2012.10.09 00:36:45 | 000,082,944 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\imageformats\qgif4.dll
MOD - [2012.10.09 00:36:45 | 000,081,920 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\imageformats\qico4.dll
MOD - [2012.10.09 00:36:45 | 000,043,008 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\libgcc_s_dw2-1.dll
MOD - [2012.10.09 00:36:45 | 000,011,362 | ---- | M] () -- C:\Users\Familie B\Downloads\KeePassX-0.4.3-win32\KeePassX\mingwm10.dll
MOD - [2010.08.04 00:39:38 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2010.08.04 00:39:32 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
========== Services (SafeList) ==========
SRV:64bit: - [2011.05.02 23:27:50 | 001,517,328 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2011.05.02 23:13:54 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2011.05.02 23:10:26 | 000,844,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2011.04.21 18:34:16 | 001,136,640 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3)
SRV:64bit: - [2011.04.21 17:42:50 | 000,134,928 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr)
SRV:64bit: - [2010.12.17 16:46:34 | 000,198,784 | ---- | M] (Conexant Systems Inc.) [Auto | Running] -- C:\Windows\SysNative\CxAudMsg64.exe -- (CxAudMsg)
SRV:64bit: - [2010.09.23 03:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2013.05.15 18:58:47 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.05.15 14:15:32 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.05.10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.04.01 19:57:53 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013.04.01 19:57:39 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013.02.28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.12.14 02:42:10 | 000,277,616 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2011.04.30 09:32:54 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe -- (DirMngr)
SRV - [2011.02.22 22:20:21 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011.02.22 22:20:17 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011.02.15 18:01:48 | 000,019,968 | ---- | M] (Fork Ltd.) [Auto | Running] -- C:\Prey\platform\windows\cronsvc.exe -- (CronService)
SRV - [2011.02.11 21:40:00 | 000,997,712 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2011.02.11 21:39:58 | 001,304,912 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2011.02.11 21:39:54 | 000,907,600 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010.10.07 02:46:42 | 000,159,752 | R--- | M] () [Auto | Running] -- C:\Program Files (x86)\PHotkey\GFNEXSrv.exe -- (GFNEXSrv)
SRV - [2010.03.18 22:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.12.19 00:40:48 | 000,104,968 | R--- | M] () [Auto | Running] -- C:\Program Files (x86)\PHotkey\ASLDRSrv.exe -- (ASLDRService)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013.04.01 19:57:57 | 000,130,016 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2013.04.01 19:57:57 | 000,100,712 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2013.04.01 19:57:57 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012.12.14 02:42:22 | 005,353,888 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2012.08.23 16:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.08.23 16:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012.08.23 16:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.31 18:57:41 | 000,230,864 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt)
DRV:64bit: - [2011.05.17 18:27:52 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2011.05.17 18:27:50 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2011.05.01 23:33:06 | 008,593,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64)
DRV:64bit: - [2011.04.26 20:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011.04.21 18:09:26 | 000,294,912 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP)
DRV:64bit: - [2011.04.21 18:09:26 | 000,294,912 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL)
DRV:64bit: - [2011.04.15 01:16:08 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2011.04.13 18:30:54 | 000,207,872 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2011.04.13 18:30:50 | 000,087,552 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.03.10 17:01:40 | 001,581,184 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2011.01.24 11:24:52 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2011.01.24 11:22:48 | 000,059,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (iBtFltCoex)
DRV:64bit: - [2011.01.24 10:56:06 | 000,274,944 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.10.20 02:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010.10.15 01:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010.09.23 22:03:06 | 000,129,008 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2010.08.24 18:55:44 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2010.01.22 11:26:50 | 000,305,200 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009.10.23 17:26:14 | 000,046,592 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009.09.11 23:11:46 | 000,014,344 | R--- | M] (PEGATRON) [Kernel | Auto | Running] -- C:\Program Files (x86)\PHotkey\PEGAGFN.sys -- (PEGAGFN)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: {eadb1184-3305-4914-9490-1d074f61546d}:1.0
FF - prefs.js..extensions.enabledAddons: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:
FF - prefs.js..browser.startup.homepage: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=hp&installDate=25/05/2013"
FF - prefs.js..keyword.URL: "hxxp://feed.snapdo.com/?publisher=SnapdoEMonYB&dpid=SnapdoEMonYB&co=DE&userid=eadb1184-3305-4914-9490-1d074f61546d&searchtype=ds&installDate=25/05/2013&q="
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.08 18:37:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.16 14:46:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.05.15 18:58:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.05.15 18:58:43 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2013.05.27 01:09:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie B\AppData\Roaming\mozilla\Extensions
[2013.05.30 15:50:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions
[2013.05.30 15:38:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie B\AppData\Roaming\mozilla\Firefox\Profiles\82e4ucv2.default\extensions\{eadb1184-3305-4914-9490-1d074f61546d}
[2012.10.19 13:42:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.03.21 01:58:45 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.06.28 10:28:54 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.09.07 08:57:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.10.19 13:42:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2011.10.21 15:21:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.11.11 01:40:27 | 000,001,937 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
========== Chrome  ==========
CHR - default_search_provider: Ixquick HTTPS - Deutsch (Enabled)
CHR - default_search_provider: search_url = https://ixquick.com/do/search?query={searchTerms}&cat=web&pl=chrome&language=deutsch
CHR - default_search_provider: suggest_url = ,
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\
CHR - Extension: Ghostery = C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.1_0\
CHR - Extension: Picasa = C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb\6.2.2_0\
CHR - Extension: Google Mail = C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Preispilot) - {C4415769-1588-4AD6-9624-B2E69DB78D1A} - C:\Program Files (x86)\preispilot\Internet Explorer\preispilot.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe (Conexant systems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [Dolby Home Theater v4] C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Dolby Laboratories Inc.)
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AeroFS.lnk = C:\Users\Familie B\AppData\Roaming\AeroFSExec\aerofs.exe ()
O4 - Startup: C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Familie B\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9:64bit: - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9:64bit: - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 10.17.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8068FE7C-7296-400B-9019-82B7F3A7BDB2}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1AEB345-498B-4D3D-A2B8-DB5469020C02}: DhcpNameServer =
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{9372c1ea-864e-11e1-940e-bc77371ff891}\Shell - "" = AutoRun
O33 - MountPoints2\{9372c1ea-864e-11e1-940e-bc77371ff891}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.06.02 23:36:33 | 000,000,000 | ---D | C] -- C:\Users\Familie B\Desktop\Malware Entfernung
[2013.06.02 19:06:30 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.05.30 16:41:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013.05.30 16:07:43 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.05.30 16:07:33 | 000,000,000 | ---D | C] -- C:\JRT
[2013.05.27 00:29:48 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\FreeFLVConverter
[2013.05.27 00:29:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free FLV Converter
[2013.05.25 09:10:58 | 000,719,872 | -HS- | C] (Abysmal Software) -- C:\Windows\SysWow64\devil.dll
[2013.05.25 09:10:57 | 000,369,152 | -HS- | C] (The Public) -- C:\Windows\SysWow64\avisynth.dll
[2013.05.25 09:10:56 | 000,070,656 | -HS- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll
[2013.05.25 09:10:55 | 000,070,656 | -HS- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\i420vfw.dll
[2013.05.25 09:10:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5
[2013.05.25 09:06:01 | 000,000,000 | ---D | C] -- C:\Users\Familie B\Documents\eRightSoft
[2013.05.25 09:05:44 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2013.05.25 09:05:44 | 000,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) -- C:\Windows\SysWow64\nbDX.dll
[2013.05.25 09:05:44 | 000,186,880 | RHS- | C] (RadLight) -- C:\Windows\SysWow64\RLOgg.ax
[2013.05.25 09:05:44 | 000,179,200 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\DiracSplitter.ax
[2013.05.25 09:05:44 | 000,163,328 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\flvDX.dll
[2013.05.25 09:05:44 | 000,161,792 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\RealMediaDX.ax
[2013.05.25 09:05:44 | 000,123,904 | RHS- | C] (CoreCodec) -- C:\Windows\SysWow64\AVCDX.ax
[2013.05.25 09:05:44 | 000,092,672 | RHS- | C] (RadLight) -- C:\Windows\SysWow64\RLVorbisDec.ax
[2013.05.25 09:05:44 | 000,090,112 | RHS- | C] (-) -- C:\Windows\SysWow64\TTADSSplitter.ax
[2013.05.25 09:05:44 | 000,090,112 | RHS- | C] (-) -- C:\Windows\SysWow64\TTADSDecoder.ax
[2013.05.25 09:05:44 | 000,067,584 | RHS- | C] (RadLight, LLC) -- C:\Windows\SysWow64\RLTheoraDec.ax
[2013.05.25 09:05:44 | 000,031,232 | RHS- | C] (Hans Mayerl) -- C:\Windows\SysWow64\msfDX.dll
[2013.05.25 09:05:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © - by eRightSoft
[2013.05.25 09:04:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eRightSoft
[2013.05.25 01:17:47 | 000,000,000 | ---D | C] -- C:\Users\Familie B\Documents\StreamTransport
[2013.05.25 00:56:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StreamTransport
[2013.05.25 00:56:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\StreamTransport
[2013.05.25 00:12:36 | 000,000,000 | ---D | C] -- C:\Users\Familie B\Desktop\Handy
[2013.05.22 21:58:29 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\KeePass
[2013.05.22 21:56:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KeePass Password Safe 2
[2013.05.22 21:56:00 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Local\Programs
[2013.05.15 18:58:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2013.05.13 16:33:54 | 000,000,000 | R--D | C] -- C:\Users\Familie B\Documents\AeroFS
[2013.05.13 16:33:54 | 000,000,000 | -HSD | C] -- C:\Users\Familie B\Documents\.aerofs.aux.fd6a7d
[2013.05.13 16:33:19 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\AeroFS
[2013.05.13 16:33:11 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeroFS
[2013.05.13 16:33:08 | 000,000,000 | ---D | C] -- C:\Users\Familie B\AppData\Roaming\AeroFSExec
========== Files - Modified Within 30 Days ==========
[2013.06.02 23:41:35 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.06.02 23:41:35 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.06.02 23:32:52 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.06.02 23:32:43 | 000,000,022 | ---- | M] () -- C:\Windows\S.dirmngr
[2013.06.02 23:32:41 | 000,000,029 | ---- | M] () -- C:\Windows\SysWow64\TempWmicBatchFile.bat
[2013.06.02 23:32:35 | 000,067,584 | -H-- | M] () -- C:\Windows\bootstat.dat
[2013.06.02 23:32:33 | 3151,327,232 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.02 23:15:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.06.02 22:58:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.02 20:14:31 | 000,165,376 | ---- | M] () -- C:\Users\Familie B\Desktop\SystemLook_x64.exe
[2013.06.01 14:02:41 | 000,001,060 | ---- | M] () -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.05.30 21:42:45 | 000,000,747 | ---- | M] () -- C:\Windows\wiso.ini
[2013.05.30 15:50:57 | 000,000,194 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013.05.30 15:50:00 | 000,632,031 | ---- | M] () -- C:\Users\Familie B\Desktop\adwcleaner.exe
[2013.05.27 11:42:04 | 391,156,380 | ---- | M] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD! - Terra X - ZDFmediathek - ZDF Mediathek.mp4
[2013.05.27 01:02:53 | 120,545,306 | ---- | M] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek_1.flv
[2013.05.27 00:46:43 | 288,854,567 | ---- | M] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD - Terra X - ZDFmediathek - ZDF Mediathek.mp4
[2013.05.26 12:30:37 | 001,434,340 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.05.26 12:30:37 | 000,629,594 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.05.26 12:30:37 | 000,595,198 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.05.26 12:30:37 | 000,120,434 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.05.26 12:30:37 | 000,099,568 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.05.25 09:22:49 | 345,066,172 | ---- | M] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek.flv
[2013.05.25 09:03:42 | 002,463,093 | ---- | M] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek_0.flv
[2013.05.25 01:42:18 | 523,524,896 | ---- | M] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD! - Terra X - ZDFmediathek - ZDF Mediathek.flv
[2013.05.23 00:54:56 | 000,001,012 | ---- | M] () -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AeroFS.lnk
[2013.05.16 14:38:46 | 000,380,664 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2013.06.02 23:32:43 | 000,000,022 | ---- | C] () -- C:\Windows\S.dirmngr
[2013.06.02 20:14:31 | 000,165,376 | ---- | C] () -- C:\Users\Familie B\Desktop\SystemLook_x64.exe
[2013.05.30 15:50:49 | 000,000,194 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013.05.30 15:50:00 | 000,632,031 | ---- | C] () -- C:\Users\Familie B\Desktop\adwcleaner.exe
[2013.05.27 10:38:23 | 391,156,380 | ---- | C] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD! - Terra X - ZDFmediathek - ZDF Mediathek.mp4
[2013.05.27 00:52:52 | 120,545,306 | ---- | C] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek_1.flv
[2013.05.27 00:32:01 | 288,854,567 | ---- | C] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD - Terra X - ZDFmediathek - ZDF Mediathek.mp4
[2013.05.27 00:30:22 | 000,001,183 | ---- | C] () -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free FLV Converter.lnk
[2013.05.25 09:10:57 | 000,032,256 | -HS- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2013.05.25 09:08:18 | 000,002,566 | ---- | C] () -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2013.05.25 09:05:44 | 000,195,584 | RHS- | C] () -- C:\Windows\SysWow64\MatroskaDX.ax
[2013.05.25 09:05:44 | 000,188,416 | RHS- | C] () -- C:\Windows\SysWow64\winDCE32.dll
[2013.05.25 09:05:44 | 000,175,104 | RHS- | C] () -- C:\Windows\SysWow64\CoreAAC.ax
[2013.05.25 09:05:44 | 000,121,344 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.ax
[2013.05.25 09:05:44 | 000,120,832 | RHS- | C] () -- C:\Windows\SysWow64\MPCDx.ax
[2013.05.25 09:05:44 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2013.05.25 09:05:44 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\RLMPCDec.ax
[2013.05.25 09:05:44 | 000,097,280 | RHS- | C] () -- C:\Windows\SysWow64\FLACDX.ax
[2013.05.25 09:05:44 | 000,070,656 | RHS- | C] () -- C:\Windows\SysWow64\RLAPEDec.ax
[2013.05.25 09:05:44 | 000,051,712 | RHS- | C] () -- C:\Windows\SysWow64\RLSpeexDec.ax
[2013.05.25 09:05:43 | 000,227,328 | RHS- | C] () -- C:\Windows\SysWow64\ac3DX.ax
[2013.05.25 09:05:43 | 000,081,920 | RHS- | C] () -- C:\Windows\SysWow64\aac_parser.ax
[2013.05.25 09:03:30 | 002,463,093 | ---- | C] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek_0.flv
[2013.05.25 08:57:44 | 523,524,896 | ---- | C] () -- C:\Users\Familie B\Desktop\Deutschland von oben 1 &quot;Stadt&quot; - in HD! - Terra X - ZDFmediathek - ZDF Mediathek.flv
[2013.05.25 08:54:04 | 345,066,172 | ---- | C] () -- C:\Users\Familie B\Documents\Startseite - ZDF Mediathek.flv
[2013.05.22 21:56:32 | 000,001,125 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk
[2013.05.13 16:33:11 | 000,001,012 | ---- | C] () -- C:\Users\Familie B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AeroFS.lnk
[2013.04.05 12:15:22 | 000,002,833 | ---- | C] () -- C:\Users\Familie B\.recently-used.xbel
[2013.02.08 00:29:45 | 000,001,374 | ---- | C] () -- C:\Windows\SysWow64\bash.exe.stackdump
[2012.12.28 01:24:01 | 000,007,635 | ---- | C] () -- C:\Users\Familie B\AppData\Local\Resmon.ResmonCfg
[2012.12.14 02:42:30 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012.10.10 03:22:28 | 000,272,928 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng600.bin
[2012.10.10 03:22:20 | 000,963,452 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng600.bin
[2012.07.24 15:12:18 | 000,001,477 | ---- | C] () -- C:\Users\Familie B\AppData\Local\recently-used.xbel
[2012.07.24 15:10:05 | 000,003,540 | ---- | C] () -- C:\Users\Familie B\AppData\Local\ING Diba Jens.gnucash.20120724151005.gnucash
[2012.07.24 15:00:48 | 000,003,669 | ---- | C] () -- C:\Users\Familie B\AppData\Local\ING Diba Jens.gnucash
[2012.07.12 17:17:58 | 000,003,531 | ---- | C] () -- C:\Users\Familie B\AppData\Local\GnuCash.gnucash
[2012.03.19 23:31:16 | 000,963,912 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2012.03.19 23:31:16 | 000,261,208 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.11.23 23:07:32 | 000,000,747 | ---- | C] () -- C:\Windows\wiso.ini
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.05.29 19:02:15 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\AeroFS
[2013.05.30 15:38:20 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\AeroFSExec
[2012.02.28 12:16:08 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Buhl Data Service
[2013.01.08 23:53:03 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Canneverbe Limited
[2013.06.02 23:35:45 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Dropbox
[2013.05.30 15:37:32 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\FreeFLVConverter
[2013.05.30 22:48:45 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\gnupg
[2013.04.05 11:59:05 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\gtk-2.0
[2013.05.27 21:16:12 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\KeePass
[2013.05.30 15:38:21 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\KeePassX
[2011.09.01 14:20:14 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\LibreOffice
[2012.08.13 00:37:21 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\MakeMusic
[2011.09.01 13:54:02 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\MusE
[2011.11.11 01:40:27 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Opera
[2011.09.15 23:39:59 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Thunderbird
[2011.11.13 23:52:56 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\Titanium
[2012.01.31 19:08:26 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\TrueCrypt
[2013.05.30 15:38:27 | 000,000,000 | ---D | M] -- C:\Users\Familie B\AppData\Roaming\XMedia Recode
========== Purity Check ==========

< End of report >
--- --- ---

Alt 02.06.2013, 23:09   #12
/// TB-Ausbilder
snapdo und searchnu  nerven extrem - Standard

snapdo und searchnu nerven extrem


kontrollieren wir noch, ob die Scanner noch was finden. Und dann schliessen wir noch vorhandene Sicherheitslücken.
Wie läuft der Rechner so?

Schritt 1

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.

Schritt 2

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

Schritt 3

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

Bitte poste in deiner nächsten Antwort:
  • Log von MBAM
  • Log von ESET
  • Log von SecurityCheck

Alt 03.06.2013, 14:29   #13
snapdo und searchnu  nerven extrem - Standard

snapdo und searchnu nerven extrem

"Snap Do. Engine" steht noch immer unter den installierten Programmen eingetragen und lässt sich in der Systemsteuerung nicht deinstallieren.
Ansonsten bin ich mit der Performance ganz zufrieden, also meiner Meinung nach läuft der Rechner ganz gut.

Malwarebytes Anti-Malware (Test)

Datenbank Version: v2013.06.03.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Familie B :: FAMILIEB-PC [Administrator]

Schutz: Aktiviert

03.06.2013 10:07:18
mbam-log-2013-06-03 (10-07-18).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 219108
Laufzeit: 4 Minute(n), 49 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)


ESETSmartInstaller@High as downloader log:
all ok
all ok
# version=8
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=2d28d11efa05734591017801490ca42f
# engine=13979
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-03 01:03:19
# local_time=2013-06-03 03:03:19 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 96 18390 235684289 11175 0
# compatibility_mode=5893 16776574 100 94 55046399 121894449 0 0
# scanned=380294
# found=1
# cleaned=0
# scan_time=16805
sh=238F78360B456EE74CC8397E2DD38DABCD9A44FB ft=1 fh=61d65ddd3df05ceb vn="probably a variant of Win32/Adware.Yontoo.A application" ac=I fn="C:\_OTL\MovedFiles\06022013_233053\C_Program Files (x86)\WebCake\WebCakeIEClient.dll"

Results of screen317's Security Check version 0.99.64
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version
Java(TM) 6 Update 37
Java 7 Update 21
Adobe Flash Player 11.7.700.202
Adobe Reader 10.1.7 Adobe Reader out of Date!
Mozilla Firefox (7.0.1)
Mozilla Thunderbird (17.0.6)
Google Chrome 27.0.1453.93
Google Chrome 27.0.1453.94
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````

Alt 03.06.2013, 14:52   #14
/// TB-Ausbilder
snapdo und searchnu  nerven extrem - Standard

snapdo und searchnu nerven extrem

Ok, dann entfernen wir auch noch die letzten Resten von snap.do.
Auch müssen noch die veralteten Software-Versionen entfernt werden.

Schritt 1
  • Starte bitte erneut SystemLook_x64.exe.
    Vista und Win7 User: Rechtsklick und "als Administrator starten".
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:

  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Wenn der Suchlauf beendet ist, wird sich dein Editor mit den Ergebnissen öffnen. Poste diese in deinen Thread.
  • Das Log-File wird auch auf dem Desktop als SystemLook.txt gespeichert.

Schritt 2

Du hast unter anderem eine veraltete Java-Version installiert. Ältere Versionen enthalten Sicherheitslücken, die von Malware zur Infizierung per Drive-by Download missbraucht werden können.

Die aktuelle Version ist Java 7 Update 21.
  • Gehe zu
    Start --> Systemsteuerung --> Programme und Funktionen (bei Vista / Win 7)
    Start --> Systemsteuerung --> Software (bei Win XP)
    und deinstalliere alle älteren Java-Versionen.

Schritt 3

Die Version deines Adobe PDF Readers ist veraltet, wir müssen ihn updaten:
  • Deinstalliere bitte deine aktuelle Version von Adobe Reader über
    Start --> Systemsteuerung --> Software (bei Windows XP)
    Start --> Systemsteuerung --> Programme und Funktionen (bei Vista / Windows 7)
  • Besuche diese Seite von Adobe.
  • Entferne gegebenenfalls den Haken bei McAfee Security Scan bzw. Google Chrome.
  • Drücke auf Jetzt herunterladen und installiere die neuste Version.

Schritt 4

Downloade und installiere dir die neuste Version des Mozilla Firefox.

Überprüfe dann mit diesem Plugin-Check (mit dem Firefox hier), ob nun alle deine verwendeten Versionen aktuell sind und update sie anderenfalls.

Schritt 5
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Wenn der Scan beendet wurde, sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

Bitte poste in deiner nächsten Antwort:
  • Log von SystemLook
  • Log von SecurityCheck

Alt 03.06.2013, 20:02   #15
snapdo und searchnu  nerven extrem - Standard

snapdo und searchnu nerven extrem

SystemLook 30.07.11 by jpshortstuff
Log created at 20:19 on 03/06/2013 by Familie B
Administrator - Elevation successful

========== filefind ==========

Searching for "*snap.do*"
No files found.

Searching for "*snapdo*"
No files found.

Searching for "*searchnu*"
C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.searchnu.com_0.localstorage --a---- 286720 bytes [19:39 28/05/2013] [17:18 02/06/2013] D2FA16D0F1ADC343A083695015A26DCC
C:\Users\Familie B\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.searchnu.com_0.localstorage-journal --a---- 16384 bytes [19:39 28/05/2013] [17:18 02/06/2013] 53ABF1FD77F9A64AFC81CD1FD713BCE0

========== folderfind ==========

Searching for "*snap.do*"
No folders found.

Searching for "*snapdo*"
No folders found.

Searching for "*searchnu*"
No folders found.

========== regfind ==========

Searching for "snap.do"
"DisplayName"="Snap.Do Engine"
"DisplayName"="Snap.Do Engine"

Searching for "snapdo"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_USERS\S-1-5-21-3290196298-4204039042-1804756541-1000\Software\Microsoft\Internet Explorer\SearchUrl]

Searching for "searchnu"
No data found.

-= EOF =-

Results of screen317's Security Check version 0.99.64
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version
Java 7 Update 21
Adobe Flash Player 11.7.700.202
Adobe Reader XI
Mozilla Firefox (21.0)
Mozilla Thunderbird (17.0.6)
Google Chrome 27.0.1453.93
Google Chrome 27.0.1453.94
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````


