![]() |
|
Plagegeister aller Art und deren Bekämpfung: Malwarebytes Anti-Malware mal wieder ....1Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() Malwarebytes Anti-Malware mal wieder ....1 Hallo, mich hat's nun auch mal wieder erwischt ![]() Nachdem ich mir heute die Malwarebytes Anti-Malware Pro Version gekauft habe wurden gleich etliche PUPs festgestellt, von denen ich mir auch nicht sicher bin, ob ich die ALLE entfernen lassen soolte?? Ich hab hier gleich mal den FRST.txt und Addition.txt angefügt mt der Bitte um fachkundige Hilfe ![]() Gruß OpaPaule P.S. Das System meldet, dass mein Text zu lang sei! Deshalb habe ich die Addition.txt im nächsten Thread, sorry! Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Ich (administrator) on ICH-PC on 10-10-2013 17:01:56 Running from C:\Users\Ich\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe (IOBit) C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe (FarStone Inc.) C:\Program Files (x86)\FarStone DriveClone\Files\FsSvcExe.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAcat.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Systweak Software, (www.systweak.com)) C:\Program Files (x86)\Advanced System Optimizer 3\ASO3DefragSrv64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Fork Ltd.) C:\Prey\platform\windows\cronsvc.exe () C:\Program Files (x86)\abylonsoft\CRYPT-BOX\CryptBoxSerX64.EXE (Brio) C:\Program Files\FolderSize\FolderSizeSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware 21.5.13\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware 21.5.13\mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe () C:\Users\Ich\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Conduit) C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Conduit) C:\PROGRA~2\SearchProtect\SearchProtect\bin\cltmng.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware 21.5.13\mbamgui.exe (Conduit) C:\PROGRA~2\SearchProtect\UI\bin\cltmngui.exe (Simplygen) C:\Program Files (x86)\HomeTab\ProtectedSearch.exe (Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Bitsum) C:\Program Files\Process Lasso\processgovernor.exe (Bitsum) C:\Program Files\Process Lasso\processlasso.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Monitor.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (SHADOWDEFENDER.COM) C:\Program Files\Shadow Defender\DefenderDaemon.exe () C:\Program Files (x86)\Snappy Fax Version 5\sfpagent.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe (1&1 Mail & Media GmbH) C:\Users\Ich\AppData\Local\WEB.DE Application {sync-000021}\webde_onlinespeicher.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe () C:\Tools\TaskmgrPro\TaskmgrPro.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (PGWARE LLC) C:\Tools\PCBoost\PCBoostTray.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (IncrediMail, Ltd.) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe (IncrediMail, Ltd.) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe (Microsoft Corporation) C:\Windows\sysWOW64\wbem\wmiprvse.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Asc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware 21.5.13\mbam.exe (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\avscan.exe (Systweak Software, (www.systweak.com)) C:\Program Files (x86)\Advanced System Optimizer 3\ASO3.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Ocs_SM] - C:\Users\Ich\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [106496 2013-03-29] (OCS) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [517912 2013-02-15] (Acronis) HKLM\...\Run: [Shadow Defender Daemon] - C:\Program Files\Shadow Defender\DefenderDaemon.exe [325760 2013-03-31] (SHADOWDEFENDER.COM) HKLM\...\Run: [Snappy Fax Printer virtual printer agent] - C:\Program Files (x86)\Snappy Fax Version 5\sfpagent.exe [116224 2009-10-05] () HKCU\...\Run: [Advanced SystemCare Ultimate] - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe [512384 2012-11-07] (IObit) HKCU\...\Run: [Browser Infrastructure Helper] - C:\Users\Ich\AppData\Local\Smartbar\Application\SnapDo.exe [21024 2013-08-07] (Smartbar) HKCU\...\Run: [TaskmgrPro] - C:\Tools\TaskmgrPro\TaskmpStart.exe [92504 2013-09-05] () HKCU\...\Run: [WEB.DE Application {sync-000021}] - C:\Users\Ich\AppData\Local\WEB.DE Application {sync-000021}\webde_onlinespeicher.exe [875008 2013-09-13] (1&1 Mail & Media GmbH) HKCU\...\Run: [1und1DispatcherCorp] - C:\Users\Ich\AppData\Local\1und1UpdaterCorpE\SchedDispatcher.exe [220808 2013-05-29] (1&1 Mail & Media GmbH) HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-09-04] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe [578560 2013-07-18] (Samsung Electronics) HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-09-04] (Samsung) HKCU\...\Policies\Explorer: [NoInstrumentation] 1 HKCU\...\Policies\Explorer: [NoCDBurning] 1 MountPoints2: I - I:\start.exe MountPoints2: {e3a922e9-cccc-11e2-926e-00a0d1ab34e8} - M:\LxSetup.exe HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [542632 2013-01-31] (Lavasoft) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [6405376 2013-03-28] (Acronis) HKLM-x32\...\Run: [AcronisTibMounterMonitor] - C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1105848 2013-01-10] (Acronis) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IObit Malware Fighter] - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [1549120 2013-08-16] (IObit) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.) HKLM-x32\...\Run: [PCBoost] - C:\Tools\PCBoost\PCBoostTray.exe [1811096 2013-09-08] (PGWARE LLC) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.) HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [1300256 2013-10-06] (Conduit) AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [980768 2013-10-06] (Conduit) Startup: C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=DE&userid=2687232b-c47b-224d-a605-090a62d86506&searchtype=ds&q={searchTerms}&installDate=10/09/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3314932&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPE87DD8A5-A194-43EB-B140-7865469CCE47 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFFCAEAA96228CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=DE&userid=2687232b-c47b-224d-a605-090a62d86506&searchtype=ds&q={searchTerms}&installDate=10/09/2013 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www1.delta-search.com/?affID=119776&babsrc=HP_ss_pr&mntrId=2EB10016EA9A6B4E HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.portaldosites.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9640320AS_5WX0S82RXXXX5WX0S82R&ts=1376149482 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.6&ts=1378013812866.000007&tguid=66920-6787-1378013812866-B816DA149CE32BB127529DD2057379EC&st=chrome&q= HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.portaldosites.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9640320AS_5WX0S82RXXXX5WX0S82R&ts=1376149482 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.portaldosites.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9640320AS_5WX0S82RXXXX5WX0S82R&ts=1376149482 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.6&ts=1378013812866.000007&tguid=66920-6787-1378013812866-B816DA149CE32BB127529DD2057379EC&st=chrome&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.portaldosites.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9640320AS_5WX0S82RXXXX5WX0S82R&ts=1376149482 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.6&ts=1378013812866.000007&tguid=66920-6787-1378013812866-B816DA149CE32BB127529DD2057379EC&st=chrome&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.6&ts=1378013812866.000007&tguid=66920-6787-1378013812866-B816DA149CE32BB127529DD2057379EC&st=chrome&q= StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.portaldosites.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9640320AS_5WX0S82RXXXX5WX0S82R&ts=1376149482 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.portaldosites.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=ST9640320AS_5WX0S82RXXXX5WX0S82R&ts=1376149483 SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=DE&userid=2687232b-c47b-224d-a605-090a62d86506&searchtype=ds&q={searchTerms}&installDate=10/09/2013 SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314932&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPE87DD8A5-A194-43EB-B140-7865469CCE47&q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=DE&userid=2687232b-c47b-224d-a605-090a62d86506&searchtype=ds&q={searchTerms}&installDate=10/09/2013 SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314932&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPE87DD8A5-A194-43EB-B140-7865469CCE47&q={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E62696E672E636F6D2F7365617263683F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826464F524D3D494531305352&st={searchTerms}&clid=2325b234-ec0b-43a5-b88e-268568c155da&pid=freewarede&k=0 BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Ich\AppData\Roaming\Complitly\64\Complitly64.dll (SimplyGen) BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Freecorder extension x64 - {B15BBE59-42F5-4206-B3F0-BE98F5DC4B93} - C:\Program Files\Freecorder extension x64\ScriptHost.dll (Applian Technologies Inc.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Ich\AppData\Roaming\Complitly\Complitly.dll (SimplyGen) BHO-x32: Chat Undetected - {11111111-1111-1111-1111-110111491117} - C:\Program Files (x86)\Chat Undetected\Chat Undetected.dll (Crossrider) BHO-x32: PriceGong - Price Comparison - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.6.10\PriceGongIE.dll (PriceGong) BHO-x32: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: amazon - {84B94901-3645-4D80-A6B7-4D0050B19455} - C:\Program Files (x86)\Preispiraten6\IEButtonAmazonInterface.dll () BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files (x86)\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent) BHO-x32: HomeTab - {a25e7121-3dd8-41b3-855b-756c5bc45449} - C:\Users\Ich\AppData\Roaming\HomeTab\HomeTab.dll (Simply Tech Ltd.) BHO-x32: Wajam - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll (Wajam) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Freecorder extension - {B15BBE59-42F5-4206-B3F0-BE98F5DC4B93} - C:\Program Files (x86)\Freecorder extension\ScriptHost.dll (Applian Technologies Inc.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\BrowerProtect\ASCPlugin_Protection.dll (IObit) BHO-x32: No Name - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - No File BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: IEHlprObj Class - {DA5A2A9E-DF07-4a8e-B423-BC5CD4D1880C} - C:\Program Files (x86)\FileStream\Web Boomerang\IEHelper.dll () BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Preispiraten - {E9E027BF-C3F3-4022-8F6B-8F6D39A59684} - C:\Program Files (x86)\Preispiraten6\IEButtonPPInterface.dll () Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - HomeTab - {a25e7121-3dd8-41b3-855b-756c5bc45449} - C:\Users\Ich\AppData\Roaming\HomeTab\HomeTab.dll (Simply Tech Ltd.) Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default FF user.js: detected! => C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\user.js FF NewTab: about:home FF SearchEngineOrder.1: Web Search FF Homepage: about:home FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=DE&userid=2687232b-c47b-224d-a605-090a62d86506&searchtype=ds&installDate=10/09/2013&q= FF NetworkProxy: "ftp", "187.1.116.8" FF NetworkProxy: "ftp_port", 8080 FF NetworkProxy: "gopher", "187.1.116.8" FF NetworkProxy: "gopher_port", 8080 FF NetworkProxy: "http", "187.1.116.8" FF NetworkProxy: "http_port", 8080 FF NetworkProxy: "type", 1 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Freecorder - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\addon@freecorder.com FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\ascsurfingprotection@iobit.com FF Extension: Виявлення пристроїв Logitech - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\DeviceDetection@logitech.com FF Extension: DoNotTrackMe - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\donottrackplus@abine.com FF Extension: Shopping-preise.de - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\mail@shopping-preise.de FF Extension: MinimizeToTray revived (MinTrayR) - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\mintrayr@tn123.ath.cx FF Extension: TooManyTabs - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\TooManyTabs@visibotech.com FF Extension: 瀏覽頁組管理員 - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30} FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{20cc25e2-48c9-45e1-9a1f-1ccc1882b81b} FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{2687232b-c47b-224d-a605-090a62d86506} FF Extension: TV-Fox - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4} FF Extension: Complitly - Speed up your search with your personal search suggestions tool - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516} FF Extension: Flashblock - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f}-trash FF Extension: HomeTab - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} FF Extension: ReminderFox - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae} FF Extension: DownloadHelper - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: Flash and Video Download - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} FF Extension: TextMarker Go - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{cd6c4ebf-366e-45a0-98b5-b8217288eed7} FF Extension: CSHelper - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{d91a2be6-3b56-4dfb-97f5-5e48fe3ed473} FF Extension: FoxLingo - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66} FF Extension: about-addons-memory - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\about-addons-memory@tn123.org.xpi FF Extension: bookmarkfaviconchanger - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\bookmarkfaviconchanger@sonthakit.xpi FF Extension: canitbecheaper - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\canitbecheaper@trafficbroker.co.uk.xpi FF Extension: facebook - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\facebook@disconnect.me.xpi FF Extension: gutegutscheine - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\gutegutscheine@gutegutscheine.com.xpi FF Extension: info - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\info@skymeissner.com.xpi FF Extension: pricepeep - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\pricepeep@getpricepeep.com.xpi FF Extension: support - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\support@free-hideip.com.xpi FF Extension: tabcounter - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\tabcounter@morac.xpi FF Extension: tabpopup - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\tabpopup@adarsh.tp.xpi FF Extension: toolbar - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\toolbar@web.de.xpi FF Extension: treestyletab - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\treestyletab@piro.sakura.ne.jp.xpi FF Extension: webbooster - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\webbooster@iminent.com.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\WTB_GLOBAL.sqlite FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{398e77b8-2304-11dc-8314-0800200c9a66}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{791DB184-BFBA-11DA-9C61-0638DF403F48}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{792BDDFE-2E7C-42ed-B18D-18154D2761BD}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKCU\...\Firefox\Extensions: [sparpilot@sparpilot.com] - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\pz5o8de2.default\extensions\sparpilot@sparpilot.com FF HKCU\...\Firefox\Extensions: [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}] - C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: () - C:\Users\Ich\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0 CHR Extension: (YouTube) - C:\Users\Ich\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_1 CHR Extension: (Google Search) - C:\Users\Ich\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1 CHR Extension: () - C:\Users\Ich\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\6.32.3.1_0 CHR Extension: (Chat Undetected) - C:\Users\Ich\AppData\Local\Google\Chrome\User Data\Default\Extensions\llmfehnfojojfamjjijjciopbjimcffa\1.23.59_0 CHR Extension: () - C:\Users\Ich\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje\1.0_1 CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Ich\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_1 CHR Extension: (Yontoo) - C:\Users\Ich\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.3_1 CHR Extension: (Gmail) - C:\Users\Ich\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [bddpogknpjlgfpbboediomaiiaecfajn] - C:\Program Files (x86)\HomeTab\chrome\HomeTab.crx CHR HKLM-x32\...\Chrome\Extension: [dlfienamagdnkekbbbocojppncdambda] - C:\Program Files (x86)\Complitly\chrome\ComplitlyChrome.crx CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Ich\AppData\Roaming\BabSolution\CR\delta1.crx CHR HKLM-x32\...\Chrome\Extension: [gpicboiclhmnllnjdcfcffifpoaebgkm] - C:\Program Files (x86)\Freecorder extension\Freecorder.crx CHR HKLM-x32\...\Chrome\Extension: [hbcennhacfaagdopikcegfcobcadeocj] - C:\Program Files (x86)\Common Files\Spigot\GC\saebay_1.0.crx CHR HKLM-x32\...\Chrome\Extension: [icdlfehblmklkikfigmjhbmmpmkmpooj] - C:\Program Files (x86)\Common Files\Spigot\GC\errorassistant_1.1.crx CHR HKLM-x32\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\Ich\AppData\Local\Wajam\Chrome\wajam.crx CHR HKLM-x32\...\Chrome\Extension: [mhkaekfpcppmmioggniknbnbdbcigpkk] - C:\Program Files (x86)\Common Files\Spigot\GC\coupons_2.4.crx CHR HKLM-x32\...\Chrome\Extension: [nbmafkdmkkckhggblphicnnhlgljnoje] - C:\Program Files (x86)\TornTV.com\torn2_10.crx CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\BrowerProtect\ASC_GhromePlugin.crx CHR HKLM-x32\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Program Files (x86)\Yontoo\YontooLayers.crx CHR HKLM-x32\...\Chrome\Extension: [pfndaklgolladniicklehhancnlgocpp] - C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-05-05] (Adobe Systems) R2 AdvancedSystemCareService6; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe [1051088 2012-12-13] (IObit) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-01] (Avira Operations GmbH & Co. KG) S3 Apache2.2; C:\Program Files (x86)\SMTPing\Apache\bin\httpd.exe [20549 2012-01-28] (Apache Software Foundation) R2 ASCAntivirusSrv; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [621008 2012-12-14] (IOBit) R2 ASO3DiskOptimizer; C:\Program Files (x86)\Advanced System Optimizer 3\ASO3DefragSrv64.exe [264488 2013-09-18] (Systweak Software, (www.systweak.com)) S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [137960 2013-05-09] (AVAST Software) S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [32808 2013-07-01] (Just Develop It) R2 CltMngSvc; C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe [1752864 2013-10-06] (Conduit) R2 CronService; C:\Prey\platform\windows\cronsvc.exe [23552 2013-05-08] (Fork Ltd.) R2 CryptBox; C:\Program Files (x86)\abylonsoft\CRYPT-BOX\CryptBoxSerX64.EXE [387112 2013-05-17] () R2 FolderSize; C:\Program Files\FolderSize\FolderSizeSvc.exe [163840 2013-02-13] (Brio) R2 FSDcSvc; C:\Program Files (x86)\FarStone DriveClone\Files\FsSvcExe.exe [338944 2013-06-20] (FarStone Inc.) S4 hola_svc; C:\Program Files\Hola\app\hola_svc.exe [5542976 2013-08-12] (Hola Networks Ltd.) S4 hola_updater; C:\Program Files\Hola\app\hola_updater.exe [5542976 2013-08-12] (Hola Networks Ltd.) R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [335168 2013-04-25] (IObit) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware 21.5.13\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware 21.5.13\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 OAcat; C:\Program Files (x86)\Online Armor\OAcat.exe [216072 2012-10-02] (Emsisoft GmbH) S3 PyCron; C:\Program Files (x86)\SMTPing\PyCron\pycron.exe [24576 2006-06-05] () S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [123664 2012-12-16] (SANDBOXIE L.T.D) R2 SearchAnonymizer; C:\Users\Ich\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2013-03-29] () S4 SProtection; C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe [2868544 2013-08-07] (Iminent) S3 SvcOnlineArmor; C:\Program Files (x86)\Online Armor\oasrv.exe [4463864 2012-10-02] (Emsisoft GmbH) S3 SystemExplorerHelpService; C:\Tools\System Explorer\service\SystemExplorerService64.exe [821720 2012-11-25] (Mister Group) S4 WajamUpdater; C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [109064 2013-02-26] (Wajam) S2 WsysSvc; S4 Yontoo Desktop Updater; "C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe" "C:\Users\Ich\AppData\Roaming\Yontoo\YontooDesktop.exe" ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R1 aswFW; C:\Windows\System32\Drivers\aswFW.sys [131232 2013-05-09] (AVAST Software) R0 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12368 2013-02-18] (ALWIL Software) R0 aswNdis2; C:\Windows\System32\Drivers\aswNdis2.sys [270824 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-28] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-28] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-28] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105856 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) R2 bdfsfltr; C:\Windows\system32\Drivers\bdfsfltr.sys [431176 2011-03-24] (BitDefender) R2 bdfsfltr; C:\Windows\system32\Drivers\bdfsfltr.sys [431176 2011-03-24] (BitDefender) S3 BrSerIf; C:\Windows\System32\DRIVERS\BrSerIf.sys [97280 2006-12-12] (Brother Industries Ltd.) R0 diskpt; C:\Windows\System32\drivers\diskpt.sys [261352 2013-03-31] (SHADOWDEFENDER.COM) R1 DVDHelp; C:\Windows\System32\drivers\DVDHelp.sys [28696 2013-04-13] () R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [30752 2012-08-02] (EldoS Corporation) R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [30752 2012-08-02] (EldoS Corporation) S3 FARMNTIO; c:\windows\system32\drivers\farmntio.sys [25144 2013-04-11] () S3 FARMNTIO; c:\windows\system32\drivers\farmntio.sys [25144 2013-04-11] () R3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit) R3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit) S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-07-18] () S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-07-18] () S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [38456 2013-02-11] (GFI Software) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-03-30] (GFI Software) R1 hola-drv; C:\Windows\System32\DRIVERS\hola_drv.sys [582080 2013-08-12] (Hola Networks Ltd.) R1 hola-mon-drv; C:\Windows\System32\DRIVERS\hola_mon_drv.sys [88696 2013-08-12] (Hola Networks Ltd.) R1 hola_net; C:\Windows\System32\DRIVERS\hola_net.sys [87232 2013-08-12] (Hola Networks Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.) R1 OADevice; C:\Windows\SysWow64\Drivers\OADriver.sys [61632 2012-10-02] () R1 OADevice; C:\Windows\SysWow64\Drivers\OADriver.sys [61632 2012-10-02] () R1 oahlpXX; C:\Windows\syswow64\drivers\oahlp64.sys [62016 2012-10-02] () R1 oahlpXX; C:\Windows\syswow64\drivers\oahlp64.sys [62016 2012-10-02] () R1 OAmon; C:\Windows\SysWOW64\Drivers\OAmon.sys [40520 2012-10-02] (Emsisoft) R1 OAmon; C:\Windows\SysWOW64\Drivers\OAmon.sys [40520 2012-10-02] (Emsisoft) R3 OAnet; C:\Windows\System32\DRIVERS\oanet.sys [35376 2012-10-02] (Emsisoft) R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34336 2013-03-26] (IObit.com) R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34336 2013-03-26] (IObit.com) S3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [114568 2012-08-27] (Renesas Electronics Corporation) S3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [230280 2012-08-27] (Renesas Electronics Corporation) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202632 2012-12-16] (SANDBOXIE L.T.D) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] () R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-24] (Synaptics Incorporated) R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2013-05-05] (Acronis International GmbH) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [183224 2013-05-05] (Acronis) R3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-03-26] (IObit.com) R3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-03-26] (IObit.com) R0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [117024 2013-05-05] (Acronis International GmbH) R2 WinisoCDBus; C:\Windows\System32\drivers\WinisoCDBus.sys [204032 2013-05-10] (WinISO.com) S3 cpuz130; \??\C:\Users\Ich\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x] U3 DfSdkS; S3 EverestDriver; \??\H:\Tools\Everest_Ultimate_Edition_v.5.30.1964_Beta_(Portable)_by_PP-Elite\kerneld.amd64 [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-10 17:01 - 2013-10-10 17:01 - 00000000 ____D C:\FRST 2013-10-10 17:00 - 2013-10-10 17:00 - 01954124 _____ (Farbar) C:\Users\Ich\Downloads\FRST64.exe 2013-10-10 10:27 - 2013-10-10 10:27 - 00006622 ____N C:\spyhunter.log 2013-10-10 10:04 - 2013-10-10 10:04 - 00000000 ____D C:\SoloApp 2013-10-10 08:28 - 2013-10-10 08:30 - 00017759 _____ C:\sh4_service.log 2013-10-10 07:58 - 2013-10-10 09:52 - 00000000 ____D C:\Users\Ich\AppData\Local\SearchProtect 2013-10-10 07:57 - 2013-10-10 05:16 - 00008192 _____ C:\shldr.mbr 2013-10-10 07:57 - 2012-11-02 16:23 - 00285747 _____ C:\shldr 2013-10-10 05:26 - 2013-10-10 10:41 - 00000000 ____D C:\ProgramData\SecTaskMan 2013-10-10 05:25 - 2013-10-10 10:41 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2013-10-10 05:24 - 2013-10-10 05:25 - 00000000 ____D C:\Users\Ich\Downloads\S.T.M.1.8g 2013-10-10 05:15 - 2013-10-10 05:16 - 00000000 ____D C:\sh4ldr 2013-10-10 05:15 - 2013-10-10 05:15 - 00000000 ____D C:\Program Files (x86)\Enigma Software Group 2013-10-10 05:14 - 2013-10-10 10:47 - 00000000 ____D C:\Windows\DB847E94446B49E0AC5DC5627EC8B0C0.TMP 2013-10-10 05:06 - 2013-10-10 05:06 - 00000000 ____D C:\Windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP 2013-10-10 05:00 - 2013-10-10 05:00 - 00000000 _____ C:\autoexec.bat 2013-10-10 04:56 - 2013-10-10 04:56 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-09 11:17 - 2013-10-09 11:17 - 00000000 ____D C:\PDFToWordConverter 2013-10-09 10:45 - 2013-10-09 10:45 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-10-09 10:43 - 2013-07-18 07:34 - 00233472 _____ (Teruten) C:\Windows\SysWOW64\FsUsbExService.Exe 2013-10-09 10:43 - 2013-07-18 07:34 - 00037344 _____ C:\Windows\SysWOW64\FsUsbExDisk.Sys 2013-10-09 10:43 - 2012-12-18 10:08 - 00110592 _____ () C:\Windows\SysWOW64\FsUsbExDevice.Dll 2013-10-09 10:40 - 2013-10-09 10:44 - 00001970 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk 2013-10-09 10:40 - 2013-10-09 10:40 - 00001960 _____ C:\Users\Public\Desktop\Samsung Kies.lnk 2013-10-09 10:35 - 2012-12-18 10:06 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll 2013-10-09 10:30 - 2013-10-10 10:47 - 00000000 ____D C:\Program Files (x86)\SearchProtect 2013-10-09 10:30 - 2013-10-09 10:30 - 00000000 _____ C:\END 2013-10-05 12:14 - 2013-10-05 12:14 - 00000000 ____D C:\Users\Ich\.android 2013-10-05 12:12 - 2013-10-05 12:23 - 00000000 ____D C:\Users\Ich\AppData\Roaming\MyPhoneExplorer 2013-10-05 12:12 - 2013-10-05 12:12 - 00002025 _____ C:\Users\Public\Desktop\MyPhoneExplorer.lnk 2013-10-05 12:11 - 2013-10-05 12:12 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer 2013-10-04 06:10 - 2013-10-09 13:53 - 00000000 ____D C:\Users\Ich\Desktop\PDF 2013-10-03 16:21 - 2013-10-03 16:21 - 00000000 ____D C:\ProgramData\Fighters 2013-10-03 16:19 - 2013-10-03 16:19 - 00001740 _____ C:\Users\Public\Desktop\SLOW-PCfighter.lnk 2013-10-03 16:15 - 2013-10-03 16:15 - 00000000 ____D C:\Program Files\Bildbearbeitung 2013-10-03 09:13 - 2013-10-10 09:53 - 00000310 _____ C:\Windows\Tasks\SLOW-PCfighter64-Ich-Startup.job 2013-10-03 09:13 - 2013-10-10 09:52 - 00000312 _____ C:\Windows\Tasks\SLOW-PCfighter64-Ich-Notification.job 2013-10-03 09:13 - 2013-10-03 09:13 - 00003368 _____ C:\Windows\System32\Tasks\SLOW-PCfighter64-Ich-Notification 2013-10-03 09:13 - 2013-10-03 09:13 - 00002682 _____ C:\Windows\System32\Tasks\SLOW-PCfighter64-Ich-Startup 2013-10-01 17:33 - 2013-10-01 17:33 - 00000000 ____D C:\Users\Ich\Documents\Benutzerdefinierte Office-Vorlagen 2013-10-01 12:55 - 2013-10-01 12:55 - 00000000 ____D C:\Users\Ich\Documents\spp 2013-10-01 12:55 - 2013-10-01 12:55 - 00000000 ____D C:\Users\Ich\Documents\apdf 2013-10-01 12:55 - 2013-10-01 12:55 - 00000000 ____D C:\ProgramData\A-PDF 2013-10-01 12:48 - 2013-10-01 12:48 - 00000000 ____D C:\Program Files (x86)\A-PDF Scan Paper 2013-10-01 12:33 - 2013-10-01 12:33 - 00478624 _____ C:\Users\Ich\Downloads\Franzis_Office_2010_Vorlagen4-Downloader.exe 2013-10-01 12:33 - 2013-10-01 12:33 - 00478624 _____ C:\Users\Ich\Downloads\Franzis_Office_2010_Vorlagen3-Downloader.exe 2013-10-01 12:33 - 2013-10-01 12:33 - 00478624 _____ C:\Users\Ich\Downloads\Franzis_Office_2010_Vorlagen2-Downloader.exe 2013-10-01 12:33 - 2013-10-01 12:33 - 00478624 _____ C:\Users\Ich\Downloads\Franzis_Office_2010_Vorlagen1-Downloader.exe 2013-09-29 10:50 - 2013-09-29 10:51 - 00011264 _____ C:\Users\Ich\qlgt.db 2013-09-29 10:49 - 2013-09-29 10:49 - 00000000 ____D C:\Program Files (x86)\QLandkarteGT 2013-09-28 07:14 - 2007-05-25 14:57 - 00061440 _____ () C:\Windows\SysWOW64\CIUtils.dll 2013-09-28 07:13 - 2013-09-28 07:13 - 00000000 ____D C:\Program Files (x86)\Franzis 2013-09-27 12:32 - 2013-09-27 12:32 - 00000000 ____D C:\ProgramData\PGWARE 2013-09-26 15:48 - 2013-09-26 15:48 - 00000000 ____D C:\Users\Ich\Downloads\Advanced System Optimizer 3.5.1000.15559 2013-09-26 14:59 - 2013-09-26 15:00 - 00000000 ____D C:\Users\Ich\WEB.DE Online-Speicher 2013-09-26 14:59 - 2013-09-26 15:00 - 00000000 ____D C:\Users\Ich\AppData\Local\WEB.DE Application {sync-000021} 2013-09-26 14:59 - 2013-09-26 15:00 - 00000000 ____D C:\Users\Ich\AppData\Local\1und1UpdaterCorpE 2013-09-26 14:59 - 2013-09-26 14:59 - 00001332 _____ C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WEB.DE Online-Speicher.lnk 2013-09-26 14:59 - 2013-09-26 14:59 - 00001324 _____ C:\Users\Ich\Desktop\WEB.DE Online-Speicher.lnk 2013-09-26 14:59 - 2013-09-26 14:59 - 00000000 ____D C:\ProgramData\UUdb 2013-09-26 13:09 - 2013-09-26 13:09 - 04012336 _____ (1&1 Mail & Media GmbH) C:\Users\Ich\Downloads\webde_onlinespeicher_setup_bundled.exe 2013-09-25 15:12 - 2013-10-10 15:12 - 00000426 _____ C:\Windows\Tasks\ASO-OneClickCare.job 2013-09-25 15:12 - 2013-10-09 15:12 - 00000456 _____ C:\Windows\Tasks\ASO-AutoCheckUpdate7Days.job 2013-09-25 15:12 - 2013-09-25 15:12 - 00003328 _____ C:\Windows\System32\Tasks\ASO-AutoCheckUpdate7Days 2013-09-25 15:12 - 2013-09-25 15:12 - 00003296 _____ C:\Windows\System32\Tasks\ASO-OneClickCare 2013-09-25 15:11 - 2013-09-26 15:51 - 00000000 ____D C:\Program Files (x86)\Advanced System Optimizer 3 2013-09-25 15:11 - 2013-09-25 15:11 - 00001486 _____ C:\Users\Public\Desktop\Intelligente PC-Wartung.lnk 2013-09-25 15:11 - 2013-09-25 15:11 - 00001434 _____ C:\Users\Public\Desktop\Advanced System Optimizer.lnk 2013-09-25 11:10 - 2013-09-25 11:10 - 00003094 _____ C:\Windows\System32\Tasks\Process Lasso Core Engine Only 2013-09-25 11:10 - 2013-09-25 11:10 - 00003088 _____ C:\Windows\System32\Tasks\Process Lasso Management Console (GUI) 2013-09-25 11:10 - 2013-09-25 11:10 - 00000000 ____D C:\Users\Ich\AppData\Roaming\ProcessLasso 2013-09-25 11:10 - 2013-09-25 11:10 - 00000000 ____D C:\ProgramData\ProcessLasso 2013-09-25 11:10 - 2013-09-25 11:10 - 00000000 ____D C:\Program Files\Process Lasso 2013-09-22 13:48 - 2013-09-22 13:49 - 00000000 ____D C:\Users\Ich\AppData\Roaming\TaskmgrPro 2013-09-22 13:47 - 2013-09-22 13:47 - 00000000 ____D C:\Users\Ich\Documents\TaskmgrPro 2013-09-22 07:24 - 2013-09-22 07:24 - 43966464 _____ C:\Windows\system32\config\components.iobit 2013-09-20 11:04 - 2013-09-20 11:04 - 00001028 _____ C:\Users\Public\Desktop\BORG Calendar.lnk 2013-09-20 11:04 - 2013-09-20 11:04 - 00000000 ____D C:\Program Files (x86)\BORGCalendar 2013-09-19 14:29 - 2013-09-19 14:29 - 00001747 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-09-19 14:27 - 2013-09-19 14:29 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-09-19 14:27 - 2013-09-19 14:28 - 00000000 ____D C:\Program Files\iTunes 2013-09-19 14:27 - 2013-09-19 14:28 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-09-19 14:27 - 2013-09-19 14:27 - 00000000 ____D C:\Program Files\iPod 2013-09-19 13:26 - 2013-09-19 13:37 - 1138668207 _____ C:\Users\Ich\Downloads\iPad2,2_7.0_11A465_Restore.ipsw 2013-09-19 11:03 - 2013-09-19 11:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-18 16:33 - 2013-09-18 16:33 - 00000008 _____ C:\Users\Ich\AppData\Roaming\pdfdrawcodec.dll 2013-09-18 16:32 - 2013-09-18 16:33 - 00000000 ____D C:\Program Files (x86)\WinPDFEditor 2013-09-17 08:49 - 2013-09-17 08:49 - 00000000 ____D C:\Users\Ich\Downloads\BZ-170913 100 Einkommen 2013-09-16 13:23 - 2013-09-16 13:23 - 90402816 _____ C:\Windows\system32\config\software.iobit 2013-09-16 13:23 - 2013-09-16 13:23 - 00327680 _____ C:\Windows\system32\config\default.iobit 2013-09-16 13:23 - 2013-09-16 13:23 - 00032768 _____ C:\Windows\system32\config\sam.iobit 2013-09-16 13:23 - 2013-09-16 13:23 - 00028672 _____ C:\Windows\system32\config\security.iobit 2013-09-15 14:45 - 2013-09-15 14:45 - 00001981 _____ C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shotcut.lnk 2013-09-15 10:45 - 2013-09-15 10:45 - 00000000 ____D C:\Users\Ich\AppData\Local\Microsoft Toolkit 2013-09-15 09:38 - 2013-10-10 10:20 - 00005054 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Ich-PC-Ich Ich-PC 2013-09-12 15:28 - 2013-09-12 15:28 - 00000000 ____D C:\Windows\SysWOW64\iq 2013-09-12 07:05 - 2013-09-12 07:06 - 00000000 ____D C:\Users\Ich\Desktop\Player 2013-09-12 06:53 - 2013-09-12 06:54 - 97238077 _____ C:\Windows\SysWOW64\㏥퐣Ḭ 2013-09-11 16:24 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-11 16:24 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-11 16:24 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-11 16:24 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-11 16:24 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-11 16:24 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-11 16:24 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-11 16:24 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-11 16:24 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-11 16:24 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-11 16:24 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-11 16:24 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-11 16:24 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-11 16:24 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-11 16:24 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-11 16:24 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-11 16:24 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-11 16:24 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-11 16:24 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-11 16:24 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-11 16:24 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-11 14:48 - 2013-09-11 14:48 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2013-09-11 14:48 - 2013-09-11 14:48 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2013-09-11 14:48 - 2013-09-11 14:48 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2013-09-11 14:48 - 2013-09-11 14:48 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2013-09-11 14:48 - 2013-09-11 14:48 - 00000000 ____D C:\Program Files (x86)\OpenAL 2013-09-11 14:44 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2013-09-11 14:44 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2013-09-11 13:23 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 13:23 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-11 13:23 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-11 13:23 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-11 13:23 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-11 13:23 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-11 13:23 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-11 13:23 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 13:23 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-11 13:23 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 13:23 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-11 13:23 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-11 13:23 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-11 13:23 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-11 13:23 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-11 13:23 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 13:23 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-11 13:23 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-11 13:23 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-11 13:23 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-11 13:23 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-11 13:23 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 13:23 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-11 13:23 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 13:23 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 13:23 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-11 13:23 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-11 12:39 - 2013-09-11 12:39 - 97080355 _____ C:\Windows\SysWOW64\睍奨ḬC 2013-09-10 07:26 - 2013-09-10 07:26 - 00002362 _____ C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2013-09-10 07:26 - 2013-09-10 07:26 - 00002300 _____ C:\Users\Ich\Desktop\Search.lnk 2013-09-10 07:25 - 2013-10-10 10:47 - 00000000 ____D C:\Users\Ich\AppData\Local\Smartbar ==================== One Month Modified Files and Folders ======= 2013-10-10 17:01 - 2013-10-10 17:01 - 00000000 ____D C:\FRST 2013-10-10 17:00 - 2013-10-10 17:00 - 01954124 _____ (Farbar) C:\Users\Ich\Downloads\FRST64.exe 2013-10-10 16:51 - 2013-06-08 08:01 - 00000029 _____ C:\Windows\SysWOW64\TempWmicBatchFile.bat 2013-10-10 16:48 - 2013-03-24 16:55 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-10 16:29 - 2013-03-24 10:13 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-10 16:29 - 2013-03-24 10:13 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-10 16:09 - 2013-08-12 14:26 - 00000370 _____ C:\Windows\Tasks\WpsUpdateTask_Ich.job 2013-10-10 15:47 - 2013-03-24 08:57 - 01373651 _____ C:\Windows\WindowsUpdate.log 2013-10-10 15:12 - 2013-09-25 15:12 - 00000426 _____ C:\Windows\Tasks\ASO-OneClickCare.job 2013-10-10 15:01 - 2013-08-19 19:53 - 00000272 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job 2013-10-10 12:53 - 2013-07-10 13:03 - 00000370 _____ C:\Windows\Tasks\Lyrics-Pal Update.job 2013-10-10 12:22 - 2013-03-24 12:21 - 00000000 ____D C:\Users\Ich\.gigaflat 2013-10-10 10:47 - 2013-10-10 05:14 - 00000000 ____D C:\Windows\DB847E94446B49E0AC5DC5627EC8B0C0.TMP 2013-10-10 10:47 - 2013-10-09 10:30 - 00000000 ____D C:\Program Files (x86)\SearchProtect 2013-10-10 10:47 - 2013-09-10 07:25 - 00000000 ____D C:\Users\Ich\AppData\Local\Smartbar 2013-10-10 10:47 - 2013-08-22 17:00 - 00000000 ____D C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam 2013-10-10 10:47 - 2013-08-22 17:00 - 00000000 ____D C:\Program Files (x86)\Wajam 2013-10-10 10:47 - 2013-08-10 17:45 - 00000000 ____D C:\ProgramData\eSafe 2013-10-10 10:47 - 2013-08-10 17:44 - 00000000 ____D C:\Users\Ich\AppData\Roaming\eIntaller 2013-10-10 10:47 - 2013-05-11 08:33 - 00000000 ____D C:\Program Files (x86)\iPrint 2013-10-10 10:47 - 2013-04-15 07:56 - 00000000 ____D C:\Users\Ich\AppData\Roaming\BabSolution 2013-10-10 10:47 - 2013-04-15 07:56 - 00000000 ____D C:\ProgramData\BrowserProtect 2013-10-10 10:47 - 2013-04-15 07:55 - 00000000 ____D C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com 2013-10-10 10:47 - 2013-04-15 07:55 - 00000000 ____D C:\Program Files (x86)\TornTV.com 2013-10-10 10:47 - 2013-04-06 15:41 - 00000000 ____D C:\Users\Ich\AppData\Roaming\PC Speed Maximizer 2013-10-10 10:47 - 2013-04-01 18:06 - 00000000 ____D C:\Users\Ich\AppData\Roaming\OpenCandy 2013-10-10 10:47 - 2013-03-29 10:55 - 00000000 ____D C:\Program Files (x86)\Iminent 2013-10-10 10:47 - 2013-03-29 10:54 - 00000000 ____D C:\Program Files (x86)\PriceGong 2013-10-10 10:47 - 2013-03-28 07:52 - 00000000 ____D C:\Program Files (x86)\Chat Undetected 2013-10-10 10:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-10-10 10:41 - 2013-10-10 05:26 - 00000000 ____D C:\ProgramData\SecTaskMan 2013-10-10 10:41 - 2013-10-10 05:25 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2013-10-10 10:27 - 2013-10-10 10:27 - 00006622 ____N C:\spyhunter.log 2013-10-10 10:22 - 2013-03-24 09:14 - 00000000 ____D C:\Users\Ich 2013-10-10 10:20 - 2013-09-15 09:38 - 00005054 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Ich-PC-Ich Ich-PC 2013-10-10 10:04 - 2013-10-10 10:04 - 00000000 ____D C:\SoloApp 2013-10-10 10:03 - 2009-07-14 06:45 - 00021616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-10 10:03 - 2009-07-14 06:45 - 00021616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-10 09:58 - 2013-03-27 14:18 - 00000000 ____D C:\Users\Ich\AppData\Local\CrashDumps 2013-10-10 09:53 - 2013-10-03 09:13 - 00000310 _____ C:\Windows\Tasks\SLOW-PCfighter64-Ich-Startup.job 2013-10-10 09:52 - 2013-10-10 07:58 - 00000000 ____D C:\Users\Ich\AppData\Local\SearchProtect 2013-10-10 09:52 - 2013-10-03 09:13 - 00000312 _____ C:\Windows\Tasks\SLOW-PCfighter64-Ich-Notification.job 2013-10-10 09:52 - 2013-04-17 08:02 - 00000410 _____ C:\Windows\Tasks\PC Optimizer Pro64 startups.job 2013-10-10 09:50 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-10 08:30 - 2013-10-10 08:28 - 00017759 _____ C:\sh4_service.log 2013-10-10 05:25 - 2013-10-10 05:24 - 00000000 ____D C:\Users\Ich\Downloads\S.T.M.1.8g 2013-10-10 05:16 - 2013-10-10 07:57 - 00008192 _____ C:\shldr.mbr 2013-10-10 05:16 - 2013-10-10 05:15 - 00000000 ____D C:\sh4ldr 2013-10-10 05:15 - 2013-10-10 05:15 - 00000000 ____D C:\Program Files (x86)\Enigma Software Group 2013-10-10 05:06 - 2013-10-10 05:06 - 00000000 ____D C:\Windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP 2013-10-10 05:00 - 2013-10-10 05:00 - 00000000 _____ C:\autoexec.bat 2013-10-10 04:56 - 2013-10-10 04:56 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-10 04:19 - 2013-05-05 08:16 - 00003914 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{1C2F9F06-259B-477B-9268-915DE5B95F26} 2013-10-10 04:11 - 2013-04-10 10:32 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-09 16:24 - 2013-03-24 10:13 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-09 16:24 - 2013-03-24 10:13 - 00003848 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-09 15:12 - 2013-09-25 15:12 - 00000456 _____ C:\Windows\Tasks\ASO-AutoCheckUpdate7Days.job 2013-10-09 13:53 - 2013-10-04 06:10 - 00000000 ____D C:\Users\Ich\Desktop\PDF 2013-10-09 11:48 - 2013-03-24 16:55 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 11:48 - 2013-03-24 16:55 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 11:48 - 2013-03-24 16:55 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-09 11:17 - 2013-10-09 11:17 - 00000000 ____D C:\PDFToWordConverter 2013-10-09 11:17 - 2013-03-29 10:53 - 00000000 ____D C:\Users\Ich\AppData\Local\DownloadGuide 2013-10-09 10:45 - 2013-10-09 10:45 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-10-09 10:45 - 2013-03-27 09:30 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-10-09 10:44 - 2013-10-09 10:40 - 00001970 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk 2013-10-09 10:44 - 2013-04-27 14:12 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-10-09 10:44 - 2013-03-27 13:26 - 00000000 ____D C:\Users\Ich\AppData\Local\Downloaded Installations 2013-10-09 10:41 - 2013-04-27 14:22 - 00000000 ____D C:\Users\Ich\AppData\Roaming\Samsung 2013-10-09 10:41 - 2013-04-27 14:22 - 00000000 ____D C:\Users\Ich\AppData\Local\Samsung 2013-10-09 10:40 - 2013-10-09 10:40 - 00001960 _____ C:\Users\Public\Desktop\Samsung Kies.lnk 2013-10-09 10:35 - 2013-04-27 14:12 - 00000000 ____D C:\ProgramData\Samsung 2013-10-09 10:30 - 2013-10-09 10:30 - 00000000 _____ C:\END 2013-10-09 07:44 - 2009-07-14 19:58 - 02221790 _____ C:\Windows\system32\perfh007.dat 2013-10-09 07:44 - 2009-07-14 19:58 - 00669242 _____ C:\Windows\system32\perfc007.dat 2013-10-09 07:44 - 2009-07-14 07:13 - 00006256 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-08 17:02 - 2013-03-24 09:14 - 00000000 ___RD C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-08 11:54 - 2013-08-31 16:17 - 00000000 ____D C:\Users\Ich\AppData\Roaming\vlc 2013-10-07 16:02 - 2013-09-05 06:24 - 00000999 _____ C:\Users\Public\Desktop\Free Hide IP.lnk 2013-10-06 13:39 - 2013-03-24 10:13 - 00000000 ____D C:\Users\Ich\AppData\Local\Google 2013-10-06 13:10 - 2013-03-24 12:42 - 00000000 ____D C:\Users\Ich\Documents\Recht 2013-10-06 08:49 - 2013-03-24 12:23 - 00000000 ____D C:\Users\Ich\Documents\Abmahnung 2013-10-06 08:12 - 2013-05-12 09:20 - 00000000 ____D C:\Users\Ich\Desktop\Tools 2013-10-05 18:27 - 2013-03-24 10:13 - 00002147 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-05 13:03 - 2013-03-24 12:41 - 00000000 ____D C:\Users\Ich\Documents\Outlook-Dateien 2013-10-05 12:23 - 2013-10-05 12:12 - 00000000 ____D C:\Users\Ich\AppData\Roaming\MyPhoneExplorer 2013-10-05 12:14 - 2013-10-05 12:14 - 00000000 ____D C:\Users\Ich\.android 2013-10-05 12:12 - 2013-10-05 12:12 - 00002025 _____ C:\Users\Public\Desktop\MyPhoneExplorer.lnk 2013-10-05 12:12 - 2013-10-05 12:11 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer 2013-10-05 09:58 - 2013-03-24 12:26 - 00000000 ____D C:\Users\Ich\Documents\Handy 2013-10-04 17:03 - 2013-08-30 08:47 - 00000000 ____D C:\Users\Ich\Desktop\Bildbearbeitung 2013-10-03 16:21 - 2013-10-03 16:21 - 00000000 ____D C:\ProgramData\Fighters 2013-10-03 16:19 - 2013-10-03 16:19 - 00001740 _____ C:\Users\Public\Desktop\SLOW-PCfighter.lnk 2013-10-03 16:15 - 2013-10-03 16:15 - 00000000 ____D C:\Program Files\Bildbearbeitung 2013-10-03 09:13 - 2013-10-03 09:13 - 00003368 _____ C:\Windows\System32\Tasks\SLOW-PCfighter64-Ich-Notification 2013-10-03 09:13 - 2013-10-03 09:13 - 00002682 _____ C:\Windows\System32\Tasks\SLOW-PCfighter64-Ich-Startup 2013-10-03 09:12 - 2013-04-04 06:01 - 00000000 ____D C:\Tools 2013-10-01 17:35 - 2013-03-24 12:23 - 00000000 ____D C:\Users\Ich\Documents\1 und 1 2013-10-01 17:33 - 2013-10-01 17:33 - 00000000 ____D C:\Users\Ich\Documents\Benutzerdefinierte Office-Vorlagen 2013-10-01 12:58 - 2013-08-30 11:53 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-10-01 12:58 - 2013-08-30 11:51 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-10-01 12:58 - 2013-08-30 11:51 - 00105856 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-10-01 12:58 - 2013-08-30 11:51 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-10-01 12:55 - 2013-10-01 12:55 - 00000000 ____D C:\Users\Ich\Documents\spp 2013-10-01 12:55 - 2013-10-01 12:55 - 00000000 ____D C:\Users\Ich\Documents\apdf 2013-10-01 12:55 - 2013-10-01 12:55 - 00000000 ____D C:\ProgramData\A-PDF 2013-10-01 12:48 - 2013-10-01 12:48 - 00000000 ____D C:\Program Files (x86)\A-PDF Scan Paper 2013-10-01 12:33 - 2013-10-01 12:33 - 00478624 _____ C:\Users\Ich\Downloads\Franzis_Office_2010_Vorlagen4-Downloader.exe 2013-10-01 12:33 - 2013-10-01 12:33 - 00478624 _____ C:\Users\Ich\Downloads\Franzis_Office_2010_Vorlagen3-Downloader.exe 2013-10-01 12:33 - 2013-10-01 12:33 - 00478624 _____ C:\Users\Ich\Downloads\Franzis_Office_2010_Vorlagen2-Downloader.exe 2013-10-01 12:33 - 2013-10-01 12:33 - 00478624 _____ C:\Users\Ich\Downloads\Franzis_Office_2010_Vorlagen1-Downloader.exe 2013-09-29 10:51 - 2013-09-29 10:50 - 00011264 _____ C:\Users\Ich\qlgt.db 2013-09-29 10:49 - 2013-09-29 10:49 - 00000000 ____D C:\Program Files (x86)\QLandkarteGT 2013-09-28 07:14 - 2013-05-08 11:36 - 00000000 ____D C:\Program Files (x86)\Bildbearbeitung 2013-09-28 07:13 - 2013-09-28 07:13 - 00000000 ____D C:\Program Files (x86)\Franzis 2013-09-27 12:32 - 2013-09-27 12:32 - 00000000 ____D C:\ProgramData\PGWARE 2013-09-27 09:30 - 2013-04-24 12:13 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-27 09:29 - 2009-07-14 04:34 - 00000478 _____ C:\Windows\win.ini 2013-09-27 09:07 - 2013-03-24 12:42 - 00000000 ____D C:\Users\Ich\Documents\Rente 2013-09-26 16:46 - 2013-03-24 08:52 - 00000000 ____D C:\Windows\Panther 2013-09-26 15:54 - 2013-08-19 19:54 - 00000000 ____D C:\ProgramData\Systweak 2013-09-26 15:51 - 2013-09-25 15:11 - 00000000 ____D C:\Program Files (x86)\Advanced System Optimizer 3 2013-09-26 15:48 - 2013-09-26 15:48 - 00000000 ____D C:\Users\Ich\Downloads\Advanced System Optimizer 3.5.1000.15559 2013-09-26 15:00 - 2013-09-26 14:59 - 00000000 ____D C:\Users\Ich\WEB.DE Online-Speicher 2013-09-26 15:00 - 2013-09-26 14:59 - 00000000 ____D C:\Users\Ich\AppData\Local\WEB.DE Application {sync-000021} 2013-09-26 15:00 - 2013-09-26 14:59 - 00000000 ____D C:\Users\Ich\AppData\Local\1und1UpdaterCorpE 2013-09-26 14:59 - 2013-09-26 14:59 - 00001332 _____ C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WEB.DE Online-Speicher.lnk 2013-09-26 14:59 - 2013-09-26 14:59 - 00001324 _____ C:\Users\Ich\Desktop\WEB.DE Online-Speicher.lnk 2013-09-26 14:59 - 2013-09-26 14:59 - 00000000 ____D C:\ProgramData\UUdb 2013-09-26 13:09 - 2013-09-26 13:09 - 04012336 _____ (1&1 Mail & Media GmbH) C:\Users\Ich\Downloads\webde_onlinespeicher_setup_bundled.exe 2013-09-25 15:13 - 2013-06-13 13:16 - 00000000 ____D C:\Users\Ich\AppData\Roaming\Systweak 2013-09-25 15:12 - 2013-09-25 15:12 - 00003328 _____ C:\Windows\System32\Tasks\ASO-AutoCheckUpdate7Days 2013-09-25 15:12 - 2013-09-25 15:12 - 00003296 _____ C:\Windows\System32\Tasks\ASO-OneClickCare 2013-09-25 15:11 - 2013-09-25 15:11 - 00001486 _____ C:\Users\Public\Desktop\Intelligente PC-Wartung.lnk 2013-09-25 15:11 - 2013-09-25 15:11 - 00001434 _____ C:\Users\Public\Desktop\Advanced System Optimizer.lnk 2013-09-25 11:10 - 2013-09-25 11:10 - 00003094 _____ C:\Windows\System32\Tasks\Process Lasso Core Engine Only 2013-09-25 11:10 - 2013-09-25 11:10 - 00003088 _____ C:\Windows\System32\Tasks\Process Lasso Management Console (GUI) 2013-09-25 11:10 - 2013-09-25 11:10 - 00000000 ____D C:\Users\Ich\AppData\Roaming\ProcessLasso 2013-09-25 11:10 - 2013-09-25 11:10 - 00000000 ____D C:\ProgramData\ProcessLasso 2013-09-25 11:10 - 2013-09-25 11:10 - 00000000 ____D C:\Program Files\Process Lasso 2013-09-24 10:36 - 2013-03-24 12:40 - 00000000 ____D C:\Users\Ich\Documents\Job 2013-09-23 13:26 - 2013-03-27 15:55 - 00000000 ____D C:\Users\Ich\AppData\Roaming\Apple Computer 2013-09-22 13:49 - 2013-09-22 13:48 - 00000000 ____D C:\Users\Ich\AppData\Roaming\TaskmgrPro 2013-09-22 13:47 - 2013-09-22 13:47 - 00000000 ____D C:\Users\Ich\Documents\TaskmgrPro 2013-09-22 07:24 - 2013-09-22 07:24 - 43966464 _____ C:\Windows\system32\config\components.iobit 2013-09-21 15:33 - 2013-03-29 09:03 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-09-20 11:04 - 2013-09-20 11:04 - 00001028 _____ C:\Users\Public\Desktop\BORG Calendar.lnk 2013-09-20 11:04 - 2013-09-20 11:04 - 00000000 ____D C:\Program Files (x86)\BORGCalendar 2013-09-19 14:29 - 2013-09-19 14:29 - 00001747 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-09-19 14:29 - 2013-09-19 14:27 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-09-19 14:28 - 2013-09-19 14:27 - 00000000 ____D C:\Program Files\iTunes 2013-09-19 14:28 - 2013-09-19 14:27 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-09-19 14:27 - 2013-09-19 14:27 - 00000000 ____D C:\Program Files\iPod 2013-09-19 13:37 - 2013-09-19 13:26 - 1138668207 _____ C:\Users\Ich\Downloads\iPad2,2_7.0_11A465_Restore.ipsw 2013-09-19 12:06 - 2013-03-24 11:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-19 11:04 - 2013-09-19 11:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-19 11:04 - 2013-03-24 11:53 - 00000000 ____D C:\Users\Ich\AppData\Local\Mozilla 2013-09-18 16:33 - 2013-09-18 16:33 - 00000008 _____ C:\Users\Ich\AppData\Roaming\pdfdrawcodec.dll 2013-09-18 16:33 - 2013-09-18 16:32 - 00000000 ____D C:\Program Files (x86)\WinPDFEditor 2013-09-17 08:49 - 2013-09-17 08:49 - 00000000 ____D C:\Users\Ich\Downloads\BZ-170913 100 Einkommen 2013-09-16 13:26 - 2013-03-24 12:22 - 00000000 ____D C:\Users\Ich\Tracing 2013-09-16 13:23 - 2013-09-16 13:23 - 90402816 _____ C:\Windows\system32\config\software.iobit 2013-09-16 13:23 - 2013-09-16 13:23 - 00327680 _____ C:\Windows\system32\config\default.iobit 2013-09-16 13:23 - 2013-09-16 13:23 - 00032768 _____ C:\Windows\system32\config\sam.iobit 2013-09-16 13:23 - 2013-09-16 13:23 - 00028672 _____ C:\Windows\system32\config\security.iobit 2013-09-15 14:45 - 2013-09-15 14:45 - 00001981 _____ C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shotcut.lnk 2013-09-15 14:44 - 2013-04-13 16:12 - 00000000 ____D C:\Program Files (x86)\Video 2013-09-15 12:38 - 2013-03-24 12:41 - 00000000 ____D C:\Users\Ich\Documents\PC 2013-09-15 12:37 - 2013-06-19 14:48 - 00003182 _____ C:\Windows\System32\Tasks\AdobeFlashPlayerUpdate 2 2013-09-15 12:37 - 2013-06-19 14:47 - 00003442 _____ C:\Windows\System32\Tasks\AdobeFlashPlayerUpdate 2013-09-15 10:45 - 2013-09-15 10:45 - 00000000 ____D C:\Users\Ich\AppData\Local\Microsoft Toolkit 2013-09-14 09:15 - 2013-03-24 12:39 - 00000000 ____D C:\Users\Ich\Documents\IPP 2013-09-12 16:05 - 2013-04-04 12:56 - 00000000 ____D C:\Program Files (x86)\Brother 2013-09-12 15:32 - 2013-03-24 12:23 - 00000000 ____D C:\Users\Ich\Documents\Acer 2013-09-12 15:28 - 2013-09-12 15:28 - 00000000 ____D C:\Windows\SysWOW64\iq 2013-09-12 15:22 - 2013-03-24 12:34 - 00000000 ____D C:\Users\Ich\Documents\IM 2013-09-12 15:20 - 2013-03-24 12:34 - 00000000 ____D C:\Users\Ich\Documents\Holzen 2013-09-12 07:06 - 2013-09-12 07:05 - 00000000 ____D C:\Users\Ich\Desktop\Player 2013-09-12 07:00 - 2013-03-24 12:22 - 00000000 ___RD C:\Users\Ich\Virtual Machines 2013-09-12 07:00 - 2013-03-24 09:14 - 00000000 ___RD C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 06:58 - 2009-07-14 06:45 - 05196144 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 06:54 - 2013-09-12 06:53 - 97238077 _____ C:\Windows\SysWOW64\㏥퐣Ḭ 2013-09-11 16:23 - 2013-07-14 08:07 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 16:20 - 2013-03-24 11:14 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 14:48 - 2013-09-11 14:48 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2013-09-11 14:48 - 2013-09-11 14:48 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2013-09-11 14:48 - 2013-09-11 14:48 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2013-09-11 14:48 - 2013-09-11 14:48 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2013-09-11 14:48 - 2013-09-11 14:48 - 00000000 ____D C:\Program Files (x86)\OpenAL 2013-09-11 12:39 - 2013-09-11 12:39 - 97080355 _____ C:\Windows\SysWOW64\睍奨ḬC 2013-09-10 14:07 - 2013-09-08 14:46 - 00000000 ____D C:\Program Files (x86)\Filedrop 2013-09-10 14:07 - 2013-05-15 05:57 - 00000000 ____D C:\ProgramData\iolo 2013-09-10 14:07 - 2013-05-12 14:49 - 00000000 ____D C:\Users\Ich\Desktop\Anti-Viren 2013-09-10 14:07 - 2013-05-10 06:44 - 00000000 ____D C:\ProgramData\SystemExplorer 2013-09-10 14:07 - 2013-04-24 12:49 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform 2013-09-10 14:07 - 2013-04-17 07:47 - 00000000 ____D C:\Users\Ich\AppData\Roaming\Applian FLV and Media Player 2013-09-10 07:26 - 2013-09-10 07:26 - 00002362 _____ C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2013-09-10 07:26 - 2013-09-10 07:26 - 00002300 _____ C:\Users\Ich\Desktop\Search.lnk Files to move or delete: ==================== C:\Users\Ich\Atlas.exe Some content of TEMP: ==================== C:\Users\Ich\AppData\Local\Temp\apptorun.exe C:\Users\Ich\AppData\Local\Temp\avgnt.exe C:\Users\Ich\AppData\Local\Temp\fwonekke.dll C:\Users\Ich\AppData\Local\Temp\jlxxrmfq.dll C:\Users\Ich\AppData\Local\Temp\lwzoeyvp.dll C:\Users\Ich\AppData\Local\Temp\nsh3243.exe C:\Users\Ich\AppData\Local\Temp\nsr34A4.exe C:\Users\Ich\AppData\Local\Temp\nsr3763.exe C:\Users\Ich\AppData\Local\Temp\nsx22D.exe C:\Users\Ich\AppData\Local\Temp\nsx5D6.exe C:\Users\Ich\AppData\Local\Temp\SHSetup.exe C:\Users\Ich\AppData\Local\Temp\swt-win32-3347.dll C:\Users\Ich\AppData\Local\Temp\zwluwv3h.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-04-11 19:41 ==================== End Of Log ============================ |
Themen zu Malwarebytes Anti-Malware mal wieder ....1 |
ad-aware, adobe, antivir, avast, avira, bonjour, browser, coupons, desktop, emsisoft, entfernen, farbar, farbar recovery scan tool, firefox, flash player, ftp, google, home, homepage, iexplore.exe, installation, malware, mozilla, online armor, plug-in, regclean, registry, samsung kies, scan, security, services.exe, smartbar, software, sprotection, svchost.exe, system, systweak, wajam |