![]() |
|
Plagegeister aller Art und deren Bekämpfung: SM.de in Google Chrome - Wie entfernen?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
![]() | ![]() SM.de in Google Chrome - Wie entfernen? Guten Tag! Computer gerade heute erst gekauft und schon den ersten dicken Fehler gemacht. Zumindest habe ich nämlich jetzt in Google Chrome (Internet Explorer bzw. Opera habe ich noch nicht nachgeguckt) diese lästige sm.de Sache. Da ich noch nicht viel installiert habe außer open office, thunderbird und dem vlc-Player, muss es wohl letzterer sein, wenn man ihn denn an falscher Stelle runterlädt (zumindest habe ich das gelesen). Das Problem äußert sich dadurch, dass bei allen Suchanfragen, die direkt in die url-Leiste eingegeben werden, die Suche unter sm.de stattfindet. Ich hatte bis eben gerade noch das kostenlose McAfee drauf, das mitgeliefert wurde. Das ist allerdings mittlerweile sauber deinstalliert. Ich habe erst "normal" deinstalliert und dann firmeneigene tool hinterher benutzt, so wie im folgenden link empohlen: hxxp://www.chip.de/artikel/McAfee-deinstallieren-Den-Virenscanner-sicher-entfernen_49782902.html Was soll ich mir runterladen, um den PC (Windows 8, 64 Bit) zu scannen und runterzuladen? Ich wäre dankbar, wenn man mich genau instruieren könnte wie ich denn mein search-log hier zu posten habe und vor allem wie ich die Pest dann sicher kille. Achja, sollte ich den vlc-Player löschen und nochmal neu installieren, natürlich diesmal von einer sicheren Quellen runtergeladen? Ein schönes Wochenende! Frege23 Ich nehme mir die Freiheit schon einmal ein wenig vorzuarbeiten, ich habe einen entsprechenden thread hier im board gefunden: http://www.trojaner-board.de/147495-...-download.html Ich hoffe, mein Fall verhält sich analog. Also ich habe FRST-64 runtergeladen und wie im gelinkten thread den scaan einfach gestartet. Nach Beendigung ploppten zwei txt.-Dateien auf: Die FRST.txt und die Addition.txt. Ich poste beide hier im Folgenden: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Maximilian (administrator) on STUDIUM on 15-03-2014 20:53:03 Running from C:\Users\Maximilian\Downloads Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) c:\Program Files (x86)\Nero\Update\NASvc.exe (Pokki) C:\Users\Maximilian\AppData\Local\Pokki\Engine\pokki.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2890640 2013-04-22] (ELAN Microelectronics Corp.) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13427784 2013-03-18] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-14] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer\Run: [BtvStack] - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-04-15] ( (Atheros Communications)) HKU\S-1-5-21-3330215313-1446325240-127864654-1001\...\Run: [Pokki] - C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startfenster.de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com SearchScopes: HKLM - DefaultScope {1595DF99-8D4A-4059-B375-D13B2EC85900} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {1595DF99-8D4A-4059-B375-D13B2EC85900} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM - {D0E9D0EF-D32A-40DA-8CCC-FE88C9E574DC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS SearchScopes: HKLM-x32 - DefaultScope {D0E9D0EF-D32A-40DA-8CCC-FE88C9E574DC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS SearchScopes: HKLM-x32 - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM-x32 - {D0E9D0EF-D32A-40DA-8CCC-FE88C9E574DC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS SearchScopes: HKCU - DefaultScope {1595DF99-8D4A-4059-B375-D13B2EC85900} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {1595DF99-8D4A-4059-B375-D13B2EC85900} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKCU - {D0E9D0EF-D32A-40DA-8CCC-FE88C9E574DC} URL = BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 Chrome: ======= CHR HomePage: https://www.google.com/ CHR DefaultSearchKeyword: suchmaschine CHR DefaultSearchProvider: SuchMaschine CHR DefaultSearchURL: hxxp://www.sm.de/?q={searchTerms} CHR DefaultNewTabURL: CHR Extension: (Google Docs) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-14] CHR Extension: (Google Drive) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-14] CHR Extension: (YouTube) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-14] CHR Extension: (Google-Suche) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-14] CHR Extension: (Matt W. Moore) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhfnkfaeekjcmeadbdcohacjdjdmlmia [2014-03-14] CHR Extension: (AdBlock) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-03-14] CHR Extension: (Google Wallet) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-14] CHR Extension: (Google Mail) - C:\Users\Maximilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-14] ==================== Services (Whitelisted) ================= R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [228480 2013-04-15] (Qualcomm Atheros Commnucations) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-27] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [662088 2013-03-15] (Acer Incorporated) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2013-04-22] (ELAN Microelectronics Corp.) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-08] (Intel Corporation) R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-06-18] (Acer Incorporate) S3 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4230016 2013-01-28] (Symantec Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-04-21] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-13] (Advanced Micro Devices, Inc.) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-04-15] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) S3 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0403000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation) R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99800 2013-05-08] (Intel Corporation) R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-15 20:53 - 2014-03-15 20:53 - 00010201 _____ () C:\Users\Maximilian\Downloads\FRST.txt 2014-03-15 20:52 - 2014-03-15 20:53 - 00000000 ____D () C:\FRST 2014-03-15 20:51 - 2014-03-15 20:51 - 02157056 _____ (Farbar) C:\Users\Maximilian\Downloads\FRST64.exe 2014-03-15 20:15 - 2014-03-15 20:15 - 01950720 _____ () C:\Users\Maximilian\Downloads\adwcleaner_3.022 (2).exe 2014-03-15 20:07 - 2014-03-15 20:07 - 03218352 _____ (McAfee, Inc.) C:\Users\Maximilian\Downloads\MCPR68.exe 2014-03-15 20:05 - 2014-03-15 20:05 - 01950720 _____ () C:\Users\Maximilian\Downloads\adwcleaner_3.022 (1).exe 2014-03-15 20:00 - 2014-03-15 20:00 - 01950720 _____ () C:\Users\Maximilian\Downloads\adwcleaner_3.022.exe 2014-03-15 19:46 - 2014-03-15 16:50 - 04777428 _____ () C:\Users\Maximilian\Desktop\bookmarks_15.03.14.html 2014-03-15 18:42 - 2014-03-15 18:43 - 00000000 ____D () C:\Users\Maximilian\Desktop\ToshibaExtern 2014-03-15 17:49 - 2014-03-15 17:49 - 00000465 _____ () C:\Users\Maximilian\Downloads\url.htm 2014-03-15 17:43 - 2014-03-15 17:44 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\MusicBee 2014-03-15 17:05 - 2014-03-15 17:05 - 00000000 ____D () C:\Program Files\7-Zip 2014-03-15 17:04 - 2014-03-15 17:04 - 01444352 _____ () C:\Users\Maximilian\Downloads\7z922-x64.msi 2014-03-15 16:54 - 2014-03-15 16:54 - 00001011 _____ () C:\Users\Maximilian\Desktop\MusicBee.lnk 2014-03-15 16:54 - 2014-03-15 16:54 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicBee 2014-03-15 16:54 - 2014-03-15 16:54 - 00000000 ____D () C:\Program Files (x86)\MusicBee 2014-03-15 16:50 - 2014-03-15 16:50 - 15843392 _____ () C:\Users\Maximilian\Downloads\MusicBeeSetup_2_3.zip 2014-03-15 16:43 - 2014-03-15 16:43 - 00000000 ____D () C:\Program Files\WinDjView 2014-03-15 16:33 - 2014-03-15 16:33 - 14941181 _____ (Andrew Zhezherun) C:\Users\Maximilian\Downloads\WinDjView-2.0.2-Setup.exe 2014-03-15 15:25 - 2014-03-15 15:25 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2014-03-15 15:25 - 2014-03-15 15:25 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\OpenOffice 2014-03-15 15:24 - 2014-03-15 15:24 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-15 15:20 - 2014-03-15 15:21 - 163606685 _____ () C:\Users\Maximilian\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe 2014-03-15 14:28 - 2014-03-15 14:28 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\McAfee 2014-03-15 14:27 - 2014-03-15 14:27 - 00541592 _____ (McAfee, Inc.) C:\Users\Maximilian\Downloads\MVTInstaller.exe 2014-03-15 14:03 - 2014-03-15 14:03 - 00001966 _____ () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Mail.lnk 2014-03-15 14:03 - 2014-03-15 14:03 - 00001958 _____ () C:\Users\Maximilian\Desktop\Opera Mail.lnk 2014-03-15 14:03 - 2014-03-15 14:03 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Opera Mail 2014-03-15 14:03 - 2014-03-15 14:03 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Opera Mail 2014-03-15 13:57 - 2014-03-15 13:59 - 12101952 _____ (Opera Software ASA) C:\Users\Maximilian\Downloads\Opera-Mail-1.0-1040.i386.exe 2014-03-15 13:54 - 2014-03-15 13:54 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk 2014-03-15 13:54 - 2014-03-15 13:54 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Opera Software 2014-03-15 13:54 - 2014-03-15 13:54 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Opera Software 2014-03-15 13:54 - 2014-03-15 13:54 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-03-15 13:53 - 2014-03-15 13:53 - 34741696 _____ (Opera Software ASA) C:\Users\Maximilian\Downloads\Opera_20.0.1387.77_Setup.exe 2014-03-15 13:13 - 2014-03-15 13:13 - 00002090 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Thunderbird 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Mozilla 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Thunderbird 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\ProgramData\Mozilla 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-15 13:12 - 2014-03-15 13:12 - 21987088 _____ (Mozilla) C:\Users\Maximilian\Downloads\Thunderbird_Setup_24.3.0.exe 2014-03-15 08:10 - 2014-03-15 08:20 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\vlc 2014-03-15 07:22 - 2014-03-15 07:22 - 00002080 _____ () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk 2014-03-15 07:20 - 2014-03-15 07:20 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\clear.fi 2014-03-14 22:45 - 2014-03-14 22:45 - 00002023 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-03-14 22:44 - 2014-03-14 22:44 - 00000000 ____D () C:\ProgramData\Adobe 2014-03-14 22:44 - 2014-03-14 22:44 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-03-14 22:42 - 2014-03-15 18:37 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Adobe 2014-03-14 22:05 - 2014-03-14 22:05 - 00000875 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-03-14 22:05 - 2014-03-14 22:05 - 00000000 ____D () C:\Program Files\VideoLAN 2014-03-14 22:04 - 2014-03-14 22:04 - 00001196 _____ () C:\Users\Maximilian\Desktop\Startfenster.lnk 2014-03-14 22:04 - 2014-03-14 22:04 - 00001196 _____ () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk 2014-03-14 20:57 - 2014-03-14 20:57 - 00038741 _____ () C:\Users\Maximilian\Downloads\Live-USB.htm 2014-03-14 19:35 - 2014-03-15 20:40 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-14 19:35 - 2014-03-15 20:26 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-14 19:35 - 2014-03-15 13:41 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-14 19:35 - 2014-03-14 19:35 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-14 19:35 - 2014-03-14 19:35 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-14 19:34 - 2014-03-14 19:35 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Google 2014-03-14 19:34 - 2014-03-14 19:35 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-14 19:34 - 2014-03-14 19:34 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Deployment 2014-03-14 19:34 - 2014-03-14 19:34 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Apps\2.0 2014-03-14 19:33 - 2014-03-14 19:33 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Macromedia 2014-03-14 18:25 - 2014-03-14 18:25 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2014-03-14 18:22 - 2014-03-15 20:31 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3330215313-1446325240-127864654-1001 2014-03-14 18:18 - 2014-03-14 18:18 - 00000000 ____D () C:\ProgramData\Pokki 2014-03-14 18:16 - 2014-03-14 18:16 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Atheros 2014-03-14 18:15 - 2014-03-15 18:37 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Adobe 2014-03-14 18:15 - 2014-03-14 18:15 - 00001442 _____ () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-03-14 18:15 - 2014-03-14 18:15 - 00000000 ___RD () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-14 18:15 - 2014-03-14 18:15 - 00000000 ___RD () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-14 18:15 - 2014-03-14 18:15 - 00000000 ____D () C:\ProgramData\OEM_YAHOO 2014-03-14 18:15 - 2014-03-14 18:15 - 00000000 ____D () C:\Program Files\Accessory Store 2014-03-14 18:14 - 2014-03-14 18:15 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Packages 2014-03-14 18:14 - 2014-03-14 18:14 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\VirtualStore 2014-03-14 18:13 - 2014-03-15 07:22 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Pokki 2014-03-14 18:13 - 2014-03-14 19:40 - 00000000 ____D () C:\Users\Maximilian 2014-03-14 18:13 - 2014-03-14 18:13 - 00000020 ___SH () C:\Users\Maximilian\ntuser.ini 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Vorlagen 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Startmenü 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Netzwerkumgebung 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Lokale Einstellungen 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Eigene Dateien 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Druckumgebung 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Documents\Eigene Musik 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Documents\Eigene Bilder 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\AppData\Local\Verlauf 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\AppData\Local\Anwendungsdaten 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Anwendungsdaten 2014-03-14 18:13 - 2013-08-28 04:12 - 00000000 ___RD () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-14 18:13 - 2012-07-26 09:13 - 00000000 ___RD () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-03-14 18:13 - 2012-07-26 09:13 - 00000000 ___RD () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-03-14 18:13 - 2012-07-26 09:13 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Programme 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Dokumente und Einstellungen ==================== One Month Modified Files and Folders ======= 2021-10-21 14:36 - 2013-08-28 04:22 - 00000852 _____ () C:\Windows\system32\Drivers\RTKHDRC.dat 2021-10-04 08:34 - 2013-08-28 04:22 - 00000712 _____ () C:\Windows\system32\Drivers\RTMICEQ0.dat 2014-03-15 20:53 - 2014-03-15 20:53 - 00010201 _____ () C:\Users\Maximilian\Downloads\FRST.txt 2014-03-15 20:53 - 2014-03-15 20:52 - 00000000 ____D () C:\FRST 2014-03-15 20:51 - 2014-03-15 20:51 - 02157056 _____ (Farbar) C:\Users\Maximilian\Downloads\FRST64.exe 2014-03-15 20:50 - 2013-08-28 04:10 - 01500746 _____ () C:\Windows\WindowsUpdate.log 2014-03-15 20:40 - 2014-03-14 19:35 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-15 20:32 - 2013-08-28 13:55 - 00753134 _____ () C:\Windows\system32\perfh007.dat 2014-03-15 20:32 - 2013-08-28 13:55 - 00155826 _____ () C:\Windows\system32\perfc007.dat 2014-03-15 20:32 - 2012-07-26 08:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-15 20:31 - 2014-03-14 18:22 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3330215313-1446325240-127864654-1001 2014-03-15 20:26 - 2014-03-14 19:35 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-15 20:26 - 2013-08-12 13:41 - 00010104 _____ () C:\Windows\PFRO.log 2014-03-15 20:26 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-15 20:15 - 2014-03-15 20:15 - 01950720 _____ () C:\Users\Maximilian\Downloads\adwcleaner_3.022 (2).exe 2014-03-15 20:14 - 2013-08-12 13:41 - 00307760 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-15 20:11 - 2012-07-26 09:12 - 00000000 ___HD () C:\Windows\ELAMBKUP 2014-03-15 20:07 - 2014-03-15 20:07 - 03218352 _____ (McAfee, Inc.) C:\Users\Maximilian\Downloads\MCPR68.exe 2014-03-15 20:05 - 2014-03-15 20:05 - 01950720 _____ () C:\Users\Maximilian\Downloads\adwcleaner_3.022 (1).exe 2014-03-15 20:00 - 2014-03-15 20:00 - 01950720 _____ () C:\Users\Maximilian\Downloads\adwcleaner_3.022.exe 2014-03-15 20:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru 2014-03-15 18:43 - 2014-03-15 18:42 - 00000000 ____D () C:\Users\Maximilian\Desktop\ToshibaExtern 2014-03-15 18:37 - 2014-03-14 22:42 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Adobe 2014-03-15 18:37 - 2014-03-14 18:15 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Adobe 2014-03-15 17:49 - 2014-03-15 17:49 - 00000465 _____ () C:\Users\Maximilian\Downloads\url.htm 2014-03-15 17:44 - 2014-03-15 17:43 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\MusicBee 2014-03-15 17:05 - 2014-03-15 17:05 - 00000000 ____D () C:\Program Files\7-Zip 2014-03-15 17:04 - 2014-03-15 17:04 - 01444352 _____ () C:\Users\Maximilian\Downloads\7z922-x64.msi 2014-03-15 16:54 - 2014-03-15 16:54 - 00001011 _____ () C:\Users\Maximilian\Desktop\MusicBee.lnk 2014-03-15 16:54 - 2014-03-15 16:54 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicBee 2014-03-15 16:54 - 2014-03-15 16:54 - 00000000 ____D () C:\Program Files (x86)\MusicBee 2014-03-15 16:50 - 2014-03-15 19:46 - 04777428 _____ () C:\Users\Maximilian\Desktop\bookmarks_15.03.14.html 2014-03-15 16:50 - 2014-03-15 16:50 - 15843392 _____ () C:\Users\Maximilian\Downloads\MusicBeeSetup_2_3.zip 2014-03-15 16:43 - 2014-03-15 16:43 - 00000000 ____D () C:\Program Files\WinDjView 2014-03-15 16:33 - 2014-03-15 16:33 - 14941181 _____ (Andrew Zhezherun) C:\Users\Maximilian\Downloads\WinDjView-2.0.2-Setup.exe 2014-03-15 15:25 - 2014-03-15 15:25 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2014-03-15 15:25 - 2014-03-15 15:25 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\OpenOffice 2014-03-15 15:24 - 2014-03-15 15:24 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-15 15:22 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\restore 2014-03-15 15:21 - 2014-03-15 15:20 - 163606685 _____ () C:\Users\Maximilian\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe 2014-03-15 14:28 - 2014-03-15 14:28 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\McAfee 2014-03-15 14:27 - 2014-03-15 14:27 - 00541592 _____ (McAfee, Inc.) C:\Users\Maximilian\Downloads\MVTInstaller.exe 2014-03-15 14:17 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-03-15 14:03 - 2014-03-15 14:03 - 00001966 _____ () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Mail.lnk 2014-03-15 14:03 - 2014-03-15 14:03 - 00001958 _____ () C:\Users\Maximilian\Desktop\Opera Mail.lnk 2014-03-15 14:03 - 2014-03-15 14:03 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Opera Mail 2014-03-15 14:03 - 2014-03-15 14:03 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Opera Mail 2014-03-15 13:59 - 2014-03-15 13:57 - 12101952 _____ (Opera Software ASA) C:\Users\Maximilian\Downloads\Opera-Mail-1.0-1040.i386.exe 2014-03-15 13:54 - 2014-03-15 13:54 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk 2014-03-15 13:54 - 2014-03-15 13:54 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Opera Software 2014-03-15 13:54 - 2014-03-15 13:54 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Opera Software 2014-03-15 13:54 - 2014-03-15 13:54 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-03-15 13:53 - 2014-03-15 13:53 - 34741696 _____ (Opera Software ASA) C:\Users\Maximilian\Downloads\Opera_20.0.1387.77_Setup.exe 2014-03-15 13:41 - 2014-03-14 19:35 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-15 13:25 - 2012-07-26 08:21 - 00021469 _____ () C:\Windows\setupact.log 2014-03-15 13:13 - 2014-03-15 13:13 - 00002090 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Thunderbird 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Mozilla 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Thunderbird 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\ProgramData\Mozilla 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-15 13:13 - 2014-03-15 13:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-15 13:12 - 2014-03-15 13:12 - 21987088 _____ (Mozilla) C:\Users\Maximilian\Downloads\Thunderbird_Setup_24.3.0.exe 2014-03-15 08:20 - 2014-03-15 08:10 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\vlc 2014-03-15 07:38 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-03-15 07:22 - 2014-03-15 07:22 - 00002080 _____ () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk 2014-03-15 07:22 - 2014-03-14 18:13 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Pokki 2014-03-15 07:20 - 2014-03-15 07:20 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\clear.fi 2014-03-14 22:45 - 2014-03-14 22:45 - 00002023 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-03-14 22:44 - 2014-03-14 22:44 - 00000000 ____D () C:\ProgramData\Adobe 2014-03-14 22:44 - 2014-03-14 22:44 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-03-14 22:05 - 2014-03-14 22:05 - 00000875 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-03-14 22:05 - 2014-03-14 22:05 - 00000000 ____D () C:\Program Files\VideoLAN 2014-03-14 22:04 - 2014-03-14 22:04 - 00001196 _____ () C:\Users\Maximilian\Desktop\Startfenster.lnk 2014-03-14 22:04 - 2014-03-14 22:04 - 00001196 _____ () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk 2014-03-14 20:57 - 2014-03-14 20:57 - 00038741 _____ () C:\Users\Maximilian\Downloads\Live-USB.htm 2014-03-14 19:40 - 2014-03-14 18:13 - 00000000 ____D () C:\Users\Maximilian 2014-03-14 19:35 - 2014-03-14 19:35 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-14 19:35 - 2014-03-14 19:35 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-14 19:35 - 2014-03-14 19:34 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Google 2014-03-14 19:35 - 2014-03-14 19:34 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-14 19:34 - 2014-03-14 19:34 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Deployment 2014-03-14 19:34 - 2014-03-14 19:34 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Apps\2.0 2014-03-14 19:33 - 2014-03-14 19:33 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Macromedia 2014-03-14 18:25 - 2014-03-14 18:25 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2014-03-14 18:18 - 2014-03-14 18:18 - 00000000 ____D () C:\ProgramData\Pokki 2014-03-14 18:16 - 2014-03-14 18:16 - 00000000 ____D () C:\Users\Maximilian\AppData\Roaming\Atheros 2014-03-14 18:16 - 2013-08-12 14:34 - 00000000 ___HD () C:\OEM 2014-03-14 18:15 - 2014-03-14 18:15 - 00001442 _____ () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-03-14 18:15 - 2014-03-14 18:15 - 00000000 ___RD () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-14 18:15 - 2014-03-14 18:15 - 00000000 ___RD () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-14 18:15 - 2014-03-14 18:15 - 00000000 ____D () C:\ProgramData\OEM_YAHOO 2014-03-14 18:15 - 2014-03-14 18:15 - 00000000 ____D () C:\Program Files\Accessory Store 2014-03-14 18:15 - 2014-03-14 18:14 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\Packages 2014-03-14 18:15 - 2013-08-28 04:41 - 00003550 _____ () C:\Windows\System32\Tasks\Norton Online Backup ARA 2014-03-14 18:15 - 2013-08-28 04:41 - 00000000 ____D () C:\ProgramData\Norton 2014-03-14 18:14 - 2014-03-14 18:14 - 00000000 ____D () C:\Users\Maximilian\AppData\Local\VirtualStore 2014-03-14 18:14 - 2012-07-26 09:12 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel 2014-03-14 18:14 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\WinStore 2014-03-14 18:13 - 2014-03-14 18:13 - 00000020 ___SH () C:\Users\Maximilian\ntuser.ini 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Vorlagen 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Startmenü 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Netzwerkumgebung 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Lokale Einstellungen 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Eigene Dateien 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Druckumgebung 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Documents\Eigene Musik 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Documents\Eigene Bilder 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\AppData\Local\Verlauf 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\AppData\Local\Anwendungsdaten 2014-03-14 18:13 - 2014-03-14 18:13 - 00000000 _SHDL () C:\Users\Maximilian\Anwendungsdaten 2014-03-14 17:51 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-03-14 17:50 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\rescache 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Programme 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2014-03-14 17:48 - 2014-03-14 17:48 - 00000000 _SHDL () C:\Dokumente und Einstellungen 2014-03-14 17:48 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Windows NT 2014-03-14 17:48 - 2012-07-26 06:37 - 00000000 __RHD () C:\Users\Default Some content of TEMP: ==================== C:\Users\Maximilian\AppData\Local\Temp\install_reader11_de_mssd_aaa_aih.exe C:\Users\Maximilian\AppData\Local\Temp\oct10DE.tmp.exe C:\Users\Maximilian\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Maximilian\AppData\Local\Temp\pyl28EA.tmp.exe C:\Users\Maximilian\AppData\Local\Temp\pyl5DF0.tmp.exe C:\Users\Maximilian\AppData\Local\Temp\pyl65AB.tmp.exe C:\Users\Maximilian\AppData\Local\Temp\sqlite3.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-12 13:41 ==================== End Of Log ============================ --- --- ---
|
Themen zu SM.de in Google Chrome - Wie entfernen? |
branding, chrome, direkt, entfernen, explorer, fehler, folge, folgende, frage, fragen, gekauft, google, guten, installiert, internet, internet explorer, kostenlose, launch, link, mcafee, office, opera, pokki, problem, scan, scannen, sm.de, suche, tool, vlc-player, wie entfernen?, wildtangent games, windows, windowsapps |