|
Plagegeister aller Art und deren Bekämpfung: Trojaner SupTab u.a.Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
30.03.2014, 16:16 | #1 |
| Trojaner SupTab u.a. Hallo, habe hier ein Problem mit einem Trojaner (mind.). Vermutlich durch den Download von jpgtopdf.exe Ich habe schon FRST laufen lassen und die Dateien angehängt. Hoffe, das genügt und dass irgendjemand sich mit diesem verrückten Zeug auskennt!!! Vielen Dank! Andreas |
30.03.2014, 17:53 | #2 |
/// the machine /// TB-Ausbilder | Trojaner SupTab u.a. Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
30.03.2014, 21:15 | #3 |
| Trojaner SupTab u.a. Also hier ist der Text 1:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by andreas (administrator) on ANDREAS-SAMS-PC on 30-03-2014 17:06:07 Running from C:\Users\andreas\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Microsoft Corporation) C:\Windows\System32\lpksetup.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe (Arainia Solutions) C:\Program Files (x86)\Gizmo\gservice.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (PcWinTech.com) C:\Program Files (x86)\CleanMem\mini_monitor.exe (Auslogics) C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE (Mister Group) C:\Program Files (x86)\System Explorer\SystemExplorer.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Copernic, a division of N. Harris Copernic Systems) C:\Program Files (x86)\Copernic \DesktopSearch4\Copernic.DesktopSearch.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Arainia Solutions) C:\Program Files (x86)\Gizmo\gizmo.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Mindjet) C:\Program Files (x86)\Mindjet\MindManager 6\MmReminderService.exe (Dropbox, Inc.) C:\Users\andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\netzmanager.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel_64.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\33.0.1750.154\nacl64.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\33.0.1750.154\nacl64.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\system32\lpksetup.exe (Mister Group) C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (SAMSUNG Electronics) C:\Program Files (x86)\Common Files\Samsung\SSCSettings\SSCSettings.exe (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe (Microsoft Corporation) C:\Windows\sysWow64\SearchProtocolHost.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11660904 2010-12-01] (Realtek Semiconductor) HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2782096 2010-07-26] (CANON INC.) HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2817872 2012-04-25] (ELAN Microelectronics Corp.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [400480 2012-01-30] (BillP Studios) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07- 02] (Oracle Corporation) HKLM-x32\...\Run: [MMReminderService] - C:\Program Files (x86)\Mindjet\MindManager 6\MMReminderService.exe [31232 2006-12- 14] (Mindjet) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer- Networking Ltd.) HKLM\...\RunOnce: [NCInstallQueue] - rundll32 netman.dll,ProcessQueue [360448 2009-07-14] (Microsoft Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Google Update] - C:\Users\andreas\AppData\Local\Google\Update \GoogleUpdate.exe [136176 2011-05-13] (Google Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware \SUPERAntiSpyware.exe [6563608 2014-01-15] (SUPERAntiSpyware) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office \Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [SystemExplorerAutoStart] - C:\Program Files (x86)\System Explorer\SystemExplorer.exe [2750936 2012-09-03] (Mister Group) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive \googledrivesync.exe [21822128 2014-01-30] (Google) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [B0D7A430849FA67EEA71A56253A48520238199B4._service_run] - C: \Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple \Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple \Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Facebook Update] - "C:\Users\andreas\AppData\Local\Facebook \Update\FacebookUpdate.exe" /c /nocrashserver HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Copernic Desktop Search 4] - C:\Program Files (x86)\Copernic \DesktopSearch4\Copernic.DesktopSearch.exe [1568832 2014-02-25] (Copernic, a division of N. Harris Copernic Systems) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GoogleChromeAutoLaunch_1DDDD6B09271C2EB3C06CC9B1731B636] - C: \Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GizmoDriveDelegate] - C:\Program Files (x86)\Gizmo\gizmo.exe [223640 2011-09-14] (Arainia Solutions) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\MountPoints2: {131db821-f56a-11e0-8ea6-e811322169d9} - F: \NokiaPCIA_Autorun.exe AppInit_DLLs: C:\PROGRA~2\SupTab\SearchProtect64.dll => C:\PROGRA~2\SupTab\SearchProtect64.dll File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SearchProtect32.dll => "C:\PROGRA~2\SupTab\SearchProtect32.dll" File Not Found Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled () Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG) Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office \Office14\ONENOTEM.EXE (Microsoft Corporation) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/? type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/? type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/? type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/? type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/? type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/? type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/? type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/? type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/? type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/? type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/? type=sc&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx? gd=&ctid=CT3324790&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=58&CUI=&UM=5&UP=SPD64F7ECC-B1EB-4DD1-8B2B- FE27A7C23C95&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office \Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin \ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: W2PBrowser Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - C:\Program Files (x86)\Mindjet \MindManager 6\Mm6InternetExplorer.dll (Mindjet) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office \Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin \jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - Ask Toolbar - {4D594333-0076-A76A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork \Toolbar\MYC3\Passport.dll (APN LLC.) Toolbar: HKLM-x32 - Ask Shopping Toolbar - {4D594333-2D53-4154-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\MYC3-SAT\Passport.dll (APN LLC.) Toolbar: HKCU - No Name - {4D594333-0076-A76A-76A7-7A786E7484D7} - No File Toolbar: HKCU - No Name - {4D594333-2D53-4154-00A7-7A786E7484D7} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default FF NewTab: hxxp://istart.webssearches.com/newtab/? type=nt&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX FF DefaultSearchEngine: webssearches FF SelectedSearchEngine: webssearches FF Homepage: hxxp://istart.webssearches.com/? type=hp&ts=1396123703&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player \npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared \npYState.dll (Yahoo! Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update \1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update \1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @octoshape.com/Octoshape Streaming Services,version=1.0 - C:\Users\andreas\AppData\Roaming\Octoshape \Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\andreas\AppData\Local\Google\Update \1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\andreas\AppData\Local\Google\Update \1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\andreas\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\webssearches.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: HQ-Vid-1.9f - C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default\Extensions\ee5ad154 -f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com [2014-03-29] FF Extension: TinEye Reverse Image Search - C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default \Extensions\tineye@ideeinc.com.xpi [2011-09-22] FF Extension: Ask Toolbar - C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default\Extensions \toolbar_MYC3@apn.ask.com.xpi [2013-08-23] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-20] FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-05-23] FF HKCU\...\Firefox\Extensions: [{b9aa91db-385d-4c69-8a2f-96790aa9405b}] - c:\program files (x86)\copernic \desktopsearch4\firefoxconnector FF Extension: Copernic Desktop Search - Search Firefox content - c:\program files (x86)\copernic \desktopsearch4\firefoxconnector [2013-08-31] FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://istart.webssearches.com/? type=sc&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR Extension: (Google Docs) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \aohghmighlieiainnegkcijnfilokake [2014-03-30] CHR Extension: (Google Drive) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \apdfllckaahabafndbhieahigkjlhalf [2014-03-30] CHR Extension: (YouTube) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-30] CHR Extension: (Copernic Desktop Search Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default \Extensions\cnnbdaahphjgdgfhliignpepgnbnfomp [2014-03-30] CHR Extension: (Google-Suche) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \coobgpohoikkiipiblmjeljniedjpjpf [2014-03-30] CHR Extension: (Gmail offline) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \ejidjjhkpiempkbhmpbfngldlkglhimk [2014-03-30] CHR Extension: (Zotero Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \ekhagklcjbdpajgpjgmbionohlpdbjgc [2014-03-30] CHR Extension: (Highlight to Search) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \floipahigmmkfhkoapmnijnlnboniglg [2014-03-30] CHR Extension: (TinEye Reverse Image Search) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \haebnnbpedcbhciplfhjjkbafijpncjl [2014-03-30] CHR Extension: (WEB.DE MailCheck) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \jaogepninmlbinccpbiakcgiolijlllo [2014-03-30] CHR Extension: (Hipmunk) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \jeabbdefhlelidlhahnfpbllaomkioke [2014-03-30] CHR Extension: (Social Network Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \jijghdpcfakjjecmadmkembnmmpojdfo [2014-03-30] CHR Extension: (Klout (beta)) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \jjaakbhpcbpmojkhpiaacepfcaniglak [2014-03-30] CHR Extension: (Webcam Toy) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \lfbgimoladefibpklnfmkpknadbklade [2014-03-30] CHR Extension: (fIRST lOVE) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \lighpcanjnomdcjmfficdanifpdmgmhp [2014-03-30] CHR Extension: (Google Maps) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \lneaknkopdijkpnocmklfnjbeapigfbh [2014-03-30] CHR Extension: (Google Wallet) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2014-03-30] CHR Extension: (Buffer) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \noojglkidnpfjbincgijbaiedldjfbhh [2014-03-30] CHR Extension: (Picasa) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-03-30] CHR Extension: (Google Mail) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions \pjkljhegncpnkpknbcohdijeoejaedia [2014-03-30] CHR HKCU\...\Chrome\Extension: [cnnbdaahphjgdgfhliignpepgnbnfomp] - c:\program files (x86)\copernic \desktopsearch4\ChromeConnector\ChromeConnector.crx [2014-02-25] CHR HKLM-x32\...\Chrome\Extension: [aaaajolaholnbffbeflpmmdnkjmgknom] - C:\ProgramData\AskPartnerNetwork\Toolbar\MYC3-SAT \CRX\ToolbarCR.crx [2013-07-26] CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player \chrome\DivXHTML5\DivXHTML5.crx [2013-05-06] CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-29] CHR StartMenuInternet: Google Chrome - C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe hxxp://istart.webssearches.com/?type=sc&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-09-14] (SUPERAntiSpyware.com) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S4 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [164816 2013-08-23] (APN LLC.) R2 CTDevice_Srv; C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe [61440 2007-04-02] (Creative Technology Ltd) S3 CTUPnPSv; C:\Program Files (x86)\Creative\Creative Centrale\CTUPnPSv.exe [64000 2008-05-21] (Creative Technology Ltd) S4 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe [544768 2009-08-24] (mst software GmbH, Germany) R2 Gizmo Central; C:\Program Files (x86)\Gizmo\gservice.exe [34728 2011-09-14] (Arainia Solutions) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-08- 21] (Mister Group) ==================== Drivers (Whitelisted) ==================== S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) R1 GizmoDrv; C:\Windows\System32\Drivers\GizmoDrv.sys [34704 2011-09-14] (Arainia Solutions LLC) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-03-30] (Malwarebytes Corporation) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) S4 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2012-01-18] () S4 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2012-01-18] () S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [66704 2013-09-09] (Fuzhou Rockchip Electronics Co,Ltd.) S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2011-02-14] (Windows (R) 2003 DDK 3790 provider) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-30 17:06 - 2014-03-30 17:07 - 00033092 _____ () C:\Users\andreas\Downloads\FRST.txt 2014-03-30 17:05 - 2014-03-30 17:06 - 00000000 ____D () C:\FRST 2014-03-30 17:05 - 2014-03-30 17:05 - 02157056 _____ (Farbar) C:\Users\andreas\Downloads\FRST64.exe 2014-03-30 17:04 - 2014-03-30 17:04 - 01145856 _____ (Farbar) C:\Users\andreas\Downloads\FRST.exe 2014-03-30 15:50 - 2014-03-30 16:55 - 00000000 ____D () C:\AdwCleaner 2014-03-30 15:50 - 2014-03-30 15:50 - 01950720 _____ () C:\Users\andreas\Downloads\adwcleaner.exe 2014-03-30 15:48 - 2014-03-30 15:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Downloads\revosetup95.exe 2014-03-30 15:48 - 2014-03-30 15:48 - 00001238 _____ () C:\Users\andreas\Desktop\Revo Uninstaller.lnk 2014-03-30 15:47 - 2014-03-30 16:44 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers \MBAMSwissArmy.sys 2014-03-30 15:46 - 2014-03-30 15:46 - 00001078 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-30 15:46 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers \mbamchameleon.sys 2014-03-30 15:46 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-30 15:46 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-30 15:45 - 2014-03-30 15:46 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\andreas\Downloads\mbam-setup- 2.0.0.1000.exe 2014-03-30 01:06 - 2014-03-30 01:06 - 49940480 _____ () C:\Program Files (x86)\GUT1321.tmp 2014-03-30 01:06 - 2014-03-30 01:06 - 00000000 ____D () C:\Program Files (x86)\GUM1320.tmp 2014-03-30 00:56 - 2014-03-30 00:56 - 00003144 _____ () C:\Windows\System32\Tasks\{203A3670-6A66-495F-B4A0-4907C6887A94} 2014-03-30 00:37 - 2014-03-30 00:44 - 00000643 _____ () C:\Windows\wininit.ini 2014-03-30 00:22 - 2014-03-30 00:22 - 00000000 ____D () C:\Users\andreas\AppData\Local\PDF Writer 2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\PDF Writer 2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\ProgramData\PDF Writer 2014-03-30 00:20 - 2013-07-13 12:15 - 00805376 _____ () C:\Windows\SysWOW64\EditCtlsU.ocx 2014-03-30 00:20 - 2013-07-12 22:57 - 00539648 _____ () C:\Windows\SysWOW64\LblCtlsU.ocx 2014-03-30 00:20 - 2013-04-05 13:55 - 00476160 _____ () C:\Windows\SysWOW64\TabStripCtlU.ocx 2014-03-30 00:20 - 2013-03-03 14:37 - 01061888 _____ () C:\Windows\SysWOW64\ExLvwU.ocx 2014-03-30 00:19 - 2013-09-01 12:59 - 01103872 _____ () C:\Windows\SysWOW64\CBLCtlsU.ocx 2014-03-30 00:19 - 2013-03-28 23:13 - 00645632 _____ () C:\Windows\SysWOW64\BtnCtlsU.ocx 2014-03-30 00:18 - 2014-03-30 00:18 - 08198048 _____ (Bullzip ) C:\Users\andreas\Downloads \Setup_BullzipPDFPrinter_10_4_0_2240_STD.exe 2014-03-30 00:15 - 2014-03-30 00:15 - 00563720 _____ () C:\Users\andreas\Downloads\Java (1).exe 2014-03-29 22:10 - 2014-03-29 22:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-03-29 22:09 - 2014-03-30 00:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-03-29 22:09 - 2014-03-29 22:12 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-03-29 22:09 - 2014-03-29 22:09 - 00001357 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-03-29 22:09 - 2013-09-20 11:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2014-03-29 22:08 - 2014-03-29 22:08 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\spybot-2.2.exe 2014-03-29 22:06 - 2014-03-30 00:59 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Activeris 2014-03-29 22:04 - 2014-03-29 22:05 - 19425127 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\Nicht bestätigt 322160.crdownload 2014-03-29 22:03 - 2014-03-29 22:03 - 00320520 _____ () C:\Users\andreas\Downloads\Java.exe 2014-03-29 21:51 - 2014-03-29 21:51 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\dlg 2014-03-29 21:50 - 2014-03-30 00:57 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-29 21:50 - 2014-03-29 21:51 - 00000000 ____D () C:\Program Files (x86)\Jpg2Pdf 2014-03-29 21:49 - 2014-03-29 21:49 - 00001065 _____ () C:\Users\Public\Desktop\7-PDF Maker.lnk 2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\7-PDFMaker 2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Program Files (x86)\7-PDF 2014-03-29 21:45 - 2014-03-29 21:46 - 55633177 _____ (7-PDF, Germany ) C:\Users\andreas\Downloads\7p141.exe 2014-03-29 21:43 - 2014-03-29 21:43 - 00930952 _____ (CNET Download.com) C:\Users\andreas\Downloads\cbsidlm-cbsi183- Free_JPG_to_PDF-ORG-75732662.exe 2014-03-27 23:21 - 2014-03-27 23:21 - 00000000 ____D () C:\Users\andreas\AppData\Local\Skype 2014-03-27 23:20 - 2014-03-27 23:20 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-27 22:54 - 2014-03-27 22:54 - 00476024 _____ (1&1 Mail & Media GmbH) C:\Users\andreas\Downloads \WEB.DE_MailCheck_chrome_setup (2).exe 2014-03-15 09:17 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-15 09:17 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-15 09:17 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-15 09:17 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-15 09:17 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-15 09:17 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-15 09:17 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-15 09:17 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-15 09:17 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-15 09:17 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-15 09:17 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-15 09:17 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-15 09:17 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-15 09:17 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows \system32\MsSpellCheckingFacility.exe 2014-03-15 09:17 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-15 09:17 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-15 09:17 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-15 09:17 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-15 09:17 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-15 09:17 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-15 09:17 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-15 09:17 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-15 09:17 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-15 09:17 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-15 09:17 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-15 09:17 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-15 09:17 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-15 09:17 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-15 09:17 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-15 09:17 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-15 09:17 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-15 09:17 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-15 09:17 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-15 09:17 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-15 09:17 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-15 09:17 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-15 09:17 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-15 09:17 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-15 09:17 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-15 09:17 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-15 09:17 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-15 09:17 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-15 09:17 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-15 09:17 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-15 09:17 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-15 09:17 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-15 09:17 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-15 09:17 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-11 22:07 - 2014-03-11 22:07 - 04550656 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr 2014-03-01 14:26 - 2014-03-01 14:26 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 14:00 - 2014-03-01 14:16 - 00000000 ____D () C:\ff602098354a13baca66adf688cd6c8a 2014-03-01 13:58 - 2014-03-01 13:58 - 00000000 ____D () C:\Program Files (x86)\QuickTime ==================== One Month Modified Files and Folders ======= 2014-03-30 17:07 - 2014-03-30 17:06 - 00033092 _____ () C:\Users\andreas\Downloads\FRST.txt 2014-03-30 17:06 - 2014-03-30 17:05 - 00000000 ____D () C:\FRST 2014-03-30 17:06 - 2011-05-13 17:36 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718 -708133086-1000UA.job 2014-03-30 17:05 - 2014-03-30 17:05 - 02157056 _____ (Farbar) C:\Users\andreas\Downloads\FRST64.exe 2014-03-30 17:05 - 2010-12-17 23:56 - 00703176 _____ () C:\Windows\system32\perfh007.dat 2014-03-30 17:05 - 2010-12-17 23:56 - 00150784 _____ () C:\Windows\system32\perfc007.dat 2014-03-30 17:05 - 2009-07-14 07:13 - 01629212 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-30 17:04 - 2014-03-30 17:04 - 01145856 _____ (Farbar) C:\Users\andreas\Downloads\FRST.exe 2014-03-30 17:02 - 2013-10-03 13:29 - 00000000 ____D () C:\Users\andreas\AppData\Local\E2BABF81-CECF-40E0-A839- 5CA03E1839C9.aplzod 2014-03-30 17:02 - 2012-04-12 19:52 - 00001146 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139- 235724718-708133086-1000UA.job 2014-03-30 17:01 - 2011-09-22 19:16 - 00000000 ____D () C:\Users\andreas\Videos\Documents\Outlook-Dateien 2014-03-30 17:00 - 2011-11-08 22:04 - 00000000 ___RD () C:\Users\andreas\Dropbox 2014-03-30 17:00 - 2011-11-08 22:00 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Dropbox 2014-03-30 16:59 - 2013-02-12 16:12 - 00000000 ___RD () C:\Users\andreas\Google Drive 2014-03-30 16:57 - 2012-02-09 01:07 - 00000330 _____ () C:\Windows\Tasks\GlaryInitialize.job 2014-03-30 16:57 - 2011-06-05 14:26 - 00051847 _____ () C:\Windows\setupact.log 2014-03-30 16:57 - 2011-05-21 22:56 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-30 16:57 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-30 16:56 - 2010-12-17 23:29 - 02000004 _____ () C:\Windows\WindowsUpdate.log 2014-03-30 16:55 - 2014-03-30 15:50 - 00000000 ____D () C:\AdwCleaner 2014-03-30 16:51 - 2011-05-13 17:39 - 00002450 _____ () C:\Users\andreas\Desktop\Google Chrome.lnk 2014-03-30 16:44 - 2014-03-30 15:47 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers \MBAMSwissArmy.sys 2014-03-30 16:19 - 2012-05-16 19:55 - 00001152 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718 -708133086-500UA.job 2014-03-30 16:17 - 2011-05-21 22:56 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-30 16:08 - 2012-05-08 00:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-30 16:06 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P- 1.C7483456-A289-439d-8115-601632D005A0 2014-03-30 16:06 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P- 0.C7483456-A289-439d-8115-601632D005A0 2014-03-30 15:50 - 2014-03-30 15:50 - 01950720 _____ () C:\Users\andreas\Downloads\adwcleaner.exe 2014-03-30 15:48 - 2014-03-30 15:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Downloads\revosetup95.exe 2014-03-30 15:48 - 2014-03-30 15:48 - 00001238 _____ () C:\Users\andreas\Desktop\Revo Uninstaller.lnk 2014-03-30 15:48 - 2011-05-13 19:19 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-03-30 15:46 - 2014-03-30 15:46 - 00001078 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-30 15:46 - 2014-03-30 15:45 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\andreas\Downloads\mbam-setup- 2.0.0.1000.exe 2014-03-30 15:16 - 2011-06-23 11:30 - 00489538 _____ () C:\Windows\PFRO.log 2014-03-30 01:06 - 2014-03-30 01:06 - 49940480 _____ () C:\Program Files (x86)\GUT1321.tmp 2014-03-30 01:06 - 2014-03-30 01:06 - 00000000 ____D () C:\Program Files (x86)\GUM1320.tmp 2014-03-30 01:06 - 2011-12-27 12:05 - 00008224 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-30 01:05 - 2012-07-12 09:30 - 00000000 ___RD () C:\Users\Administrator\Podcasts 2014-03-30 01:05 - 2012-05-16 19:55 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-03-30 01:05 - 2011-12-27 12:05 - 00001417 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-03-30 01:05 - 2011-12-27 12:05 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-30 01:05 - 2011-12-27 12:05 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-30 01:02 - 2011-05-13 19:01 - 00000000 ____D () C:\Users\andreas\Desktop\weniger genutzte software 2014-03-30 00:59 - 2014-03-29 22:06 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Activeris 2014-03-30 00:57 - 2014-03-29 21:50 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-30 00:57 - 2011-05-13 11:23 - 00001421 _____ () C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu \Programs\Internet Explorer.lnk 2014-03-30 00:56 - 2014-03-30 00:56 - 00003144 _____ () C:\Windows\System32\Tasks\{203A3670-6A66-495F-B4A0-4907C6887A94} 2014-03-30 00:44 - 2014-03-30 00:37 - 00000643 _____ () C:\Windows\wininit.ini 2014-03-30 00:35 - 2014-03-29 22:09 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-03-30 00:22 - 2014-03-30 00:22 - 00000000 ____D () C:\Users\andreas\AppData\Local\PDF Writer 2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\PDF Writer 2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\ProgramData\PDF Writer 2014-03-30 00:18 - 2014-03-30 00:18 - 08198048 _____ (Bullzip ) C:\Users\andreas\Downloads \Setup_BullzipPDFPrinter_10_4_0_2240_STD.exe 2014-03-30 00:15 - 2014-03-30 00:15 - 00563720 _____ () C:\Users\andreas\Downloads\Java (1).exe 2014-03-29 22:38 - 2011-06-05 17:37 - 00000000 ____D () C:\Users\andreas\AppData\Local\CrashDumps 2014-03-29 22:12 - 2014-03-29 22:09 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-03-29 22:10 - 2014-03-29 22:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-03-29 22:09 - 2014-03-29 22:09 - 00001357 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-03-29 22:08 - 2014-03-29 22:08 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\spybot-2.2.exe 2014-03-29 22:06 - 2011-09-20 22:05 - 00001332 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-29 22:06 - 2011-05-13 17:36 - 00001076 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718 -708133086-1000Core.job 2014-03-29 22:05 - 2014-03-29 22:04 - 19425127 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\Nicht bestätigt 322160.crdownload 2014-03-29 22:03 - 2014-03-29 22:03 - 00320520 _____ () C:\Users\andreas\Downloads\Java.exe 2014-03-29 21:51 - 2014-03-29 21:51 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\dlg 2014-03-29 21:51 - 2014-03-29 21:50 - 00000000 ____D () C:\Program Files (x86)\Jpg2Pdf 2014-03-29 21:50 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-03-29 21:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-03-29 21:49 - 2014-03-29 21:49 - 00001065 _____ () C:\Users\Public\Desktop\7-PDF Maker.lnk 2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\7-PDFMaker 2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Program Files (x86)\7-PDF 2014-03-29 21:48 - 2011-05-13 11:23 - 00000000 ___RD () C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu \Programs\Startup 2014-03-29 21:46 - 2014-03-29 21:45 - 55633177 _____ (7-PDF, Germany ) C:\Users\andreas\Downloads\7p141.exe 2014-03-29 21:43 - 2014-03-29 21:43 - 00930952 _____ (CNET Download.com) C:\Users\andreas\Downloads\cbsidlm-cbsi183- Free_JPG_to_PDF-ORG-75732662.exe 2014-03-29 16:35 - 2012-05-16 19:55 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718 -708133086-500Core.job 2014-03-29 16:35 - 2012-04-12 19:52 - 00001124 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139- 235724718-708133086-1000Core.job 2014-03-27 23:56 - 2014-01-01 20:55 - 00001026 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-03-27 23:55 - 2011-05-23 21:57 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\vlc 2014-03-27 23:37 - 2011-10-09 22:18 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Skype 2014-03-27 23:21 - 2014-03-27 23:21 - 00000000 ____D () C:\Users\andreas\AppData\Local\Skype 2014-03-27 23:21 - 2011-05-13 11:21 - 00000000 ____D () C:\ProgramData\Skype 2014-03-27 23:20 - 2014-03-27 23:20 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-27 22:54 - 2014-03-27 22:54 - 00476024 _____ (1&1 Mail & Media GmbH) C:\Users\andreas\Downloads \WEB.DE_MailCheck_chrome_setup (2).exe 2014-03-26 22:18 - 2011-06-14 19:06 - 00000000 ____D () C:\Users\andreas\Videos\Documents\Youcam 2014-03-21 15:59 - 2011-09-15 02:51 - 00147456 _____ (Bullzip) C:\Windows\SysWOW64\bzpdfc.dll 2014-03-19 20:38 - 2013-08-15 10:24 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-19 20:36 - 2011-05-13 16:38 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-19 19:13 - 2009-07-14 06:45 - 00459824 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-19 19:11 - 2013-03-13 10:05 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-19 19:11 - 2013-03-13 10:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-15 10:36 - 2011-09-14 21:22 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-03-15 10:08 - 2012-05-08 00:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-15 10:08 - 2012-05-08 00:40 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-15 10:08 - 2011-08-22 23:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-11 22:07 - 2014-03-11 22:07 - 04550656 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr 2014-03-10 22:52 - 2011-11-07 09:32 - 01603492 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-03-05 09:26 - 2014-03-30 15:46 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers \mbamchameleon.sys 2014-03-05 09:26 - 2014-03-30 15:46 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-05 09:26 - 2014-03-30 15:46 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-01 14:26 - 2014-03-01 14:26 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 14:16 - 2014-03-01 14:00 - 00000000 ____D () C:\ff602098354a13baca66adf688cd6c8a 2014-03-01 13:58 - 2014-03-01 13:58 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-03-01 08:05 - 2014-03-15 09:17 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 07:17 - 2014-03-15 09:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 07:16 - 2014-03-15 09:17 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 06:58 - 2014-03-15 09:17 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 06:52 - 2014-03-15 09:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 06:51 - 2014-03-15 09:17 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 06:42 - 2014-03-15 09:17 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 06:40 - 2014-03-15 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 06:37 - 2014-03-15 09:17 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 06:33 - 2014-03-15 09:17 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 06:33 - 2014-03-15 09:17 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 06:32 - 2014-03-15 09:17 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 06:30 - 2014-03-15 09:17 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 06:23 - 2014-03-15 09:17 - 00940032 _____ (Microsoft Corporation) C:\Windows \system32\MsSpellCheckingFacility.exe 2014-03-01 06:17 - 2014-03-15 09:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 06:11 - 2014-03-15 09:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 06:02 - 2014-03-15 09:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 05:54 - 2014-03-15 09:17 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 05:52 - 2014-03-15 09:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 05:51 - 2014-03-15 09:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 05:47 - 2014-03-15 09:17 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 05:43 - 2014-03-15 09:17 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 05:43 - 2014-03-15 09:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 05:42 - 2014-03-15 09:17 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 05:40 - 2014-03-15 09:17 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 05:38 - 2014-03-15 09:17 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 05:37 - 2014-03-15 09:17 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 05:35 - 2014-03-15 09:17 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 05:18 - 2014-03-15 09:17 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 05:16 - 2014-03-15 09:17 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 05:14 - 2014-03-15 09:17 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 05:10 - 2014-03-15 09:17 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 05:03 - 2014-03-15 09:17 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 05:00 - 2014-03-15 09:17 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 04:57 - 2014-03-15 09:17 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 04:38 - 2014-03-15 09:17 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 04:32 - 2014-03-15 09:17 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 04:27 - 2014-03-15 09:17 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 04:25 - 2014-03-15 09:17 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 04:25 - 2014-03-15 09:17 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Some content of TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\avgnt.exe C:\Users\Administrator\AppData\Local\Temp\DivXSetup.exe C:\Users\Administrator\AppData\Local\Temp\MSN9A3E.exe C:\Users\andreas\AppData\Local\Temp\avgnt.exe C:\Users\andreas\AppData\Local\Temp\ose00000.exe C:\Users\andreas\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-20 19:35 ==================== End Of Log ============================ |
30.03.2014, 21:20 | #4 |
| Trojaner SupTab u.a. Und hier ist der Text 2: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by andreas at 2014-03-30 17:08:12 Running from C:\Users\andreas\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== „Messenger“ pagalbinė priemonė (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden „Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden „Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden „Windows Live Mesh ActiveX“ nuotolinių ryšių valdiklis (HKLM-x32\...\{9024FE65-46B8-4C8A-9D98-8DCB6BD5F598}) (Version: 15.4.5722.2 - Microsoft Corporation) „Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden „Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 7-PDF Maker Version 1.4.1 (Build 128) (HKLM-x32\...\7-PDF Maker_is1) (Version: 7-PDF Maker - Version 1.4.1 (Build 128) - 7 -PDF, Germany - Thorsten Hodes) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) 7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - ) ActiveX контрола на Windows Live Mesh за отдалечени връзки (HKLM-x32\...\{B3BA4D1C-23EF-4859-9C11-1B2CCB7FADBB}) (Version: 15.4.5722.2 - Microsoft Corporation) ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (HKLM-x32\...\{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5}) (Version: 15.4.5722.2 - Microsoft Corporation) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.3.0.3670 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.3.0.3670 - Adobe Systems Incorporated) Hidden Adobe Connect Add-in (HKCU\...\Adobe Connect Add-in) (Version: - ) Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version: - ) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.) AIM for Windows (HKCU\...\AIM) (Version: - AOL Inc.) Amazon Kindle (HKCU\...\Amazon Kindle) (Version: - Amazon) Amazon MP3-Downloader 1.0.9 (HKLM-x32\...\Amazon MP3-Downloader) (Version: - ) Android Sync Manager WiFi (HKLM-x32\...\{13D946AF-DAD9-0200-0000-000000000000}) (Version: 11.10.2763 - Mobile Action) Android-Sync v0.369 (HKLM-x32\...\{B148E192-F289-4297-85BF-70E2A422EB25}_is1) (Version: - Android-Sync.com) Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Ashampoo WinOptimizer 2010 Advanced (HKLM-x32\...\Ashampoo WinOptimizer 2010 Advanced_is1) (Version: 6.5.0 - Ashampoo GmbH & Co. KG) Ask Shopping Toolbar (HKLM-x32\...\{4D594333-2D53-4154-00A7-A758B70C0202}) (Version: 12.2.2.652 - Ask Partner Network) <==== ATTENTION Ask Toolbar (HKLM-x32\...\{4D594333-0076-A76A-76A7-A758B70C0300}) (Version: 12.3.0.959 - APN, LLC) <==== ATTENTION Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros) Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team) Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: version 3.3 - Auslogics Software Pty Ltd) Avidemux 2.5 (32-bit) (HKLM-x32\...\Avidemux 2.5) (Version: 2.5.4.7200 - ) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) BatteryLifeExtender (HKLM-x32\...\{EA257ECF-5F72-4461-B890-959394DCD087}) (Version: 1.0.10 - Samsung) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 5.60.48.55 - Broadcom Corporation) Bullzip PDF Printer 10.4.0.2240 (HKLM\...\Bullzip PDF Printer_is1) (Version: 10.4.0.2240 - Bullzip) Camfrog Video Chat 6.5 (HKLM-x32\...\Camfrog 6.5) (Version: 6.5.300 - Camshare, Inc.) Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - ) Canon MG5100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series) (Version: - ) Canon MP Navigator 1.0 (HKLM-x32\...\MP Navigator 1.0) (Version: - ) Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - ) CleanMem (HKLM-x32\...\CleanMem) (Version: v2.2.0 - PcWinTech.com) Complément Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Complemento Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Control ActiveX Windows Live Mesh pentru conexiuni la distanță (HKLM-x32\...\{260E3D78-94E6-47EC-8E29-46301572BB1E}) (Version: 15.4.5722.2 - Microsoft Corporation) Controle ActiveX do Windows Live Mesh para Conexões Remotas (HKLM-x32\...\{39B3184E-0BFB-40FA-ADDC-E7E2D535CDA9}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) Copernic Desktop Search 4 (HKLM-x32\...\CopernicDesktopSearch4) (Version: 4.0.5.1231 - Copernic) Copernic Desktop Search 4 (x32 Version: 4.0.5.1231 - Copernic) Hidden Creative Centrale (HKLM-x32\...\Creative Centrale) (Version: 1.19.02 - Creative Technology Ltd.) Creative Centrale (x32 Version: 1.19.02 - Creative Technology Ltd.) Hidden Creative Software Update (x32 Version: 1.03.01 - Creative Technology Ltd.) Hidden Creative ZEN X-Fi2 Dokumentation (HKLM-x32\...\ZENXFI2UG) (Version: - Creative Technology Ltd.) CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.) CyberLink Media Suite (x32 Version: 8.0.2227 - CyberLink Corp.) Hidden CyberLink Media+ Player10 (HKLM-x32\...\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 - CyberLink Corp.) CyberLink Media+ Player10 (x32 Version: 10.0.1110.00 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.) CyberLink Power2Go (x32 Version: 6.1.3802 - CyberLink Corp.) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3509 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.1.3509 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{92C42EDD-6524-4577-B2EB-6C68C63B6D4A}) (Version: - Microsoft) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.41 - DivX, LLC) Doplnok programu Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.) Easy Content Share (HKLM-x32\...\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD) Easy Display Manager (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.) Easy Migration (HKLM-x32\...\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0.0.5 - Samsung Electronics Co., Ltd.) Easy Network Manager (HKLM-x32\...\{FCF2085E-ABE5-4AA8-B07C-65BBD56DA243}) (Version: 4.4.6 - Samsung) Easy SpeedUp Manager (HKLM-x32\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.1.1.1 - Samsung Electronics Co.,Ltd.) EasyBatteryManager (HKLM-x32\...\{4A331D24-A9E8-484F-835E-1BA7B139689C}) (Version: 4.0.0.4 - Samsung) EasyFileShare (HKLM-x32\...\{EA76E65F-6679-495A-A8A6-42AD6602ED4C}) (Version: 1.0.11 - Samsung) ETDWare PS/2-X64 10.7.14.12_WHQL (HKLM\...\Elantech) (Version: 10.7.14.12 - ELAN Microelectronic Corp.) Extended Asian Language font pack for Adobe Reader XI (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-A00000000004}) (Version: 11.0.0 - Adobe Systems Incorporated) Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook) Fast Start (HKLM-x32\...\{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}) (Version: 2.2.0.0 - SAMSUNG) FastConnect 1.2.2 (HKLM-x32\...\FastConnect) (Version: 1.2.2 - The Cloud Networks) FeedReader (HKLM-x32\...\FeedReader_is1) (Version: - i-Systems Inc.) FirstClass® Client (HKLM-x32\...\{2869279D-7AE2-4A13-96B8-46078BA3F75B}) (Version: 11.0 (build 11.033) - Open Text Corporation.) Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61- B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Free Download Manager 3.0 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG) Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com) FreeMind (HKLM-x32\...\B991B020-2968-11D8-AF23-444553540000_is1) (Version: 0.9.0 - ) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Gizmo Central (HKLM-x32\...\Gizmo Central) (Version: v2.7.9 - Arainia Solutions, LLC) Glary Utilities 2.42.0.1389 (HKLM-x32\...\Glary Utilities_is1) (Version: 2.42.0.1389 - Glarysoft Ltd) Google Chrome (HKCU\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.) Google Drive (HKLM-x32\...\{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}) (Version: 1.14.6059.644 - Google, Inc.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden Hoffnung für heute (HKLM-x32\...\{9447C5C8-6A1B-412F-B9A6-99AFE7C09773}) (Version: 3.2.1 - ) iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) ICQ7.5 (HKLM-x32\...\{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}) (Version: 7.5 - ICQ) IHMC CmapTools v5.05.01 (HKLM-x32\...\IHMC CmapTools v5.05.01) (Version: 5.0.5.1 - Institute for Human & Machine Cognition) iMODELER - Consideo GmbH (HKLM-x32\...\iMODELER) (Version: - ) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.3.1001 - Intel Corporation) Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.02.00.1002 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.28 - Irfan Skiljan) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) iWisoft Free Video Converter 1.2 (HKLM-x32\...\iWisoft Free Video Converter_is1) (Version: 1.2 - www.easy-video- converter.com) IZArc 4.1.6 (HKLM-x32\...\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1) (Version: 4.1.6 - Ivan Zahariev) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 37 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216037FF}) (Version: 6.0.370 - Oracle) JLC's Internet TV (HKLM-x32\...\JLC's Internet TV) (Version: - ) Jpg2Pdf version 1.2 (HKLM-x32\...\{533D415A-4151-4AC5-858E-4068524C8051}_is1) (Version: 1.2 - Office Necessities inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden KaraFun Player (HKLM-x32\...\KaraFun Player_is1) (Version: 1.20.86.771 - Recisio) K-Lite Codec Pack 6.0.4 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 6.0.4 - ) Kontrola Windows Live Mesh ActiveX za daljinske veze (HKLM-x32\...\{19CBDE24-2761-49A5-816B-D2BA65D0CA8D}) (Version: 15.4.5722.2 - Microsoft Corporation) Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (HKLM-x32\...\{CA227A9D-09BE-4BFB-9764-48FED2DA5454}) (Version: 15.4.5722.2 - Microsoft Corporation) LinkedIn Outlook Connector (HKLM-x32\...\LinkedIn Outlook Connector) (Version: 1.1.10.0 - LinkedIn) MagicDisc 2.7.106 (HKLM-x32\...\MagicDisc 2.7.106) (Version: - ) Malwarebytes Anti-Malware Version 2.00.0.1000 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 - Malwarebytes Corporation) ManyCam 3.1.59 (HKLM-x32\...\ManyCam) (Version: 3.1.59 - ManyCam LLC) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Assistent (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger kísérő (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger Pratilac (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger Suradnik (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger 사이트 공유 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger 分享元件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger 浏览器插件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger-kumppani (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Outlook Social Connector Provider for Facebook 32-bit (HKLM-x32\...\{95140000-007C-0409-0000-0000000FF1CE}) (Version: 14.0.6114.5003 - Microsoft Corporation) Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\...\{95140000-007D-0409-0000- 0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\...\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation) Mindjet MindManager Pro 6 (HKLM-x32\...\{9FC3EA3B-A6FB-436E-8A69-8595548CACBF}) (Version: 6.2.399 - Mindjet LLC) MiniTool Partition Wizard Home Edition 7.1 (HKLM-x32\...\{34A153FE-6926-4C14-B48A-B71E68C672A8}_is1) (Version: - MiniTool Solution Ltd.) Mobipocket Reader 6.2 (HKLM-x32\...\{342126E1-173C-4585-BFBE-3EBDD20E3E9E}) (Version: 6.2.608 - Mobipocket.com) Movie Color Enhancer (HKLM-x32\...\{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}) (Version: 1.0 - Samsung Electronics Co., Ltd.) Mozilla Firefox 14.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 14.0.1 (x86 de)) (Version: 14.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 14.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.2 - F.J. Wechselberger) NAVIGON Fresh 3.4.1 (HKLM-x32\...\NAVIGON Fresh) (Version: 3.4.1 - NAVIGON) Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.071 - Deutsche Telekom AG) Netzmanager (Version: 1.071 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden Nur Entfernen der CopyTrans Suite möglich (HKCU\...\CopyTrans Suite) (Version: 2.33 - WindSolutions) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation) NVIDIA Grafiktreiber 267.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.54 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.265.39.0 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 267.54 (Version: 267.54 - NVIDIA Corporation) Hidden Octoshape Streaming Services (HKCU\...\Octoshape Streaming Services) (Version: - Octoshape ApS) OpenOffice 4.0.0 (HKLM-x32\...\{B28DBCBA-60F8-40ED-B35B-F510C327946C}) (Version: 4.00.9702 - Apache Software Foundation) Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74- A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation) Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F- C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation) PDF24 Creator 5.3.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) PDFill PDF Editor with FREE Writer and FREE Tools (HKLM\...\{D1399216-81B2-457C-A0F7-73B9A2EF6902}) (Version: 9.0 - PlotSoft LLC) PDF-XChange 3 (HKLM-x32\...\PDF-XChange 3_is1) (Version: - Tracker Software) PhoneShare (HKLM-x32\...\{E31F454E-4813-4C88-B0D3-4BB174993770}) (Version: 1.0.4 - Samsung) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pomocnik Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Python 2.7.2 (HKLM-x32\...\{2E295B5B-1AD4-4d36-97C2-A316084722CF}) (Version: 2.7.2150 - Python Software Foundation) QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.33.1125.2010 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6257 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.) Samsung AnyWeb Print (HKLM-x32\...\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 1.1.21.0 - Samsung Electronics Co., Ltd.) Samsung AnyWeb Print (x32 Version: 1.0 - Samsung Electronics Co., Ltd.) Hidden Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.0.8 - Samsung) Samsung Support Center 1.0 (HKLM-x32\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.38 - Samsung) Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: 2.01.06.00:16 - Samsung Electronics Co., Ltd.) Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 1.2.1.0 - Samsung Electronics Co., Ltd.) Samsung Update Plus (HKLM-x32\...\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.1.17 - Samsung Electronics Co., Ltd.) Screencast-O-Matic (HKCU\...\Screencast-O-Matic) (Version: - Screencast-O-Matic) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Spotify (HKCU\...\Spotify) (Version: 0.9.7.16.g4b197456 - Spotify AB) Spremljevalec Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.) SRS Premium Sound Control Panel (HKLM\...\{2998191E-A35E-47E2-BE38-7702C731D722}) (Version: 1.10.1000 - SRS Labs, Inc.) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1108 - SUPERAntiSpyware.com) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden System Explorer 3.9.1 (HKLM-x32\...\System Explorer_is1) (Version: - Mister Group) System Explorer 3.9.4 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version: - Mister Group) Tango (HKCU\...\Tango) (Version: 1.6.14117 - TangoMe, Inc.) Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE} _Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_ {3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE} _Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE} _Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE} _Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE} _Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE} _Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE} _Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE} _Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE} _Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000- 0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2878227) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{5D357893-40BA-4323-86BA-D97C66CD72F4}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}) (Version: - Microsoft) UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - ) Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (HKLM-x32\...\{241E7104-937A-4366-AD57-8FDDDB003939}) (Version: 15.4.5722.2 - Microsoft Corporation) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7000 - Broadcom Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live fotoattēlu galerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Foto-galerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797- 0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX kontrola za daljinske veze (HKLM-x32\...\{8985AE5E-622A-4980-8BF8-0A1830643220}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX vadīkla attālajiem savienojumiem (HKLM-x32\...\{A3A775C9-5A63-4C55-8FDD-427A5B8F5D2B}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (HKLM-x32\...\{09B7C7EB-3140-4B5E-842F-9C79A7137139}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX-objekt til fjernforbindelser (HKLM-x32\...\{57220148-3B2B-412A-A2E0-82B9DF423696}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (HKLM-x32\...\{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Meshin etäyhteyksien ActiveX-komponentti (HKLM-x32\...\{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Pošta (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 메일 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 사진 갤러리 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 필수 패키지 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 照片库 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 软件包 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows-Treiberpaket - Android-Sync.com (WinUSB) AndroidUsbDeviceClass (10/21/2011 4.0.0000.11021) (HKLM\... \6D51958587F750FB22B14F3587024652DE17F288) (Version: 10/21/2011 4.0.0000.11021 - Android-Sync.com) WinPatrol (HKLM\...\{007811BF-E310-4285-BFC6-55DB29B3EDDE}) (Version: 24.1.2012 - BillP Studios) WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) XING Outlook Connector (HKLM\...\{3B8AF990-AE63-481C-BC4B-8BB8D7A93B80}) (Version: 2.2.0 - XING) xplorer² lite 32 bit (HKLM-x32\...\xplorer2l) (Version: 2.3.0.1 - Zabkat) Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.) Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version: - ) Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - ) YouTube Song Downloader (HKLM-x32\...\{4281435C-AD1D-4C8A-B9C0-3961C11EF142}_is1) (Version: 8.2 - Abelssoft) Zotero Standalone 3.0.14 (x86 en-US) (HKLM-x32\...\Zotero Standalone 3.0.14 (x86 en-US)) (Version: 3.0.14 - Zotero) Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation) Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47- FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Компаньон Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Помощник на Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2- 8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden מסייע Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ตัวควบคุม ActiveX ใน Windows Live Mesh สำหรับการเชื่อมต่อระยะไกล (ไทย) (HKLM-x32\...\{A2EDAEEB-C981-46D5-8163-CF8F5F640EEE}) (Version: 15.4.5722.2 - Microsoft Corporation) 원격 연결을 위한 Windows Live Mesh ActiveX 컨트롤 (HKLM-x32\...\{61920449-0393-4707-B7DD-E6C0013C8B2C}) (Version: 15.4.5722.2 - Microsoft Corporation) 用于远程连接的 Windows Live Mesh ActiveX 控件(简体中文) (HKLM-x32\...\{F992409C-9D10-4AE2-BAEB-B5409AD3785E}) (Version: 15.4.5722.2 - Microsoft Corporation) 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Restore Points ========================= 26-03-2014 18:24:35 Windows Update 29-03-2014 20:05:06 Uniblue SpeedUpMyPC installation 29-03-2014 22:41:47 S 30-03-2014 13:49:58 Revo Uninstaller's restore point - Ask Shopping Toolbar 30-03-2014 14:43:56 Revo Uninstaller's restore point - ooVoo 30-03-2014 14:44:50 Removed ooVoo ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0666A132-9CBC-4EE0-885F-AB0465900A46} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung \EasySpeedUpManager\EasySpeedUpManager2.exe [2010-12-01] (Samsung Electronics) Task: {07409B9B-7821-4253-91E7-116AFCF83E69} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2010-11-28] (Samsung Electronics Co., Ltd.) Task: {1318A8AD-A403-404D-ADFA-59FA3D8956FD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google \Update\GoogleUpdate.exe [2011-05-21] (Google Inc.) Task: {1623FBDB-E473-4D9E-9F23-7A929E229916} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {185C37D1-20B4-4A1F-995A-0B3AE22033D1} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-11-17] (SEC) Task: {24FF686B-BFF6-4A3C-9C78-0E00F254409B} - System32\Tasks\xingoscupdate => C:\Program Files\XING\XING Outlook Connector\xingoscupdate.exe [2014-01-08] (XING) Task: {256E2E78-825E-4930-B00E-E86DC6762ED9} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung \Samsung Support Center\SSCKbdHk.exe [2011-09-04] (SAMSUNG Electronics) Task: {299D73B6-AE07-4510-BDF3-53538E412FED} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {29C2FC45-A051-4254-A333-AC168384DC37} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung \EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.) Task: {38B2690F-5140-4B97-8006-5B6105746F2F} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe [2010-11-28] (Samsung Electronics Co., Ltd.) Task: {3927588F-2B07-4A40-A858-43BC63300A91} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {420C63BC-0E55-4D7D-9746-3E5B9FF83E5D} - System32\Tasks\SRS Premium Sound => C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel_64.exe [2010-11-29] (SRS Labs, Inc.) Task: {47656083-02C7-4E54-808F-7263466606B5} - System32\Tasks\Xing Social Recommendations => C:\Program Files\XING\XING Outlook Connector\32-bit\XingSocial.exe [2014-01-08] (XING AG) Task: {56E8FB28-DB36-48DC-8D7A-379AA0CF63F1} - System32\Tasks\{EB5A17F7-59B1-4914-80F9-8981CBF7FF0B} => C:\Program Files (x86)\Gizmo\gizmo.exe [2011-09-14] (Arainia Solutions) Task: {773AE63E-EACB-4047-8A3F-2E395CF9E670} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2011-12-20] (Samsung Electronics) Task: {7821C008-BFDF-45B6-B2A7-12BC3E0ACD8D} - System32\Tasks\CleanMem Mini Monitor => C:\Program Files (x86)\CleanMem \mini_monitor.exe [2011-07-09] (PcWinTech.com) Task: {8014A37B-FB9B-451C-A2B4-1BF82CC7DA59} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed \Flash\FlashPlayerUpdateService.exe [2014-03-15] (Adobe Systems Incorporated) Task: {83C4A256-9C9E-48ED-8770-83C3BFDE7ACF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086- 500UA => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-16] (Google Inc.) Task: {8D8D58A3-BC0D-4C52-83BA-7F40EA4E7386} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google \Update\GoogleUpdate.exe [2011-05-21] (Google Inc.) Task: {97533C0E-FAF4-42D9-8670-CF1F351EFB00} - System32\Tasks\Auslogics\Disk Defrag\Start On andreas Logon => C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe [2011-11-14] (Auslogics) Task: {9B159597-B87B-4B9E-A7F4-ECC53F52F214} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718- 708133086-1000Core => C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {A9405DF1-8498-42EB-9911-E2B1CBC0572C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718- 708133086-1000UA => C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {AA11DF3E-CFAF-4851-AB5C-20C5BC31E5AE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086- 500Core => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-16] (Google Inc.) Task: {BFC3AF24-E903-4FA6-A78C-E1B0C2600A77} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {C5E417A0-E558-4656-8B2A-3B90AC109C24} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung \BatteryLifeExtender\BatteryLifeExtender.exe [2010-12-01] (Samsung Electronics. Co. Ltd.) Task: {CABA96D1-D5A0-43F3-9384-32474FD032E2} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe [2010-08-19] (Samsung Electronics Co., Ltd.) Task: {CDD96E60-7A5E-426C-9FB3-4CF76D015A57} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart \SmartRestarter.exe [2010-08-05] (Samsung Electronics Co., Ltd.) Task: {CDE3AF8E-A54A-4CB4-B998-C76152EEE3F2} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam \YCMMirage.exe [2010-11-10] (CyberLink) Task: {D10419DA-B0D7-4A0D-98CB-AAFF7C8D73EA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086- 1000UA => C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13] (Google Inc.) Task: {D185EA38-12BC-44E7-9A58-DD32DED0AA3E} - System32\Tasks\Clean System Memory => C:\Windows\syswow64\CleanMem.exe [2011-07-09] (PcWinTech.com) Task: {E1C99093-2BA9-4FF4-AE92-92237CB501CF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086- 1000Core => C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13] (Google Inc.) Task: {FEB14CB6-EA1B-4FC4-B812-0C7DA408E53C} - System32\Tasks\GlaryInitialize => C:\Program Files (x86)\Glary Utilities \initialize.exe [2012-02-03] (Glarysoft Ltd) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job => C:\Users\andreas \AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job => C:\Users\andreas \AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GlaryInitialize.job => C:\Program Files (x86)\Glary Utilities\initialize.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job => C:\Users\andreas \AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job => C:\Users\andreas\AppData \Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500Core.job => C:\Users\Administrator \AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500UA.job => C:\Users\Administrator \AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-05-13 11:20 - 2008-06-05 01:53 - 00027648 _____ () C:\Windows\System32\spd__l.dll 2010-10-19 09:31 - 2010-10-19 09:31 - 00205312 _____ () C:\Program Files\Netzmanager\NMInfraIS2\driver64\SoftplugLib.DLL 2011-05-13 11:20 - 2010-04-21 01:44 - 00719872 _____ () C:\Windows\system32\SnMinDrv.dll 2012-11-01 17:46 - 2012-09-19 19:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2012-02-02 03:41 - 2011-11-14 16:09 - 00348376 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag \madExcept_.bpl 2012-02-02 03:41 - 2011-11-14 16:09 - 00182488 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag \madBasic_.bpl 2012-02-02 03:41 - 2011-11-14 16:09 - 00048856 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag \madDisAsm_.bpl 2012-02-02 03:41 - 2011-11-14 16:09 - 00254680 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag \AusShellExt.dll 2010-12-17 06:51 - 2010-07-05 12:42 - 00203776 _____ () C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 00051016 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\chrome_elf.dll 2013-09-14 01:51 - 2013-09-14 01:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services \zlib1.dll 2013-09-14 01:50 - 2013-09-14 01:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services \libxml2.dll 2014-02-25 18:52 - 2014-02-25 18:52 - 01563200 _____ () C:\Program Files (x86)\Copernic \DesktopSearch4\Copernic.System.RT.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared \office14\Cultures\office.odf 2011-09-14 23:44 - 2011-09-14 23:44 - 00166816 _____ () C:\Program Files (x86)\Gizmo\GImage.DLL 2011-09-14 23:44 - 2011-09-14 23:44 - 00315800 _____ () C:\Program Files (x86)\Gizmo\gmanager.DLL 2011-09-14 23:44 - 2011-09-14 23:44 - 00404384 _____ () C:\Program Files (x86)\Gizmo\gdatabase.dll 2011-09-14 23:44 - 2011-09-14 23:44 - 00394656 _____ () C:\Program Files (x86)\Gizmo\gdrive.dll 2011-09-14 23:44 - 2011-09-14 23:44 - 00339864 _____ () C:\Program Files (x86)\Gizmo\geditor.dll 2011-09-14 23:44 - 2011-09-14 23:44 - 00372632 _____ () C:\Program Files (x86)\Gizmo\ghash.dll 2011-09-14 23:44 - 2011-09-14 23:44 - 00339864 _____ () C:\Program Files (x86)\Gizmo\gscript.dll 2012-02-06 01:20 - 2011-04-15 03:01 - 00548854 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll 2005-03-16 15:34 - 2005-03-16 15:34 - 00110592 ____R () C:\Program Files (x86)\Mindjet\MindManager 6\zlib.dll 2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\andreas\AppData\Roaming\Dropbox\bin\libcef.dll 2010-12-17 06:49 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll 2014-03-29 22:09 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2014-03-29 22:09 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2014-03-30 16:58 - 2014-03-30 16:58 - 00098816 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32api.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00110080 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pywintypes27.dll 2014-03-30 16:57 - 2014-03-30 16:57 - 00364544 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pythoncom27.dll 2014-03-30 16:58 - 2014-03-30 16:58 - 00044032 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_socket.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 01157120 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_ssl.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00320512 _____ () C:\Users\andreas\AppData\Local\Temp \_MEI29722\win32com.shell.shell.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00712192 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_hashlib.pyd 2014-03-30 16:57 - 2014-03-30 16:57 - 01175040 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._core_.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00805888 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._gdi_.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00811008 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._windows_.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 01062400 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._controls_.pyd 2014-03-30 16:57 - 2014-03-30 16:57 - 00735232 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._misc_.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00128512 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_elementtree.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00127488 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pyexpat.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00557056 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pysqlite2._sqlite.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00087040 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_ctypes.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00119808 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32file.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00108544 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32security.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00018432 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32event.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00038912 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32inet.pyd 2014-03-30 16:57 - 2014-03-30 16:57 - 00122368 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._wizard.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00070656 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._html2.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00026624 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_multiprocessing.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00010240 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\select.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00024064 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32pipe.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00686080 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\unicodedata.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00025600 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32pdh.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00525640 _____ () C:\Users\andreas\AppData\Local\Temp \_MEI29722\windows._lib_cacheinvalidation.pyd 2014-03-30 16:57 - 2014-03-30 16:57 - 00011264 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32crypt.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00035840 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32process.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00017408 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32profile.pyd 2014-03-30 16:57 - 2014-03-30 16:57 - 00022528 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32ts.pyd 2014-03-19 20:10 - 2014-03-15 02:50 - 00716616 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\libglesv2.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 00100168 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\libegl.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 04061000 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\pdf.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 00394568 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\ppGoogleNaClPluginChrome.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 01647432 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\ffmpegsumo.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 13637448 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\PepperFlash\pepflashplayer.dll 2014-03-29 22:09 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2009-11-02 07:20 - 2009-11-02 07:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:07BF512B ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Bluetooth Device (Personal Area Network) #2 Description: Bluetooth-Gerät (PAN) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: BthPan Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (03/30/2014 05:07:17 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: netzmanager.exe, Version: 1.71.0.301, Zeitstempel: 0x500948ae Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677 Ausnahmecode: 0xe053534f Fehleroffset: 0x000000000000940d ID des fehlerhaften Prozesses: 0x%9 Startzeit der fehlerhaften Anwendung: 0xnetzmanager.exe0 Pfad der fehlerhaften Anwendung: netzmanager.exe1 Pfad des fehlerhaften Moduls: netzmanager.exe2 Berichtskennung: netzmanager.exe3 Error: (03/30/2014 04:49:44 PM) (Source: Application Hang) (User: ) Description: Programm chrome.exe, Version 33.0.1750.154 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1d14 Startzeit: 01cf4c26b8061c6a Endzeit: 7 Anwendungspfad: C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe Berichts-ID: 7f21641c-b81a-11e3-aa82-e811322169d9 Error: (03/30/2014 03:52:02 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:52:01 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:59 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:56 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome System errors: ============= Error: (03/30/2014 05:10:41 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Error: (03/30/2014 05:06:46 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Error: (03/30/2014 05:02:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/30/2014 05:02:36 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SSDP-Suche erreicht. Error: (03/30/2014 05:01:56 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/30/2014 05:01:52 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (03/30/2014 04:58:57 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/30/2014 04:58:57 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht. Error: (03/30/2014 04:58:13 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/30/2014 04:58:13 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Microsoft Office Sessions: ========================= Error: (03/30/2014 05:07:17 PM) (Source: Application Error)(User: ) Description: netzmanager.exe1.71.0.301500948aeKERNELBASE.dll6.1.7601.1822951fb1677e053534f000000000000940d Error: (03/30/2014 04:49:44 PM) (Source: Application Hang)(User: ) Description: chrome.exe33.0.1750.1541d1401cf4c26b8061c6a7C:\Users\andreas\AppData\Local\Google\Chrome\Application \chrome.exe7f21641c-b81a-11e3-aa82-e811322169d9 Error: (03/30/2014 03:52:02 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:52:01 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:59 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:56 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) ==================== Memory info =========================== Percentage of memory in use: 56% Total physical RAM: 3956.56 MB Available physical RAM: 1714.84 MB Total Pagefile: 7911.3 MB Available Pagefile: 4460.76 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:178 GB) (Free:38.82 GB) NTFS Drive d: () (Fixed) (Total:266.14 GB) (Free:16.1 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 741D8EA4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=178 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=266 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=22 GB) - (Type=27) ==================== End Of Log ============================Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by andreas at 2014-03-30 17:08:12 Running from C:\Users\andreas\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== „Messenger“ pagalbinė priemonė (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden „Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden „Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden „Windows Live Mesh ActiveX“ nuotolinių ryšių valdiklis (HKLM-x32\...\{9024FE65-46B8-4C8A-9D98-8DCB6BD5F598}) (Version: 15.4.5722.2 - Microsoft Corporation) „Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden „Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 7-PDF Maker Version 1.4.1 (Build 128) (HKLM-x32\...\7-PDF Maker_is1) (Version: 7-PDF Maker - Version 1.4.1 (Build 128) - 7 -PDF, Germany - Thorsten Hodes) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) 7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - ) ActiveX контрола на Windows Live Mesh за отдалечени връзки (HKLM-x32\...\{B3BA4D1C-23EF-4859-9C11-1B2CCB7FADBB}) (Version: 15.4.5722.2 - Microsoft Corporation) ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (HKLM-x32\...\{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5}) (Version: 15.4.5722.2 - Microsoft Corporation) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.3.0.3670 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.3.0.3670 - Adobe Systems Incorporated) Hidden Adobe Connect Add-in (HKCU\...\Adobe Connect Add-in) (Version: - ) Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version: - ) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.) AIM for Windows (HKCU\...\AIM) (Version: - AOL Inc.) Amazon Kindle (HKCU\...\Amazon Kindle) (Version: - Amazon) Amazon MP3-Downloader 1.0.9 (HKLM-x32\...\Amazon MP3-Downloader) (Version: - ) Android Sync Manager WiFi (HKLM-x32\...\{13D946AF-DAD9-0200-0000-000000000000}) (Version: 11.10.2763 - Mobile Action) Android-Sync v0.369 (HKLM-x32\...\{B148E192-F289-4297-85BF-70E2A422EB25}_is1) (Version: - Android-Sync.com) Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Ashampoo WinOptimizer 2010 Advanced (HKLM-x32\...\Ashampoo WinOptimizer 2010 Advanced_is1) (Version: 6.5.0 - Ashampoo GmbH & Co. KG) Ask Shopping Toolbar (HKLM-x32\...\{4D594333-2D53-4154-00A7-A758B70C0202}) (Version: 12.2.2.652 - Ask Partner Network) <==== ATTENTION Ask Toolbar (HKLM-x32\...\{4D594333-0076-A76A-76A7-A758B70C0300}) (Version: 12.3.0.959 - APN, LLC) <==== ATTENTION Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros) Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team) Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: version 3.3 - Auslogics Software Pty Ltd) Avidemux 2.5 (32-bit) (HKLM-x32\...\Avidemux 2.5) (Version: 2.5.4.7200 - ) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) BatteryLifeExtender (HKLM-x32\...\{EA257ECF-5F72-4461-B890-959394DCD087}) (Version: 1.0.10 - Samsung) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 5.60.48.55 - Broadcom Corporation) Bullzip PDF Printer 10.4.0.2240 (HKLM\...\Bullzip PDF Printer_is1) (Version: 10.4.0.2240 - Bullzip) Camfrog Video Chat 6.5 (HKLM-x32\...\Camfrog 6.5) (Version: 6.5.300 - Camshare, Inc.) Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - ) Canon MG5100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series) (Version: - ) Canon MP Navigator 1.0 (HKLM-x32\...\MP Navigator 1.0) (Version: - ) Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - ) CleanMem (HKLM-x32\...\CleanMem) (Version: v2.2.0 - PcWinTech.com) Complément Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Complemento Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Control ActiveX Windows Live Mesh pentru conexiuni la distanță (HKLM-x32\...\{260E3D78-94E6-47EC-8E29-46301572BB1E}) (Version: 15.4.5722.2 - Microsoft Corporation) Controle ActiveX do Windows Live Mesh para Conexões Remotas (HKLM-x32\...\{39B3184E-0BFB-40FA-ADDC-E7E2D535CDA9}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) Copernic Desktop Search 4 (HKLM-x32\...\CopernicDesktopSearch4) (Version: 4.0.5.1231 - Copernic) Copernic Desktop Search 4 (x32 Version: 4.0.5.1231 - Copernic) Hidden Creative Centrale (HKLM-x32\...\Creative Centrale) (Version: 1.19.02 - Creative Technology Ltd.) Creative Centrale (x32 Version: 1.19.02 - Creative Technology Ltd.) Hidden Creative Software Update (x32 Version: 1.03.01 - Creative Technology Ltd.) Hidden Creative ZEN X-Fi2 Dokumentation (HKLM-x32\...\ZENXFI2UG) (Version: - Creative Technology Ltd.) CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.) CyberLink Media Suite (x32 Version: 8.0.2227 - CyberLink Corp.) Hidden CyberLink Media+ Player10 (HKLM-x32\...\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 - CyberLink Corp.) CyberLink Media+ Player10 (x32 Version: 10.0.1110.00 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.) CyberLink Power2Go (x32 Version: 6.1.3802 - CyberLink Corp.) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3509 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.1.3509 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{92C42EDD-6524-4577-B2EB-6C68C63B6D4A}) (Version: - Microsoft) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.41 - DivX, LLC) Doplnok programu Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.) Easy Content Share (HKLM-x32\...\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD) Easy Display Manager (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.) Easy Migration (HKLM-x32\...\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0.0.5 - Samsung Electronics Co., Ltd.) Easy Network Manager (HKLM-x32\...\{FCF2085E-ABE5-4AA8-B07C-65BBD56DA243}) (Version: 4.4.6 - Samsung) Easy SpeedUp Manager (HKLM-x32\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.1.1.1 - Samsung Electronics Co.,Ltd.) EasyBatteryManager (HKLM-x32\...\{4A331D24-A9E8-484F-835E-1BA7B139689C}) (Version: 4.0.0.4 - Samsung) EasyFileShare (HKLM-x32\...\{EA76E65F-6679-495A-A8A6-42AD6602ED4C}) (Version: 1.0.11 - Samsung) ETDWare PS/2-X64 10.7.14.12_WHQL (HKLM\...\Elantech) (Version: 10.7.14.12 - ELAN Microelectronic Corp.) Extended Asian Language font pack for Adobe Reader XI (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-A00000000004}) (Version: 11.0.0 - Adobe Systems Incorporated) Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook) Fast Start (HKLM-x32\...\{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}) (Version: 2.2.0.0 - SAMSUNG) FastConnect 1.2.2 (HKLM-x32\...\FastConnect) (Version: 1.2.2 - The Cloud Networks) FeedReader (HKLM-x32\...\FeedReader_is1) (Version: - i-Systems Inc.) FirstClass® Client (HKLM-x32\...\{2869279D-7AE2-4A13-96B8-46078BA3F75B}) (Version: 11.0 (build 11.033) - Open Text Corporation.) Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61- B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Free Download Manager 3.0 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG) Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com) FreeMind (HKLM-x32\...\B991B020-2968-11D8-AF23-444553540000_is1) (Version: 0.9.0 - ) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Gizmo Central (HKLM-x32\...\Gizmo Central) (Version: v2.7.9 - Arainia Solutions, LLC) Glary Utilities 2.42.0.1389 (HKLM-x32\...\Glary Utilities_is1) (Version: 2.42.0.1389 - Glarysoft Ltd) Google Chrome (HKCU\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.) Google Drive (HKLM-x32\...\{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}) (Version: 1.14.6059.644 - Google, Inc.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden Hoffnung für heute (HKLM-x32\...\{9447C5C8-6A1B-412F-B9A6-99AFE7C09773}) (Version: 3.2.1 - ) iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) ICQ7.5 (HKLM-x32\...\{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}) (Version: 7.5 - ICQ) IHMC CmapTools v5.05.01 (HKLM-x32\...\IHMC CmapTools v5.05.01) (Version: 5.0.5.1 - Institute for Human & Machine Cognition) iMODELER - Consideo GmbH (HKLM-x32\...\iMODELER) (Version: - ) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.3.1001 - Intel Corporation) Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.02.00.1002 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.28 - Irfan Skiljan) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) iWisoft Free Video Converter 1.2 (HKLM-x32\...\iWisoft Free Video Converter_is1) (Version: 1.2 - www.easy-video- converter.com) IZArc 4.1.6 (HKLM-x32\...\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1) (Version: 4.1.6 - Ivan Zahariev) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 37 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216037FF}) (Version: 6.0.370 - Oracle) JLC's Internet TV (HKLM-x32\...\JLC's Internet TV) (Version: - ) Jpg2Pdf version 1.2 (HKLM-x32\...\{533D415A-4151-4AC5-858E-4068524C8051}_is1) (Version: 1.2 - Office Necessities inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden KaraFun Player (HKLM-x32\...\KaraFun Player_is1) (Version: 1.20.86.771 - Recisio) K-Lite Codec Pack 6.0.4 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 6.0.4 - ) Kontrola Windows Live Mesh ActiveX za daljinske veze (HKLM-x32\...\{19CBDE24-2761-49A5-816B-D2BA65D0CA8D}) (Version: 15.4.5722.2 - Microsoft Corporation) Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (HKLM-x32\...\{CA227A9D-09BE-4BFB-9764-48FED2DA5454}) (Version: 15.4.5722.2 - Microsoft Corporation) LinkedIn Outlook Connector (HKLM-x32\...\LinkedIn Outlook Connector) (Version: 1.1.10.0 - LinkedIn) MagicDisc 2.7.106 (HKLM-x32\...\MagicDisc 2.7.106) (Version: - ) Malwarebytes Anti-Malware Version 2.00.0.1000 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 - Malwarebytes Corporation) ManyCam 3.1.59 (HKLM-x32\...\ManyCam) (Version: 3.1.59 - ManyCam LLC) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Assistent (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger kísérő (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger Pratilac (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger Suradnik (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger 사이트 공유 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger 分享元件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger 浏览器插件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger-kumppani (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Outlook Social Connector Provider for Facebook 32-bit (HKLM-x32\...\{95140000-007C-0409-0000-0000000FF1CE}) (Version: 14.0.6114.5003 - Microsoft Corporation) Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\...\{95140000-007D-0409-0000- 0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\...\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation) Mindjet MindManager Pro 6 (HKLM-x32\...\{9FC3EA3B-A6FB-436E-8A69-8595548CACBF}) (Version: 6.2.399 - Mindjet LLC) MiniTool Partition Wizard Home Edition 7.1 (HKLM-x32\...\{34A153FE-6926-4C14-B48A-B71E68C672A8}_is1) (Version: - MiniTool Solution Ltd.) Mobipocket Reader 6.2 (HKLM-x32\...\{342126E1-173C-4585-BFBE-3EBDD20E3E9E}) (Version: 6.2.608 - Mobipocket.com) Movie Color Enhancer (HKLM-x32\...\{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}) (Version: 1.0 - Samsung Electronics Co., Ltd.) Mozilla Firefox 14.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 14.0.1 (x86 de)) (Version: 14.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 14.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.2 - F.J. Wechselberger) NAVIGON Fresh 3.4.1 (HKLM-x32\...\NAVIGON Fresh) (Version: 3.4.1 - NAVIGON) Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.071 - Deutsche Telekom AG) Netzmanager (Version: 1.071 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden Nur Entfernen der CopyTrans Suite möglich (HKCU\...\CopyTrans Suite) (Version: 2.33 - WindSolutions) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation) NVIDIA Grafiktreiber 267.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.54 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.265.39.0 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 267.54 (Version: 267.54 - NVIDIA Corporation) Hidden Octoshape Streaming Services (HKCU\...\Octoshape Streaming Services) (Version: - Octoshape ApS) OpenOffice 4.0.0 (HKLM-x32\...\{B28DBCBA-60F8-40ED-B35B-F510C327946C}) (Version: 4.00.9702 - Apache Software Foundation) Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74- A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation) Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F- C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation) PDF24 Creator 5.3.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) PDFill PDF Editor with FREE Writer and FREE Tools (HKLM\...\{D1399216-81B2-457C-A0F7-73B9A2EF6902}) (Version: 9.0 - PlotSoft LLC) PDF-XChange 3 (HKLM-x32\...\PDF-XChange 3_is1) (Version: - Tracker Software) PhoneShare (HKLM-x32\...\{E31F454E-4813-4C88-B0D3-4BB174993770}) (Version: 1.0.4 - Samsung) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pomocnik Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Python 2.7.2 (HKLM-x32\...\{2E295B5B-1AD4-4d36-97C2-A316084722CF}) (Version: 2.7.2150 - Python Software Foundation) QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.33.1125.2010 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6257 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.) Samsung AnyWeb Print (HKLM-x32\...\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 1.1.21.0 - Samsung Electronics Co., Ltd.) Samsung AnyWeb Print (x32 Version: 1.0 - Samsung Electronics Co., Ltd.) Hidden Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.0.8 - Samsung) Samsung Support Center 1.0 (HKLM-x32\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.38 - Samsung) Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: 2.01.06.00:16 - Samsung Electronics Co., Ltd.) Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 1.2.1.0 - Samsung Electronics Co., Ltd.) Samsung Update Plus (HKLM-x32\...\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.1.17 - Samsung Electronics Co., Ltd.) Screencast-O-Matic (HKCU\...\Screencast-O-Matic) (Version: - Screencast-O-Matic) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Spotify (HKCU\...\Spotify) (Version: 0.9.7.16.g4b197456 - Spotify AB) Spremljevalec Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.) SRS Premium Sound Control Panel (HKLM\...\{2998191E-A35E-47E2-BE38-7702C731D722}) (Version: 1.10.1000 - SRS Labs, Inc.) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1108 - SUPERAntiSpyware.com) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden System Explorer 3.9.1 (HKLM-x32\...\System Explorer_is1) (Version: - Mister Group) System Explorer 3.9.4 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version: - Mister Group) Tango (HKCU\...\Tango) (Version: 1.6.14117 - TangoMe, Inc.) Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE} _Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_ {3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE} _Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE} _Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE} _Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE} _Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE} _Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE} _Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE} _Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE} _Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000- 0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2878227) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{5D357893-40BA-4323-86BA-D97C66CD72F4}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE} _Office14.SingleImage_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}) (Version: - Microsoft) UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - ) Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (HKLM-x32\...\{241E7104-937A-4366-AD57-8FDDDB003939}) (Version: 15.4.5722.2 - Microsoft Corporation) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7000 - Broadcom Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live fotoattēlu galerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Foto-galerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797- 0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX kontrola za daljinske veze (HKLM-x32\...\{8985AE5E-622A-4980-8BF8-0A1830643220}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX vadīkla attālajiem savienojumiem (HKLM-x32\...\{A3A775C9-5A63-4C55-8FDD-427A5B8F5D2B}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (HKLM-x32\...\{09B7C7EB-3140-4B5E-842F-9C79A7137139}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX-objekt til fjernforbindelser (HKLM-x32\...\{57220148-3B2B-412A-A2E0-82B9DF423696}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (HKLM-x32\...\{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Meshin etäyhteyksien ActiveX-komponentti (HKLM-x32\...\{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Pošta (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 메일 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 사진 갤러리 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 필수 패키지 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 照片库 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 软件包 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows-Treiberpaket - Android-Sync.com (WinUSB) AndroidUsbDeviceClass (10/21/2011 4.0.0000.11021) (HKLM\... \6D51958587F750FB22B14F3587024652DE17F288) (Version: 10/21/2011 4.0.0000.11021 - Android-Sync.com) WinPatrol (HKLM\...\{007811BF-E310-4285-BFC6-55DB29B3EDDE}) (Version: 24.1.2012 - BillP Studios) WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) XING Outlook Connector (HKLM\...\{3B8AF990-AE63-481C-BC4B-8BB8D7A93B80}) (Version: 2.2.0 - XING) xplorer² lite 32 bit (HKLM-x32\...\xplorer2l) (Version: 2.3.0.1 - Zabkat) Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.) Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version: - ) Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - ) YouTube Song Downloader (HKLM-x32\...\{4281435C-AD1D-4C8A-B9C0-3961C11EF142}_is1) (Version: 8.2 - Abelssoft) Zotero Standalone 3.0.14 (x86 en-US) (HKLM-x32\...\Zotero Standalone 3.0.14 (x86 en-US)) (Version: 3.0.14 - Zotero) Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation) Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47- FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Компаньон Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Помощник на Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2- 8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden מסייע Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ตัวควบคุม ActiveX ใน Windows Live Mesh สำหรับการเชื่อมต่อระยะไกล (ไทย) (HKLM-x32\...\{A2EDAEEB-C981-46D5-8163-CF8F5F640EEE}) (Version: 15.4.5722.2 - Microsoft Corporation) 원격 연결을 위한 Windows Live Mesh ActiveX 컨트롤 (HKLM-x32\...\{61920449-0393-4707-B7DD-E6C0013C8B2C}) (Version: 15.4.5722.2 - Microsoft Corporation) 用于远程连接的 Windows Live Mesh ActiveX 控件(简体中文) (HKLM-x32\...\{F992409C-9D10-4AE2-BAEB-B5409AD3785E}) (Version: 15.4.5722.2 - Microsoft Corporation) 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Restore Points ========================= 26-03-2014 18:24:35 Windows Update 29-03-2014 20:05:06 Uniblue SpeedUpMyPC installation 29-03-2014 22:41:47 S 30-03-2014 13:49:58 Revo Uninstaller's restore point - Ask Shopping Toolbar 30-03-2014 14:43:56 Revo Uninstaller's restore point - ooVoo 30-03-2014 14:44:50 Removed ooVoo ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts |
30.03.2014, 21:22 | #5 |
| Trojaner SupTab u.a. Und der zweite Teil der zweiten File (Additions) ==================== Scheduled Tasks (whitelisted) ============= Task: {0666A132-9CBC-4EE0-885F-AB0465900A46} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung \EasySpeedUpManager\EasySpeedUpManager2.exe [2010-12-01] (Samsung Electronics) Task: {07409B9B-7821-4253-91E7-116AFCF83E69} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2010-11-28] (Samsung Electronics Co., Ltd.) Task: {1318A8AD-A403-404D-ADFA-59FA3D8956FD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google \Update\GoogleUpdate.exe [2011-05-21] (Google Inc.) Task: {1623FBDB-E473-4D9E-9F23-7A929E229916} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {185C37D1-20B4-4A1F-995A-0B3AE22033D1} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-11-17] (SEC) Task: {24FF686B-BFF6-4A3C-9C78-0E00F254409B} - System32\Tasks\xingoscupdate => C:\Program Files\XING\XING Outlook Connector\xingoscupdate.exe [2014-01-08] (XING) Task: {256E2E78-825E-4930-B00E-E86DC6762ED9} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung \Samsung Support Center\SSCKbdHk.exe [2011-09-04] (SAMSUNG Electronics) Task: {299D73B6-AE07-4510-BDF3-53538E412FED} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {29C2FC45-A051-4254-A333-AC168384DC37} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung \EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.) Task: {38B2690F-5140-4B97-8006-5B6105746F2F} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe [2010-11-28] (Samsung Electronics Co., Ltd.) Task: {3927588F-2B07-4A40-A858-43BC63300A91} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {420C63BC-0E55-4D7D-9746-3E5B9FF83E5D} - System32\Tasks\SRS Premium Sound => C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel_64.exe [2010-11-29] (SRS Labs, Inc.) Task: {47656083-02C7-4E54-808F-7263466606B5} - System32\Tasks\Xing Social Recommendations => C:\Program Files\XING\XING Outlook Connector\32-bit\XingSocial.exe [2014-01-08] (XING AG) Task: {56E8FB28-DB36-48DC-8D7A-379AA0CF63F1} - System32\Tasks\{EB5A17F7-59B1-4914-80F9-8981CBF7FF0B} => C:\Program Files (x86)\Gizmo\gizmo.exe [2011-09-14] (Arainia Solutions) Task: {773AE63E-EACB-4047-8A3F-2E395CF9E670} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2011-12-20] (Samsung Electronics) Task: {7821C008-BFDF-45B6-B2A7-12BC3E0ACD8D} - System32\Tasks\CleanMem Mini Monitor => C:\Program Files (x86)\CleanMem \mini_monitor.exe [2011-07-09] (PcWinTech.com) Task: {8014A37B-FB9B-451C-A2B4-1BF82CC7DA59} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed \Flash\FlashPlayerUpdateService.exe [2014-03-15] (Adobe Systems Incorporated) Task: {83C4A256-9C9E-48ED-8770-83C3BFDE7ACF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086- 500UA => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-16] (Google Inc.) Task: {8D8D58A3-BC0D-4C52-83BA-7F40EA4E7386} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google \Update\GoogleUpdate.exe [2011-05-21] (Google Inc.) Task: {97533C0E-FAF4-42D9-8670-CF1F351EFB00} - System32\Tasks\Auslogics\Disk Defrag\Start On andreas Logon => C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe [2011-11-14] (Auslogics) Task: {9B159597-B87B-4B9E-A7F4-ECC53F52F214} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718- 708133086-1000Core => C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {A9405DF1-8498-42EB-9911-E2B1CBC0572C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718- 708133086-1000UA => C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {AA11DF3E-CFAF-4851-AB5C-20C5BC31E5AE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086- 500Core => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-16] (Google Inc.) Task: {BFC3AF24-E903-4FA6-A78C-E1B0C2600A77} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {C5E417A0-E558-4656-8B2A-3B90AC109C24} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung \BatteryLifeExtender\BatteryLifeExtender.exe [2010-12-01] (Samsung Electronics. Co. Ltd.) Task: {CABA96D1-D5A0-43F3-9384-32474FD032E2} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe [2010-08-19] (Samsung Electronics Co., Ltd.) Task: {CDD96E60-7A5E-426C-9FB3-4CF76D015A57} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart \SmartRestarter.exe [2010-08-05] (Samsung Electronics Co., Ltd.) Task: {CDE3AF8E-A54A-4CB4-B998-C76152EEE3F2} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam \YCMMirage.exe [2010-11-10] (CyberLink) Task: {D10419DA-B0D7-4A0D-98CB-AAFF7C8D73EA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086- 1000UA => C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13] (Google Inc.) Task: {D185EA38-12BC-44E7-9A58-DD32DED0AA3E} - System32\Tasks\Clean System Memory => C:\Windows\syswow64\CleanMem.exe [2011-07-09] (PcWinTech.com) Task: {E1C99093-2BA9-4FF4-AE92-92237CB501CF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086- 1000Core => C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13] (Google Inc.) Task: {FEB14CB6-EA1B-4FC4-B812-0C7DA408E53C} - System32\Tasks\GlaryInitialize => C:\Program Files (x86)\Glary Utilities \initialize.exe [2012-02-03] (Glarysoft Ltd) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job => C:\Users\andreas \AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job => C:\Users\andreas \AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GlaryInitialize.job => C:\Program Files (x86)\Glary Utilities\initialize.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job => C:\Users\andreas \AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job => C:\Users\andreas\AppData \Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500Core.job => C:\Users\Administrator \AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500UA.job => C:\Users\Administrator \AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-05-13 11:20 - 2008-06-05 01:53 - 00027648 _____ () C:\Windows\System32\spd__l.dll 2010-10-19 09:31 - 2010-10-19 09:31 - 00205312 _____ () C:\Program Files\Netzmanager\NMInfraIS2\driver64\SoftplugLib.DLL 2011-05-13 11:20 - 2010-04-21 01:44 - 00719872 _____ () C:\Windows\system32\SnMinDrv.dll 2012-11-01 17:46 - 2012-09-19 19:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2012-02-02 03:41 - 2011-11-14 16:09 - 00348376 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag \madExcept_.bpl 2012-02-02 03:41 - 2011-11-14 16:09 - 00182488 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag \madBasic_.bpl 2012-02-02 03:41 - 2011-11-14 16:09 - 00048856 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag \madDisAsm_.bpl 2012-02-02 03:41 - 2011-11-14 16:09 - 00254680 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag \AusShellExt.dll 2010-12-17 06:51 - 2010-07-05 12:42 - 00203776 _____ () C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 00051016 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\chrome_elf.dll 2013-09-14 01:51 - 2013-09-14 01:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services \zlib1.dll 2013-09-14 01:50 - 2013-09-14 01:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services \libxml2.dll 2014-02-25 18:52 - 2014-02-25 18:52 - 01563200 _____ () C:\Program Files (x86)\Copernic \DesktopSearch4\Copernic.System.RT.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared \office14\Cultures\office.odf 2011-09-14 23:44 - 2011-09-14 23:44 - 00166816 _____ () C:\Program Files (x86)\Gizmo\GImage.DLL 2011-09-14 23:44 - 2011-09-14 23:44 - 00315800 _____ () C:\Program Files (x86)\Gizmo\gmanager.DLL 2011-09-14 23:44 - 2011-09-14 23:44 - 00404384 _____ () C:\Program Files (x86)\Gizmo\gdatabase.dll 2011-09-14 23:44 - 2011-09-14 23:44 - 00394656 _____ () C:\Program Files (x86)\Gizmo\gdrive.dll 2011-09-14 23:44 - 2011-09-14 23:44 - 00339864 _____ () C:\Program Files (x86)\Gizmo\geditor.dll 2011-09-14 23:44 - 2011-09-14 23:44 - 00372632 _____ () C:\Program Files (x86)\Gizmo\ghash.dll 2011-09-14 23:44 - 2011-09-14 23:44 - 00339864 _____ () C:\Program Files (x86)\Gizmo\gscript.dll 2012-02-06 01:20 - 2011-04-15 03:01 - 00548854 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll 2005-03-16 15:34 - 2005-03-16 15:34 - 00110592 ____R () C:\Program Files (x86)\Mindjet\MindManager 6\zlib.dll 2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\andreas\AppData\Roaming\Dropbox\bin\libcef.dll 2010-12-17 06:49 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll 2014-03-29 22:09 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2014-03-29 22:09 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2014-03-30 16:58 - 2014-03-30 16:58 - 00098816 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32api.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00110080 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pywintypes27.dll 2014-03-30 16:57 - 2014-03-30 16:57 - 00364544 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pythoncom27.dll 2014-03-30 16:58 - 2014-03-30 16:58 - 00044032 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_socket.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 01157120 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_ssl.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00320512 _____ () C:\Users\andreas\AppData\Local\Temp \_MEI29722\win32com.shell.shell.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00712192 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_hashlib.pyd 2014-03-30 16:57 - 2014-03-30 16:57 - 01175040 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._core_.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00805888 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._gdi_.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00811008 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._windows_.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 01062400 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._controls_.pyd 2014-03-30 16:57 - 2014-03-30 16:57 - 00735232 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._misc_.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00128512 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_elementtree.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00127488 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pyexpat.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00557056 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pysqlite2._sqlite.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00087040 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_ctypes.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00119808 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32file.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00108544 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32security.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00018432 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32event.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00038912 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32inet.pyd 2014-03-30 16:57 - 2014-03-30 16:57 - 00122368 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._wizard.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00070656 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._html2.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00026624 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_multiprocessing.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00010240 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\select.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00024064 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32pipe.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00686080 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\unicodedata.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00025600 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32pdh.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00525640 _____ () C:\Users\andreas\AppData\Local\Temp \_MEI29722\windows._lib_cacheinvalidation.pyd 2014-03-30 16:57 - 2014-03-30 16:57 - 00011264 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32crypt.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00035840 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32process.pyd 2014-03-30 16:58 - 2014-03-30 16:58 - 00017408 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32profile.pyd 2014-03-30 16:57 - 2014-03-30 16:57 - 00022528 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32ts.pyd 2014-03-19 20:10 - 2014-03-15 02:50 - 00716616 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\libglesv2.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 00100168 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\libegl.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 04061000 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\pdf.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 00394568 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\ppGoogleNaClPluginChrome.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 01647432 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\ffmpegsumo.dll 2014-03-19 20:10 - 2014-03-15 02:50 - 13637448 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application \33.0.1750.154\PepperFlash\pepflashplayer.dll 2014-03-29 22:09 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2009-11-02 07:20 - 2009-11-02 07:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:07BF512B ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Bluetooth Device (Personal Area Network) #2 Description: Bluetooth-Gerät (PAN) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: BthPan Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (03/30/2014 05:07:17 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: netzmanager.exe, Version: 1.71.0.301, Zeitstempel: 0x500948ae Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677 Ausnahmecode: 0xe053534f Fehleroffset: 0x000000000000940d ID des fehlerhaften Prozesses: 0x%9 Startzeit der fehlerhaften Anwendung: 0xnetzmanager.exe0 Pfad der fehlerhaften Anwendung: netzmanager.exe1 Pfad des fehlerhaften Moduls: netzmanager.exe2 Berichtskennung: netzmanager.exe3 Error: (03/30/2014 04:49:44 PM) (Source: Application Hang) (User: ) Description: Programm chrome.exe, Version 33.0.1750.154 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1d14 Startzeit: 01cf4c26b8061c6a Endzeit: 7 Anwendungspfad: C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe Berichts-ID: 7f21641c-b81a-11e3-aa82-e811322169d9 Error: (03/30/2014 03:52:02 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:52:01 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:59 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:56 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller) (User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome System errors: ============= Error: (03/30/2014 05:10:41 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Error: (03/30/2014 05:06:46 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Error: (03/30/2014 05:02:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/30/2014 05:02:36 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SSDP-Suche erreicht. Error: (03/30/2014 05:01:56 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/30/2014 05:01:52 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (03/30/2014 04:58:57 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/30/2014 04:58:57 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht. Error: (03/30/2014 04:58:13 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/30/2014 04:58:13 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Microsoft Office Sessions: ========================= Error: (03/30/2014 05:07:17 PM) (Source: Application Error)(User: ) Description: netzmanager.exe1.71.0.301500948aeKERNELBASE.dll6.1.7601.1822951fb1677e053534f000000000000940d Error: (03/30/2014 04:49:44 PM) (Source: Application Hang)(User: ) Description: chrome.exe33.0.1750.1541d1401cf4c26b8061c6a7C:\Users\andreas\AppData\Local\Google\Chrome\Application \chrome.exe7f21641c-b81a-11e3-aa82-e811322169d9 Error: (03/30/2014 03:52:02 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:52:01 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:59 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:56 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller)(User: andreas-sams-PC) Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie mit der Deinstallation fortfahren: Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL) ==================== Memory info =========================== Percentage of memory in use: 56% Total physical RAM: 3956.56 MB Available physical RAM: 1714.84 MB Total Pagefile: 7911.3 MB Available Pagefile: 4460.76 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:178 GB) (Free:38.82 GB) NTFS Drive d: () (Fixed) (Total:266.14 GB) (Free:16.1 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 741D8EA4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=178 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=266 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=22 GB) - (Type=27) ==================== End Of Log ============================ |
31.03.2014, 13:04 | #6 |
/// the machine /// TB-Ausbilder | Trojaner SupTab u.a.So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Revo Uninstaller - Download - Filepony Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION Mit Revo auch Moderat die Reste entfernen lassen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Trojaner SupTab u.a. |
31.03.2014, 21:12 | #7 |
| Trojaner SupTab u.a.Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 31.03.2014 Suchlauf-Zeit: 21:38:10 Logdatei: mbam.txt Administrator: Ja Version: 2.00.0.1000 Malware Datenbank: v2014.03.31.08 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: andreas Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 305876 Verstrichene Zeit: 1 Std, 5 Min, 35 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 1 PUP.Optional.WebsSearches.A, C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hp&ts=1396123703&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX");), Ersetzt,[cc342ad67f812cd4869790a89272966a] Physische Sektoren: 0 (No malicious items detected) (end) zunächst mal vielen Dank für die Unterstützung.Ich bin jetzt mit Malware durch, werde jetzt noch adwcleaner laufen lassen. Aktuell beunruhigt mich, dass mein Winpatrol mir anzeigt (nach Malwarebytes Antimalware Durchlauf) dass ein neues Programm sich in das Startup eintragen will: Winlogon:Userinit Soll ich das genehmigen? Schönen Abend und Danke nochmal. Andreas Hier ist das Ergebnis von Adwcleaner: AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.022 - Bericht erstellt am 31/03/2014 um 21:53:17 # Aktualisiert 13/03/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : andreas - ANDREAS-SAMS-PC # Gestartet von : C:\Users\andreas\Downloads\adwcleaner.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v14.0.1 (de) [ Datei : C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default\prefs.js ] [ Datei : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\4xvkcneo.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\preferences ] [ Datei : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [10536 octets] - [30/03/2014 15:50:46] AdwCleaner[R1].txt - [1264 octets] - [30/03/2014 16:53:14] AdwCleaner[R2].txt - [1123 octets] - [31/03/2014 21:53:17] AdwCleaner[S0].txt - [10116 octets] - [30/03/2014 15:54:56] AdwCleaner[S1].txt - [1325 octets] - [30/03/2014 16:55:29] ########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1304 octets] ########## [/CODE] Der Bericht JRT: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.3 (03.23.2014:1) OS: Windows 7 Home Premium x64 Ran by andreas on 31.03.2014 at 21:57:03,59 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APNSetup1_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APNSetup1_RASMANCS ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Folder] "C:\Users\andreas\appdata\local\apn" Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{01F479DE-02E9-419C-BCCE-8EC2DC396856} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{03670469-3B61-47A0-A7E8-D0586E6B7301} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{04AF73CA-F6BF-4F03-9086-C3C6B74C5663} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{0B904789-8EB4-48A9-976E-CC64DAD12AB7} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{0E47285E-E020-46B3-A37E-85C75D6E5438} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{0E700F60-F823-4A4A-9F84-9D9324FC7A0A} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{0FAEDC09-9068-46AE-84EA-F9BF6F474E46} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{11210F71-8032-47DF-889A-004FD6CE5453} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{124BA32D-3BBC-4630-BAD3-38BCFD599014} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{188989FB-9930-4317-A687-66744B994952} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{18DF775B-A32D-4C67-BF9B-E7A124689DC1} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{22BEB94B-B425-499E-BDC6-70923397FB1F} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{269ED8E0-438C-4A5E-96C5-43FC029EBAF7} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{276C6A57-4674-4C2E-9CC4-CEE8FAC721BF} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{2863D2E0-D189-4A04-B63F-E15F754B76B0} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{2AE19B92-1B44-4528-9156-D03735FA8631} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{2B0948EA-7363-43EA-842E-2D70AB531C86} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{30E7BFF1-6EFD-4C79-8CD1-188ED773BC5A} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{31D7D9EF-0EDB-47F5-B174-1743089BC435} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{3680AB0C-8590-495C-96E0-6D74784BDDBF} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{38CEEFA7-30F7-4D9E-B76A-69F9664BFAEA} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{3D3A8D27-0924-4931-B430-8DA3C56A220F} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{3E25A31B-C2D8-4A52-8B32-02C0D15867D8} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{3F9C741E-4F6E-4A00-A846-F4D2007E839F} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{40FDB91F-059D-4463-A3E4-6FD2B9E14983} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{41B4178B-4A1B-424A-B54A-2D2F0B2EB161} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{41F5A304-5037-4798-AEA2-C78D3CFB19EF} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{4349D868-CC6A-4E42-A756-F22A048903CA} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{471E19FA-2841-4C5E-A078-61F8B8FB5A9C} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{4763342B-0B7A-46AE-ADDB-5EED4C350CAD} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{48002ACE-5994-4C12-98E5-4C39802D4EEA} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{4899E682-0447-423E-AD81-4CE30BE76DD6} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{498EEA5A-0DF2-4BAF-BAF1-187D0F1F8342} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{4A9D7DCC-5224-4048-AFFA-04E7461E5162} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{4BE84766-40B6-4E5A-84BC-F1F128859E2A} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{50B4187D-23F4-499C-8691-323FFBF5B292} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5562880D-6844-41E3-8515-AD1B2C47794A} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5799B68A-D29C-477C-8A56-4D79B539A275} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5AB68723-AB79-43FB-937E-9E24795129AB} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5C28E9EE-8A8A-443C-AEC5-4AB149E4B1DB} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5DB5B319-FC09-43F2-B348-2F80D45FF318} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5E7D33CD-F1F2-4272-B07F-4F80676A0744} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5F71D9AE-AADD-49EB-AD8B-2EC71020EC46} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{6199A814-ED34-4A86-A361-455ABF0421FB} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{625616F3-ABC6-46F6-B642-58D073A7F065} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{62DFE49D-630A-482B-B343-96C40545A270} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{67B66530-0487-43DA-8511-87306E05EB20} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{680A577C-4F58-46BD-B046-A1FC2CC33758} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{6A57BC74-8D8F-4493-92D0-F5D2E4EEB33C} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{6C73AB49-8AF0-4437-A753-39BD4ADFD476} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{6E1C2FE5-8DE4-45DB-970C-A9E6268FA254} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{6ECA903B-A1A8-4FB6-A72A-F9FD3BBD08EB} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{7030BB90-E379-4F5F-A798-E0C45DFE21F3} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{7546E5A9-441D-4C60-83A0-B40711D956E7} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{7CB62F16-B93C-49E6-9D30-A81FC53A3BDF} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{7F98F680-84B7-40B8-B3E3-8F057C6A6579} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{81365A5F-7923-439D-980A-39132648EEDC} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{87B892B7-DD00-4D52-8A26-F3FE1D7DA5FC} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{87F8A9DD-A10E-43B6-9DFC-1D180F38950E} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{897FBDC0-4D4C-4543-B78F-BBD805D1197D} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{89D0F8F9-1924-494A-9B94-9F8E7E0FC07F} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{8ED99657-0F43-43FF-9996-3EB163ED0AA1} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{93AFFFE2-37DF-4DBB-AF44-79D3ADE29ED2} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{94722005-CED6-47B6-B990-982D0A546959} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{952BF56B-E63C-4026-A785-892EC1385F80} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{996A1F39-4A2D-4DE7-B798-31425AA4FB52} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{9CA78A19-3928-48E3-980C-FB39B1E95C51} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{9CB59B7C-9B92-4419-94A5-48D78AB1928B} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{9F9539BE-3997-4DF5-B935-47259F2E6AFB} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{A4299913-9E9B-4129-AE2D-029B40B16177} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{A56FD045-4915-4D54-862E-163419D49C5F} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{A87AFF25-6E6F-4B19-8414-A47DAAA9D074} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{A930FD36-CA67-48EA-9D0C-5E37C3831784} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{AB98AA02-4AB3-4FF2-A9F8-E1B8A7122D56} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{AC107F42-D6D0-45B4-BE11-721F30AB49D9} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{ADC36449-04E1-4BE3-9DA6-834DCCEAE55C} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{AE195860-8CD2-4E07-A80B-7924B4B599CB} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{AE4F5D47-0453-4743-9746-25AFB76830BA} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{AF003137-CF2A-403E-AF42-77D421DB8764} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{B26DB251-6FB4-4837-A863-FB17767F38F1} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{B5BBAD17-2C23-4FF5-BE5B-2FCF65C4259C} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{B610AA1C-0D04-4167-AA5D-25B27BCD6EEA} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{B7AEBD40-AEFB-44E3-994C-943BE049C9BF} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{BB4783C5-D0C4-4A50-B178-1A21BC662044} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{BE9ECFBC-9491-4829-B1AA-041425A089BF} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{C0A0C92F-E5A3-4070-8FCA-E55AA1FA32B1} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{C38D11B5-5037-4B82-BEDD-35D27A14F1CE} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{C5A795F9-2DF5-44F4-BA5B-9E4EC17F4AC5} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{C7DEDAF9-0108-4CA4-8C89-44BCBB559EB2} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{CA27D0DA-6F48-4FBA-A2EF-84007A3B2B78} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{CC1E993D-5F3C-4120-A52C-8B9614E18052} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{CF6AF331-84EC-40C8-88A9-6C1263547938} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{D30CDFF0-2D5F-43F3-9B4A-27CAFA5DD99B} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{D63980CA-5704-423F-B9DD-A134B4BD0A9F} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{D9D5FD53-BA5F-4B44-8A6F-94E05AFF5DCF} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{DBD91B71-F1BE-4E29-AFF4-563E9E86109C} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{DF63C20B-0F20-4F77-AD9A-A748A3EF800C} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{DFDB1748-6FE1-486C-AF2D-6993CA235677} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{E0A8433E-9558-4656-9863-96915C576075} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{E499963F-CA3E-4031-AB21-CAC26D395AAD} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{E7C271F8-F2CC-4459-9F8A-C3CD9E5F192D} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{E7FA5B45-0B8F-4364-8281-2BF22DDAC655} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{EC5208C4-A465-4471-8DD8-0DF49418E0F4} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{EDFEAA6C-1266-485A-8661-B2634362E529} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{F03F1AAF-3982-420A-91B0-D48A688DF3F4} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{F171035B-7A0F-412D-9637-2ECA506E3355} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{F1A1D697-C01F-428F-A38E-6BAAE1085117} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{F47AE261-FD18-4E84-AD26-A246C9B8421D} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{F8461A33-C917-4C9B-B1C5-600D99F9FCF9} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{FCD557BA-03FF-4980-9BB7-8A7016098351} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{FD118B8E-3D2E-41A6-8DA8-5DBFC16CE81B} Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{FDEA7313-EB96-439A-AAB5-6E745DA34066} ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 31.03.2014 at 22:05:53,21 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by andreas (administrator) on ANDREAS-SAMS-PC on 31-03-2014 22:10:48 Running from C:\Users\andreas\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe (Arainia Solutions) C:\Program Files (x86)\Gizmo\gservice.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (PcWinTech.com) C:\Program Files (x86)\CleanMem\mini_monitor.exe (Auslogics) C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel_64.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE (Mister Group) C:\Program Files (x86)\System Explorer\SystemExplorer.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Mister Group) C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Copernic, a division of N. Harris Copernic Systems) C:\Program Files (x86)\Copernic\DesktopSearch4\Copernic.DesktopSearch.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (Arainia Solutions) C:\Program Files (x86)\Gizmo\gizmo.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Dropbox, Inc.) C:\Users\andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\netzmanager.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Mindjet) C:\Program Files (x86)\Mindjet\MindManager 6\MmReminderService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\system32\taskmgr.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11660904 2010-12-01] (Realtek Semiconductor) HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2782096 2010-07-26] (CANON INC.) HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2817872 2012-04-25] (ELAN Microelectronics Corp.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [400480 2012-01-30] (BillP Studios) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [MMReminderService] - C:\Program Files (x86)\Mindjet\MindManager 6\MMReminderService.exe [31232 2006-12-14] (Mindjet) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Google Update] - C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-05-13] (Google Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563608 2014-01-15] (SUPERAntiSpyware) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [SystemExplorerAutoStart] - C:\Program Files (x86)\System Explorer\SystemExplorer.exe [2750936 2012-09-03] (Mister Group) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [B0D7A430849FA67EEA71A56253A48520238199B4._service_run] - C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Facebook Update] - "C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Copernic Desktop Search 4] - C:\Program Files (x86)\Copernic\DesktopSearch4\Copernic.DesktopSearch.exe [1568832 2014-02-25] (Copernic, a division of N. Harris Copernic Systems) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GoogleChromeAutoLaunch_1DDDD6B09271C2EB3C06CC9B1731B636] - C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GizmoDriveDelegate] - C:\Program Files (x86)\Gizmo\gizmo.exe [223640 2011-09-14] (Arainia Solutions) HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\MountPoints2: {131db821-f56a-11e0-8ea6-e811322169d9} - F:\NokiaPCIA_Autorun.exe HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] - C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-05-13] (Google Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563608 2014-01-15] (SUPERAntiSpyware) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SystemExplorerAutoStart] - C:\Program Files (x86)\System Explorer\SystemExplorer.exe [2750936 2012-09-03] (Mister Group) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [B0D7A430849FA67EEA71A56253A48520238199B4._service_run] - C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Facebook Update] - "C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Copernic Desktop Search 4] - C:\Program Files (x86)\Copernic\DesktopSearch4\Copernic.DesktopSearch.exe [1568832 2014-02-25] (Copernic, a division of N. Harris Copernic Systems) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleChromeAutoLaunch_1DDDD6B09271C2EB3C06CC9B1731B636] - C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GizmoDriveDelegate] - C:\Program Files (x86)\Gizmo\gizmo.exe [223640 2011-09-14] (Arainia Solutions) HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {131db821-f56a-11e0-8ea6-e811322169d9} - F:\NokiaPCIA_Autorun.exe HKU\S-1-5-21-1290605139-235724718-708133086-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [Google Update] - C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-05-16] (Google Inc.) HKU\S-1-5-21-1290605139-235724718-708133086-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [GizmoDriveDelegate] - C:\Program Files (x86)\Gizmo\gizmo.exe [223640 2011-09-14] (Arainia Solutions) AppInit_DLLs: C:\PROGRA~2\SupTab\SearchProtect64.dll => C:\PROGRA~2\SupTab\SearchProtect64.dll File Not Found Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled () Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG) Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3324790&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=58&CUI=&UM=5&UP=SPD64F7ECC-B1EB-4DD1-8B2B-FE27A7C23C95&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: W2PBrowser Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - C:\Program Files (x86)\Mindjet\MindManager 6\Mm6InternetExplorer.dll (Mindjet) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {4D594333-0076-A76A-76A7-7A786E7484D7} - No File Toolbar: HKCU - No Name - {4D594333-2D53-4154-00A7-7A786E7484D7} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default FF NewTab: hxxp://istart.webssearches.com/newtab/?type=nt&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX FF SelectedSearchEngine: webssearches FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @octoshape.com/Octoshape Streaming Services,version=1.0 - C:\Users\andreas\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\andreas\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\andreas\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\andreas\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\webssearches.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: TinEye Reverse Image Search - C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default\Extensions\tineye@ideeinc.com.xpi [2011-09-22] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-20] FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-05-23] FF HKCU\...\Firefox\Extensions: [{b9aa91db-385d-4c69-8a2f-96790aa9405b}] - c:\program files (x86)\copernic\desktopsearch4\firefoxconnector FF Extension: Copernic Desktop Search - Search Firefox content - c:\program files (x86)\copernic\desktopsearch4\firefoxconnector [2013-08-31] FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR Extension: (Google Docs) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-30] CHR Extension: (Google Drive) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-30] CHR Extension: (YouTube) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-30] CHR Extension: (Copernic Desktop Search Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnnbdaahphjgdgfhliignpepgnbnfomp [2014-03-30] CHR Extension: (Google-Suche) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-30] CHR Extension: (Gmail offline) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2014-03-30] CHR Extension: (Zotero Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekhagklcjbdpajgpjgmbionohlpdbjgc [2014-03-30] CHR Extension: (Highlight to Search) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\floipahigmmkfhkoapmnijnlnboniglg [2014-03-30] CHR Extension: (TinEye Reverse Image Search) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2014-03-30] CHR Extension: (WEB.DE MailCheck) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo [2014-03-30] CHR Extension: (Hipmunk) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeabbdefhlelidlhahnfpbllaomkioke [2014-03-30] CHR Extension: (Social Network Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jijghdpcfakjjecmadmkembnmmpojdfo [2014-03-30] CHR Extension: (Klout (beta)) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjaakbhpcbpmojkhpiaacepfcaniglak [2014-03-30] CHR Extension: (Webcam Toy) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2014-03-30] CHR Extension: (fIRST lOVE) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lighpcanjnomdcjmfficdanifpdmgmhp [2014-03-30] CHR Extension: (Google Maps) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-03-30] CHR Extension: (Google Wallet) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2014-03-30] CHR Extension: (Buffer) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\noojglkidnpfjbincgijbaiedldjfbhh [2014-03-30] CHR Extension: (Picasa) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-03-30] CHR Extension: (Google Mail) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-30] CHR HKCU\...\Chrome\Extension: [cnnbdaahphjgdgfhliignpepgnbnfomp] - c:\program files (x86)\copernic\desktopsearch4\ChromeConnector\ChromeConnector.crx [2014-02-25] CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-05-06] CHR StartMenuInternet: Google Chrome - Chrome.exe ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-09-14] (SUPERAntiSpyware.com) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 CTDevice_Srv; C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe [61440 2007-04-02] (Creative Technology Ltd) S3 CTUPnPSv; C:\Program Files (x86)\Creative\Creative Centrale\CTUPnPSv.exe [64000 2008-05-21] (Creative Technology Ltd) S4 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe [544768 2009-08-24] (mst software GmbH, Germany) R2 Gizmo Central; C:\Program Files (x86)\Gizmo\gservice.exe [34728 2011-09-14] (Arainia Solutions) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-08-21] (Mister Group) ==================== Drivers (Whitelisted) ==================== S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) R1 GizmoDrv; C:\Windows\System32\Drivers\GizmoDrv.sys [34704 2011-09-14] (Arainia Solutions LLC) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) S4 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2012-01-18] () S4 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2012-01-18] () S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [66704 2013-09-09] (Fuzhou Rockchip Electronics Co,Ltd.) S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2011-02-14] (Windows (R) 2003 DDK 3790 provider) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-31 22:05 - 2014-03-31 22:05 - 00013364 _____ () C:\Users\andreas\Desktop\JRT.txt 2014-03-31 21:56 - 2014-03-31 21:56 - 01038974 _____ (Thisisu) C:\Users\andreas\Downloads\JRT.exe 2014-03-31 21:56 - 2014-03-31 21:56 - 00000000 ____D () C:\Windows\ERUNT 2014-03-31 21:51 - 2014-03-31 21:51 - 00013391 _____ () C:\Users\andreas\Desktop\adwcleaner - Verknüpfung.lnk 2014-03-31 21:47 - 2014-03-31 21:52 - 00000000 ____D () C:\ProgramData\SecTaskMan 2014-03-31 21:47 - 2014-03-31 21:47 - 00000000 ____D () C:\Program Files (x86)\Security Task Manager 2014-03-31 21:46 - 2014-03-31 21:46 - 02365840 _____ () C:\Users\andreas\Downloads\SecurityTaskManager_Setup.exe 2014-03-31 21:40 - 2014-03-31 21:40 - 00001462 _____ () C:\Users\andreas\Desktop\mbam.txt 2014-03-31 20:39 - 2014-03-31 20:40 - 00008210 _____ () C:\Users\andreas\Downloads\contact_list.php 2014-03-30 17:16 - 2014-03-30 17:16 - 00070081 _____ () C:\Users\andreas\Desktop\Addition.txt 2014-03-30 17:15 - 2014-03-30 17:15 - 00061530 _____ () C:\Users\andreas\Desktop\FRST Scan Result.txt 2014-03-30 17:08 - 2014-03-30 17:11 - 00070081 _____ () C:\Users\andreas\Downloads\Addition.txt 2014-03-30 17:06 - 2014-03-31 22:10 - 00032873 _____ () C:\Users\andreas\Downloads\FRST.txt 2014-03-30 17:05 - 2014-03-31 22:10 - 00000000 ____D () C:\FRST 2014-03-30 17:05 - 2014-03-30 17:05 - 02157056 _____ (Farbar) C:\Users\andreas\Downloads\FRST64.exe 2014-03-30 17:04 - 2014-03-30 17:04 - 01145856 _____ (Farbar) C:\Users\andreas\Downloads\FRST.exe 2014-03-30 15:50 - 2014-03-31 21:53 - 00000000 ____D () C:\AdwCleaner 2014-03-30 15:50 - 2014-03-30 15:50 - 01950720 _____ () C:\Users\andreas\Downloads\adwcleaner.exe 2014-03-30 15:48 - 2014-03-30 15:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Downloads\revosetup95.exe 2014-03-30 15:48 - 2014-03-30 15:48 - 00001238 _____ () C:\Users\andreas\Desktop\Revo Uninstaller.lnk 2014-03-30 15:47 - 2014-03-31 20:32 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-30 15:46 - 2014-03-30 15:46 - 00001078 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-30 15:46 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-30 15:46 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-30 15:46 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-30 15:45 - 2014-03-30 15:46 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\andreas\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-30 01:06 - 2014-03-30 01:06 - 49940480 _____ () C:\Program Files (x86)\GUT1321.tmp 2014-03-30 01:06 - 2014-03-30 01:06 - 00000000 ____D () C:\Program Files (x86)\GUM1320.tmp 2014-03-30 00:56 - 2014-03-30 00:56 - 00003144 _____ () C:\Windows\System32\Tasks\{203A3670-6A66-495F-B4A0-4907C6887A94} 2014-03-30 00:37 - 2014-03-30 00:44 - 00000643 _____ () C:\Windows\wininit.ini 2014-03-30 00:22 - 2014-03-30 00:22 - 00000000 ____D () C:\Users\andreas\AppData\Local\PDF Writer 2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\PDF Writer 2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\ProgramData\PDF Writer 2014-03-30 00:20 - 2013-07-13 12:15 - 00805376 _____ () C:\Windows\SysWOW64\EditCtlsU.ocx 2014-03-30 00:20 - 2013-07-12 22:57 - 00539648 _____ () C:\Windows\SysWOW64\LblCtlsU.ocx 2014-03-30 00:20 - 2013-04-05 13:55 - 00476160 _____ () C:\Windows\SysWOW64\TabStripCtlU.ocx 2014-03-30 00:20 - 2013-03-03 14:37 - 01061888 _____ () C:\Windows\SysWOW64\ExLvwU.ocx 2014-03-30 00:19 - 2013-09-01 12:59 - 01103872 _____ () C:\Windows\SysWOW64\CBLCtlsU.ocx 2014-03-30 00:19 - 2013-03-28 23:13 - 00645632 _____ () C:\Windows\SysWOW64\BtnCtlsU.ocx 2014-03-30 00:18 - 2014-03-30 00:18 - 08198048 _____ (Bullzip ) C:\Users\andreas\Downloads\Setup_BullzipPDFPrinter_10_4_0_2240_STD.exe 2014-03-29 22:10 - 2014-03-29 22:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-03-29 22:09 - 2014-03-30 00:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-03-29 22:09 - 2014-03-29 22:12 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-03-29 22:09 - 2014-03-29 22:09 - 00001357 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-03-29 22:09 - 2013-09-20 11:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2014-03-29 22:08 - 2014-03-29 22:08 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\spybot-2.2.exe 2014-03-29 22:06 - 2014-03-30 00:59 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Activeris 2014-03-29 22:04 - 2014-03-29 22:05 - 19425127 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\Nicht bestätigt 322160.crdownload 2014-03-29 21:51 - 2014-03-29 21:51 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\dlg 2014-03-29 21:50 - 2014-03-30 00:57 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-29 21:50 - 2014-03-29 21:51 - 00000000 ____D () C:\Program Files (x86)\Jpg2Pdf 2014-03-29 21:49 - 2014-03-29 21:49 - 00001065 _____ () C:\Users\Public\Desktop\7-PDF Maker.lnk 2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\7-PDFMaker 2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Program Files (x86)\7-PDF 2014-03-29 21:45 - 2014-03-29 21:46 - 55633177 _____ (7-PDF, Germany ) C:\Users\andreas\Downloads\7p141.exe 2014-03-29 21:43 - 2014-03-29 21:43 - 00930952 _____ (CNET Download.com) C:\Users\andreas\Downloads\cbsidlm-cbsi183-Free_JPG_to_PDF-ORG-75732662.exe 2014-03-27 23:21 - 2014-03-27 23:21 - 00000000 ____D () C:\Users\andreas\AppData\Local\Skype 2014-03-27 23:20 - 2014-03-27 23:20 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-27 22:54 - 2014-03-27 22:54 - 00476024 _____ (1&1 Mail & Media GmbH) C:\Users\andreas\Downloads\WEB.DE_MailCheck_chrome_setup (2).exe 2014-03-15 09:17 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-15 09:17 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-15 09:17 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-15 09:17 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-15 09:17 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-15 09:17 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-15 09:17 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-15 09:17 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-15 09:17 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-15 09:17 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-15 09:17 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-15 09:17 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-15 09:17 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-15 09:17 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-15 09:17 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-15 09:17 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-15 09:17 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-15 09:17 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-15 09:17 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-15 09:17 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-15 09:17 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-15 09:17 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-15 09:17 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-15 09:17 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-15 09:17 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-15 09:17 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-15 09:17 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-15 09:17 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-15 09:17 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-15 09:17 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-15 09:17 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-15 09:17 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-15 09:17 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-15 09:17 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-15 09:17 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-15 09:17 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-15 09:17 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-15 09:17 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-15 09:17 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-15 09:17 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-15 09:17 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-15 09:17 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-15 09:17 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-15 09:17 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-15 09:17 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-15 09:17 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-15 09:17 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-15 09:17 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-11 22:07 - 2014-03-11 22:07 - 04550656 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr 2014-03-01 14:26 - 2014-03-01 14:26 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 14:00 - 2014-03-01 14:16 - 00000000 ____D () C:\ff602098354a13baca66adf688cd6c8a 2014-03-01 13:58 - 2014-03-01 13:58 - 00000000 ____D () C:\Program Files (x86)\QuickTime ==================== One Month Modified Files and Folders ======= 2014-03-31 22:11 - 2014-03-30 17:06 - 00032873 _____ () C:\Users\andreas\Downloads\FRST.txt 2014-03-31 22:10 - 2014-03-30 17:05 - 00000000 ____D () C:\FRST 2014-03-31 22:08 - 2012-05-08 00:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-31 22:06 - 2011-05-13 17:36 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job 2014-03-31 22:05 - 2014-03-31 22:05 - 00013364 _____ () C:\Users\andreas\Desktop\JRT.txt 2014-03-31 21:56 - 2014-03-31 21:56 - 01038974 _____ (Thisisu) C:\Users\andreas\Downloads\JRT.exe 2014-03-31 21:56 - 2014-03-31 21:56 - 00000000 ____D () C:\Windows\ERUNT 2014-03-31 21:53 - 2014-03-30 15:50 - 00000000 ____D () C:\AdwCleaner 2014-03-31 21:52 - 2014-03-31 21:47 - 00000000 ____D () C:\ProgramData\SecTaskMan 2014-03-31 21:51 - 2014-03-31 21:51 - 00013391 _____ () C:\Users\andreas\Desktop\adwcleaner - Verknüpfung.lnk 2014-03-31 21:47 - 2014-03-31 21:47 - 00000000 ____D () C:\Program Files (x86)\Security Task Manager 2014-03-31 21:46 - 2014-03-31 21:46 - 02365840 _____ () C:\Users\andreas\Downloads\SecurityTaskManager_Setup.exe 2014-03-31 21:40 - 2014-03-31 21:40 - 00001462 _____ () C:\Users\andreas\Desktop\mbam.txt 2014-03-31 21:19 - 2012-05-16 19:55 - 00001152 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500UA.job 2014-03-31 21:17 - 2011-05-21 22:56 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-31 21:06 - 2011-05-13 17:36 - 00001076 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job 2014-03-31 20:40 - 2014-03-31 20:39 - 00008210 _____ () C:\Users\andreas\Downloads\contact_list.php 2014-03-31 20:32 - 2014-03-30 15:47 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-31 20:12 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-31 20:12 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-31 20:09 - 2011-09-22 19:16 - 00000000 ____D () C:\Users\andreas\Videos\Documents\Outlook-Dateien 2014-03-31 20:08 - 2010-12-17 23:29 - 02036827 _____ () C:\Windows\WindowsUpdate.log 2014-03-31 20:02 - 2012-04-12 19:52 - 00001146 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job 2014-03-31 19:46 - 2013-10-03 13:29 - 00000000 ____D () C:\Users\andreas\AppData\Local\E2BABF81-CECF-40E0-A839-5CA03E1839C9.aplzod 2014-03-31 19:42 - 2011-11-08 22:04 - 00000000 ___RD () C:\Users\andreas\Dropbox 2014-03-31 19:42 - 2011-11-08 22:00 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Dropbox 2014-03-31 19:41 - 2013-02-12 16:12 - 00000000 ___RD () C:\Users\andreas\Google Drive 2014-03-31 19:38 - 2012-02-09 01:07 - 00000330 _____ () C:\Windows\Tasks\GlaryInitialize.job 2014-03-31 19:38 - 2011-05-21 22:56 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-31 19:38 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-31 19:37 - 2011-06-05 14:26 - 00051959 _____ () C:\Windows\setupact.log 2014-03-30 22:25 - 2011-06-23 11:30 - 00509628 _____ () C:\Windows\PFRO.log 2014-03-30 22:15 - 2012-06-19 23:25 - 00000000 ____D () C:\Windows\sk 2014-03-30 17:16 - 2014-03-30 17:16 - 00070081 _____ () C:\Users\andreas\Desktop\Addition.txt 2014-03-30 17:15 - 2014-03-30 17:15 - 00061530 _____ () C:\Users\andreas\Desktop\FRST Scan Result.txt 2014-03-30 17:11 - 2014-03-30 17:08 - 00070081 _____ () C:\Users\andreas\Downloads\Addition.txt 2014-03-30 17:05 - 2014-03-30 17:05 - 02157056 _____ (Farbar) C:\Users\andreas\Downloads\FRST64.exe 2014-03-30 17:05 - 2010-12-17 23:56 - 00703176 _____ () C:\Windows\system32\perfh007.dat 2014-03-30 17:05 - 2010-12-17 23:56 - 00150784 _____ () C:\Windows\system32\perfc007.dat 2014-03-30 17:05 - 2009-07-14 07:13 - 01629212 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-30 17:04 - 2014-03-30 17:04 - 01145856 _____ (Farbar) C:\Users\andreas\Downloads\FRST.exe 2014-03-30 16:51 - 2011-05-13 17:39 - 00002450 _____ () C:\Users\andreas\Desktop\Google Chrome.lnk 2014-03-30 15:50 - 2014-03-30 15:50 - 01950720 _____ () C:\Users\andreas\Downloads\adwcleaner.exe 2014-03-30 15:48 - 2014-03-30 15:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Downloads\revosetup95.exe 2014-03-30 15:48 - 2014-03-30 15:48 - 00001238 _____ () C:\Users\andreas\Desktop\Revo Uninstaller.lnk 2014-03-30 15:48 - 2011-05-13 19:19 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-03-30 15:46 - 2014-03-30 15:46 - 00001078 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-30 15:46 - 2014-03-30 15:45 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\andreas\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-30 01:06 - 2014-03-30 01:06 - 49940480 _____ () C:\Program Files (x86)\GUT1321.tmp 2014-03-30 01:06 - 2014-03-30 01:06 - 00000000 ____D () C:\Program Files (x86)\GUM1320.tmp 2014-03-30 01:06 - 2011-12-27 12:05 - 00008224 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-30 01:05 - 2012-07-12 09:30 - 00000000 ___RD () C:\Users\Administrator\Podcasts 2014-03-30 01:05 - 2012-05-16 19:55 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-03-30 01:05 - 2011-12-27 12:05 - 00001417 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-03-30 01:05 - 2011-12-27 12:05 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-30 01:05 - 2011-12-27 12:05 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-30 01:02 - 2011-05-13 19:01 - 00000000 ____D () C:\Users\andreas\Desktop\weniger genutzte software 2014-03-30 00:59 - 2014-03-29 22:06 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Activeris 2014-03-30 00:57 - 2014-03-29 21:50 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-30 00:57 - 2011-05-13 11:23 - 00001421 _____ () C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-03-30 00:56 - 2014-03-30 00:56 - 00003144 _____ () C:\Windows\System32\Tasks\{203A3670-6A66-495F-B4A0-4907C6887A94} 2014-03-30 00:44 - 2014-03-30 00:37 - 00000643 _____ () C:\Windows\wininit.ini 2014-03-30 00:35 - 2014-03-29 22:09 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-03-30 00:22 - 2014-03-30 00:22 - 00000000 ____D () C:\Users\andreas\AppData\Local\PDF Writer 2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\PDF Writer 2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\ProgramData\PDF Writer 2014-03-30 00:18 - 2014-03-30 00:18 - 08198048 _____ (Bullzip ) C:\Users\andreas\Downloads\Setup_BullzipPDFPrinter_10_4_0_2240_STD.exe 2014-03-29 22:38 - 2011-06-05 17:37 - 00000000 ____D () C:\Users\andreas\AppData\Local\CrashDumps 2014-03-29 22:12 - 2014-03-29 22:09 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-03-29 22:10 - 2014-03-29 22:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-03-29 22:09 - 2014-03-29 22:09 - 00001357 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-03-29 22:08 - 2014-03-29 22:08 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\spybot-2.2.exe 2014-03-29 22:06 - 2011-09-20 22:05 - 00001332 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-29 22:05 - 2014-03-29 22:04 - 19425127 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\Nicht bestätigt 322160.crdownload 2014-03-29 21:51 - 2014-03-29 21:51 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\dlg 2014-03-29 21:51 - 2014-03-29 21:50 - 00000000 ____D () C:\Program Files (x86)\Jpg2Pdf 2014-03-29 21:50 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-03-29 21:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-03-29 21:49 - 2014-03-29 21:49 - 00001065 _____ () C:\Users\Public\Desktop\7-PDF Maker.lnk 2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\7-PDFMaker 2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Program Files (x86)\7-PDF 2014-03-29 21:48 - 2011-05-13 11:23 - 00000000 ___RD () C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-29 21:46 - 2014-03-29 21:45 - 55633177 _____ (7-PDF, Germany ) C:\Users\andreas\Downloads\7p141.exe 2014-03-29 21:43 - 2014-03-29 21:43 - 00930952 _____ (CNET Download.com) C:\Users\andreas\Downloads\cbsidlm-cbsi183-Free_JPG_to_PDF-ORG-75732662.exe 2014-03-29 16:35 - 2012-05-16 19:55 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500Core.job 2014-03-29 16:35 - 2012-04-12 19:52 - 00001124 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job 2014-03-27 23:56 - 2014-01-01 20:55 - 00001026 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-03-27 23:55 - 2011-05-23 21:57 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\vlc 2014-03-27 23:37 - 2011-10-09 22:18 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Skype 2014-03-27 23:21 - 2014-03-27 23:21 - 00000000 ____D () C:\Users\andreas\AppData\Local\Skype 2014-03-27 23:21 - 2011-05-13 11:21 - 00000000 ____D () C:\ProgramData\Skype 2014-03-27 23:20 - 2014-03-27 23:20 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-27 22:54 - 2014-03-27 22:54 - 00476024 _____ (1&1 Mail & Media GmbH) C:\Users\andreas\Downloads\WEB.DE_MailCheck_chrome_setup (2).exe 2014-03-26 22:18 - 2011-06-14 19:06 - 00000000 ____D () C:\Users\andreas\Videos\Documents\Youcam 2014-03-21 15:59 - 2011-09-15 02:51 - 00147456 _____ (Bullzip) C:\Windows\SysWOW64\bzpdfc.dll 2014-03-19 20:38 - 2013-08-15 10:24 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-19 20:36 - 2011-05-13 16:38 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-19 19:13 - 2009-07-14 06:45 - 00459824 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-19 19:11 - 2013-03-13 10:05 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-19 19:11 - 2013-03-13 10:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-15 10:36 - 2011-09-14 21:22 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-03-15 10:08 - 2012-05-08 00:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-15 10:08 - 2012-05-08 00:40 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-15 10:08 - 2011-08-22 23:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-11 22:07 - 2014-03-11 22:07 - 04550656 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr 2014-03-10 22:52 - 2011-11-07 09:32 - 01603492 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-03-05 09:26 - 2014-03-30 15:46 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-05 09:26 - 2014-03-30 15:46 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-05 09:26 - 2014-03-30 15:46 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-01 14:26 - 2014-03-01 14:26 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 14:16 - 2014-03-01 14:00 - 00000000 ____D () C:\ff602098354a13baca66adf688cd6c8a 2014-03-01 13:58 - 2014-03-01 13:58 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-03-01 08:05 - 2014-03-15 09:17 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 07:17 - 2014-03-15 09:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 07:16 - 2014-03-15 09:17 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 06:58 - 2014-03-15 09:17 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 06:52 - 2014-03-15 09:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 06:51 - 2014-03-15 09:17 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 06:42 - 2014-03-15 09:17 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 06:40 - 2014-03-15 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 06:37 - 2014-03-15 09:17 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 06:33 - 2014-03-15 09:17 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 06:33 - 2014-03-15 09:17 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 06:32 - 2014-03-15 09:17 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 06:30 - 2014-03-15 09:17 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 06:23 - 2014-03-15 09:17 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 06:17 - 2014-03-15 09:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 06:11 - 2014-03-15 09:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 06:02 - 2014-03-15 09:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 05:54 - 2014-03-15 09:17 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 05:52 - 2014-03-15 09:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 05:51 - 2014-03-15 09:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 05:47 - 2014-03-15 09:17 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 05:43 - 2014-03-15 09:17 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 05:43 - 2014-03-15 09:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 05:42 - 2014-03-15 09:17 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 05:40 - 2014-03-15 09:17 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 05:38 - 2014-03-15 09:17 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 05:37 - 2014-03-15 09:17 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 05:35 - 2014-03-15 09:17 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 05:18 - 2014-03-15 09:17 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 05:16 - 2014-03-15 09:17 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 05:14 - 2014-03-15 09:17 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 05:10 - 2014-03-15 09:17 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 05:03 - 2014-03-15 09:17 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 05:00 - 2014-03-15 09:17 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 04:57 - 2014-03-15 09:17 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 04:38 - 2014-03-15 09:17 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 04:32 - 2014-03-15 09:17 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 04:27 - 2014-03-15 09:17 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 04:25 - 2014-03-15 09:17 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 04:25 - 2014-03-15 09:17 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Some content of TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\avgnt.exe C:\Users\Administrator\AppData\Local\Temp\DivXSetup.exe C:\Users\Administrator\AppData\Local\Temp\MSN9A3E.exe C:\Users\andreas\AppData\Local\Temp\avgnt.exe C:\Users\andreas\AppData\Local\Temp\ose00000.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-20 19:35 ==================== End Of Log ============================ --- --- --- |
01.04.2014, 12:42 | #8 |
/// the machine /// TB-Ausbilder | Trojaner SupTab u.a.ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Trojaner SupTab u.a. |
auskennt, dateien, download, jpg, laufe, laufen, problem, suptab, troja, trojaner, vermutlich, verrückte |